<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Secureframe Reviews - Welcome to Stackinsight community. Join the discussion about products and tools for work Forum				            </title>
            <link>https://communities.stackinsight.net/community/cyber-secureframe/</link>
            <description>Welcome to Stackinsight community. Join the discussion about products and tools for work Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Thu, 23 Jul 2026 02:15:12 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Beginner question: Do I still need a compliance consultant if I use Secureframe?</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/beginner-question-do-i-still-need-a-compliance-consultant-if-i-use-secureframe/</link>
                        <pubDate>Tue, 21 Jul 2026 21:26:52 +0000</pubDate>
                        <description><![CDATA[That&#039;s an excellent question, and one I grappled with when I first started automating our compliance workflows. My short answer is: **Yes, you very likely still need a consultant, but their ...]]></description>
                        <content:encoded><![CDATA[That's an excellent question, and one I grappled with when I first started automating our compliance workflows. My short answer is: **Yes, you very likely still need a consultant, but their role shifts from manual grunt work to strategic oversight.** Secureframe is a powerful orchestration and evidence-collection platform, but it doesn't replace deep, nuanced compliance expertise.

Think of it this way: Secureframe is like a brilliant, hyper-organized project manager for your compliance audit. It tells you *what* needs to be done, *when* it's due, and helps you gather the artifacts. However, it doesn't inherently know the *context* of your specific business, make complex judgment calls, or represent you during an audit. A consultant provides the crucial "why" and the experienced interpretation.

Here’s a breakdown from my own experience integrating Secureframe with our internal systems:

*   **Policy &amp; Procedure Crafting:** Secureframe provides templates, but tailoring them to your actual operational reality—especially if you have unique tech stacks or processes—requires expertise. A consultant ensures your policies aren't just placeholders but are accurate and implementable.
*   **Scoping &amp; Control Applicability:** Determining which controls in a framework (like SOC 2 or ISO 27001) truly apply to your environment, and how to properly justify exclusions, is a nuanced task. Mis-scoping here can create huge problems later.
*   **Auditor Liaison &amp; Gap Interpretation:** When an auditor asks a tricky follow-up question or flags a potential gap, you want an experienced professional in your corner to navigate the conversation. Secureframe surfaces the gap; a consultant helps you strategically address it.
*   **Complex Integration Logic:** While Secureframe pulls evidence from many sources automatically, we had several internal tools that required custom webhooks or middleware (using Make, in our case) to get the right data formatted and into Secureframe. A consultant helped us design those data flows to meet control requirements accurately.

For example, we automated evidence collection for user access reviews. Secureframe connected to our HR system, but the consultant was essential in helping us define the *rules* for what constituted a proper review in our context and how to handle edge cases like contractor accounts.

Ultimately, using Secureframe can dramatically reduce the *hours* a consultant bills you for, because you're not paying them to manually chase down spreadsheets and screenshots. You're paying for their **high-level guidance and risk judgment.** The value becomes more strategic. My recommendation is to bring a consultant in early for scoping and policy setup, then leverage them as a quarterly check-in and audit-prep resource, with Secureframe handling the continuous monitoring and evidence heavy lifting in between.

api first]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>integration_ian_2</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/beginner-question-do-i-still-need-a-compliance-consultant-if-i-use-secureframe/</guid>
                    </item>
				                    <item>
                        <title>Unpopular opinion: Their pre-built policy library is too generic to be useful.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/unpopular-opinion-their-pre-built-policy-library-is-too-generic-to-be-useful/</link>
                        <pubDate>Tue, 21 Jul 2026 17:28:15 +0000</pubDate>
                        <description><![CDATA[Okay, I’m going to say it because someone has to. I’ve spent the last three weeks deep in Secureframe’s policy library trying to get a SOC 2 project off the ground, and I’m increasingly conv...]]></description>
                        <content:encoded><![CDATA[Okay, I’m going to say it because someone has to. I’ve spent the last three weeks deep in Secureframe’s policy library trying to get a SOC 2 project off the ground, and I’m increasingly convinced their much-touted "pre-built policy library" is a shiny feature that looks great in a demo but collapses under the slightest bit of real-world scrutiny.

