DISCOVER & TEST KONNECT APIS IN REAL TIME WITH INSOMNIA 13 MIGRATE 50% FASTER WITH KONG MIGRATION SERVICES DON'T MISS OUT ON API + AI SUMMIT 2026 | PRICES INCREASE SEPTEMBER 1
  • [Why Kong ](/company/why-kong)Why Kong
  • _API & AI CONNECTIVITY TECHNOLOGIES_
    The Unified API and AI Platform
    []
    API ManagementAI ManagementEvent ManagementMonetization
    Migration Services
    API Advisory Services + Forward Deployed EngineersNEW
    • RUNTIMES
    • [API Gateway ](/products/kong-gateway)API Gateway
    • [AI Gateway HOT](/products/kong-ai-gateway)AI Gateway HOT
    • [Event Gateway ](/products/event-gateway)Event Gateway
    • [Service Mesh ](/products/kong-mesh)Service Mesh
    • [Context Mesh ](/products/kong-konnect/features/context-mesh)Context Mesh
    • [Ingress Controller ](/products/kong-ingress-controller)Ingress Controller
    • [Kong Operator ](/products/kong-operator)Kong Operator
    • CORE SERVICES
    • [MCP Registry NEW](/products/mcp-registry)MCP Registry NEW
    • [API Service Catalog ](/products/kong-konnect/features/api-service-catalog)API Service Catalog
    • [Runtime Management ](/products/kong-konnect/features/runtime-management)Runtime Management
    • [APIOps & Automation ](/products/apiops-automation)APIOps & Automation
    • APPS & AI AGENTS
    • [Developer Portal ](/products/kong-konnect/features/developer-portal)Developer Portal
    • [Usage Billing & Metering ](/products/kong-konnect/features/usage-based-metering-and-billing)Usage Billing & Metering
    • [Observability ](/products/kong-konnect/features/api-observability)Observability
    • [KAi Agent ](/products/kong-konnect/features/kai-ai-agent)KAi Agent
    DEVELOPER TOOLS
    [Insomnia ](https://insomnia.rest/)Insomnia [Plugins ](https://developer.konghq.com/plugins/)Plugins [Volcano ](https://volcano.dev/)Volcano [Kong MCP ](https://developer.konghq.com/konnect-platform/konnect-mcp/)Kong MCP [Documentation ](https://docs.konghq.com/)Documentation [Open Source ](/community)Open Source
      • FOR PLATFORM TEAMS
      • [Developer Platform ](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices ](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability ](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming ](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity ](/ai-connectivity)AI Connectivity
      • [Open Banking ](/solutions/open-banking)Open Banking
      • [Legacy Migration ](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction ](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization ](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization ](/solutions/api-monetization)API Monetization
      • [AI Monetization ](/solutions/ai-monetization)AI Monetization
      • [AI FinOps ](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [Agent Gateway ](/agent-gateway)Agent Gateway
      • [AI Governance ](/solutions/ai-governance)AI Governance
      • [AI Security ](/solutions/ai-security)AI Security
      • [Token Cost Management ](/solutions/ai-cost-optimization-management)Token Cost Management
      • [Agentic Infrastructure ](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production ](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway ](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development ](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development ](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio ](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing ](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services ](/solutions/financial-services-industry)Financial Services
      • [Healthcare ](/solutions/healthcare)Healthcare
      • [Higher Education ](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance ](/solutions/insurance)Insurance
      • [Manufacturing ](/solutions/manufacturing)Manufacturing
      • [Retail ](/solutions/retail)Retail
      • [Software & Technology ](/solutions/software-and-technology)Software & Technology
      • [Transportation ](/solutions/transportation-and-logistics)Transportation
    NEW
    Kong for Startups
    Apply for $100k credits & 50% off AI Gateway
  • [Pricing ](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect ](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway ](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh ](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway ](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway ](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia ](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub ](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog ](/blog)Blog
      • [Learning Center ](/blog/learning-center)Learning Center
      • [eBooks ](/resources/e-book)eBooks
      • [Reports ](/resources/reports)Reports
      • [Demos ](/resources/demos)Demos
      • [Customer Stories ](/customer-stories)Customer Stories
      • [Videos ](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit ](/events/conferences/api-ai-summit)API + AI Summit
      • [Webinars ](/events/webinars)Webinars
      • [User Calls ](/events/user-calls)User Calls
      • [Workshops ](/events/workshops)Workshops
      • [Meetups ](/events/meetups)Meetups
      • [See All Events ](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started ](https://developer.konghq.com/)Get Started
      • [Community ](/community)Community
      • [Certification ](/academy/certification)Certification
      • [Training ](https://education.konghq.com)Training
      • COMPANY
      • [About Us ](/company/about-us)About Us
      • [We're Hiring! ](/company/careers)We're Hiring!
      • [Press Room ](/company/press-room)Press Room
      • [Contact Us ](/company/contact-us)Contact Us
      • [Kong Partner Program ](/partners)Kong Partner Program
      • [Enterprise Support Portal ](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation ](https://developer.konghq.com/?_gl=1*tphanb*_gcl_au*MTcxNTQ5NjQ0MC4xNzY5Nzg4MDY0LjIwMTI3NzEwOTEuMTc3MzMxODI2MS4xNzczMzE4MjYw*_ga*NDIwMDU4MTU3LjE3Njk3ODgwNjQ.*_ga_4JK9146J1H*czE3NzQwMjg1MjkkbzE4OSRnMCR0MTc3NDAyODUyOSRqNjAkbDAkaDA)Documentation
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway ](/blog/tag/ai-gateway)AI Gateway
  • [AI Security ](/blog/tag/ai-security)AI Security
  • [AIOps ](/blog/tag/aiops)AIOps
  • [API Security ](/blog/tag/api-security)API Security
  • [API Gateway ](/blog/tag/api-gateway)API Gateway
|
    • [API Management ](/blog/tag/api-management)API Management
    • [API Development ](/blog/tag/api-development)API Development
    • [API Design ](/blog/tag/api-design)API Design
    • [Automation ](/blog/tag/automation)Automation
    • [Service Mesh ](/blog/tag/service-mesh)Service Mesh
    • [Insomnia ](/blog/tag/insomnia)Insomnia
    • [Event Gateway ](/blog/tag/event-gateway)Event Gateway
    • [View All Blogs ](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/kong-konnect/features/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Enterprise
  4. API and Data Security: Is It Time to Switch to Kong Insomnia?
April 8, 2025
4 min read

