Compliance frameworks, security audits, and quality certifications this company maintains.
Postman maintains SOC 2 Type II certification, with annual audits covering the security, availability, and confidentiality of API Collections, environment variables, and workspace data stored on its cloud platform.
Postman is ISO 27001 certified, demonstrating that its information security management practices — spanning API secret storage, access controls, and incident response — meet international standards.
Postman complies with GDPR for all European users, providing data processing agreements, the ability to request data deletion, and clear data residency controls for enterprise workspaces hosted in EU regions.
Postman honors CCPA rights for California residents, enabling users to opt out of data sharing, request personal data exports, and delete account data through the Postman privacy portal.
Postman supports HIPAA-eligible enterprise workspaces through Business Associate Agreements, allowing healthcare organizations to safely use Postman for testing and documenting APIs that handle protected health information.
Postman actively aligns its Security Audit feature with the OWASP API Security Top 10, automatically flagging issues such as broken object-level authorization, excessive data exposure, and improper authentication in API definitions.
Postman holds CSA STAR Level 1 certification, publishing its cloud security practices through the Cloud Security Alliance registry to give enterprise customers transparency into how API data is protected in Postman cloud infrastructure.
Postman meets WCAG 2.1 AA accessibility guidelines across its web platform and desktop application, ensuring that developers with disabilities can use the Postman editor, Collection runner, and documentation features.
Security
Penetration Testing
CompliantPostman conducts annual third-party penetration testing across its API platform infrastructure and web application, with findings reviewed and remediated before enterprise customer audit cycles.
Postman participates in cross-border data transfer frameworks ensuring that API metadata, Collection content, and user data transferred between the US and EU is handled in accordance with applicable privacy regulations.