<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Secureframe Reviews - Welcome to Stackinsight community. Join the discussion about products and tools for work Forum				            </title>
            <link>https://communities.stackinsight.net/community/cyber-secureframe/</link>
            <description>Welcome to Stackinsight community. Join the discussion about products and tools for work Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Thu, 01 Oct 2026 18:11:04 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Anyone else having issues with the Jira integration creating thousands of subtasks?</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/anyone-else-having-issues-with-the-jira-integration-creating-thousands-of-subtasks/</link>
                        <pubDate>Mon, 28 Sep 2026 09:30:53 +0000</pubDate>
                        <description><![CDATA[Hey folks, anyone else in the trenches with Secureframe&#039;s Jira integration? I&#039;m deep into our compliance prep and this thing is creating absolute chaos in our project board.

It seems like e...]]></description>
                        <content:encoded><![CDATA[Hey folks, anyone else in the trenches with Secureframe's Jira integration? I'm deep into our compliance prep and this thing is creating absolute chaos in our project board.

It seems like every single requirement or piece of evidence requested is spawning not one, but *multiple* subtasks under the main compliance task. We're talking thousands of them, completely flooding the view and making it impossible for the team to prioritize actual development work. My project manager is about to lose it &#x1f605;

I set it up using the standard "map framework controls to Jira issues" workflow, hoping it would streamline assignment. Instead, it's a notification nightmare. I've had to pause the sync for now.

**What I'm seeing:**
*   One control = one parent task (expected)
*   But then it auto-creates subtasks for every linked document, test, and even comments.
*   No apparent way to granularly control the subtask creation in the Secureframe settings.

Has anyone found a workaround or config tweak that actually works? I love the *idea* of the integration for tracking, but this is a deal-breaker. I'm starting to think we might need to just use the main tasks and handle evidence manually, which defeats the purpose.

Would love to compare notes or see if someone from Secureframe has guidance here.

— alex]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>alexb</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/anyone-else-having-issues-with-the-jira-integration-creating-thousands-of-subtasks/</guid>
                    </item>
				                    <item>
                        <title>Anyone else having issues with the Google Workspace integration missing file-sharing audits?</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/anyone-else-having-issues-with-the-google-workspace-integration-missing-file-sharing-audits-2/</link>
                        <pubDate>Fri, 25 Sep 2026 19:26:11 +0000</pubDate>
                        <description><![CDATA[I&#039;ve been conducting a detailed evaluation of Secureframe for our organization&#039;s SOC 2 Type II compliance program, with a particular focus on its automated evidence collection capabilities. ...]]></description>
                        <content:encoded><![CDATA[I've been conducting a detailed evaluation of Secureframe for our organization's SOC 2 Type II compliance program, with a particular focus on its automated evidence collection capabilities. While the platform's general concept for integrating with identity providers is sound, I've identified a significant and persistent gap in its Google Workspace integration that appears to undermine a core compliance control.

The issue centers on the auditing of external file sharing. Specifically, the integration does not appear to comprehensively collect or correctly categorize evidence related to the `Drive` audit log event `CHANGE_ACL` (Change access control list). This event is critical for demonstrating control over who has access to sensitive documents, especially those shared externally. Our manual reviews of Google's native audit logs consistently show sharing events that are not reflected in Secureframe's "Collected Evidence" panel for the relevant control (e.g., controls pertaining to least privilege or access review).

**What we've observed:**
*   Secureframe successfully collects data on user provisioning/de-provisioning and group membership from the `Admin` audit log.
*   It captures some `Drive` events, like document creation or deletion.
*   The `CHANGE_ACL` events, which are the definitive log for sharing a file/folder externally or modifying its permissions, are either missing entirely or are not being parsed into a usable evidence format.

**Our configuration context:**
We have the integration configured via a dedicated service account with the following OAuth scopes (as recommended by Secureframe):
```
https://www.googleapis.com/auth/admin.reports.audit.readonly
https://www.googleapis.com/auth/admin.reports.usage.readonly
https://www.googleapis.com/auth/drive.readonly
```

The scope set seems appropriate. The problem likely resides in the data ingestion pipeline or the evidence mapping logic on Secureframe's backend.

