Postman Enterprise Platform Security
Developers love us. CISOs trust us.
Developers choose Postman because it's where API work happens. Security teams trust it because protection is built into every layer. We give CISOs visibility and controls that follow every developer and agent, with compliance evidence that's ready when your auditors ask.
Trusted by security teams at
![]()
![]()
![]()
Postman's security model gives me confidence that credentials stay where they belong environment variables keep secrets out of collection files, role-based access ensures people only see what they're supposed to, and every change is auditable and traceable.”
Adobe
AI & Agent Mode Security
Your data doesn't train our models. Your team controls who uses AI and how.
Postman Enterprise gives security teams full control over AI usage, from what data the agents can access to who can run agents and which tools that can connect too.
AI & Data Protection
Your data doesn't train our models
Credential Protection
Secret scanning before it reaches any LLM.
PII Protection
PII data redaction via third-party guardrails.
CISOs Control AI Access
Govern who can use AI in your org.
MCP Governance
Control how MCP is used in your org.
Admin Controls
You decide if the Autonomous API Engineer runs.
Humans stay in the loop
Auto-run is off by default
Information Governance & Access Control
Every developer. Every account. One governance layer.
Control who accesses Postman, how they access it, and what they can do including the accounts your security team doesn't know exist yet.
Account Discovery and Control
Domain Verification & Account Capture
Single Sign-On (SSO)
SCIM Provisioning
Role-Based Access Control
Postman Organizations
Audit Logs
Data Residency
Shared responsibility model
We rely on our users to help safeguard their data and credentials in Postman. We strongly encourage customers, security teams, and developers to use Postman securely.
Compliance & Certifications
Compliance isn't a checkbox it's a proof point. Ours are downloadable.
All compliance documents SOC 2 Type II reports, penetration test summaries, audit reports, and security questionnaire responses are available via the Postman Customer Trust Portal.
SOC 2 Type II
PCI DSS
HIPAA
GDPR
CCPA / CPRA
CSA STAR
TX-RAMP
ISO 27001
ISO 42001
SOC 2 Type II reports, penetration test summaries, security questionnaire responses, architecture diagrams, and more available on demand for your security review team.
Privacy
Privacy by design globally compliant
Postman does not sell your data for commercial purposes or share it as defined under CCPA and CPRA. All third-party vendors are required to execute Postman's standard vendor DPA before any data is shared.
Privacy Policy
Global Data Privacy Frameworks
Bug Bounty Program
We put our security to the test with the global research community
Postman runs a private bug bounty program through HackerOne, inviting security researchers worldwide to identify and responsibly disclose vulnerabilities in the Postman API Platform. All findings are scored with CVSS, assigned an owner, and tracked to resolution against internal SLAs.
Agent Mode was subjected to internal AppSec testing and its first third-party penetration test in early 2026 results available on the Trust Portal. Our bug bounty program has paid out over $350,000 to more than 800 researchers since 2017.
From the Postman security team
Perspectives from the engineers and security leaders building and defending the platform and thinking ahead on what matters most for enterprise API security.
Frequently Asked Questions
What are Postman's data encryption and key management practices?
How does Postman protect data centers?
Postman has no in-house data centers and uses AWS to manage its data centers' physical and environmental security. Our company's product data and backups are hosted on AWS servers in the EU and the U.S., which offer strong security and privacy-focused features.
How does Postman secure its applications?
What are Postman's vulnerability management processes?
Does Postman share customer data with any of its third-party partners or sub-processors?
We only share information with third parties to help us operate, support, and market our services. We do not sell your data for commercial purposes or "share" data as defined under the CCPA and CPRA. All third-party vendors, including our sub-processors, undergo a privacy risk assessment and are required to execute our standard vendor DPA. Prospective customers can request access through our Customer Trust Portal. You can also view the complete list of Postman sub-processors.
How does Postman manage attack prevention and mitigation?
What is Postman's incident response policy?
How can I contact Postman Security to report potential abuse or vulnerabilities?
Does Postman have a bug bounty program?
Yes. Postman runs a private bug bounty program through HackerOne. For full details on scope, eligibility, and how to submit a report, visit our vulnerability reporting page.
The platform your developers love. The security controls your CISO trusts.
Talk to our enterprise security team and see how Postman addresses your specific security, compliance, and governance requirements. Questions? security@postman.com