Home
Providers
Secureframe
Secureframe
Secureframe automates security and privacy compliance for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, FedRAMP, NIST 800-171 and more. Its Public API is a 112-operation, JSON:API-shaped REST contract over the compliance record of truth — frameworks, requirements, controls, tests, evidence, policies, risks, personnel, devices, cloud resources, repositories, third-party vendors, trust center requests, and the System Security Plan and POA&M artifacts CMMC and FedRAMP assessments are conducted against. Secureframe also runs a first-party hosted MCP server that exposes all 112 operations as agent-callable tools over OAuth 2.1.
Secureframe publishes 42 APIs on the APIs.io network, including Cloud Resource API, Cloud Resource Framework Asset Scope API, Comment API, and 39 more. Tagged areas include GRC, Compliance, SOC 2, ISO 27001, and Risk Management.
Secureframe’s developer surface includes documentation, API reference, pricing, signup flow, support, changelog, engineering blog, and 34 more developer resources.
1 APIs
1 MCP Servers
On this page
Kin Score
APIs 42
MCP Servers 1
Pricing Plans 1
Rate Limits 1
FinOps 1
Security Posture 4
Scopes 1
Resources 41
apis.yml
74 Operational Transparency
0 Create-or-Update Ergonomics
Composite quality — 57.1/100 · strong
Agent readiness — 42/100 · agent ready
Individual APIs this provider publishes, each with its own machine-readable definition.
First-party hosted (remote) Model Context Protocol server exposing the Secureframe compliance platform as 112 tools across 41 categories — 63 read, 49 write — mapped one-for-one...
This document describes the API for reading and updating Cloud Resources.
This document describes the API for reading and creating Framework Asset Scopes. A Framework Asset Scope defines the scope of an asset (e.g., a Cloud Resource) within a Framewor...
This document describes the API for reading, creating, updating, and deleting Comments.
This document describes the API for reading Controls.
This document describes the API for publishing data to a custom integration.
This document describes the API for reading Devices.
This document describes the API for reading and creating Framework Asset Scopes. A Framework Asset Scope defines the scope of an asset (e.g., a Device) within a Framework. Frame...
This document describes the API for reading Evidence.
This document describes the API for staging a direct-to-storage file upload.
This document describes the API for reading Frameworks.
This document describes the API for reading Framework Requirements.
This document describes the API for reading and archiving Integration Connections.
This document describes the API for reading, creating, updating, and deleting Knowledge Base Answers.
This document describes the API for reading, creating, updating, and deleting Knowledge Base Questions.
This document describes the API for reading, creating, updating, and discarding POA&M (Plan of Action & Milestones) items.
This document describes the API for reading Policies. Policies are returned in every status, including drafts and archived ones. Filter with `?q=status:published` to narrow. Not...
This document describes the API for reading and updating Repositories.
This document describes the API for reading Framework Asset Scopes. A Framework Asset Scope defines the scope of an asset (e.g., a Repository) within a Framework. Framework Asse...
This document describes the API for reading Risks.
This document describes the API for creating Security Questionnaires.
This document describes the API for reading, creating, updating, and deleting SSP Duties.
This document describes the API for reading, creating, and deleting SSP Duty Roles.
This document describes the API for reading, creating, updating, and deleting SSP Policies.
This document describes the API for reading and creating SSP Reports.
This document describes the API for reading and updating SSP Report Assessment Objectives.
This document describes the API for reading and updating SSP Report Sections.
This document describes the API for reading and updating SSP Report Section Blocks.
This document describes the API for reading, creating, updating, and deleting SSP Roles.
This document describes the API for reading, creating, updating, and deleting SSP Vendors.
This document describes the API for reading Tasks.
This document describes the API for reading, creating, and updating Tests.
This document describes the API for creating Evidence for a Test.
This document describes the API for creating a Test Export for a Test.
This document describes the API for reading a Test Export.