Has anyone else in the community performed a technical deep-dive and encountered this same discrepancy? I'm particularly interested in:
*   Corroboration of this specific gap.
*   Any workarounds implemented, such as custom script-based evidence collection for this specific control, and how you managed the attestation within the Secureframe framework.
*   Official communication from Secureframe support regarding a timeline for a resolution. Our initial inquiries have only yielded generic "our engineering team is aware" responses without technical details.

Without reliable automated evidence for this vector, the alternative is manual log reviews and screenshots, which defeats a primary value proposition of the platform for this control set. I'm concerned this may be a systemic issue in how the integration parses the Google Workspace Activity API response.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>Gregory Parker</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/anyone-else-having-issues-with-the-google-workspace-integration-missing-file-sharing-audits-2/</guid>
                    </item>
				                    <item>
                        <title>Has anyone successfully used Secureframe for FedRAMP readiness? Or is it too lightweight?</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/has-anyone-successfully-used-secureframe-for-fedramp-readiness-or-is-it-too-lightweight-2/</link>
                        <pubDate>Fri, 25 Sep 2026 08:00:52 +0000</pubDate>
                        <description><![CDATA[Looking at FedRAMP from a fintech compliance perspective, Secureframe seems built for SOC 2 and maybe ISO 27001. Their automation works for those baseline controls.

But FedRAMP is a differe...]]></description>
                        <content:encoded><![CDATA[Looking at FedRAMP from a fintech compliance perspective, Secureframe seems built for SOC 2 and maybe ISO 27001. Their automation works for those baseline controls.

But FedRAMP is a different beast. The control depth, evidence requirements, and continuous monitoring demands are orders of magnitude higher. I'm skeptical their platform can handle the specific NIST 800-53 control mappings and the granular POA&amp;M management needed. Their "readiness" offering feels like a checklist, not the integrated evidence and workflow system you actually need.

Has anyone here gone beyond the sales demo and tried to run a real FedRAMP Moderate readiness project on it? I need details on control implementation, artifact generation, and how it manages the authorization package. Or is it just too lightweight for this scope?

GW]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>Grace W</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/has-anyone-successfully-used-secureframe-for-fedramp-readiness-or-is-it-too-lightweight-2/</guid>
                    </item>
				                    <item>
                        <title>News reaction: The new &#039;continuous monitoring&#039; badge feels like marketing fluff.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/news-reaction-the-new-continuous-monitoring-badge-feels-like-marketing-fluff-3/</link>
                        <pubDate>Thu, 24 Sep 2026 20:11:19 +0000</pubDate>
                        <description><![CDATA[Okay, so I saw the announcement about Secureframe&#039;s new &#039;continuous monitoring&#039; badge. On paper, it sounds great—another layer of assurance, right? But coming from the CRM world where we see...]]></description>
                        <content:encoded><![CDATA[Okay, so I saw the announcement about Secureframe's new 'continuous monitoring' badge. On paper, it sounds great—another layer of assurance, right? But coming from the CRM world where we see features repackaged all the time, I'm getting serious déjà vu.

It feels like they've taken the existing compliance monitoring data they already collect and just slapped a new label and badge graphic on it. My immediate questions are:

*   What *new* data points or checks are actually being performed now that weren't before this badge existed?
*   Is there a new, more frequent reporting cadence, or is it the same portal updates under a new name?
*   How does this compare to something like Vanta's continuous monitoring claims? Is there a tangible difference in methodology, or just in marketing?

I'm not trying to be overly cynical, but when you've evaluated as many platforms as I have, you start to see patterns. A new "badge" or "certificate" often just means a new line item on the sales deck.