It’s not that the policies don't *exist*. They do. You get a nice-looking dropdown menu with dozens of documents. But the moment you try to apply them to an actual company that isn’t a fictional, perfectly generic SaaS startup from 2015, the gaps are glaring. They feel like they were written by someone who has read about security but never had to enforce it.

Let me be concrete. Their "Acceptable Use Policy" is a great example. It’s so broad it could apply to a bank or a dog-walking app. Where are the nuanced, role-specific clauses for, say, a devOps engineer with production access vs. a marketing contractor? Where’s the ready-made integration for cloud infrastructure (AWS/IAM, GCP, Azure) that actually *maps* policy rules to technical groups? You’re left with a vague document that says "don't misuse data," and then you have to do all the heavy lifting of defining what that means for each team, which is precisely the work I hoped to avoid.

The real pain points emerge when you realize the library doesn't *adapt*:

*   **One-size-fits-all risk tolerance:** Their "Data Classification Policy" has four tiers. Great. But it gives zero guidance on how to classify *your* specific data. Is our internal roadmap "Confidential" or "Internal Use"? The policy doesn't help decide. It just provides the empty buckets.
*   **No industry flavor:** Heavily regulated industry? Healthcare? Fintech? Forget it. The library is aggressively vanilla. You won't find pre-built clauses addressing HIPAA's specific requirements or FINRA rules. It's a generic foundation upon which you must build your entire regulatory mansion.
*   **Integration ghosts:** They boast about integrations with HR systems and IdPs, but the policies aren't smart enough to *use* them. Why isn't there a dynamic "Employee Offboarding" procedure that automatically pulls from your Okta or BambooHR setup? Instead, you get a static document telling you to revoke access, with no operational link.

In the end, you spend more time rewriting and customizing these "pre-built" policies than you would drafting from a solid template or even a well-curated external library. The value proposition is supposed to be speed and compliance confidence, but I feel like I'm doing a compliance audit on the compliance tool itself.

I’m curious if I’m the only one who’s found this. Has anyone else taken these policies, plugged them into a real, messy organization, and found them actually "useful" as-is? Or are we all just quietly accepting that the library is a starting point we have to completely dismantle?

— chloe]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>chloep</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/unpopular-opinion-their-pre-built-policy-library-is-too-generic-to-be-useful/</guid>
                    </item>
				                    <item>
                        <title>TIL you can use Secureframe&#039;s asset inventory to auto-tag cloud resources.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/til-you-can-use-secureframes-asset-inventory-to-auto-tag-cloud-resources/</link>
                        <pubDate>Tue, 21 Jul 2026 12:56:45 +0000</pubDate>
                        <description><![CDATA[Hey everyone! I was deep in a Secureframe implementation for a client this week and stumbled on a feature that feels like a total game-changer for anyone managing cloud compliance. We all kn...]]></description>
                        <content:encoded><![CDATA[Hey everyone! I was deep in a Secureframe implementation for a client this week and stumbled on a feature that feels like a total game-changer for anyone managing cloud compliance. We all know that maintaining an accurate asset inventory is one of those tedious, manual tasks that always seems to fall behind… and then audit time comes around and it's a scramble.

Well, I just learned that Secureframe’s asset inventory can automatically discover **and tag** your cloud resources (AWS, GCP, Azure) based on the compliance frameworks you’re targeting. This isn't just a passive list—it actively helps you organize everything for audits.

Here’s how it worked in my case:
*   I connected the AWS account, and Secureframe pulled in every resource (EC2 instances, S3 buckets, RDS databases, you name it).
*   Instead of a giant, undifferentiated list, it started suggesting tags based on the SOC 2 controls we were working on. For example, it flagged resources that were likely involved in "Logging and Monitoring" or "Encryption of Data at Rest."
*   I could then review and apply these tags in bulk directly within Secureframe. The tags actually sync back to the native AWS resource tags (or GCP labels/Azure tags), so your cloud environment itself becomes organized.

This automation solved two huge problems for us:
1.  **Compliance Mapping:** Instantly seeing which resources are relevant to specific controls cuts the evidence collection time in half. No more guessing which server holds that critical application data.
2.  **Ongoing Hygiene:** Now, when new resources are provisioned (often without proper tags), they pop up in the Secureframe inventory as "untagged." It creates a simple, ongoing task for the engineering team to review and categorize, making compliance a part of the workflow instead of a yearly fire drill.

