Figma AI
low riskGenerative AI Design Toolsfigma.comverified 2024-05-22
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Content is stored as long as the account is active or until deleted by the user; for enterprise, specific data retention policies can be configured via admin controls.
- Data region
- United States (primary), with options for enterprise data residency in specific regions (e.g., AWS regions)
- Certifications
- SOC 2 Type IISOC 3ISO/IEC 27001ISO/IEC 27018ISO/IEC 27017FedRAMP (Authorized at Moderate Impact Level)
- DPA available
- Yes
- Breach history
- No major public data breaches linked to AI-specific features; Figma has maintained a clean record regarding unauthorized access to user-generated AI content.
- EU AI Act
- Figma is actively monitoring the EU AI Act; as a provider of generative AI features, they are implementing transparency measures and risk assessment documentation to comply with future requirements.
Sources
- https://help.figma.com/hc/en-us/articles/17725942479127
- https://www.figma.com/trust/
- https://www.figma.com/legal/privacy/
- https://help.figma.com/hc/en-us/articles/21325608674967-Figma-AI-FAQ
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.