Secureframe Reviews (812)

Reviews

Secureframe Reviews (812)

4.7
812 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise Secureframe for its ease of use and exceptional support, which simplifies the often complex compliance processes. The platform's intuitive interface and automation features significantly reduce manual work, making compliance management more efficient and less stressful. However, some users note that the interface could benefit from further improvements.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Isael M.
IM
Isael M.
IT
Mid-Market (51-1000 emp.)
"Secureframe Made SOC 2 Compliance Easy with Great Communication"
4.5/5
What do you like best about Secureframe?

The standout feature of Secureframe was its support in achieving SOC 2 compliance. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

Honestly, there were no drawbacks. Secureframe was responsive, open, and easy to work with. Review collected by and hosted on G2.com.

Bayian Y.
BY
Bayian Y.
Head of Web Platform
Small-Business (50 or fewer emp.)
"Best of both worlds"
4/5
What do you like best about Secureframe?

Secureframe is a great choice when optimizing between cost and ease of use. We've been using Secureframe for all of our SOC2 security compliance needs for several years. They've got great customer support, integrations with 3rd party vendors are super easy to get hooked up, ease of implementation, and the dashboards are great - super easy to see what's an immediate concern and the state of compliance for your startup. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

I'd say just being proactive about notifying customers when there are bugs in the dashboard. We've been bug reporting and opening cases and the support team is quite responsive but at times the issues we've flagged are known to them, so proactive outreach would be a nice thing via email just so we're aware. Review collected by and hosted on G2.com.

Kamil Z.
KZ
Kamil Z.
Engineering Manager
Mid-Market (51-1000 emp.)
"Secureframe made compliance simple and stress free"
5/5
What do you like best about Secureframe?

Secureframe helped us get our certification faster than we thought possible. The system is very easy to use and everything is clear from the start. The layout is simple so you always know where to go and what to click. Tasks are shown in a clear list with instructions so you never have to guess the next step. Real time alerts tell you when something needs fixing and you can solve most issues right away.

Evidence is collected automatically so I do not need to ask the team for screenshots or logs. This saved us many hours every week. The process felt smooth from the first login until the final audit. I liked that Secureframe keeps both technical checks and documents in one place so I do not have to switch between tools. The support team was quick to reply and always gave answers that helped us move forward. I never felt stuck at any stage. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

I have not found any serious problems. It would be nice to have more options to change the look of the policies and templates but the default ones already work well. Review collected by and hosted on G2.com.

BG
Balakumar G.
Architect
Mid-Market (51-1000 emp.)
"User friendly product with helpful support team"
4.5/5
What do you like best about Secureframe?

Simple and straight forward UI. Integration module was is best of all. Initially we didn't use the integration module, we manually digged through every service that use to collect evidence. After integration, Secureframe was able to analyze all our Azure services, atlassian accounts in no time and showed us the wholistic picture of where we stand. For every test failure, SecureFrame provided simple and straightforward steps to pass the test.

Their customer support is really cool, those guys were able to support immediately for most part. Overall product is very easy to use and understand. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

Like any other product, they also have some glitches in the UI and in integration module. However their support team helped to overcome these glitches and move forward quickly. Review collected by and hosted on G2.com.

Paul L.
PL
Paul L.
Senior Software Engineer
Mid-Market (51-1000 emp.)
"Seamless Integrations make security compliance a breeze"
4/5
What do you like best about Secureframe?

From an engineers point of view, I absolutely love the integrations that Secureframe has built in. We were able to hook up Secureframe up to our Github repository as well as our AWS account and see where we were lacking in our security compliance. I loved that each test provided a clear indication of what resource or rule was failing, and provided not only steps in either the AWS console UI and GitHub UI, but also CDK code to fix these issues as infrastructure as code. The speed at which the tests then updated as we implemented fixes was also great. It was a very easy system to setup and maintain. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

I did not find many things to dislike with Secureframe. I did find some of the tolerance windows a little confusing to setup, for instance we had a test on AWS for having the newest version of ElasticSearch that kept failing when a new patch got released, which was fairly frequently. It wasn't very intuitive on how to set a SLA on when we would update that particular resource. I also found that some of the tests took a long time to sync from AWS back to Secureframe. Review collected by and hosted on G2.com.

AM
Alyssa M.
Business Operations Manager
Small-Business (50 or fewer emp.)
"Secureframe made SOC 2 Type 1 compliance a breeze"
5/5
What do you like best about Secureframe?

We used Secureframe for our SOC 2 Type 1 compliance and couldn’t be happier with the experience. They walked us through every step, from setup to follow-through, in a way that was easy to understand, even for someone without prior compliance experience. The platform is intuitive, the process is streamlined, and their team was responsive and knowledgeable. They took what could have been an overwhelming audit process and made it straightforward, stress-free, and efficient. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

Nothing, the process was smooth from start to finish. Review collected by and hosted on G2.com.

Arpit S.
AS
Arpit S.
DevOps Lead
Small-Business (50 or fewer emp.)
"Secureframe Makes Compliance Simple and Effective"
4.5/5
What do you like best about Secureframe?