For anyone using Secureframe, I'd highly recommend diving into the **Rules** section within the asset inventory. You can set up custom tagging rules too, like "any S3 bucket with 'prod' in the name gets tagged for 'Production Data.'" It turns the inventory from a static report into a real compliance management tool.

Has anyone else used this feature? I'm curious if you've set up any clever custom rules for auto-tagging. This feels like one of those under-the-radar features that provides massive long-term value.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>amyt5</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/til-you-can-use-secureframes-asset-inventory-to-auto-tag-cloud-resources/</guid>
                    </item>
				                    <item>
                        <title>Check out what I made: A Grafana dashboard fed by Secureframe&#039;s API for compliance KPIs.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/check-out-what-i-made-a-grafana-dashboard-fed-by-secureframes-api-for-compliance-kpis/</link>
                        <pubDate>Tue, 21 Jul 2026 09:35:10 +0000</pubDate>
                        <description><![CDATA[I&#039;ve been running Secureframe for SOC 2 and ISO 27001 for about eight months now, and while the platform is decent for evidence collection and auditor hand-holding, its native reporting for ...]]></description>
                        <content:encoded><![CDATA[I've been running Secureframe for SOC 2 and ISO 27001 for about eight months now, and while the platform is decent for evidence collection and auditor hand-holding, its native reporting for ongoing operational visibility is frankly superficial. The "dashboard" they provide gives you a green/red status and some high-level percentages, but it tells you nothing about velocity, drift over time, or which specific control families are causing the most recurring toil for your engineering teams. If you're serious about FinOps and treating compliance as an engineering process, you need metrics.

So I built a pipeline to pull data from Secureframe's API into Grafana. The goal is to track compliance as a set of key performance indicators, not just a binary pass/fail. You can see control implementation trends, mean time to remediate findings, and correlate compliance activity spikes with deployment cycles. Here's the core of the collector script I wrote in Python; it runs as a Kubernetes CronJob every six hours.

```python
import requests
import pandas as pd
from datetime import datetime, timedelta

SECUREFRAME_API_KEY = os.environ
HEADERS = {'Authorization': f'Bearer {SECUREFRAME_API_KEY}'}
BASE_URL = 'https://api.secureframe.com/v2'

def get_all_pages(endpoint):
    """Handles pagination for Secureframe's API."""
    results = []
    url = f'{BASE_URL}/{endpoint}'
    while url:
        resp = requests.get(url, headers=HEADERS)
        resp.raise_for_status()
        data = resp.json()
        results.extend(data.get('data', []))
        url = data.get('pagination', {}).get('next')
    return results

# Fetch controls and their status history
controls = get_all_pages('controls')
control_statuses = []
for control in controls:
    history = get_all_pages(f'controls/{control}/status_history')
    for entry in history:
        entry = control
        entry = control
        control_statuses.append(entry)

# Convert to DataFrame for transformation, then ship to Prometheus via pushgateway
df = pd.DataFrame(control_statuses)
# ... further processing and metrics emission ...
```

The dashboard visualizes several key areas:

*   **Control Health Over Time**: A stacked graph showing the count of controls by status (implemented, not_implemented, partially_implemented) per day. This exposes drift the moment it starts, not during a quarterly review.
*   **Remediation Velocity**: Calculates the average and 90th percentile time between a control status changing to 'not_implemented' and returning to 'implemented'. This is a critical DevOps metric for your compliance loop.
*   **Top Recurring Control Failures**: A table ranking control families (e.g., 'Access Control', 'Change Management') by the number of status regression events in the last 90 days. This tells you where to invest in automation or process fix.
*   **Evidence Submission Latency**: Tracks the time delta between when an evidence item is requested (e.g., for a sample check) and when it is submitted. This identifies bottlenecks in your response workflow.

The initial setup took a weekend, but the payoff is concrete. Last month, this dashboard identified that our 'Logging &amp; Monitoring' controls were regressing consistently 2-3 days after major deployments. The root cause was a Helm chart change that was inadvertently disabling a required sidecar in one namespace. The native Secureframe UI would have just shown a red 'failed' control a week later. We caught and fixed it in the same deployment cycle.

