RXed AI News

AI to the bone.
@RXed_EU
Audited 2026-08-13 · RXed table v1.0

Secureframe

Visit secureframe.com
“Automate compliance. Improve security. Reduce risk.” — the vendor’s own words

The best protocol surface in GRC and the most honest model disclosure I have found in the category: 100+ MCP tools across 38 categories with full read and write, and a support page that names OpenAI GPT-5 generation and says plainly that Secureframe trains no models of its own. The AI itself is thin behind that. There is no eval surface beyond a thumbs-up button, no agent layer, and the hosted MCP runs in the US and UK only.

Best for: Engineering-led teams who want their compliance program queryable and writable from Claude Code or Cursor, defense contractors working CMMC 2.0 and FedRAMP through the Defense tier, and anyone who needs the vendor to state on the record which models touch their data.
Scope17/20
Quality6/10
Where the quality sits
6Reactive
5Retrieval & Memory
8Orchestration
5Validation
5Models
Enterprise platformSecurity & ComplianceAutomation & AgentsProductivityFreemium
Vendor
Secureframe, Inc. · secureframe.com
Origin
US — San Francisco
Pricing
Fundamentals From $5,000/year · Complete Quote only · Defense Quote only
Users (official only)
6000+ customers (source, 2026-08-13)
FundamentalsFrom $5,000/yearone framework, infrastructure monitoring, evidence collection, personnel, risk and policy management, Trust Center, one custom automated test
CompleteQuote onlyadds advanced third-party risk, advanced risk management, advanced user access reviews, advanced Trust Center, advanced questionnaire automation, SSO and SCIM, unlimited custom automated tests
DefenseQuote onlyadded March 2026 for CMMC 2.0 and the defense industrial base: SPRS score tracker, SSP, POA&M, managed CUI enclave and virtual desktops

Renewal escalation is the most consistent complaint in independent reviews, driven by headcount growth pushing you up a tier or by adding a second framework. Experienced buyers negotiate a 24-36 month price cap before signing and get add-on framework pricing in writing upfront. Note the published $5,000 floor and the reported $10,000+ real-world entry point are not the same number.

checked 2026-08-13 · vendor pricing page

Element scores

Reactive
Retrieval & Memory
Orchestration
Validation
Models
Primitives
Pr6
Prompts
Em5
Embeddings
Cx7
Context
Tr7
Tracing
Lg7
LLM
Compositions
Fc9
Function calling
Vx5
Vector store
Rg8
RAG
Gr6
Guardrails
Mm4
Multimodal
Deployment
Ag6
Agents
Ft
Fine-tuning
Fw7
Frameworks & harnesses
Ev3
Evaluations
Sm
Small models
Emerging
Ma3
Multi-agent
Sy
Synthetic data
Pc9
Protocols
In6
Interpretability
Th4
Thinking models
Tap or hover any element to see why it got that score.

Strengths

Two things stand out and both are about honesty. First, the protocol work. The hosted MCP server exposes over 100 tools across 38 categories with the same read and write coverage as the REST API, authenticates through standard OAuth 2.1 so no secret ends up in a config file, and inherits the connecting user's existing permissions rather than gating everything behind an admin token. It is hosted, so there is nothing to deploy or patch. If your engineers already live in Claude Code or Cursor, this is the deepest compliance surface available to them today. Second, the model disclosure. Secureframe's support documentation names the model family, says it updates periodically, and states outright that it does not train, fine-tune or host its own models. Customer data sits in Secureframe's own AWS estate, logically segregated, and the one exception where documents pass into OpenAI vector stores is disclosed with its retention and no-training terms attached. Competitors in this category either say nothing or point at a two-year-old blog post. Underneath the AI sits a platform with 300+ integrations, 35+ frameworks including CMMC 2.0 and FedRAMP, and support staffed by former auditors that independent reviewers rate as the best in the peer group.

Honest dings

The AI is thinner than the plumbing. There is no eval surface at all beyond a thumbs up or down on a remediation reply, no published accuracy number, and independent reviewers specifically report questionnaire answers coming back incorrect or incomplete, which is exactly the failure you cannot detect without measurement. Nothing coordinates: eight AI features run as separate single-purpose automations while competitors ship named agent crews. Comply AI is enabled by default rather than opt-in. And MCP write access covers creates, updates and deletes with no inline approval gate, so the only thing between an assistant and your compliance record is the operator reading the confirmation prompt. For European buyers there is one hard constraint: the hosted MCP has US and UK endpoints and no EU one. Commercially, the published $5,000 floor is not what most teams pay, with independent trackers putting the real entry point at $10,000-$35,000 and renewal escalation the loudest recurring complaint.

Prices and details change — this passport is re-verified at least quarterly.
Sources (16) — every claim traceable

Every audit lists the research it rests on — transparency and traceability are the product. Tools evolve: each audit is a snapshot of its audit date, and re-audits supersede older versions (kept below for reference).