This document describes the API for reading and archiving Vendors for companies using the Third Party Risk Management.
This document describes the API for reading and updating Trust Center Requests.\ Note: In order to access this API, you need to have paid features enabled for Trust.
This document describes the API for reading and linking User Accounts.
This document describes the API for reading and updating Users.
This document describes the API for creating Evidence for a User.
This document describes the API for retrieving user security settings for the provided API key's company.
This document describes the API for reading and archiving Vendors.
Scroll for all 42
Model Context Protocol servers that expose these APIs to AI agents.
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
Cost, billing, and metering signals for API financial operations.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
OAuth scopes governing access to this provider's APIs.
Get Started 3
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 5
Pagination, idempotency, versioning, errors, and events
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 7
Authentication, authorization, and security posture
Scroll for all 7
Operate 7
Status, limits, changes, and where to get help
Scroll for all 7
Commercial 5
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 2
Properties that don't map to a standard resource type
Source (apis.yml)
aid: secureframe
url: https://raw.githubusercontent.com/api-evangelist/secureframe/refs/heads/main/apis.yml
name: Secureframe
kind: company
description: Secureframe automates security and privacy compliance for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, FedRAMP,
NIST 800-171 and more. Its Public API is a 112-operation, JSON:API-shaped REST contract over the compliance record of truth
— frameworks, requirements, controls, tests, evidence, policies, risks, personnel, devices, cloud resources, repositories,
third-party vendors, trust center requests, and the System Security Plan and POA&M artifacts CMMC and FedRAMP assessments
are conducted against. Secureframe also runs a first-party hosted MCP server that exposes all 112 operations as agent-callable
tools over OAuth 2.1.
deliveryModel:
model: saas
open_source: false
commercial: true
callable_host: false
label: Hosted service · you call their endpoint
confidence: medium
source:
- pricing
generated: '2026-08-28'
method: derived
accessModel:
pricing: paid
onboarding: sales
trial: false
try_now: false
public: false
label: Paid
confidence: high
source:
- plans
- https://secureframe.com/pricing
generated: '2026-08-27'
method: searched
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/secureframe.png
tags:
- GRC
- Compliance
- SOC 2
- ISO 27001
- Risk Management
- CMMC
- FedRAMP
- Security
- Audit
- Trust
tags_raw:
- GRC
- Compliance
- SOC 2
- ISO 27001
- Risk
- CMMC
- FedRAMP
- Security
- Audit
- Trust
- Risk Management
created: '2026-05-08'
modified: '2026-08-27'
specificationVersion: '0.23'
apis:
- aid: secureframe:mcp-server
name: Secureframe MCP Server
description: First-party hosted (remote) Model Context Protocol server exposing the Secureframe compliance platform as 112
tools across 41 categories — 63 read, 49 write — mapped one-for-one onto the Public API operations. Authenticated with
OAuth 2.1 (authorization code + PKCE S256, dynamic client registration) or with a REST API key and secret for headless
clients. Every request runs as a specific Secureframe user in a specific company and is bounded by that user's RBAC permissions.
humanURL: https://mcp.secureframe.com/mcp_docs
baseURL: https://mcp.secureframe.com
tags:
- MCP
- Agents
- GRC
- Compliance
properties:
- type: MCPServer
url: mcp/secureframe-mcp.yml
- type: ToolCrosswalk
url: mcp/secureframe-tool-crosswalk.yml
- type: Documentation
url: https://mcp.secureframe.com/mcp_docs
- type: OAuthScopes
url: scopes/secureframe-scopes.yml
- type: WellKnown
url: well-known/secureframe-well-known.yml
- aid: secureframe:secureframe-cloud-resource-api
name: Secureframe Cloud Resource API
description: This document describes the API for reading and updating Cloud Resources.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Cloud Resource
properties:
- type: OpenAPI
url: openapi/secureframe-cloud-resource-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-cloud-resource-framework-asset-scope-api
name: Secureframe Cloud Resource Framework Asset Scope API
description: 'This document describes the API for reading and creating Framework Asset Scopes.