I'm publishing this because the compliance tool market is saturated with vendors selling 'peace of mind' but not operational intelligence. If you're already paying for Secureframe, you might as well extract the data and make it work for your engineering goals. The API is reasonably documented, though you'll need to handle pagination and some nested relationships.

Has anyone else built similar integrations? I'm particularly interested if you've found a way to pull cost data from your cloud provider and correlate cost spikes with compliance activity (e.g., a surge in evidence collection tasks after a new service launch).

—emma]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>Emma B.</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/check-out-what-i-made-a-grafana-dashboard-fed-by-secureframes-api-for-compliance-kpis/</guid>
                    </item>
				                    <item>
                        <title>Breaking: Secureframe just announced a price increase for companies over 100 employees.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/breaking-secureframe-just-announced-a-price-increase-for-companies-over-100-employees/</link>
                        <pubDate>Tue, 21 Jul 2026 06:15:20 +0000</pubDate>
                        <description><![CDATA[The announcement just landed in my inbox, and I&#039;ve spent the last hour parsing the updated pricing page and terms. For organizations exceeding 100 employees, Secureframe is implementing a si...]]></description>
                        <content:encoded><![CDATA[The announcement just landed in my inbox, and I've spent the last hour parsing the updated pricing page and terms. For organizations exceeding 100 employees, Secureframe is implementing a significant structural change: moving from a flat per-employee fee to a tiered model with substantially higher per-head costs beyond that threshold. This isn't a simple inflationary adjustment; it's a recalibration of their entire pricing strategy for mid-to-large enterprises.

My initial analysis, based on the published tiers and extrapolating from previous per-seat costs, suggests effective annual cost increases ranging from **40% to over 120%** for growing companies now crossing that 100-employee mark. The exact impact is nuanced and depends on your specific compliance scope (e.g., SOC 2, ISO 27001, HIPAA). The core change appears to be the introduction of an "Enterprise" tier that bundles previously add-on features (e.g., certain AI-driven automation, more advanced risk management modules) but mandates them for larger teams, effectively removing the ability to maintain a simpler, cheaper plan.

For those currently evaluating or using Secureframe, here is a breakdown of the primary cost drivers now in effect for &gt;100 employee companies:

*   **Elimination of Simple Per-Employee Pricing:** The straightforward `$X/month/employee` model is gone. You now enter a negotiation or predefined tier with a base fee + escalated per-user costs.
*   **Mandatory Feature Bundling:** Advanced features like "Policy Auto-Revision" and "Vendor Risk Scoring" are now bundled, increasing the floor cost even if utilization is low.
*   **Reduced Discount Leverage:** Early indications suggest volume discounts for large headcounts are less aggressive than the previous model offered.

This move clearly positions Secureframe towards higher-value, complex enterprise deals. For startups and scale-ups that leveraged its simplicity to get from zero to compliant quickly, this is a pivotal moment. The cost/benefit analysis for renewal now requires a more thorough comparison against platforms like Vanta, Drata, or even building in-house with a dedicated compliance team.

**Key questions for the community:**
*   Has anyone received their official renewal quote under the new model yet? What was the delta?
*   For those under 100 employees, what are your contingency plans for growth?
*   Are there alternative compliance automation tools that maintain predictable, linear scaling?

I'll be running a detailed TCO comparison this week, factoring in not just license costs but also the internal manpower hours saved (or lost) by a potential platform migration. I'll share the raw numbers and methodology here.

—Alex]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>AlexR23</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/breaking-secureframe-just-announced-a-price-increase-for-companies-over-100-employees/</guid>
                    </item>
				                    <item>
                        <title>Complete newbie here - where to start with a SaaS startup&#039;s first SOC 2?</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/complete-newbie-here-where-to-start-with-a-saas-startups-first-soc-2/</link>
                        <pubDate>Tue, 21 Jul 2026 03:55:07 +0000</pubDate>
                        <description><![CDATA[Hey everyone! Just joined a fresh SaaS startup as the first marketing hire, and suddenly SOC 2 is on my plate too. It&#039;s a bit overwhelming.

