Home
Providers
Secureframe
Secureframe
Secureframe automates security and privacy compliance for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, FedRAMP, NIST 800-171 and more. Its Public API is a 112-operation, JSON:API-shaped REST contract over the compliance record of truth — frameworks, requirements, controls, tests, evidence, policies, risks, personnel, devices, cloud resources, repositories, third-party vendors, trust center requests, and the System Security Plan and POA&M artifacts CMMC and FedRAMP assessments are conducted against. Secureframe also runs a first-party hosted MCP server that exposes all 112 operations as agent-callable tools over OAuth 2.1.
Secureframe publishes 1 API on the APIs.io network: Public API. Tagged areas include GRC, Compliance, SOC 2, ISO 27001, and Risk.
Secureframe’s developer surface includes documentation, API reference, pricing, signup flow, support, changelog, engineering blog, and 34 more developer resources.
1 APIs
1 MCP Servers
On this page
Kin Score
APIs 2
MCP Servers 1
Pricing Plans 1
Rate Limits 1
FinOps 1
Security Posture 4
Scopes 1
Resources 41
apis.yml
74 Operational Transparency
0 Create-or-Update Ergonomics
Composite quality — 56.3/100 · strong
Agent readiness — 44/100 · agent ready
Individual APIs this provider publishes, each with its own machine-readable definition.
Model Context Protocol servers that expose these APIs to AI agents.
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
Cost, billing, and metering signals for API financial operations.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
OAuth scopes governing access to this provider's APIs.
Get Started 3
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 5
Pagination, idempotency, versioning, errors, and events
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 7
Authentication, authorization, and security posture
Scroll for all 7
Operate 7
Status, limits, changes, and where to get help
Scroll for all 7
Commercial 5
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 2
Properties that don't map to a standard resource type
Source (apis.yml)
aid: secureframe
url: https://raw.githubusercontent.com/api-evangelist/secureframe/refs/heads/main/apis.yml
name: Secureframe
kind: company
description: Secureframe automates security and privacy compliance for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, FedRAMP,
NIST 800-171 and more. Its Public API is a 112-operation, JSON:API-shaped REST contract over the compliance record of truth
— frameworks, requirements, controls, tests, evidence, policies, risks, personnel, devices, cloud resources, repositories,
third-party vendors, trust center requests, and the System Security Plan and POA&M artifacts CMMC and FedRAMP assessments
are conducted against. Secureframe also runs a first-party hosted MCP server that exposes all 112 operations as agent-callable
tools over OAuth 2.1.
deliveryModel:
model: saas
open_source: false
commercial: true
callable_host: false
label: Hosted service · you call their endpoint
confidence: medium
source:
- pricing
generated: '2026-08-28'
method: derived
accessModel:
pricing: paid
onboarding: sales
trial: false
try_now: false
public: false
label: Paid
confidence: high
source:
- plans
- https://secureframe.com/pricing
generated: '2026-08-27'
method: searched
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/secureframe.png
tags:
- GRC
- Compliance
- SOC 2
- ISO 27001
- Risk
- CMMC
- FedRAMP
- Security
- Audit
- Trust
created: '2026-05-08'
modified: '2026-08-27'
specificationVersion: '0.23'
apis:
- aid: secureframe:public-api
name: Secureframe Public API
description: REST API providing programmatic access to Secureframe controls, frameworks, framework requirements, tests,
evidence, policies, tasks, risks, personnel, devices, cloud resources, repositories, third-party risk vendors, knowledge
base answers, trust center requests, and the SSP and POA&M records used in CMMC and FedRAMP assessments. 76 paths, 112
operations, 41 resource tags. Resource-oriented and JSON:API-shaped, with Lucene-syntax search, page/per_page pagination
and include/relationships compound documents. Authenticated with an API key and secret sent as a single space-separated
Authorization header; permissions are inherited from the RBAC role of the user the key belongs to.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- GRC
- Compliance
- REST
- CMMC
- Audit
properties:
- type: OpenAPI
url: openapi/secureframe-public-api-openapi.yml
- type: Overlay
url: overlays/secureframe-public-api-overlay.yaml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:mcp-server
name: Secureframe MCP Server
description: First-party hosted (remote) Model Context Protocol server exposing the Secureframe compliance platform as 112
tools across 41 categories — 63 read, 49 write — mapped one-for-one onto the Public API operations. Authenticated with
OAuth 2.1 (authorization code + PKCE S256, dynamic client registration) or with a REST API key and secret for headless
clients. Every request runs as a specific Secureframe user in a specific company and is bounded by that user's RBAC permissions.
