> Depending upon its sensitivity classification, customer data is AES-256-GCM encrypted at the server-side before storage. Postman environment variables are covered in this classification and we strongly encourage you to use them to store your authentication keys and passwords. We have also added sessions in the 6.2 release onwards of Postman. We recommend using session variables for any data that you do not want to be synced to Postman's servers.
> Postman environment variables are covered in this classification and we strongly encourage you to use them to store your authentication keys and passwords.
It reads to me that they encrypt Postman environment variables and encourage you to use those.
Not sure what else is "Customer data" in that regard but it seems they consider at least that bit worthy of encryption.
I like the looks of httpie’s new desktop client but no idea if their secret handling is any better.