# API and Data Security: Is It Time to Switch to Kong Insomnia?

Adam Jiroun
Senior Product Marketing Manager, Kong

[Recent leaks](https://www.cloudsek.com/blog/postman-data-leaks-the-hidden-risks-lurking-in-your-workspaces)Recent leaks have once again brought API and data security concerns into the spotlight. Specifically, the leaks pointed at the following as major areas to consider when thinking through your API and data security strategies:

  • - Collection governance and access control
  • - Data storage and syncing
  • - Role-based access control and automated enforcement of access control best practices
  • - Encryption and location of encryption logic

When considering the above, it’s critical to think about best practices across every stage of the API lifecycle, starting with the initial phases of API design and testing. To help organizations strengthen and properly manage their API and data security postures, we built Kong Insomnia into the larger API platform offering here at Kong. Compared to a tool like Postman, Insomnia was built from the ground up to support advanced security use cases and sensitive data environments. 

In this blog, we’ll cover how to leverage some of Insomnia’s security-oriented differentiators to address concerns related to the [recent data leak](https://www.cloudsek.com/blog/postman-data-leaks-the-hidden-risks-lurking-in-your-workspaces)recent data leak.  

## Prevent data leaks with collection governance and RBAC

Collection governance is the process of implementing access controls around API collections to prevent data leakage. This is especially crucial when sharing APIs with external collaborators, as improper API access control could invite malicious actors to easily obtain and misuse sensitive business data.

