VeraxConsole
← All vendors

Figma AI

low risk

Generative AI Design Toolsfigma.comverified 2024-05-22

Data-handling profile

Trains on input
No — does not train on customer inputs
Retention
Content is stored as long as the account is active or until deleted by the user; for enterprise, specific data retention policies can be configured via admin controls.
Data region
United States (primary), with options for enterprise data residency in specific regions (e.g., AWS regions)
Certifications
SOC 2 Type IISOC 3ISO/IEC 27001ISO/IEC 27018ISO/IEC 27017FedRAMP (Authorized at Moderate Impact Level)
DPA available
Yes
Breach history
No major public data breaches linked to AI-specific features; Figma has maintained a clean record regarding unauthorized access to user-generated AI content.
EU AI Act
Figma is actively monitoring the EU AI Act; as a provider of generative AI features, they are implementing transparency measures and risk assessment documentation to comply with future requirements.

Sources

Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.

Watch this vendor

Get an email the day Figma AI changes what it does with your data. Your address is never shown publicly or shared.

Change history

No material changes recorded since monitoring began.