Postman Enterprise Platform Security

Developers love us. CISOs trust us.

Developers choose Postman because it's where API work happens. Security teams trust it because protection is built into every layer. We give CISOs visibility and controls that follow every developer and agent, with compliance evidence that's ready when your auditors ask.

Trusted by security teams at

Microsoft logo
Siemens logo
Adobe logo
PayPal logo
Mastercard logo
Salesforce logo
Cisco logo
Autodesk logo
Microsoft logo
Siemens logo
Adobe logo
PayPal logo
Mastercard logo
Salesforce logo
Postman security illustration

Postman is now AI-native and so is our security model.

APIs and AI agents are inseparable in the modern enterprise. Postman is the only platform that governs both with security controls that protect your data before it moves, not after.

Adobe logo
Postman's security model gives me confidence that credentials stay where they belong environment variables keep secrets out of collection files, role-based access ensures people only see what they're supposed to, and every change is auditable and traceable.
Adobe

AI & Agent Mode Security

Your data doesn't train our models. Your team controls who uses AI and how.

Postman Enterprise gives security teams full control over AI usage, from what data the agents can access to who can run agents and which tools that can connect too.

AI & Data Protection

Your data doesn't train our models

Credential Protection

Secret scanning before it reaches any LLM.

PII Protection

PII data redaction via third-party guardrails.

CISOs Control AI Access

Govern who can use AI in your org.

MCP Governance

Control how MCP is used in your org.

Admin Controls

You decide if the Autonomous API Engineer runs.

Humans stay in the loop

Auto-run is off by default

Secret Security

Stop credential sprawl at the source

Credential abuse causes 22% of all data breaches. Postman sits where developers first test API calls; stopping secrets before they spread, and catching anything that slips through.

Keep secrets out of Postman Cloud and Git.

View secrets documentation

Find and mitigate secrets in Postman Cloud.

Vault references are resolved just-in-time at the moment of request.

Local Vault

Encrypted on-device only with no secrets synced to Postman Cloud

Shared Vault

Per-workspace vault for secure team collaboration.

Vault Integrations

HashiCorp, AWS Secrets Manager, Azure Key Vault, 1Password.

Bring Your Own Key

Supply your own encryption key revocable at any time.

  • Layer 1

    Local Secret Protection

    Keep secrets out of Postman Cloud and Git.

    View secrets documentation
  • Layer 2

    Cloud Secret Detection

    Find and mitigate secrets in Postman Cloud.

  • Layer 3

    Secret Resolution at Runtime

    Vault references are resolved just-in-time at the moment of request.

Information Governance & Access Control

Every developer. Every account. One governance layer.

Control who accesses Postman, how they access it, and what they can do including the accounts your security team doesn't know exist yet.

Account Discovery and Control

Domain Verification & Account Capture

Single Sign-On (SSO)

SCIM Provisioning

Role-Based Access Control

Postman Organizations

Audit Logs

Data Residency

Postman governance illustration

Shared responsibility model

We rely on our users to help safeguard their data and credentials in Postman. We strongly encourage customers, security teams, and developers to use Postman securely.

Compliance & Certifications

Compliance isn't a checkbox it's a proof point. Ours are downloadable.

All compliance documents SOC 2 Type II reports, penetration test summaries, audit reports, and security questionnaire responses are available via the Postman Customer Trust Portal.

SOC 2 Type II certified.SOC 2 Type II
PCI DSS compliant.PCI DSS
HIPAA compliant.HIPAA
GDPR compliant.GDPR
CCPA / CPRA compliant.CCPA / CPRA
CSA STAR Registry certified.CSA STAR
TX-RAMP certified.TX-RAMP
ISO 27001 certified.ISO 27001
ISO 42001 certified.ISO 42001

SOC 2 Type II reports, penetration test summaries, security questionnaire responses, architecture diagrams, and more available on demand for your security review team.

Access the Customer Trust Portal

Privacy

Privacy by design globally compliant

Postman does not sell your data for commercial purposes or share it as defined under CCPA and CPRA. All third-party vendors are required to execute Postman's standard vendor DPA before any data is shared.

Global Data Privacy Frameworks

Postman security bug bounty illustration

Bug Bounty Program

We put our security to the test with the global research community

Postman runs a private bug bounty program through HackerOne, inviting security researchers worldwide to identify and responsibly disclose vulnerabilities in the Postman API Platform. All findings are scored with CVSS, assigned an owner, and tracked to resolution against internal SLAs.

Agent Mode was subjected to internal AppSec testing and its first third-party penetration test in early 2026 results available on the Trust Portal. Our bug bounty program has paid out over $350,000 to more than 800 researchers since 2017.

Frequently Asked Questions

What are Postman's data encryption and key management practices?