Insomnia prioritizes collection governance by ensuring collections are never publicly available by default — only explicitly authorized users can access them. With RBAC (role-based access control), admins can assign permissions, enforce strict access controls, and manage whether collections are allowed to be synced to the cloud. Private environments add another layer of protection by ensuring that sensitive data, like API keys, are never synced and always remain local.

Insomnia also integrates with popular third-party vaults like AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, and HashiCorp Vault — enabling streamlined secrets management and removing the need for plain-text storage. This is available out-of-the-box, with no additional add-on fee. 

*Integrate with your external vault of choice for streamlined secrets management.*

## Store data locally, via Git, or in the cloud

Data security and data locality go hand in hand. Many organizations, especially those operating in highly regulated industries, may prefer to not store their data in the cloud for security and compliance reasons. 

Insomnia provides organizations with the flexibility to store their data where they want to: 100% locally, via Git, or in the cloud. We understand that flexibility is of the utmost importance to our users, and so we offer various storage options to cater to the data compliance needs of each individual organization. 

In addition to having multiple storage options available, storage control in the Insomnia enterprise offering allows admins to mandate a specific storage location (cloud or local + Git) as the single source of truth for every user in the Insomnia project. This provides an extra layer of control to help drive compliance across every team and line of business using Insomnia. 

This helps avoid proven risks associated with syncing with publicly available GitHub repos. As called out in the [recent data leak coverage](https://www.cloudsek.com/blog/postman-data-leaks-the-hidden-risks-lurking-in-your-workspaces)recent data leak coverage, there have been leaks when, “...collections and environment files are synced or exported and stored in public repositories like GitHub. If sensitive data isn’t masked or sanitized before these files are uploaded, it becomes accessible to anyone with access to the repository. This is a common vulnerability, as developers may inadvertently publish tokens or secrets without realizing the impact.” 

*Have full control over where your Insomnia data is stored.*

## Opt-in to end-to-end encryption for the cloud 

For those who choose to store their data in the cloud, with Insomnia you can opt-in to having your data encrypted end-to-end on the client side. This means that all encryption keys are generated locally, all encryption is performed before sending any data over the network, and all decryption is performed after receiving data from the network. 

At no point in the sync process can the Insomnia servers, or an intruder, read or access your sensitive application project data.

## Choose training and support from a team of API security experts  

At the end of the day, a good product is truly only as effective as the quality of the team that backs it. 

Insomnia is owned and operated by Kong, and when you choose Kong, you get access to the same world-class team that supports the most adopted, battle-tested, and secure API platform — backed by great documentation, 24/7 support, and industry-leading expertise to help you securely govern APIs from design to deprecation.

## Get started today

[See Insomnia in action here](https://konghq.com/events/webinars/api-first-starts-with-insomnia)See Insomnia in action here and [reach out to our team](https://insomnia.rest/pricing/contact)reach out to our team to learn more. 

## More on this topic

_Reports_

## What is an AI Gateway? Governance for LLMs, Agents, and MCP

_eBooks_

## Context as a Service: How to Become an AI Supply-Side Platform

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
Adam Jiroun
Senior Product Marketing Manager, Kong

Recommended posts

# MCP Governance: The Foundation of Your Agentic AI Strategy

[Enterprise](/blog/tag)EnterpriseJuly 21, 2026

An AI agent without reliable, governed access to your systems is just an expensive chatbot. The moment agents need to take real action — querying a database, triggering a workflow, calling a partner API — they need an integration layer that was desi

Heather Halenbeck

# How to Proxy Every AI Traffic Pattern Through One Gateway

[Enterprise](/blog/tag)EnterpriseJuly 17, 2026

The first generation of production AI was simple: one application, one model, one API key. That era is over. AI adoption reached 78% of organizations in 2024, up from 55% the year before, per Stanford HAI's 2025 AI Index Report [1] . Enterprises no

Kong

# Kong and ModelOp Partner to Deliver Zero-Trust Security for the Agentic Enterprise

[Enterprise](/blog/tag)EnterpriseJuly 16, 2026

The Problem: As organizations adopt agentic AI, a massive gap exists between compliance approvals and network reality. Often, AI governance is relegated to manual reviews and "paper approvals," meaning network firewalls and gateways have no context

