Privacy Ratings

Compliance automation

Secureframe privacy rating

Hosted compliance automation platform that integrates with cloud, identity and HR systems to monitor controls and collect evidence for SOC 2, ISO 27001, FedRAMP, CMMC, HIPAA and other frameworks, with AI tools for questionnaires and risk management.

Summary

Secureframe scores 28 out of 100 (grade F) on the compliance automation criteria. It meets 1 of 8 criteria: TLS configuration. It partly meets no ads or data sales, independent audit and security headers. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.

Score 28 out of 100. How scoring works

Criteria

  • No

    Open source Weight 3 of 3

    Is all the source code needed to run the product public?

    Closed source.

  • No

    No trackers or telemetry Weight 3 of 3

    Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?

    The privacy policy names Google Analytics and describes cross-site tracking for advertising, and the website loads PostHog and HubSpot.

    secureframe.com

  • Partial

    No ads or data sales Weight 2 of 3

    Is the product funded without advertising, ad targeting or selling user data?

    Paid service with no ads, and it says it does not sell data for money, but website activity is used for personalized advertising of its own services on other sites.

    secureframe.com

  • Partial

    Independent audit Weight 2 of 3

    Has an independent security or privacy audit been published within the last three years?

    The trust center lists SOC 2 Type 2, ISO 27001, FedRAMP 20x and CMMC Level 2 assessments, but the full reports are only available on request.

    trust.secureframe.com

  • No

    Transparency report Weight 2 of 3

    Does the provider regularly publish how many government and legal requests it receives and how it responds?

    No transparency report or government request policy is published. The privacy policy only says data may be disclosed in response to lawful requests by public authorities.

    secureframe.com

  • No

    Tells users about requests Weight 1 of 3

    Does the provider promise to tell users about requests for their data, unless a court forbids it?

    No published policy on notifying users about data requests.

Automated tests

  • Yes

    TLS configuration Weight 2 of 3

    Does the website pass the Qualys SSL Labs test with a grade of A or better?

    Grade A+

    ssllabs.com

  • Partial

    Security headers Weight 1 of 3

    Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?

    Grade B (70/100+)

    developer.mozilla.org

  • Not tested yet

    Modern web standards Weight 1 of 3

    Does the website score 90% or higher on the Internet.nl website test?

    Not tested yet.

Other compliance automation

All 11 compliance automation