  • support.secureframe.com/en/articles/15111072-overvi… — Official: all eight AI features and where they live, global Comply AI toggle in Settings, opt-in OpenAI data-sharing authorisation for questionnaire AI, evidence validation limits of 10MB and 100 pages for PDFs and images, bulk vendor answers up to 50 questions in parallel, policy assistant action menu including translation, and the FAQ naming OpenAI GPT-5 generation with the statement that Secureframe does not train, fine-tune or host its own models. Also discloses temporary OpenAI vector stores for vendor assessment. Page still contains unedited internal drafting notes. (accessed 2026-08-13)
  • secureframe.com/blog/secureframe-mcp-server — Official 05/08/2026: hosted MCP server with 100+ tools across 38 categories, example tool names by category, read and write parity with the REST API, permission inheritance from the connecting user, US and UK regional endpoints, CEO quote, and the explicit warning that an assistant can create, update and delete real data (accessed 2026-08-13)
  • support.secureframe.com/en/articles/15111553-secure… — Official setup guide 04/08/2026: MCP URLs mcp.secureframe.com and mcp-uk.secureframe.com, OAuth 2.1 sign-in versus API key auth, who is allowed to connect a client, Claude Code / Claude Desktop / Cursor configuration, and best-practice guidance to review writes before confirming (accessed 2026-08-13)
  • secureframe.com/pricing — Official packages page: Fundamentals starting at $5,000/year, Complete and Defense on quote, and the full feature matrix showing one custom automated test on Fundamentals versus unlimited on Complete, Comply AI for Policies and Comply AI for Remediation placement, and the Defense tier CMMC contents (accessed 2026-08-13)
  • secureframe.com — Official homepage: 6,000+ customers, the four named AI capabilities, and the framework list covering SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST and CMMC (accessed 2026-08-13)
  • secureframe.com/integrations — Official: 300+ integrations across 15 categories, plus a pointer to the API and custom integrations for anything not covered (accessed 2026-08-13)
  • secureframe.com/about — Official company page: founded 2020, 200+ employees, $79M raised, six hubs across three countries (San Francisco, New York, Austin, Denver, Toronto, London) (accessed 2026-08-13)
  • support.secureframe.com/en/articles/15111813-2026-p… — Official 2026 release log: User Access Reviews GA, the guided ComplyAI risk workflow requiring description and owner before generating, audit log links to changed items, and onboarding localisation into French, German and Spanish (accessed 2026-08-13)
  • support.secureframe.com/en/articles/15111264-comply… — Official 13/07/2026: Comply AI for Remediation generates infrastructure-as-code fixes for AWS, Azure and GCP across CLI, CloudFormation, CDK, ARM and GCP Deployment Manager, with a follow-up chatbot (accessed 2026-08-13)
  • secureframe.com/products/questionnaires — Official: questionnaire automation described as machine-learning powered with generative AI drafting, customers reported saving 35 hours per month, Knowledge Base as the system of record, zip export of answers with evidence and policies (accessed 2026-08-13)
  • github.com/secureframe/secureframe-mcp-server — Official repo for the earlier self-hosted MCP server: 11 read-only tools, Lucene query syntax, US and UK API endpoints, public beta disclaimer telling users to validate AI-generated insights. Superseded by the hosted server but useful for seeing how far the surface has moved. (accessed 2026-08-13)
  • soc2auditors.org/insights/secureframe-review — Independent 08/07/2026: G2 4.7/5 across 700+ reviews, 6,000+ customers versus Vanta 16,000+ and Drata 8,000+, base pricing $10,000-$35,000/year and enterprise $50,000+, renewal price creep as the top complaint, advice to negotiate a 24-36 month cap, and a peer comparison table (accessed 2026-08-13)
  • compliancerated.com/tools/secureframe — Independent: G2 4.7 across 789 reviews, reported starting price around $7,500/year and average deal around $20,500, and the recurring criticisms that AI-generated questionnaire answers are sometimes incorrect or incomplete and the integration library is thin for niche or legacy tools (accessed 2026-08-13)
  • soc2auditors.org/software/secureframe — Independent software record 24/07/2026: G2 4.7 across 809 reviews, no free trial, pricing opacity and integration gaps as recurring complaints, and wire confirmation of the $56M Series B on 23/02/2022 bringing total funding to $79M (accessed 2026-08-13)
  • research.contrary.com/company/secureframe — Independent company research: founded 2020 in San Francisco by Shrav Mehta and Natasja Nielsen, $20M ARR reported October 2023, funding history across seed, $18M Series A and $56M Series B, and a customer survey reporting a 26.7% decrease in compliance costs and 5.8 hours saved per week (accessed 2026-08-13)
  • secureframe.com/frameworks-glossary/iso-42001 — Official: ISO/IEC 42001 supported as a framework in the platform, relevant for customers governing their own AI systems (accessed 2026-08-13)