We’ve used Secureframe for PCI, ISO, and SOC 2 compliance for 3+ years, and it’s made the process simple and efficient. Policy templates cover all major frameworks, and publishing policies automatically notifies employees for acknowledgment. The continuous tests help us monitor multiple cloud environments, reducing the number of new tasks each year. Their auditor recommendations have been spot-on, and support is always excellent.

Secureframe has streamlined our compliance journey and continues to be a valuable partner. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

The controls tab can be tricky to navigate, and some integrations still require manual evidence uploads. Minor issues, but worth noting. Review collected by and hosted on G2.com.

SC
Simon C.
IT Manager
Small-Business (50 or fewer emp.)
"A Game-Changer for Continuous Compliance – Secureframe Has Transformed Our Security Operations"
5/5
What do you like best about Secureframe?

As a Security & Compliance Officer who has been using Secureframe for several years, I can confidently say it has been one of the most impactful investments we’ve made in our security program. What started as a tool to help us prepare for SOC 2 quickly became the central hub for managing our entire compliance lifecycle.

Key Features and Why They Stand Out:

Automated Evidence Collection:

This feature alone has saved us countless hours each audit cycle. Secureframe seamlessly integrates with our cloud infrastructure, HR systems, and ticketing tools, pulling in the required evidence automatically. What used to be a frantic manual process is now something we monitor in the background.

Continuous Monitoring:

I’ve been consistently impressed with how thorough the continuous monitoring is. We get real-time alerts for configuration drifts, vulnerabilities, and policy deviations—allowing us to address issues before they ever become audit findings.

Policy Library & Customization:

The pre-built policy templates are excellent, but what I value most is the flexibility to tailor them to our organization’s specific needs. Secureframe has made maintaining an up-to-date policy set painless, and version control is built right in.

Vendor Risk Management:

The vendor management module has become a critical part of our third-party risk program. Secureframe gives us the tools to assess vendors quickly, track their compliance status, and centralize due diligence documentation.

Audit-Ready Reporting:

When auditors come knocking, Secureframe makes it simple to export everything they need in an organized, clear, and complete package. Our audit prep time has been reduced by well over 50%, and our auditors regularly comment on how streamlined our process is.

Overall Experience:

Over the years, Secureframe has evolved alongside industry best practices and regulatory changes, and they’ve continuously added value through new features and integrations. Their customer support team has been proactive, knowledgeable, and genuinely invested in our success.

If you’re serious about building and maintaining a mature security and compliance program—whether it’s SOC 2, ISO 27001, HIPAA, or beyond—Secureframe is the platform I would recommend without hesitation. It has fundamentally changed how we manage compliance and given us the confidence that we are always audit-ready. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

On the whole not much, as mentioned earlier the in app policy editor is very basic, it would be nicer to have some more formatting options. This could also help when adding in Descriptions or comments on items.

There can sometimes be false positives for some of the evidence testing in particular the SecureFrame Agent can report erroneous results sometimes for thinks like BitLocker being turned off, when in fact it hasn't been turned off. Review collected by and hosted on G2.com.

Jared F.
JF
Jared F.
Head of Operations & Finance
Small-Business (50 or fewer emp.)
"Secureframe makes SOC 2 simple and efficient"
5/5
What do you like best about Secureframe?

Secureframe has been an amazing vendor in our SOC 2 process. The platform makes it easy to connect with qualified auditors, track our compliance efforts, and keep all of our requirements organized in one place. It takes what could be a complex, time-consuming process and makes it straightforward and manageable. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

The only drawback is that the reminders and task tracking aren’t as strong as they could be. While the platform is excellent overall, more consistent notifications and accountability features would make it even better. Review collected by and hosted on G2.com.

Jennifer R.
JR
Jennifer R.
Global Head of HR
Mid-Market (51-1000 emp.)
"Seamless Compliance & Security for a Growing Company"
5/5
What do you like best about Secureframe?

At Goldcast, security and compliance are critical as we scale, and Secureframe has been a game-changer for us. Their platform made what could have been a complex, months-long process into something streamlined, clear, and surprisingly manageable.

From the start, the onboarding experience was excellent—our dedicated CSM walked us through every step and made sure we had all the resources and guidance we needed. The platform itself is intuitive, with clear dashboards, automated reminders, and integrations that saved our team countless hours.

What I appreciate most is that Secureframe doesn’t just “check the boxes” for audits like SOC 2; it helps us actually operate in a more secure and compliant way day-to-day. Their ongoing monitoring means we’re always prepared, and the support team is responsive and knowledgeable whenever questions come up.

If your company is growing and you want to get security and compliance right without slowing down your momentum, Secureframe is an excellent choice. Review collected by and hosted on G2.com.

What do you dislike about Secureframe?

One area for improvement: I wish there were more granular control over certain features. For example, we can’t disable specific requirements like background checks for certain roles, which means employees sometimes get multiple unnecessary pings. It’s not a dealbreaker, but more flexibility here would make the experience even better.

That said, Secureframe doesn’t just “check the boxes” for audits like SOC 2; it helps us operate more securely day-to-day. Their ongoing monitoring means we’re always prepared, and the support team is responsive and knowledgeable whenever questions come up. Review collected by and hosted on G2.com.