humanURL: https://mcp.secureframe.com/mcp_docs
baseURL: https://mcp.secureframe.com
tags:
- MCP
- Agents
- GRC
- Compliance
properties:
- type: MCPServer
url: mcp/secureframe-mcp.yml
- type: ToolCrosswalk
url: mcp/secureframe-tool-crosswalk.yml
- type: Documentation
url: https://mcp.secureframe.com/mcp_docs
- type: OAuthScopes
url: scopes/secureframe-scopes.yml
- type: WellKnown
url: well-known/secureframe-well-known.yml
common:
- type: Website
url: https://secureframe.com/
- type: DeveloperPortal
url: https://developer.secureframe.com/
- type: Developer
url: https://developer.secureframe.com/
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Pricing
url: https://secureframe.com/pricing
- type: Plans
url: plans/secureframe-plans-pricing.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- type: Login
url: https://app.secureframe.com/login
- type: SignUp
url: https://secureframe.com/request-demo
- type: Support
url: https://secureframe.com/contact
- type: HelpCenter
url: https://help.secureframe.com/
- type: StatusPage
url: https://status.secureframe.com/
- type: ChangeLog
url: https://secureframe.com/product-updates
- type: ChangeLog
url: changelog/secureframe-changelog.yml
- type: TermsOfService
url: https://secureframe.com/terms
- type: PrivacyPolicy
url: https://secureframe.com/privacy-policy
- type: GitHubOrganization
url: https://github.com/secureframe
- type: LinkedIn
url: https://www.linkedin.com/company/secureframe
- type: Blog
url: https://secureframe.com/blog
- type: Integrations
url: https://secureframe.com/integrations
- type: MCPServer
url: mcp/secureframe-mcp.yml
- type: ToolCrosswalk
url: mcp/secureframe-tool-crosswalk.yml
- type: AgentSkill
url: skills/_index.yml
- type: LLMsTxt
url: llms/secureframe-llms.txt
- type: WellKnown
url: well-known/secureframe-well-known.yml
- type: Conformance
url: conformance/secureframe-conformance.yml
- type: Compliance
url: https://trust.secureframe.com/
- type: TrustCenter
url: security/secureframe-trust-center.yml
- type: Security
url: security/secureframe-vulnerability-disclosure.yml
- type: VulnerabilityDisclosure
url: security/secureframe-vulnerability-disclosure.yml
- type: DomainSecurity
url: security/secureframe-domain-security.yml
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: OAuthScopes
url: scopes/secureframe-scopes.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: Packages
url: packages/secureframe-packages.yml
- type: Overlay
url: overlays/secureframe-public-api-overlay.yaml
- type: FinOps
url: finops/secureframe-finops.yml
integrations:
- name: Service Providers
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
x-enrichment:
date: '2026-08-27'
status: enriched
artifacts_added: 22
pass: local-v1
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.
get_provider_artifactsEvery artifact this provider publishes, grouped by type.
get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
get_provider_ratingPRO — composite, band, trend and facet scores.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This provider
curl "https://apis.io/api/v1/providers/secureframe"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/secureframe/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/secureframe/evidence"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms .
A second provider on the same verified email joins the account you already have.