Secureframe Reviews

Overall rating
Filter by
Time used
26 Reviews

- Industry: Events Services
- Company size: 51–200 Employees
- Used Monthly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
Easy to stay organized and rest assured that we're compliant
Reviewed on 2024/09/17
Secureframe ensures that our team's policy documentation is recorded and kept up to date, and...
Secureframe ensures that our team's policy documentation is recorded and kept up to date, and requires that every employee go through annual training on these policies and more. It makes it easy for our HR and IT teams to know who has accomplished the required tasks on time, and can send out personalized reminders to those who have yet to do so.
It also automatically pulls Common Vulnerabilities and Exposures data for our connected integrations, which helps our team prioritize security tasks.
Pros
Any time there is a task that needs to be done, an email is sent out by Secureframe with explicit instructions on how to accomplish it. Whether that be a new employee going through onboarding, annual SOC 2 compliance, or verifying that security policies are up to date, Secureframe ensures that the important tasks are completed in a timely manner. It would be chaos to try and manage all of this another way, and our team breathes easy knowing that we're covered by their software.
Cons
Our team receives security questionnaires at least weekly from our prospective customers, which can come in a variety of formats (Excel, Word, external site, etc). While there is a questionnaire library feature within Secureframe, it is currently limited to being able to read and fill out Excel spreadsheets. If this were the only way we received questionnaires, it would be perfect. Alas, that's not the world we live in.
Thankfully, the Secureframe success/support team has been receptive to feedback around how this could be improved and have relayed those thoughts to their Product team.
- Industry: Professional Training & Coaching
- Company size: 2–10 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
First Time CTO
Reviewed on 2024/11/15
I had a great experience with the service and would likely use it again in the future.
I had a great experience with the service and would likely use it again in the future.
Pros
The friendly support staff answered every question I had about the process or what needed to be documented in relation to the SOC2 certification I was looking to achieve. The many integrations removed a lot of work I would need to do in order to verify my cloud environment along with my other venders. They broke down the process into many steps allowing me to do a bit at a time and eventually get audited.
Cons
Like i said in the pros section, I enjoyed how they broken down the process into many different steps. Some of those steps were vague and i needed to contact Secureframes support to learn what I needed to do in order to complete the task. Like I said the support staff were great but I think the examples or explanations could have been better so I would not need to chat / email / call the support in the first place.
Alternatives Considered
A-LIGNReasons for Switching to Secureframe
I have a friend who started using Secureframe in relation to his startup and enjoyed the service which is the main reason I chose secureframe- Industry: Health, Wellness & Fitness
- Company size: 2–10 Employees
- Used Daily for 1-5 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
Great people and solid service
Reviewed on 2025/02/25
Very positive. SOC2 comes up a lot in my circles and will for sure recommend them.
Very positive. SOC2 comes up a lot in my circles and will for sure recommend them.
Pros
We reviewed a few alternatives to SecureFrame for our SOC2 compliance, and they were either buggy, or had very pushy sales people. SecureFrame staff has been very helpful and proactive, and the price has been good.
The UI has been super easy to navigate given the complexity of the software.
Cons
Sign in with Google is an upsell. Would have been nice to see this included.
Reasons for Choosing Secureframe
Trustcloud was buggy and didn't have good UX.Switched From
TrustCloudReasons for Switching to Secureframe
Price and experience with sales people was very positive.- Industry: Financial Services
- Company size: 11–50 Employees
- Used Weekly for 2+ years
-
Review Source
Overall rating
- Ease of Use
- Likelihood to recommend 7.0 /10
Good experience with SecureFrame, just needs some tuning
Reviewed on 2025/03/18
The overall experience is really good though. Like I mentioned about having the steps included, it...
The overall experience is really good though. Like I mentioned about having the steps included, it really helps a lot, and using SF has helped me learn some finer configuration aspects of Azure.
Pros
- I really like how a lot of the tests have steps that show how to pass them.
Although a lot of those procedures get outdated pretty quickly with how fast interfaces change each year, they give a great starting point to figure it out.
- I also like how once a test has its configuration set, you don't have to re-evidence that test each year. So it's kind of set-and-forget, until (if) it falls out of compliance.
Cons
- It would be great if each test had its own unique test number. It can be difficult to keep straight which test is which, as they're currently grouped under common control numbers. Take these for example:
NET-05
Security policy alerting
Security solution alerting
VM-02
External vulnerability scanning
Vulnerability and threat tracking
When looking at the titles, which test does what? It's hard to tell, so when I group evidence or keep personal notes, I always have to go back and figure out why the tests are different. In addition, it would make things way easier to reference a specific test number when collaborating with others.
- The test view filters don't stick very well. I kept having to re-save my view filters when logging in, then I just stopped trying.
- It would be helpful if zip files were a default file type for uploading. Not a big deal, but a bit of a nuisance to keep having to enable it.