Alex Rice

# AI Governance Platforms Need a Runtime Enforcement Layer

[Enterprise](/blog/tag)EnterpriseJuly 9, 2026

Gartner is explicit that AI governance platforms are not Governance, Risk and Compliance (GRC) tools with an AI label. Where traditional GRC platforms function as static repositories for point-in-time risk assessments, AIGPs are built for real-time,

Heather Halenbeck

# Shadow AI Detection: The Enterprise Governance Guide

[Enterprise](/blog/tag)EnterpriseJuly 7, 2026

Shadow AI is any AI tool, model, or API integration deployed inside an organization without IT or security approval. Unlike sanctioned systems, it operates outside every review process your governance program depends on. That makes detection the fir

Kong

# AI Agent Platforms Are Getting Hacked. Here's What's Missing.

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

The Langflow CVEs and Dify Vulnerabilities: What Actually Happened Langflow's security problems arrived in waves. CVE-2025-3248 introduced a code injection vulnerability allowing remote code execution through unsanitized user input \10\]. Months la

Kong

# How to Switch LLM Providers Without Downtime

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

AI vendor lock-in is the condition where switching providers requires rewriting application code, reconfiguring infrastructure, or retraining teams. Unlike traditional SaaS lock-in, AI vendor lock-in carries compounding risks: proprietary prompt for

Kong

# MCP Governance: The Foundation of Your Agentic AI Strategy

[Enterprise](/blog/tag)EnterpriseJuly 21, 2026

An AI agent without reliable, governed access to your systems is just an expensive chatbot. The moment agents need to take real action — querying a database, triggering a workflow, calling a partner API — they need an integration layer that was desi

Heather Halenbeck

# How to Proxy Every AI Traffic Pattern Through One Gateway

[Enterprise](/blog/tag)EnterpriseJuly 17, 2026

The first generation of production AI was simple: one application, one model, one API key. That era is over. AI adoption reached 78% of organizations in 2024, up from 55% the year before, per Stanford HAI's 2025 AI Index Report [1] . Enterprises no

Kong

# Kong and ModelOp Partner to Deliver Zero-Trust Security for the Agentic Enterprise

[Enterprise](/blog/tag)EnterpriseJuly 16, 2026

The Problem: As organizations adopt agentic AI, a massive gap exists between compliance approvals and network reality. Often, AI governance is relegated to manual reviews and "paper approvals," meaning network firewalls and gateways have no context

Alex Rice

# AI Governance Platforms Need a Runtime Enforcement Layer

[Enterprise](/blog/tag)EnterpriseJuly 9, 2026

Gartner is explicit that AI governance platforms are not Governance, Risk and Compliance (GRC) tools with an AI label. Where traditional GRC platforms function as static repositories for point-in-time risk assessments, AIGPs are built for real-time,

Heather Halenbeck

# Shadow AI Detection: The Enterprise Governance Guide

[Enterprise](/blog/tag)EnterpriseJuly 7, 2026

Shadow AI is any AI tool, model, or API integration deployed inside an organization without IT or security approval. Unlike sanctioned systems, it operates outside every review process your governance program depends on. That makes detection the fir

Kong

# AI Agent Platforms Are Getting Hacked. Here's What's Missing.

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

The Langflow CVEs and Dify Vulnerabilities: What Actually Happened Langflow's security problems arrived in waves. CVE-2025-3248 introduced a code injection vulnerability allowing remote code execution through unsanitized user input \10\]. Months la

Kong

# How to Switch LLM Providers Without Downtime

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

AI vendor lock-in is the condition where switching providers requires rewriting application code, reconfiguring infrastructure, or retraining teams. Unlike traditional SaaS lock-in, AI vendor lock-in carries compounding risks: proprietary prompt for