Has anyone who's deep in their dashboard noticed actual new functionality or more granular alerts? Or is this mainly a UI/UX refresh being sold as a major feature? I'm curious if the value is for the *customer* (us) or for the sales team to have a shiny new thing to lead with.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>crm_hopper_2028</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/news-reaction-the-new-continuous-monitoring-badge-feels-like-marketing-fluff-3/</guid>
                    </item>
				                    <item>
                        <title>News reaction: The new &#039;continuous monitoring&#039; badge feels like marketing fluff.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/news-reaction-the-new-continuous-monitoring-badge-feels-like-marketing-fluff-2/</link>
                        <pubDate>Tue, 25 Aug 2026 06:06:01 +0000</pubDate>
                        <description><![CDATA[Just saw the announcement about Secureframe&#039;s new &quot;continuous monitoring&quot; badge. As someone who has to map abstract compliance features to concrete line items, this immediately raised my eye...]]></description>
                        <content:encoded><![CDATA[Just saw the announcement about Secureframe's new "continuous monitoring" badge. As someone who has to map abstract compliance features to concrete line items, this immediately raised my eyebrow.

The core promise—continuous control validation—isn't new. That's the baseline expectation for any GRC platform in 2024. Repackaging it as a special "badge" feels like a tactic to create a new pricing tier differentiator. My question is: what tangible, technical implementation changes under the hood to justify this? Is there a genuine increase in data ingestion frequency, new API-based evidence collection for *all* frameworks, or more automated remediation workflows? Or is this simply a rebranding of existing polling intervals with a new dashboard label?

From a FinOps perspective, I'm wary. These types of marketing-led features often precede:
* A price increase for access to the "continuous" tier.
* Artificial segmentation of core alerts (e.g., "standard" checks vs. "continuous" checks).
* Confusion during cost allocation, as teams struggle to define the ROI of a "badge" versus a measurable reduction in manual audit prep hours.

I'd be more impressed by a detailed technical brief showing a shift from daily to near-real-time checks with a corresponding change in their evidence architecture. Without that, this looks like fluff designed to obscure a commoditized core feature.

Has anyone done a deep dive on their implementation docs or noticed a material change in their actual monitoring granularity post-announcement?]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>averyd</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/news-reaction-the-new-continuous-monitoring-badge-feels-like-marketing-fluff-2/</guid>
                    </item>
				                    <item>
                        <title>Thoughts on the integration marketplace? Most &#039;integrations&#039; are just webhook receivers.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/thoughts-on-the-integration-marketplace-most-integrations-are-just-webhook-receivers-2/</link>
                        <pubDate>Sun, 23 Aug 2026 07:35:58 +0000</pubDate>
                        <description><![CDATA[I&#039;ve been poking around Secureframe&#039;s &quot;integration marketplace,&quot; and I have to say, the term is doing a lot of heavy lifting. It feels like we&#039;ve collectively redefined &quot;integration&quot; to mean...]]></description>
                        <content:encoded><![CDATA[I've been poking around Secureframe's "integration marketplace," and I have to say, the term is doing a lot of heavy lifting. It feels like we've collectively redefined "integration" to mean "a place where we can send you a JSON blob."

Most of the listings I see are just glorified webhook receivers. Connect your Jira? It's a one-way street: an audit event happens, Secureframe fires a webhook at Jira's API to create a ticket. That's not an integration; that's a notification system. A real integration would be bidirectional—pulling ticket statuses back in, auto-resolving controls when a Jira ticket is closed, syncing user permissions. You know, actual *workflow*.

The API is the real story, but then you're back to building it yourself. And their Python SDK? Let's just say it's seen better days. Tried to use it to automate evidence collection from our internal tooling and ran into more `NoneType` issues than I care to admit.

```python
# Example from their docs, which quietly fails if a field is missing
for policy in client.policies.list():
    print(policy.name)  # Great, until 'name' isn't in the response.
```

So we end up with this ecosystem: a marketplace full of simple outbound webhooks that they call integrations, and the actual heavy lifting shoved onto the customer via a shaky API. It gets the compliance checkbox ticked, sure. But if you're expecting a true, deep integration that reduces manual toil, you're mostly paying for the privilege of building it yourself on their brittle plumbing.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>contrarian_coder</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/thoughts-on-the-integration-marketplace-most-integrations-are-just-webhook-receivers-2/</guid>
                    </item>
				                    <item>
                        <title>Secureframe vs Drata for a sub-50 person company - concrete cost &amp; feature breakdown.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/secureframe-vs-drata-for-a-sub-50-person-company-concrete-cost-feature-breakdown-2/</link>
                        <pubDate>Sat, 22 Aug 2026 19:55:51 +0000</pubDate>
                        <description><![CDATA[Hey everyone — I’m helping evaluate compliance tools for our startup (~35 people, SaaS). We need SOC 2 soon and are looking at Secureframe vs Drata.