A Framework Asset Scope defines the scope of an asset (e.g., a Cloud Resource) within a Framework.
Framework Asset Scopes are immutable. Once created, they cannot be modified. To update a scope, create a new resource
with the updated information.'
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Cloud Resource Framework Asset Scope
properties:
- type: OpenAPI
url: openapi/secureframe-cloud-resource-framework-asset-scope-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-comment-api
name: Secureframe Comment API
description: This document describes the API for reading, creating, updating, and deleting Comments.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Comment
properties:
- type: OpenAPI
url: openapi/secureframe-comment-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-control-api
name: Secureframe Control API
description: This document describes the API for reading Controls.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Control
properties:
- type: OpenAPI
url: openapi/secureframe-control-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-custom-integration-api
name: Secureframe Custom Integration API
description: This document describes the API for publishing data to a custom integration.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Custom Integration
properties:
- type: OpenAPI
url: openapi/secureframe-custom-integration-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-device-api
name: Secureframe Device API
description: This document describes the API for reading Devices.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Device
properties:
- type: OpenAPI
url: openapi/secureframe-device-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-device-framework-asset-scope-api
name: Secureframe Device Framework Asset Scope API
description: 'This document describes the API for reading and creating Framework Asset Scopes.
A Framework Asset Scope defines the scope of an asset (e.g., a Device) within a Framework.
Framework Asset Scopes are immutable. Once created, they cannot be modified. To update a scope, create a new resource
with the updated information.'
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Device Framework Asset Scope
properties:
- type: OpenAPI
url: openapi/secureframe-device-framework-asset-scope-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-evidence-api
name: Secureframe Evidence API
description: This document describes the API for reading Evidence.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Evidence
properties:
- type: OpenAPI
url: openapi/secureframe-evidence-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-file-upload-api
name: Secureframe File Upload API
description: This document describes the API for staging a direct-to-storage file upload.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- File Upload
properties:
- type: OpenAPI
url: openapi/secureframe-file-upload-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-framework-api
name: Secureframe Framework API
description: This document describes the API for reading Frameworks.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Framework
properties:
- type: OpenAPI
url: openapi/secureframe-framework-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-framework-requirement-api
name: Secureframe Framework Requirement API
description: This document describes the API for reading Framework Requirements.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Framework Requirement
properties:
- type: OpenAPI
url: openapi/secureframe-framework-requirement-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-integration-connection-api
name: Secureframe Integration Connection API
description: This document describes the API for reading and archiving Integration Connections.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Integration Connection
properties:
- type: OpenAPI
url: openapi/secureframe-integration-connection-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-knowledge-base-answer-api
name: Secureframe Knowledge Base Answer API
description: This document describes the API for reading, creating, updating, and deleting Knowledge Base Answers.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Knowledge Base Answer
properties:
- type: OpenAPI
url: openapi/secureframe-knowledge-base-answer-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-knowledge-base-question-api
name: Secureframe Knowledge Base Question API
description: This document describes the API for reading, creating, updating, and deleting Knowledge Base Questions.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Knowledge Base Question
properties:
- type: OpenAPI
url: openapi/secureframe-knowledge-base-question-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-poa-m-item-api
name: Secureframe POA&M Item API
description: 'This document describes the API for reading, creating, updating, and discarding POA&M
(Plan of Action & Milestones) items.'
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- POA&M Item
properties:
- type: OpenAPI
url: openapi/secureframe-poa-m-item-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-policy-api
name: Secureframe Policy API
description: 'This document describes the API for reading Policies.
Policies are returned in every status, including drafts and archived ones. Filter with
`?q=status:published` to narrow.
Note that `q` free-text search covers a Policy''s name and owner, not the content of the Policy
itself.'