- Industry: Market Research
- Company size: 51–200 Employees
- Used Monthly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
Excellent Solution for tracking Compliance, Security, SOC2
Reviewed on 2024/09/26
Super easy to manage and complete trainings, track overall team compliance status and nudge people...
Super easy to manage and complete trainings, track overall team compliance status and nudge people and track expirations.
Pros
Very helpful interface, super easy to follow and manage tasks, both as an admin and employer
Cons
Initial onboarding can be problematic. Sign up links should be available for 7 days vs. 24 hours as onboarding a new joiner can take longer than a day.
Alternatives Considered
SprintoReasons for Switching to Secureframe
Stronger impression from sales conversations, higher quality and more comprehensive- Industry: Computer Software
- Company size: 2–10 Employees
- Used Monthly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
SecureFrame is an invaluable tool for CTOs
Reviewed on 2024/09/29
PCI Compliance is a truly daunting process, but SecureFrame helps me understand what exactly we...
PCI Compliance is a truly daunting process, but SecureFrame helps me understand what exactly we need to do as an organization to stay compliant. Even with SecureFrame, there is still a lot of ongoing work that needs to be done.
Pros
SecureFrame is easy to setup, and integrates with nearly every application our business uses. It has saved us having to hire someone to monitor PCI compliance.
Cons
Probably the one issue I have is that when meeting the criteria for a "test", the system requires you to upload a document when often all that is required is an attestation or verbal explanation of how your company meets that critiera.
Alternatives Considered
SprintoReasons for Switching to Secureframe
We felt the support was going to be a little more personal.- Industry: Computer Software
- Company size: 11–50 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
How Secureframe Revolutionized Our ISO 27001 Compliance Process
Reviewed on 2024/09/23
We just completed our annual surveillance audit, and it went incredibly smoothly. Our external...
We just completed our annual surveillance audit, and it went incredibly smoothly. Our external auditor, who’s quite old-school, was initially skeptical of Secureframe, especially its ability to integrate with our systems and provide real-time compliance evidence. By the end of the audit, he said it was the best compliance tool he’d ever seen and planned to recommend it to his clients.
If that wasn’t enough, their support team is fantastic. Our Customer Success Manager, [sensitive content hidden], is super responsive, often replying to emails within the hour. If he can’t address something immediately, he loops in his team, and they follow up just as quickly.
We couldn’t be happier with Secureframe and are excited to expand its usage as our business scales and we explore support for more frameworks.
Pros
We used Secureframe to streamline our ISO 27001 compliance efforts. Before that, we worked with consulting companies that either had their own, not-so-great compliance tools or had us managing everything manually with Excel files and Dropbox—an incredibly tedious process. A colleague recommended Secureframe, and it’s been a complete game changer for us.
The integration features are outstanding. We connected it to our Azure account (and other SaaS platforms we use), and it immediately identified configuration changes we needed to make. The system provided easy-to-follow instructions to help us harden our setup and ensure compliance with our policies. This automation not only made the process smoother, but it also simplified showing evidence of controls to auditors.
Secureframe’s built-in content management system for policies is another great feature. It tracks version history and allows employees to log in and review policies based on their roles. This ensures everyone is reviewing the required policies annually for compliance.
I also found the Vendor section extremely useful. It enables us to assess and rate the risks associated with our suppliers and keep track of their compliance documents. The integrated risk register is another standout feature. While I could go on about many more features, these are the ones that have been particularly impactful for us.
Cons
From an integration standpoint, all of our major cloud and SaaS suppliers are included, but I wish there were a few more options, or if some of the integrations were a little more robust.
- Industry: Staffing & Recruiting
- Company size: 201–500 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
Secureframe: An ISO 27001 Game Changer!
Reviewed on 2024/07/22
Pros
Single repository and pane of glass for all things GRC. In our case we have an urgent imperative to get ISO 27001 Certified by year end. Tremendous value compared to Vanta and Drata. Great onboarding experience and dedicated account manager have made this process so much easier. The interface is logical, easy to navigate, and we were up and running in no time at all. I love how tests are cross-mapped to controls. The tests also rpovide clear guidance and instructions so providing suitable evidence and workarounds has proven quite easy. I also have to say our advisor has been great; she is a GRC professional, an auditor I believe so we are getting first-class consulting for the price of admission. I have learned so much from her, not just about Secureframe but about ISO in general. Secureframe also has numerous conteatcs in terms of audits, pen testing and so forth, so again, everything is provding to be so easy for us. I coudl not imagine meeting this urgent complaince goal without this partnership.
Cons
Some of the integrations (Azure, for example) rendered less than great results or could not connect for some reason (probably on MS side). You can bypass these however, by other means, so this is not really a stopper in my view.