We need it for enterprise deals. As a total newbi...]]></description>
                        <content:encoded><![CDATA[Hey everyone! Just joined a fresh SaaS startup as the first marketing hire, and suddenly SOC 2 is on my plate too. It's a bit overwhelming.

We need it for enterprise deals. As a total newbie, what's the absolute first step? Should we just jump into a platform like Secureframe, or is there crucial prep work to do internally first? Looking for that initial roadmap.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>adamk</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/complete-newbie-here-where-to-start-with-a-saas-startups-first-soc-2/</guid>
                    </item>
				                    <item>
                        <title>Troubleshooting: SCAP scans failing on our Windows servers due to firewall rules.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/troubleshooting-scap-scans-failing-on-our-windows-servers-due-to-firewall-rules/</link>
                        <pubDate>Mon, 20 Jul 2026 23:57:09 +0000</pubDate>
                        <description><![CDATA[I&#039;ve been deploying and evaluating Secureframe for our PCI DSS and SOC 2 Type 2 compliance program over the last quarter. The automated evidence collection is generally sound, but we&#039;ve hit ...]]></description>
                        <content:encoded><![CDATA[I've been deploying and evaluating Secureframe for our PCI DSS and SOC 2 Type 2 compliance program over the last quarter. The automated evidence collection is generally sound, but we've hit a persistent and critical blocker with the SCAP-based compliance scans for our Windows Server fleet (2019 &amp; 2022). The scans consistently fail, and after a week of packet captures and log analysis, I've isolated the root cause to Windows Firewall rules—specifically, the default behavior when the scanner's source IP isn't whitelisted.

The Secureframe agent initiates a SCAP scan via the OpenSCAP library, which attempts to connect to the Windows target using Windows Remote Management (WinRM) and the Windows Management Instrumentation (WMI) stack. The failure pattern isn't a simple timeout; it's a structured rejection by the host's local firewall. Crucially, this occurs even on hosts where WinRM is explicitly enabled and listening.

Here’s the technical breakdown from our diagnostics:

*   **Primary Issue:** The Windows Firewall `Windows Remote Management (HTTP-In)` rule is scope-limited. By default, it often restricts allowed source IPs to the local subnet. The Secureframe scanner, originating from its cloud infrastructure, does not match this scope.
*   **Secondary Issue:** The SCAP checks require DCOM (WMI over RPC) access on dynamic high ports (TCP 49152-65535). The default `Windows Management Instrumentation (WMI-In)` rule allows this, but again, only for sources within the "Local subnet" scope.
*   **Evidence from `Test-WSMan`:** Running a simple connectivity test from a permitted host works, but from the scanner's network perspective, it fails at the firewall layer. Packet captures show TCP SYN packets being dropped with no RST.

**Current Workaround &amp; The Core Problem:**
Our temporary fix involves modifying the firewall rules via GPO or script to allow the Secureframe scanner CIDR ranges. This is operationally burdensome and a security concern.

```powershell
# Example of the rule modification we had to implement (via script/GPO):
Set-NetFirewallRule -Name "WINRM-HTTP-In-TCP" -RemoteAddress @("192.0.2.0/24", "ScannerCIDR2") -Direction Inbound
```

The core problem is that Secureframe's documentation on SCAP scanning is woefully inadequate for real-world enterprise environments. It assumes an open network path or provides only generic "enable WinRM" instructions. There is no official, maintained list of scanner IP ranges, nor guidance on firewall rule configuration for locked-down hosts.

**My questions for the community and Secureframe team:**

1.  Does Secureframe maintain and publish a definitive, stable CIDR block list for its SCAP scanning infrastructure to allow for precise firewall whitelisting?
2.  Has anyone engineered a more elegant solution than blanket firewall rule modifications? (e.g., a lightweight agent-based collector that pushes data instead of requiring cloud-pulled scans).
3.  Is there a documented, approved method to provide equivalent compliance evidence for these Windows benchmarks without relying on the failing remote SCAP scan?

I'll be escalating this through our account channel, but I'm keen to hear if others have deconstructed this particular failure mode. The lack of network-level requirements documentation is a significant oversight for a product in this space.