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Policy
properties:
- type: OpenAPI
url: openapi/secureframe-policy-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-repository-api
name: Secureframe Repository API
description: This document describes the API for reading and updating Repositories.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Repository
properties:
- type: OpenAPI
url: openapi/secureframe-repository-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-repository-framework-asset-scope-api
name: Secureframe Repository Framework Asset Scope API
description: 'This document describes the API for reading Framework Asset Scopes.
A Framework Asset Scope defines the scope of an asset (e.g., a Repository) within a Framework.
Framework Asset Scopes are immutable. Once created, they cannot be modified. To update a scope, create a new resource
with the updated information.'
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Repository Framework Asset Scope
properties:
- type: OpenAPI
url: openapi/secureframe-repository-framework-asset-scope-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-risk-api
name: Secureframe Risk API
description: This document describes the API for reading Risks.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Risk Management
tags_raw:
- Risk
properties:
- type: OpenAPI
url: openapi/secureframe-risk-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-security-questionnaire-api
name: Secureframe Security Questionnaire API
description: This document describes the API for creating Security Questionnaires.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- Security Questionnaire
properties:
- type: OpenAPI
url: openapi/secureframe-security-questionnaire-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-duty-api
name: Secureframe SSP Duty API
description: This document describes the API for reading, creating, updating, and deleting SSP Duties.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Duty
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-duty-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-duty-role-api
name: Secureframe SSP Duty Role API
description: This document describes the API for reading, creating, and deleting SSP Duty Roles.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Duty Role
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-duty-role-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-policy-api
name: Secureframe SSP Policy API
description: This document describes the API for reading, creating, updating, and deleting SSP Policies.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Policy
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-policy-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-report-api
name: Secureframe SSP Report API
description: This document describes the API for reading and creating SSP Reports.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Report
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-report-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-report-assessment-objective-api
name: Secureframe SSP Report Assessment Objective API
description: This document describes the API for reading and updating SSP Report Assessment Objectives.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Report Assessment Objective
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-report-assessment-objective-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-report-section-api
name: Secureframe SSP Report Section API
description: This document describes the API for reading and updating SSP Report Sections.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Report Section
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-report-section-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-report-section-block-api
name: Secureframe SSP Report Section Block API
description: This document describes the API for reading and updating SSP Report Section Blocks.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Report Section Block
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-report-section-block-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-role-api
name: Secureframe SSP Role API
description: This document describes the API for reading, creating, updating, and deleting SSP Roles.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Role
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-role-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
- type: Authentication
url: authentication/secureframe-authentication.yml
- type: ErrorCatalog
url: errors/secureframe-problem-types.yml
- type: Conventions
url: conventions/secureframe-conventions.yml
- type: DataModel
url: data-model/secureframe-data-model.yml
- type: Lifecycle
url: lifecycle/secureframe-lifecycle.yml
- type: Deprecation
url: lifecycle/secureframe-lifecycle.yml
- type: RateLimits
url: rate-limits/secureframe-rate-limits.yml
- aid: secureframe:secureframe-ssp-vendor-api
name: Secureframe SSP Vendor API
description: This document describes the API for reading, creating, updating, and deleting SSP Vendors.
humanURL: https://developer.secureframe.com/
baseURL: https://api.secureframe.com
tags:
- SSP Vendor
properties:
- type: OpenAPI
url: openapi/secureframe-ssp-vendor-api-openapi.yml
- type: Documentation
url: https://developer.secureframe.com/
- type: APIReference
url: https://api.secureframe.com/docs
# --- truncated at 32 KB (46 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/secureframe/refs/heads/main/apis.yml
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.
get_provider_artifactsEvery artifact this provider publishes, grouped by type.
get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
get_provider_ratingPRO — composite, band, trend and facet scores.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This provider
curl "https://apis.io/api/v1/providers/secureframe"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/secureframe/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/secureframe/evidence"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms .
A second provider on the same verified email joins the account you already have.