Other platorms provide a real-time comparison for other frameworks, even though you have not paid for them. I was told that we can request to see what out status would be at any time, however.
- Industry: Investment Management
- Company size: 11–50 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
Treasury Curve Review
Reviewed on 2025/01/30
Our firm uses it daily. It helps with reducing risk, improving communication and productivity.
Our firm uses it daily. It helps with reducing risk, improving communication and productivity.
Pros
The product is great for managing critical daily items
Cons
Learning curve for me. It took a few weeks to learn the lingo.
- Industry: Medical Devices
- Company size: 51–200 Employees
- Used Daily for 1-5 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 9.0 /10
Good platform, excellent support
Reviewed on 2025/03/19
Pros
Customer support team is extremely helpful and responsive. Platform is well designed, great automation features. Easy to use.
Cons
Not all integrations prove to be helpful, unclear what setting up an integration will accomplish beforehand. Some operations throw unexplained errors sometimes, but one can generally work around issues and support has been excellent.
- Industry: Computer Software
- Company size: 11–50 Employees
- Used Monthly for 2+ years
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
Great way to simplify SOC2 compliance and tracking
Reviewed on 2024/11/20
Implementation was easy, and provided policy docs helped us have a great starting point. They also...
Implementation was easy, and provided policy docs helped us have a great starting point. They also had a great customer success team to help us get things going, and partners for low cost, but reputable, audits and penetration tests. We have used it for SOC2 type 1 and type 2.
Pros
It was extremely simple to get started, and they have everything we needed to get SOC2 compliant and maintain monitoring without having to go through a lengthy process. For a startup where SOC2 is important, but our team doesn't have budget for a dedicated security and compliance team, it was great. The integrations with the 3rd party applications for ongoing monitoring were great, and the continuous compliance checklist is helpful as well. We have used it for SOC2 type 1 and type 2.
Cons
The device management and asset tracking could be better, but seems to be improving. I also wish the tasks for team members for ongoing activities like yearly security trainings, device management, etc. would be more clear. Last, adding HIPPA compliance checklists without a significant additional cost or separate process would be nice.
- Industry: Financial Services
- Company size: 201–500 Employees
- Used Daily for 6-12 months
-
Review Source
Overall rating
- Ease of Use
- Likelihood to recommend 9.0 /10
Streamlined Compliance with Minimal Effort
Reviewed on 2024/11/19
Pros
Secureframe provides a seamless way to manage and automate compliance processes, saving significant time and effort. The intuitive interface, robust integrations with tools like AWS and Google Workspace, and the clear guidance for SOC 2 and ISO PCI-DSS audits make it invaluable. The ability to continuously monitor systems and simplify evidence collection is a game changer for ensuring audit readiness.
Cons
the setup process can feel a bit overwhelming initially without proper guidance, though their support team is helpful. It would also be beneficial to have more customization options for smaller, niche compliance frameworks.
- Industry: Computer Software
- Company size: 51–200 Employees
- Used Weekly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 7.0 /10
Solid Security Tool
Reviewed on 2024/09/19
Pros
Secureframe is actively developing its platform so missing features are usually on the roadmap
Cons
There is a general lack of work management integrations so all work has to be tracked in Secureframe itself. This gives my team multiple sources of truth.
- Industry: Telecommunications
- Company size: 11–50 Employees
- Used Weekly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Easy to Use
Reviewed on 2024/09/12
Very thankful for Secureframe. It has been very helpful in preparing for our upcoming ISO audit.
Very thankful for Secureframe. It has been very helpful in preparing for our upcoming ISO audit.
Pros
Secureframe was very easy to use and makes ISO compliance understandable
Cons
Sometimes it is not obvious how to do something in Secureframe, however I have a contact who is very responsive and helpful with my questions so that hasn't been a major issue.
- Industry: Computer Software
- Company size: 51–200 Employees
- Used Weekly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Best GRC on the market
Reviewed on 2024/09/23
I have been using Secureframe for two years. The platform is very easy to navigate and integrate...
I have been using Secureframe for two years. The platform is very easy to navigate and integrate with vendors and keep your policies and procedures organized. The ease of onboarding is a plus.
Pros
Easy to implement and excellent customer success management team.
Cons
Nothing negative to report. Things have been working out just fine.
- Industry: Financial Services
- Company size: 2–10 Employees
- Used Weekly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Secureframe makes audit readiness a breeze
Reviewed on 2024/09/30
The experience with Secureframe was great from start to finish. They were just and email or call...
The experience with Secureframe was great from start to finish. They were just and email or call away if help was needed.
Pros
Secureframe helped us become SOC ready and was easy to use.
Cons
Some of the step by step remedies were a little out dated, but still invaluable.
