figma

Keeping your data in Figma safe and secure: SOC 2 Type 2, SSO, and more | Figma Blog (opens in new tab)

Figma presents security as a core part of its infrastructure and product development, emphasizing protection of customer data and design intellectual property. Its efforts include SOC 2 certification, privacy compliance for European customers, secure plugin architecture, and enterprise SAML single sign-on. An update later confirmed that Figma completed SOC 2 Type 2 certification and obtained a SOC 3 report.

SOC 2 Certification

  • Figma initially achieved SOC 2 Type 1 certification after auditing its infrastructure, software, HR processes, and customer-data policies.
  • Type 1 evaluates controls at a specific point in time.
  • Type 2 provides stronger assurance by examining whether those controls operate effectively over an extended period.
  • By January 2020, Figma had completed SOC 2 Type 2 certification and secured a publicly downloadable SOC 3 report.

European Data Protection

  • Figma highlights its readiness for growing European usage.
  • It complies with relevant data-protection requirements and was certified under:
    • The EU–U.S. Privacy Shield Framework
    • The Swiss–U.S. Privacy Shield Framework

Security-First Product Development

  • Security is considered during the design of new features, not added afterward.
  • Figma’s plugin system deliberately limits access:
    • A plugin can access only one design file at a time.
    • Plugins cannot access a user’s entire account.
    • Plugins are isolated from one another’s data.
    • Plugins cannot modify Figma’s user interface, reducing phishing and user-misdirection risks.
  • These restrictions sometimes reduced available capabilities, but Figma prioritized security, stability, and performance.

SAML Single Sign-On

  • SAML integrations help organizations deploy Figma securely and manage user access centrally.
  • Figma supported Okta and Microsoft Azure Active Directory, and added OneLogin.
  • Enterprise administrators can simplify authentication while maintaining organizational access controls.

Figma’s overall approach is to combine independent compliance audits, privacy frameworks, careful product architecture, and centralized enterprise authentication. Organizations evaluating Figma should review its security and privacy documentation and consider enterprise SSO controls for managing access.