I’ve seen high-level comparisons, but I’...]]></description>
                        <content:encoded><![CDATA[Hey everyone — I’m helping evaluate compliance tools for our startup (~35 people, SaaS). We need SOC 2 soon and are looking at Secureframe vs Drata.

I’ve seen high-level comparisons, but I’m struggling to find concrete, current details for a company our size. Could anyone share:

- Actual pricing you’re paying (or recent quotes) for around 50 seats? Ballpark is fine.
- Which core features actually mattered most during your audit?
- Any gotchas or extra costs that surprised you during onboarding?

We’re mostly using Google Workspace, AWS, and GitHub. I’m especially curious about how automated evidence collection really is for those. Thanks! &#x1f64f;]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>finnm</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/secureframe-vs-drata-for-a-sub-50-person-company-concrete-cost-feature-breakdown-2/</guid>
                    </item>
				                    <item>
                        <title>Just built a custom control mapping for SOC 2 using their API - here&#039;s the script.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/just-built-a-custom-control-mapping-for-soc-2-using-their-api-heres-the-script/</link>
                        <pubDate>Fri, 21 Aug 2026 09:01:09 +0000</pubDate>
                        <description><![CDATA[I&#039;ve been knee-deep in our SOC 2 prep, and one of the more tedious parts has always been mapping our internal security controls to the official Trust Services Criteria. The out-of-the-box ma...]]></description>
                        <content:encoded><![CDATA[I've been knee-deep in our SOC 2 prep, and one of the more tedious parts has always been mapping our internal security controls to the official Trust Services Criteria. The out-of-the-box mappings in Secureframe are good, but our setup is... particular. We have a lot of custom, in-house tooling for deployment and access reviews.

Since I live in the terminal, I decided to use Secureframe's API to automate it. The goal was to create a script that takes our internal control IDs and links them to the relevant Secureframe control objects, saving our compliance team hours of manual clicking.

Here's the gist of the approach:
*   The API is RESTful and well-documented. The key endpoint for this is `POST /v2/control_mappings`.
*   You need to first fetch the list of existing Secureframe controls (via `GET /v2/controls`) to get their UUIDs.
*   The script then reads a CSV where each row has our internal control code and the corresponding Secureframe control ID(s). It's basically a data pipeline: extract from CSV, transform/lookup IDs, load to API.

The main gotcha was handling the many-to-many relationships. One of our internal controls might map to three SOC 2 criteria, and the API payload needs to reflect that. Also, error handling is crucial—you don't want to silently fail on a partial batch.

This has been a game-changer for our workflow. It ensures consistency and lets us version our mappings in git. Curious if anyone else has tried something similar? I'm wondering about the long-term maintenance, especially when Secureframe updates their standard library. Do you just re-run the mapping script and review the diffs?

—Claire]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>ClaireN</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/just-built-a-custom-control-mapping-for-soc-2-using-their-api-heres-the-script/</guid>
                    </item>
				                    <item>
                        <title>Just built a custom alert for when critical controls have no evidence for &gt;7 days.</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/just-built-a-custom-alert-for-when-critical-controls-have-no-evidence-for-7-days-2/</link>
                        <pubDate>Wed, 19 Aug 2026 20:16:03 +0000</pubDate>
                        <description><![CDATA[Hey everyone, been using Secureframe for about three months now to help with our SOC 2 prep. I&#039;m still pretty new to all this compliance stuff, so apologies if this is obvious!

I kept runni...]]></description>
                        <content:encoded><![CDATA[Hey everyone, been using Secureframe for about three months now to help with our SOC 2 prep. I'm still pretty new to all this compliance stuff, so apologies if this is obvious!

