VendorScore · Design · Data-access posture
A plain-language answer from Figma's public Security, Help Center and legal pages. EKM covers file checkpoints and uploaded media; Figma still decrypts files to render and collaborate on them.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, Figma can read your design files by design (with controls). EKM encrypts file checkpoints and uploaded media with your AWS KMS key, but metadata, comments and component definitions stay on Figma keys, and Figma decrypts files to render them.
Scored configuration: Figma Enterprise with the Governance+ add-on, including Enterprise Key Management (EKM) on AWS KMS.
Default (no Governance+/EKM): Figma-managed keys; the report estimates Overall ~54.
Report confidence: Medium. Staff-access detail comes from an older SOC 3 report (Nov 2021–Oct 2022).
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
AI content training is on by default for Figma Starter and Professional teams (admin opt-out) and off on Organization and Enterprise plans.
Evidence: Figma AI settings helpFigma EKM doesn't encrypt metadata, comments or database-stored component definitions with your key, and Figma "doesn't fully support offboarding from EKM".
Evidence: Governance+ for FigmaOur report flags these gaps in Figma's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, Figma can read your design files by design (with controls). EKM encrypts file checkpoints and uploaded media with your AWS KMS key, but metadata, comments and component definitions stay on Figma keys, and Figma decrypts files to render them. VendorScore rates Figma 59/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Figma Enterprise with the Governance+ add-on, including Enterprise Key Management (EKM) on AWS KMS.
Figma's SOC 3 report says customer data is encrypted at rest with AES-256 and in transit with TLS. With Governance+ on Enterprise, EKM encrypts file checkpoints (shapes, text, frames, layers) and uploaded images and videos with your own AWS KMS key, and "you can grant, monitor, and revoke Figma's access to the encryption key at any time." Metadata, comments and component definitions stored in databases stay on Figma keys, and Figma "doesn't fully support offboarding from EKM". It's not E2EE: Figma decrypts files to render them.
Figma's older SOC 3 report (period Nov 2021–Oct 2022) says its admin console "only provides access to meta-data" and that "Customers must explicitly invite employees to access their design files." It adds that a limited number of senior engineers can download files through the admin console upon customer consent, with actions logged in a support ticket. We didn't find this on Figma's current pages, so the current procedure is Unknown.
It depends on your plan. Figma's AI Terms say: "When 'Content Training' is toggled on within Customer's administrative user settings, Figma may use Customer Content to maintain, improve, and enhance Figma's products and services by training machine learning and artificial intelligence algorithms and models." Content training is on by default for Starter and Professional teams, and admins can turn it off. On Organization and Enterprise plans it's off and can't be toggled on.
VendorScore doesn't certify compliance; Figma publishes a DPA at https://www.figma.com/legal/dpa/. The DPA says new subprocessors are added to the list at least 15 days before they process Customer Content, with a right to object.
Figma's list (last updated September 22, 2026) names Datadog, Sentry and Snowflake for all services with Customer Content, and Cloudflare for image and video content. Figma AI uses Anthropic, AWS, Cerebras, Fireworks, Google Vertex, Jasper, Microsoft Azure, OpenAI and Recraft; Figma Weave adds more than a dozen further model vendors; Agora handles audio and transcription. The list is published at https://www.figma.com/sub-processors/.
Public docs don't confirm an EU region. Figma's subprocessor page says AWS hosting is in the "United States (or, for Enterprise plans, the hosting location selected)", and the Governance+ docs mention data locality, but the pages we read don't name a specific EU region.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (figma.md), evidence dated 2026-10-07.