Kong

# MCP Governance: The Foundation of Your Agentic AI Strategy

[Enterprise](/blog/tag)EnterpriseJuly 21, 2026

An AI agent without reliable, governed access to your systems is just an expensive chatbot. The moment agents need to take real action — querying a database, triggering a workflow, calling a partner API — they need an integration layer that was desi

Heather Halenbeck

# How to Proxy Every AI Traffic Pattern Through One Gateway

[Enterprise](/blog/tag)EnterpriseJuly 17, 2026

The first generation of production AI was simple: one application, one model, one API key. That era is over. AI adoption reached 78% of organizations in 2024, up from 55% the year before, per Stanford HAI's 2025 AI Index Report [1] . Enterprises no

Kong

# Kong and ModelOp Partner to Deliver Zero-Trust Security for the Agentic Enterprise

[Enterprise](/blog/tag)EnterpriseJuly 16, 2026

The Problem: As organizations adopt agentic AI, a massive gap exists between compliance approvals and network reality. Often, AI governance is relegated to manual reviews and "paper approvals," meaning network firewalls and gateways have no context

Alex Rice

# AI Governance Platforms Need a Runtime Enforcement Layer

[Enterprise](/blog/tag)EnterpriseJuly 9, 2026

Gartner is explicit that AI governance platforms are not Governance, Risk and Compliance (GRC) tools with an AI label. Where traditional GRC platforms function as static repositories for point-in-time risk assessments, AIGPs are built for real-time,

Heather Halenbeck

# Shadow AI Detection: The Enterprise Governance Guide

[Enterprise](/blog/tag)EnterpriseJuly 7, 2026

Shadow AI is any AI tool, model, or API integration deployed inside an organization without IT or security approval. Unlike sanctioned systems, it operates outside every review process your governance program depends on. That makes detection the fir

Kong

# AI Agent Platforms Are Getting Hacked. Here's What's Missing.

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

The Langflow CVEs and Dify Vulnerabilities: What Actually Happened Langflow's security problems arrived in waves. CVE-2025-3248 introduced a code injection vulnerability allowing remote code execution through unsanitized user input \10\]. Months la

Kong

# How to Switch LLM Providers Without Downtime

[Enterprise](/blog/tag)EnterpriseJuly 2, 2026

AI vendor lock-in is the condition where switching providers requires rewriting application code, reconfiguring infrastructure, or retraining teams. Unlike traditional SaaS lock-in, AI vendor lock-in carries compounding risks: proprietary prompt for

Kong

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo

## step-0

    • Company
    • [About Kong ](/company/about-us)About Kong
    • [Customers ](/customer-stories)Customers
    • [Careers ](/company/careers)Careers
    • [Press ](/company/press-room)Press
    • [Events ](/events)Events
    • [Contact ](/company/contact-us)Contact
    • [Pricing ](/pricing)Pricing
      •    * [Terms](/legal/terms-of-use)
      •    * [Privacy](/legal/privacy-policy)
      •    * [Trust and Compliance](https://trust.konghq.com/)
    • Platform
    • [Kong AI Gateway ](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect ](/products/kong-konnect)Kong Konnect
    • [Kong Gateway ](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway ](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia ](/products/kong-insomnia)Kong Insomnia
    • [Documentation ](https://developer.konghq.com)Documentation
    • [Book Demo ](/contact-sales)Book Demo
    • Compare
    • [AI Gateway Alternatives ](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee ](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs AWS ](/performance-comparison/kong-vsaws)Kong vs AWS
    • [Kong vs IBM ](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Mulesoft ](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
    • [Kong vs Postman ](/performance-comparison/kong-vs-postman)Kong vs Postman
    • Explore More
    • [Kong for Startups ](/solutions/startup-program)Kong for Startups
    • [Open Banking API Solutions ](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions ](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration ](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management ](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy ](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • Open Source
    • [Kong Gateway ](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma ](https://kuma.io/)Kuma
    • [Insomnia ](https://insomnia.rest/)Insomnia
    • [Kong Community ](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • English
  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
[Everything is 200 OK](https://status.konghq.com/)
© Kong Inc. 2026
Interaction mode