I kept running into this issue: we'd have a critical control (like "daily log review") that would go "stale" because someone forgot to upload evidence. We'd only realize it during our internal weekly check, which felt risky. The platform alerts you when a control *fails*, but not necessarily when it's just... empty for a while.

So I spent an afternoon in their automation/alerting section and figured out how to build a custom alert that triggers if a control tagged as "critical" has had no evidence uploaded for more than 7 days. It uses a simple filter for control priority and evidence last updated date. It's been a lifesaver for our team—we get a Slack message and can nudge the right person before it becomes a real gap.

My question is: Is this a common workaround? Do more experienced users have other custom alerts set up that they find indispensable? I'm wondering what else I might be missing that could help us stay proactive. Also, is there a downside to pinging people too often that I haven't considered?

Really appreciating learning from this community.
New here!]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>hannahm</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/just-built-a-custom-alert-for-when-critical-controls-have-no-evidence-for-7-days-2/</guid>
                    </item>
				                    <item>
                        <title>Has anyone tried the Slack integration for policy updates? Does it reduce email noise?</title>
                        <link>https://communities.stackinsight.net/community/cyber-secureframe/has-anyone-tried-the-slack-integration-for-policy-updates-does-it-reduce-email-noise-2/</link>
                        <pubDate>Tue, 18 Aug 2026 03:01:08 +0000</pubDate>
                        <description><![CDATA[Hi everyone. I’ve been evaluating Secureframe for the past few weeks as part of a broader SOC 2 readiness project at my company. We’re a team of about 80, and one of the pain points we’re tr...]]></description>
                        <content:encoded><![CDATA[Hi everyone. I’ve been evaluating Secureframe for the past few weeks as part of a broader SOC 2 readiness project at my company. We’re a team of about 80, and one of the pain points we’re trying to solve is communication overload, specifically around policy and control updates.

Right now, every minor change or required acknowledgment gets blasted via email, and things get lost. I saw that Secureframe offers a Slack integration specifically for policy updates and employee acknowledgments. On paper, this seems like a perfect way to cut down on inbox noise and increase engagement, since our team lives in Slack.

However, I’m hesitant to propose enabling it without some real-world feedback. My concerns are less about the technical setup and more about the practical, day-to-day impact. I’d be very grateful if anyone who has implemented this could share their experience.

My main questions are:

*   **Adoption &amp; Behavior:** Did employees actually acknowledge policies faster or more reliably in Slack versus email? Or did the Slack notifications just become another form of ignored noise?
*   **Granularity &amp; Control:** Can you finely tune what triggers a Slack notification? For instance, can we set it so only *new* policy releases or *major* revisions trigger a channel message, while minor edits do not?
*   **Workflow Fit:** How does it handle the acknowledgment workflow itself? Does the user get a clean, actionable Slack message with a button to acknowledge, or is it just a link back to Secureframe?
*   **Administrative Overhead:** From an admin perspective, was setting up and maintaining the integration straightforward? Were there any unexpected hurdles or configuration nuances?
*   **Overall Impact:** Would you say the net effect was a genuine reduction in email clutter and an improvement in compliance workflow velocity, or did it just shift the clutter to a different channel?

I’m also thinking about the Total Cost of Ownership in terms of time and attention. Switching a critical process like policy acknowledgment to a chat platform feels like it could either be a sleek efficiency gain or a distracting fragmentation.

Any insights, even if they’re just from a pilot or a short trial, would be incredibly helpful for my evaluation. I’m compiling a comparison for our procurement team, and firsthand details on this specific feature would carry a lot of weight.]]></content:encoded>
						                            <category domain="https://communities.stackinsight.net/community/cyber-secureframe/">Secureframe Reviews</category>                        <dc:creator>evanj</dc:creator>
                        <guid isPermaLink="true">https://communities.stackinsight.net/community/cyber-secureframe/has-anyone-tried-the-slack-integration-for-policy-updates-does-it-reduce-email-noise-2/</guid>
                    </item>
							        </channel>
        </rss>
		