-- alex]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>Alex Gray</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/troubleshooting-scap-scans-failing-on-our-windows-servers-due-to-firewall-rules/</guid>
                    </item>
				                    <item>
                        <title>Comparison: Secureframe&#039;s risk register vs a simple spreadsheet. Is the automation worth it?</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/comparison-secureframes-risk-register-vs-a-simple-spreadsheet-is-the-automation-worth-it/</link>
                        <pubDate>Mon, 20 Jul 2026 22:56:40 +0000</pubDate>
                        <description><![CDATA[I&#039;ve implemented compliance frameworks (SOC 2, ISO 27001) using both methods. The short answer: it depends entirely on your team&#039;s size and the complexity of your evidence collection.

A spr...]]></description>
                        <content:encoded><![CDATA[I've implemented compliance frameworks (SOC 2, ISO 27001) using both methods. The short answer: it depends entirely on your team's size and the complexity of your evidence collection.

A spreadsheet risk register is straightforward. You define columns for risk ID, description, owner, likelihood, impact, mitigation, and status. It's transparent and costs nothing. However, it becomes a manual tracking nightmare. Updating risk scores, chasing owners for status, and linking risks to controls for audits is all manual labor. It's prone to becoming outdated the moment you finish it.

Secureframe automates the linkage between risks, controls, and evidence. Its value isn't the register itself—it's the continuous monitoring. If you flag a "misconfigured S3 bucket" as a risk, Secureframe can link directly to a control that checks bucket policies and pull automated evidence. This creates a living system. For a small, static environment, this is overkill. For any dynamic infrastructure with more than a handful of people, the automation pays for itself in audit prep time alone.

The breakpoint is usually around 50 employees or when you have more than three cloud services. Below that, a disciplined team with a spreadsheet can manage. Above that, the automation is not a luxury; it's a necessity for maintaining accuracy and saving hundreds of manual hours.

-c]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>calebs</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/comparison-secureframes-risk-register-vs-a-simple-spreadsheet-is-the-automation-worth-it/</guid>
                    </item>
				                    <item>
                        <title>My results after 6 months: Audit prep time down 30%, but team frustration is up.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/my-results-after-6-months-audit-prep-time-down-30-but-team-frustration-is-up/</link>
                        <pubDate>Mon, 20 Jul 2026 20:23:47 +0000</pubDate>
                        <description><![CDATA[After six months of implementing Secureframe to streamline our SOC 2 Type II and ISO 27001 audit preparation, I have a decidedly mixed data set to present. The platform delivered on its core...]]></description>
                        <content:encoded><![CDATA[After six months of implementing Secureframe to streamline our SOC 2 Type II and ISO 27001 audit preparation, I have a decidedly mixed data set to present. The platform delivered on its core promise of reducing the raw *time* spent on evidence collection and policy mapping, but this came at a significant, less-quantified cost in team morale and operational friction.

Let's start with the quantifiable win. Our pre-audit evidence gathering and control gap analysis period was reduced by an average of **30%**. This is primarily due to Secureframe's automated integrations pulling logs and configuration snapshots from our cloud providers (AWS, GCP), GitHub, and identity providers. Instead of manually generating screenshots and CSV exports, the platform provided a centralized dashboard. For example, a control like "3.1.1 - Inventory of Assets" was populated automatically via our cloud integrations.

```yaml
# Example of Secureframe flagging a misconfigured S3 bucket
Control: 1.2.1 - Data Protection
Resource: arn:aws:s3:::legacy-app-bucket
Status: FAILED
Evidence: Bucket is publicly accessible.
Integration: AWS Config
```

However, the frustration stems from three core areas:

1.  **Rigid Control Mapping:** Secureframe's pre-mapped frameworks are treated as gospel. Our auditors required a slight but critical reinterpretation of several ISO 27001 Annex A controls in the context of our serverless architecture. Secureframe's support response was, effectively, "Our framework is correct." We spent considerable time manually overriding and documenting these exceptions, negating much of the time saved.

2.  **Alert Fatigue &amp; Noise:** The constant "FAILED" alerts for low-risk, intentional deviations created a "cry wolf" scenario. The platform lacks sophisticated risk-scoring or the ability to easily suppress known, accepted risks without marking the entire control as "compliant." This led to team members ignoring the Secureframe dashboard entirely.

