Last Updated on August 30, 2026 by Mat Diekhake
Security Overview
Poshmark is a large social‑commerce and resale marketplace running on modern cloud infrastructure. Technical scans show valid HTTPS, reputable hosting, and no current malware or phishing flags. Its external attack surface is rated as having a generally strong security posture, with some configuration findings but no active compromise.
SSL/TLS & Encryption
Poshmark enforces HTTPS across its platform and uses a valid TLS certificate.
- HTTPS: Enabled and required
- Certificate: Valid TLS certificate (A+ rating on independent SSL tests)
- Issuer: Major certificate authority via AWS CloudFront edge
- Mixed‑content issues: None reported in automated scans
- Weak cipher suites: TLS 1.2+ with modern ciphers; no weak‑cipher warnings in public reports
All browser–server communication is encrypted using current TLS standards.
Hosting & Infrastructure
- Hosting provider: AWS CloudFront (GLOBAL) edge network
- Server location: Edge endpoint reported in Paris, France for poshmark.com at scan time
- CDN usage: Global CDN via AWS CloudFront for content delivery and performance
- Reverse proxy: CloudFront acts as reverse proxy and edge security layer
- Domain founded: May 10, 2011 (Registered: 2011‑05‑10)
- Uptime reputation: Rated 97/100 Trust Score with “No Threats Found” by PCrisk’s website scanner
- Infrastructure risks: UpGuard notes some configuration issues (e.g., secure/HttpOnly cookies not consistently enforced, CSP warnings), but no critical infrastructure‑level risk or compromise
Overall, Poshmark’s infrastructure is typical of a large, cloud‑hosted e‑commerce platform.
Malware & Phishing Scan
External automated checks show:
- Malware detection: 0/91 threat engines flagged poshmark.com; no malware detected
- Phishing flags: Not listed in major phishing or spam blocklists (Google, Spamhaus, SURBL, Phishtank, etc.)
- Blacklist checks: Clean across 91 checked security engines
- Redirect behavior: Standard HTTPS redirects only; no malicious or deceptive redirect chains reported
- Suspicious scripts: No flagged external resources or iframes; 71 external links and 18 referenced domains all clean at scan time
- Third‑party injections: Third‑party services (AWS, SendGrid, Salesforce, Google Analytics, etc.) appear as documented supply‑chain components rather than unauthorized injections
There is no indication that Poshmark is being used to distribute malware or conduct phishing at the technical level.
Privacy & Data Handling
Poshmark processes data typical of a large marketplace:
- Data collected:
- Account and profile information
- Listings, orders, and transaction data
- Payment‑related metadata (via payment processors)
- Device and usage analytics
- Tracking technologies:
- Google Analytics
- Google Tag Manager
- Facebook integrations
- Email and marketing tools such as SendGrid, Mailchimp, Klaviyo
- Cookie behavior:
- Uses cookies for sessions, preferences, and tracking
- UpGuard notes that secure and HttpOnly flags are not consistently enforced on all cookies, which increases theoretical exposure to interception or client‑side access
- Analytics providers:
- Google Analytics
- Salesforce, Statuspage, and other SaaS tools for operations and communication
- Privacy risks:
- Large volume of PII and transaction data due to its role as a marketplace
- Some cookie and CSP configuration findings, but no evidence of active exploitation
Poshmark publishes a privacy policy and terms of service and is documented as SOC 2 compliant and CSA Star Level 1 compliant, indicating structured governance around data handling.
App Permissions (If Applicable)
The Poshmark mobile apps (iOS/Android) typically request:
- Notifications: For offers, messages, and order updates
- Camera and file access: For listing photos and image uploads
- Optional location access: For shipping, discovery, and localized experiences
These permissions match the app’s purpose (social resale marketplace) and do not appear excessive or unrelated to core functionality.
Breach History
Poshmark has experienced a publicly disclosed data breach:
- Known breach: In 2019, Poshmark reported a security incident involving unauthorized access to user account information (e.g., hashed passwords and profile data).
- Response: The company notified users, recommended password changes, and strengthened security controls.
- Recent incidents: No major new breaches have been publicly reported in current vendor‑risk profiles.
- Leaked databases / credential‑stuffing: The 2019 incident led to exposure of account data, but there is no evidence of ongoing compromise of the current platform in recent technical scans.
The historical breach is relevant to overall risk history but does not indicate current technical compromise.
Security Certifications
Poshmark’s documented security program includes:
- SOC 2: SOC 2 compliant
- ISO 27001: Not explicitly listed in public profiles; primary emphasis is on SOC 2 and CSA Star
- GDPR compliance: Listed as GDPR‑aligned in vendor‑risk documentation
- HIPAA: Not relevant to Poshmark’s business model (fashion and home goods marketplace)
- PCI DSS: Payment processing handled via established providers; PCI DSS obligations are met at the processor level
- CSA STAR: CSA Star Level 1 compliant
These certifications and frameworks indicate a structured, mature security posture for a consumer marketplace.
Final Safety Verdict
Poshmark is technically safe to use in its current state. It runs on encrypted HTTPS/TLS, uses reputable cloud infrastructure (AWS CloudFront), and shows a clean profile in malware and phishing scans. External assessments highlight some cookie and CSP configuration issues and a historical breach in 2019, but current technical scans and vendor‑risk reports do not show active compromise or elevated technical risk. For users, Poshmark meets modern technical security expectations, with the caveat that strong, unique passwords and two‑factor authentication are especially advisable given its past breach history.
Domain: poshmark.com
