Figma
Multiplayer design files with Dev Mode handoff, so engineers pull specs and tokens without asking the designer.
What it does
| Visual style and output | Generates polished, pixel-precise UI designs and prototypes suitable for production handoff. |
|---|---|
| Collaboration model | Multiplayer design files with persistent accounts, commenting, version history, and dedicated Dev Mode for engineers. |
| Licensing and cost | Pricing details not provided in the data; typically operates on a freemium or subscription model for teams. |
| Feature scope | Full design suite including vector editing, prototyping, design systems, plugins, and developer handoff tools. |
Pick Figma if
- You're designing user interfaces or high-fidelity prototypes for web or mobile apps
- You need multiplayer collaboration with version control, commenting, and role-based access
- Your workflow includes developer handoff with specs, tokens, and asset export (Dev Mode)
- You require a comprehensive design system, plugins, and integration with engineering tools
- Security header quality is a consideration (Figma scores B vs. Excalidraw's D)
- You need a dedicated UI/UX design and prototyping tool with robust component libraries and design systems
Compare
Security headers: B, 70 out of 100
Number 37 of 95 in the ranking. Missing 4 of the 9 headers we check.
Meets the B minimum (70/100) in our RFP clause.
With these headers missing, figma.com is more exposed to clickjacking.
Missing 4
-
Referrer-Policy 0 of 10
Limits how much of the current URL is passed to other sites when a user follows a link or the page loads a third-party resource.
Without it: Full URLs, including paths and query strings that can carry document IDs, search terms, customer names or reset tokens, can leak to every outside script, image host and outbound link. Recent browsers default to a safer policy; older ones and embedded webviews do not.
-
Permissions-Policy 0 of 10
Switches off browser features the product does not use, such as camera, microphone, location and payments, for the page and anything embedded in it.
Without it: Any script or iframe on the page, including third-party ads and chat widgets, can ask the user for camera, microphone or location access under the vendor's name.
-
Cross-Origin-Opener-Policy 0 of 5
Cuts the link between the product's window and windows opened by, or opening, other sites.
Without it: A page that opens the product keeps a handle on its window and can later redirect it to a look-alike sign-in or payment page (tab-nabbing) while the user thinks they are still on the real site. It is also part of the isolation browsers need to defend against Spectre-style attacks.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
Sent 5
-
Content-Security-Policy 25 of 25
default-src 'self' https://accounts.google.com/gsi/ ; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://platform.twitter.com/js/ https://platform.twitter.com/widgets.js https://player.vimeo.com/api/player.js https://www.youtube.com/iframe_api https://www.youtube.com/s/player/ https://accounts.google.com/gsi/client https://adora-cdn.com/adora-start.js https://decagon.ai ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ https://accounts.google.com/gsi/style ; object-src 'none' ; base-uri 'self' ; font-src 'self' https://fonts.gstatic.com ; connect-src 'self' https://static.figma.com https://forms.figma.com https://boards-api.greenhouse.io/v1/boards/figma/jobs https://vimeo.com https://accounts.google.com/gsi/ https://figma.com/api/figment-proxy/monitor https://staging.figma.com/api/figment-proxy/monitor https://figma.com/api/figment-proxy/identify https://staging.figma.com/api/figment-proxy/identify https://figma.com/api/figment-proxy/page https://staging.figma.com/api/figment-proxy/page https://staging.figma.com/api/user/help-center https://www.figma.com/api/user/help-center https://cdn.sanity.io https://events.statsigapi.net/v1/rgstr https://statsigapi.net/v1/sdk_exception https://prodregistryv2.org/v1/rgstr https://featuregates.org/v1/initialize https://featureassets.org/v1/initialize https://o22594.ingest.sentry.io *.adora-cdn.com https://figma-marketing-tools.vercel.app/api/white-background https://decagon.ai ; frame-src 'self' *.figma.site https://www.figma.com https://marketing.figma.com https://marketing.staging.figma.com https://platform.twitter.com https://player.vimeo.com https://www.youtube.com https://accounts.google.com/gsi/ https://figma.com/api/figment-proxy/monitor https://staging.figma.com/api/figment-proxy/monitor https://figma.com/api/figment-proxy/identify https://staging.figma.com/api/figment-proxy/identify https://figma.com/api/figment-proxy/page https://staging.figma.com/api/figment-proxy/page https://decagon.ai ; img-src 'self' data: blob: https://cdn.sanity.io https://i.vimeocdn.com https://*.figma.com https://i.ytimg.com https://www.gravatar.com https://i0.wp.com/s3-alpha.figma.com/ https://i1.wp.com/s3-alpha.figma.com/ https://i2.wp.com/s3-alpha.figma.com/ https://i3.wp.com/s3-alpha.figma.com/ ; media-src 'self' https://cdn.sanity.io https://static.figma.com ; worker-src 'self' ; upgrade-insecure-requests
-
Strict-Transport-Security 20 of 20
max-age=31536000; includeSubDomains; preload
-
X-Content-Type-Options 10 of 10
nosniff, nosniff
-
Frame protection 10 of 10
SAMEORIGIN
-
No version disclosure 5 of 5