VendorScore · Design · Data-access posture

Can Figma read your design files?

A plain-language answer from Figma's public Security, Help Center and legal pages. EKM covers file checkpoints and uploaded media; Figma still decrypts files to render and collaborate on them.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, Figma can read your design files by design (with controls). EKM encrypts file checkpoints and uploaded media with your AWS KMS key, but metadata, comments and component definitions stay on Figma keys, and Figma decrypts files to render them.

59 / 100 overall

Scored configuration: Figma Enterprise with the Governance+ add-on, including Enterprise Key Management (EKM) on AWS KMS.

Default (no Governance+/EKM): Figma-managed keys; the report estimates Overall ~54.

Report confidence: Medium. Staff-access detail comes from an older SOC 3 report (Nov 2021–Oct 2022).

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Figma's public documentation:

  • Staff-access evidence comes from a 2021–22 SOC 3 report; Figma's current procedure is Unknown without the current SOC 2.
  • A specific EU hosting region isn't stated in the pages we read.
  • Figma AI and Figma Weave route prompts and content to many model vendors when used.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Figma data access, AI training, GDPR and residency

Can Figma read your design files?

Yes, Figma can read your design files by design (with controls). EKM encrypts file checkpoints and uploaded media with your AWS KMS key, but metadata, comments and component definitions stay on Figma keys, and Figma decrypts files to render them. VendorScore rates Figma 59/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Figma Enterprise with the Governance+ add-on, including Enterprise Key Management (EKM) on AWS KMS.

Is Figma data encrypted at rest? What does Figma EKM cover?

Figma's SOC 3 report says customer data is encrypted at rest with AES-256 and in transit with TLS. With Governance+ on Enterprise, EKM encrypts file checkpoints (shapes, text, frames, layers) and uploaded images and videos with your own AWS KMS key, and "you can grant, monitor, and revoke Figma's access to the encryption key at any time." Metadata, comments and component definitions stored in databases stay on Figma keys, and Figma "doesn't fully support offboarding from EKM". It's not E2EE: Figma decrypts files to render them.

Can Figma employees see my files?

Figma's older SOC 3 report (period Nov 2021–Oct 2022) says its admin console "only provides access to meta-data" and that "Customers must explicitly invite employees to access their design files." It adds that a limited number of senior engineers can download files through the admin console upon customer consent, with actions logged in a support ticket. We didn't find this on Figma's current pages, so the current procedure is Unknown.

Does Figma train AI on my designs?

It depends on your plan. Figma's AI Terms say: "When 'Content Training' is toggled on within Customer's administrative user settings, Figma may use Customer Content to maintain, improve, and enhance Figma's products and services by training machine learning and artificial intelligence algorithms and models." Content training is on by default for Starter and Professional teams, and admins can turn it off. On Organization and Enterprise plans it's off and can't be toggled on.

Is Figma GDPR compliant? Where is the Figma DPA?

VendorScore doesn't certify compliance; Figma publishes a DPA at https://www.figma.com/legal/dpa/. The DPA says new subprocessors are added to the list at least 15 days before they process Customer Content, with a right to object.

Who are Figma's subprocessors, and do AI vendors see my files?

Figma's list (last updated September 22, 2026) names Datadog, Sentry and Snowflake for all services with Customer Content, and Cloudflare for image and video content. Figma AI uses Anthropic, AWS, Cerebras, Fireworks, Google Vertex, Jasper, Microsoft Azure, OpenAI and Recraft; Figma Weave adds more than a dozen further model vendors; Agora handles audio and transcription. The list is published at https://www.figma.com/sub-processors/.

Can I keep Figma data in the EU (data residency)?

Public docs don't confirm an EU region. Figma's subprocessor page says AWS hosting is in the "United States (or, for Enterprise plans, the hosting location selected)", and the Governance+ docs mention data locality, but the pages we read don't name a specific EU region.

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (figma.md), evidence dated 2026-10-07.