Compliance frameworks, security audits, and quality certifications this company maintains.
Annual security audit covering Figma cloud platform, file storage, and real-time collaboration infrastructure.
Information security management certification for Figma global operations and cloud infrastructure.
EU data protection compliance enabling Figma to serve European teams with appropriate data residency and DPA agreements.
California Consumer Privacy Act compliance for Figma user data handling and privacy rights.
Figma maintains PCI DSS Level 1 certification for its billing and payment infrastructure, ensuring that credit card data from Figma Professional, Organization, and Enterprise subscribers is handled with the highest level of payment security.
Figma complies with the California Privacy Rights Act, providing California-based designers and enterprise customers rights to access, correct, and delete their personal data collected through the Figma platform and FigJam.
Figma supports HIPAA-compliant workflows for healthcare enterprise customers using Figma for design collaboration, providing Business Associate Agreements to organizations that handle protected health information in their design processes.
Figma's web and desktop applications are designed to meet WCAG 2.1 Level AA accessibility standards, and Figma provides accessibility annotation toolkits to help designers build accessible products for their own users.
Figma is pursuing FedRAMP authorization to expand its design collaboration platform into US federal government agency workflows, enabling secure use of Figma in classified and sensitive government design projects.
Figma holds CSA STAR Level 1 certification, demonstrating transparency in its cloud security practices and controls for enterprise customers evaluating the security of the Figma design collaboration platform.