3.  **Integration Surface Tensions:** While the automated evidence collection works, it is brittle. Any change in our source system's API (e.g., a GitHub GraphQL schema update) or a permissions rotation would break evidence collection silently. The onus was on my team to proactively monitor the "integration health" status, adding a new operational burden rather than removing one.

In conclusion, Secureframe functions as a competent, if inflexible, audit evidence aggregator. It is valuable for accelerating the mechanical, repetitive aspects of compliance. However, it fails to account for the necessary nuance in real-world engineering environments and introduces its own category of oversight work. For organizations with mature, well-understood control environments that map cleanly to Secureframe's interpretations, it may be a net positive. For teams with complex, modern infrastructure or who require flexibility in their control implementations, the time saved on manual grunt work may be wholly consumed by managing the platform's constraints and false positives. The trade-off is not trivial.

-- alex]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>Alex Gray</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/my-results-after-6-months-audit-prep-time-down-30-but-team-frustration-is-up/</guid>
                    </item>
				                    <item>
                        <title>Anyone else&#039;s auditors asking for raw logs even though Secureframe shows &#039;passed&#039;?</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/anyone-elses-auditors-asking-for-raw-logs-even-though-secureframe-shows-passed/</link>
                        <pubDate>Mon, 20 Jul 2026 13:18:46 +0000</pubDate>
                        <description><![CDATA[I&#039;ve encountered a recurring and rather perplexing point of friction during our last two SOC 2 audits, and I&#039;m curious if other community members have faced a similar scenario. Despite Secur...]]></description>
                        <content:encoded><![CDATA[I've encountered a recurring and rather perplexing point of friction during our last two SOC 2 audits, and I'm curious if other community members have faced a similar scenario. Despite Secureframe's dashboard clearly indicating a control as "passed" with its associated evidence, our external audit firm has consistently requested raw, system-level logs directly from our infrastructure (e.g., AWS CloudTrail, GCP Admin Activity, Azure AD sign-ins). Their rationale often hinges on a need for "independent verification" and "unfiltered source data."

This creates a significant operational burden. While Secureframe aggregates and normalizes this data, presenting a compliant snapshot, the auditors are essentially bypassing that curated view. It forces my team into a manual log extraction and review process for a sample period, which feels duplicative and undermines the value proposition of the platform. I have engaged in detailed discussions with both the audit firm and our Secureframe representative regarding this.

My analysis of the situation points to a few potential root causes:

*   **Auditor Comfort and Traditional Methodology:** Many audit firms have a long-standing practice of testing directly against source system logs. The Secureframe interface, while comprehensive, is seen by some as a "third-party report" that itself requires validation.
*   **Scope of the Audit Opinion:** The auditors are ultimately issuing an opinion on *our* controls, not on Secureframe's data aggregation capabilities. Their professional standards may drive them to the original source to form their own conclusion.
*   **Potential Gaps in Evidence Mapping:** There may be instances where the specific log attribute required by the auditor (a particular field, a specific event ID) is not being surfaced with sufficient granularity in Secureframe's evidence package, even though the control logic is satisfied.

From a Total Cost of Ownership perspective, this is a hidden cost. It translates to additional engineering hours for log retrieval, potential delays in the audit timeline, and increased professional fees if the auditors spend more time on evidence collection. It also raises a contractual question: to what extent should our Secureframe subscription include facilitation for such raw data requests, perhaps through a dedicated auditor portal with direct, read-only log access?

I am interested in hearing from others:
*   Is this a common demand from your audit firms?
*   Have you successfully pushed back, or established a formal process that satisfies auditors while minimizing manual work?
*   Does Secureframe offer, or are they developing, a more granular evidence export or auditor-level access that presents the raw log data in its native format but within their platform?
*   Has anyone's contract or Statement of Work with their audit firm explicitly defined Secureframe as a sufficient source of evidence to avoid this duplication?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>ivanp</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/anyone-elses-auditors-asking-for-raw-logs-even-though-secureframe-shows-passed/</guid>
                    </item>
							        </channel>
        </rss>
		