Skip to content

PostmanCompliance, certifications and attestations

Certifications held, by family8 held
Trust center
8
Certifications held
2
Backed by a registry
8
Pieces of evidence
Sep 24, 2026
Last captured

SOC reports

ISO standards

AI governance

US government

Health

Payments

Privacy

Cloud security

Regional

From public trust centers and registries on the date shown. Confirm scope with the vendor. Logos via logo.dev; trademarks belong to their owners.

History

Added or renewedUpgradedIn process or ReadyLapsed or removed
  1. AddedData Privacy FrameworkPostman, Inc.
  2. AddedCSA STARFirst listed in the CSA STAR Registry

Evidence

Every source, what it says and when it was read.

SOC 21 source

Held · Type IIVendor compliance page
...Compliance isn't a checkbox it's a proof point. Ours are downloadable. All compliance documents SOC 2 Type II reports, penetration test summaries, audit reports, and security questionnaire responses are available...
Captured Sep 24, 2026Open source

ISO/IEC 270011 source

HeldVendor compliance page
...Postman Customer Trust Portal. SOC 2 Type II PCI DSS HIPAA GDPR CCPA / CPRA CSA STAR TX-RAMP ISO 27001 ISO 42001 SOC 2 Type II reports, penetration test summaries, security questionnaire responses, architecture diagrams,...
Captured Sep 24, 2026Open source

ISO/IEC 420011 source

HeldVendor compliance page
...Customer Trust Portal. SOC 2 Type II PCI DSS HIPAA GDPR CCPA / CPRA CSA STAR TX-RAMP ISO 27001 ISO 42001 SOC 2 Type II reports, penetration test summaries, security questionnaire responses, architecture diagrams, and...
Captured Sep 24, 2026Open source

HIPAA (BAA)1 source

HeldVendor compliance page
...questionnaire responses are available via the Postman Customer Trust Portal. SOC 2 Type II PCI DSS HIPAA GDPR CCPA / CPRA CSA STAR TX-RAMP ISO 27001 ISO 42001 SOC 2 Type II reports, penetration test summaries, security...
Captured Sep 24, 2026Open source

PCI DSS1 source

HeldVendor compliance page
...questionnaire responses are available via the Postman Customer Trust Portal. SOC 2 Type II PCI DSS HIPAA GDPR CCPA / CPRA CSA STAR TX-RAMP ISO 27001 ISO 42001 SOC 2 Type II reports, penetration test summaries,...
Captured Sep 24, 2026Open source

Data Privacy Framework1 source

HeldData Privacy Framework List

EU-US, UK extension, Swiss-US; non-HR data and HR data. Postman, Inc.

EU-US status: Active; certified since 2023-10-31; recertification due 2026-10-21; verification: Self-Assessment
Captured Sep 23, 2026Since Oct 31, 2023Renewal due Oct 21, 2026Open source

CSA STAR1 source

Held · Level 1CSA STAR Registry

CAIQ

Listed as Postman, Inc. since 2022-06-28; Level 1 (self-assessment)
Captured Sep 23, 2026Since Jun 28, 2022Open source

Compare with

Weekly: vendors that gained or lost a certification, Wednesdays.