postman.com

Postman Enterprise Platform Security

Developers love us. CISOs trust us.

Developers choose Postman because it's where API work happens. Security teams trust it because protection is built into every layer. We give CISOs visibility and controls that follow every developer and agent, with compliance evidence that's ready when your auditors ask.

Trusted by security teams at

Microsoft logo

Siemens logo

Adobe logo

PayPal logo

Mastercard logo

Salesforce logo

Cisco logo

Autodesk logo

Microsoft logo

Siemens logo

Adobe logo

PayPal logo

Mastercard logo

Salesforce logo

Adobe logo

Postman's security model gives me confidence that credentials stay where they belong environment variables keep secrets out of collection files, role-based access ensures people only see what they're supposed to, and every change is auditable and traceable.

Adobe

AI & Agent Mode Security

Your data doesn't train our models. Your team controls who uses AI and how.

Postman Enterprise gives security teams full control over AI usage, from what data the agents can access to who can run agents and which tools that can connect too.

AI & Data Protection

Your data doesn't train our models

Credential Protection

Secret scanning before it reaches any LLM.

PII Protection

PII data redaction via third-party guardrails.

CISOs Control AI Access

Govern who can use AI in your org.

MCP Governance

Control how MCP is used in your org.

Admin Controls

You decide if the Autonomous API Engineer runs.

Humans stay in the loop

Auto-run is off by default

Information Governance & Access Control

Every developer. Every account. One governance layer.

Control who accesses Postman, how they access it, and what they can do including the accounts your security team doesn't know exist yet.

Account Discovery and Control

Domain Verification & Account Capture

Single Sign-On (SSO)

SCIM Provisioning

Role-Based Access Control

Postman Organizations

Audit Logs

Data Residency

Postman governance illustration

Shared responsibility model

We rely on our users to help safeguard their data and credentials in Postman. We strongly encourage customers, security teams, and developers to use Postman securely.

Compliance & Certifications

Compliance isn't a checkbox it's a proof point. Ours are downloadable.

All compliance documents SOC 2 Type II reports, penetration test summaries, audit reports, and security questionnaire responses are available via the Postman Customer Trust Portal.

SOC 2 Type II certified.SOC 2 Type II

PCI DSS compliant.PCI DSS

HIPAA compliant.HIPAA

GDPR compliant.GDPR

CCPA / CPRA compliant.CCPA / CPRA

CSA STAR Registry certified.CSA STAR

TX-RAMP certified.TX-RAMP

ISO 27001 certified.ISO 27001

ISO 42001 certified.ISO 42001

SOC 2 Type II reports, penetration test summaries, security questionnaire responses, architecture diagrams, and more available on demand for your security review team.

Access the Customer Trust Portal

Privacy

Privacy by design globally compliant

Postman does not sell your data for commercial purposes or share it as defined under CCPA and CPRA. All third-party vendors are required to execute Postman's standard vendor DPA before any data is shared.

Privacy Policy

Global Data Privacy Frameworks

Postman security bug bounty illustration

Bug Bounty Program

We put our security to the test with the global research community

Postman runs a private bug bounty program through HackerOne, inviting security researchers worldwide to identify and responsibly disclose vulnerabilities in the Postman API Platform. All findings are scored with CVSS, assigned an owner, and tracked to resolution against internal SLAs.

Agent Mode was subjected to internal AppSec testing and its first third-party penetration test in early 2026 results available on the Trust Portal. Our bug bounty program has paid out over $350,000 to more than 800 researchers since 2017.

From the Postman security team

Perspectives from the engineers and security leaders building and defending the platform and thinking ahead on what matters most for enterprise API security.

Frequently Asked Questions

What are Postman's data encryption and key management practices?

How does Postman protect data centers?

Postman has no in-house data centers and uses AWS to manage its data centers' physical and environmental security. Our company's product data and backups are hosted on AWS servers in the EU and the U.S., which offer strong security and privacy-focused features.

How does Postman secure its applications?

What are Postman's vulnerability management processes?

Does Postman share customer data with any of its third-party partners or sub-processors?

We only share information with third parties to help us operate, support, and market our services. We do not sell your data for commercial purposes or "share" data as defined under the CCPA and CPRA. All third-party vendors, including our sub-processors, undergo a privacy risk assessment and are required to execute our standard vendor DPA. Prospective customers can request access through our Customer Trust Portal. You can also view the complete list of Postman sub-processors.

How does Postman manage attack prevention and mitigation?

What is Postman's incident response policy?

How can I contact Postman Security to report potential abuse or vulnerabilities?

Does Postman have a bug bounty program?

Yes. Postman runs a private bug bounty program through HackerOne. For full details on scope, eligibility, and how to submit a report, visit our vulnerability reporting page.

Postman trust illustration

The platform your developers love. The security controls your CISO trusts.

Talk to our enterprise security team and see how Postman addresses your specific security, compliance, and governance requirements. Questions? security@postman.com

Visit Trust Portal →

Read the original on postman.com ↗