Postman uses strong encryption (AES-256-GCM) for data at rest and TLS for data in transit. All sensitive data, including environment variables, secrets, and access tokens, is encrypted at the application layer and managed via a key management system (KMS).

Enterprise customers can also opt for Postman's Bring Your Own Key (BYOK) encryption feature, which enables them to manage and control their own encryption keys. These keys are never accessible by Postman, and all encryption events are logged for compliance and auditing.

Postman does not use customer data in internal testing. All validation and QA efforts are conducted on a production-mirrored internal stack using fictitious data only.

We keep your data in secure offline backups for 15 days after you delete your account or end your relationship with us. After that period, Postman permanently deletes your data from the product.


How does Postman protect data centers?

Postman has no in-house data centers and uses AWS to manage its data centers' physical and environmental security. Our company's product data and backups are hosted on AWS servers in the EU and the U.S., which offer strong security and privacy-focused features.


How does Postman secure its applications?

Postman secures its applications at every layer and phase, from development to deployment and operation. Our applications run on the latest stable version of Node.js, an open-source programming language. We use containerization to isolate software, set architectural security guidelines, and perform code reviews. Industry standards and security frameworks are applied throughout the software development lifecycle, with testing for OWASP vulnerabilities. Annually, third-party firms validate our ecosystem's security, and our bug bounty program allows anyone to report potential vulnerabilities in the Postman API Platform.

Our company's automated and manual code review processes search for any code that could potentially violate corporate security policies. We also have patching mechanisms built into the operating systems to update devices automatically.


What are Postman's vulnerability management processes?

We monitor the security of our products and applications through various ongoing activities, including regularly scheduled Vulnerability Assessment and Penetration Testing (VAPT) for all product releases.

We also conduct vulnerability scans on the network, application, and operating system layers at regular intervals throughout the year, enabling us to patch vulnerabilities across Postman's computing devices and applications.

All issues found are assigned a score using the Common Vulnerability Scoring System (CVSS), an owner, and a deadline based on an internal Service Level Agreement (SLA) for fixing vulnerabilities. We may also remove and turn off services.

Additionally, we use an automated tool for source code analysis, which runs before every production release. This tool covers vulnerabilities in open-source software and libraries. You can view applicable third-party licenses and a list of open-source software.


Does Postman share customer data with any of its third-party partners or sub-processors?

We only share information with third parties to help us operate, support, and market our services. We do not sell your data for commercial purposes or "share" data as defined under the CCPA and CPRA. All third-party vendors, including our sub-processors, undergo a privacy risk assessment and are required to execute our standard vendor DPA. Prospective customers can request access through our Customer Trust Portal. You can also view the complete list of Postman sub-processors.


How does Postman manage attack prevention and mitigation?

We log activity across our platform, from individual API requests to infrastructure configuration changes. Logs are aggregated for monitoring, analysis, and anomaly detection and archived in vaulted storage.

Our company further implements measures to detect and prevent log tampering or interruptions. To detect security breaches, we monitor access patterns and network data flow patterns using automated systems that alert us to any anomalies. In addition, we run automated scans on each feature release to ensure we reduce any security issues from third-party libraries.

Also, our leadership team is notified automatically in the event of a customer-reported breach. In accordance with Postman's corporate policies, we respond to the report within a few hours.


What is Postman's incident response policy?

Our company has incident response policies and procedures to help mitigate cyber risks around service availability, integrity, security, privacy, and confidentiality. As a result, we train our Postman teams to:

  • Promptly respond to alerts of potential incidents
  • Analyze and assess the severity of potential incidents
  • Execute mitigation and containment measures
  • Communicate with relevant internal and external stakeholders, including notifying affected customers and meeting contractual obligations around breach or incident notifications.
  • Gather and preserve forensic evidence for investigative efforts
  • Conduct and document a postmortem while developing a permanent triage plan

The incident response policies and processes are audited as part of our System and Organization Controls (SOC 2) and other security assessments.


How can I contact Postman Security to report potential abuse or vulnerabilities?

Please contact our customer support team or security@postman.com to report potentially abusive behavior or malicious activity involving Postman accounts or resources.

To report a vulnerability, check out our reporting page on HackerOne. Security researchers should also review our security guidelines and policy for reporting security vulnerabilities through our bug bounty program.

If you want additional information about our security policies, please contact us at security@postman.com. You can use our PGP public key to encrypt your communications with us.


Does Postman have a bug bounty program?

Yes. Postman runs a private bug bounty program through HackerOne. For full details on scope, eligibility, and how to submit a report, visit our vulnerability reporting page.


Postman trust illustration

The platform your developers love. The security controls your CISO trusts.

Talk to our enterprise security team and see how Postman addresses your specific security, compliance, and governance requirements. Questions? security@postman.com

Visit Trust Portal →