- Industry: Telecommunications
- Company size: 51–200 Employees
- Used Weekly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
Secureframe UI
Reviewed on 2024/09/23
Pros
very easy to use the UI and the flow of info
Cons
Some say that Secureframe limits access for non-users, which can impact collaboration
- Industry: Computer Software
- Company size: 51–200 Employees
- Used Monthly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
Secure Frame compliance certification
Reviewed on 2024/12/03
If we end up going for a SOC 2 Type II, I can’t see why we wouldn’t use them.
If we end up going for a SOC 2 Type II, I can’t see why we wouldn’t use them.
Pros
The Soc2 compliance process is smooth withe ease of access and navigation and nice audit tool that got it done in time
Cons
Initially It gives you a long list of things to do. There are times when you don’t have to do 100% of those things – you have to hit 90-something. I think their prioritization is good,
- Industry: Outsourcing/Offshoring
- Company size: 11–50 Employees
- Used Monthly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Secureframe will help get you where you need to be !
Reviewed on 2024/09/17
Excellent service. Extremely knowledgeable staff . Very prompt to answer questions that arise...
Excellent service. Extremely knowledgeable staff . Very prompt to answer questions that arise throughout the process. I highly recommend their services.
Pros
They genuinely want to see you succeed. They are always responsive and demonstrate true professionalism. Highly recommend their services and I personally look forward to all of out future interactions.
Cons
There was really no downside to my interactions with Secureframe.
- Industry: Information Technology & Services
- Company size: 2–10 Employees
- Used Monthly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 7.0 /10
Great Tool for Compliance and Audit
Reviewed on 2024/08/27
We've been using Secureframe for one of the clients to organize all the evidence for SOC audits and...
We've been using Secureframe for one of the clients to organize all the evidence for SOC audits and it's been really helpful to present to the auditors.
Pros
Great tool to collect and organize the evidence for audits
Cons
needs constant verification of instance running on each system. Maybe automation to automatically register or detect.
- Industry: Computer Software
- Company size: 2–10 Employees
- Used Monthly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 8.0 /10
- Industry: Insurance
- Company size: 11–50 Employees
- Used Monthly for 1-5 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Easy to use
Reviewed on 2024/10/17
Pros
The guidance provided to resolve issues was thorough and easy to follow
Cons
No terraform support for issue resolution

- Industry: Computer Software
- Company size: 2–10 Employees
- Used Weekly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Made Getting SOC 2 Type I a breeze. Easily saved hundreds of hours
Reviewed on 2021/08/24
Secureframe helped us secure our SOC 2 Type 1 incredibly quickly, which was instrumental to helping...
Secureframe helped us secure our SOC 2 Type 1 incredibly quickly, which was instrumental to helping us unblock some of our enterprise opportunities and move along deals. Plus, it also helped our company start taking security more seriously as we continue to grow and scale.
Pros
Secureframe’s platform made getting our SOC 2 super easy and easily helped us save hundreds of hours of time and engineering resources. The software helped streamline the evidence collection process, vendor management, policy creation, and even security awareness training. It literally did almost everything we needed to get SOC 2 compliant. I was impressed with the breath of integrations. They helped save a lot of time with pulling in evidence from our existing vendors. Finally, the support is really top notch. Anything we had a question, we got a response within 24 hours, sometimes within just hours. We always felt like Secureframe was there for us.
Cons
Reality is, you still have to read over the policies and make sure you’re setting up the integrations properly. But, I felt like Secureframe’s team was there to help us with any questions we had and get us moving through the process quickly.

- Industry: Computer Software
- Company size: 11–50 Employees
- Used Weekly for 6-12 months
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Great product, great team
Reviewed on 2021/09/26
Using Secureframe to complete SOC audits. Very happy with the product, as well as the level of...
Using Secureframe to complete SOC audits. Very happy with the product, as well as the level of support our team has received from the Secureframe customer success team.
Pros
Platform is very easy to use for folks like myself who are not compliance/security experts. Easy to see all data and what needs to be done in one place.
Cons
Some workflows are still manual, but the team is working on automation.
- Industry: Information Technology & Services
- Company size: 2–10 Employees
- Used Monthly for 1+ year
-
Review Source
Overall rating
- Value for Money
- Ease of Use
- Customer Support
- Likelihood to recommend 10.0 /10
Fantastic Customer Service & Onboarding Experience
Reviewed on 2022/09/02
Pros
Secureframe makes it possible for small shops to finally overcome the daunting task of becoming SOC II Type I and Type II compliant.
The best part about picking Secureframe is you'll get access to their customer support team via Slack and recurring meetings as you prepare for your audit.
I also thought the platform was intuitive, which made it easy to track where you and your team are at any point in the process.
If you're looking for a way to become compliant quickly - look no further!
Cons
You occasionally have to provide a screenshot if you have a product that they haven't yet integrated with. However, the platform makes it incredibly easy to upload and track evidence (screenshots). Overall, they provide a great alternative when/if needed.