I work in banking in Europe, one of the internet-only ones. We have super rigid governance routines regarding cloud storage. You can’t store a single byte on any cloud service, even incidentally, without a thorough review ensuring that no customer data is present.
Meaning, e.g. there are specific, rigid rules regarding how Postman can be used while developing backend services, to avoid that customer info is inadvertently transmitted during testing.
Of course, it’s a PITA, but it serves its purpose.