trust.secureframe.com

Secureframe Trust Center

Secureframe is committed to ensuring the confidentiality, integrity, and availability of your data. Here is how we protect information and comply with industry standards and regulations. If you are a federal agency, click "see resources" below.

See resources

Monitoring

Continuously monitored by Secureframe

Compliance

We adhere to the highest standards of security

SOC 2 Type 2

SOC 2 Type 2

Service Organization Controls (SOC 2) (Type II) trust services principles

ISO 27001

ISO 27001

ISO/IEC 27001:2022 information security, cybersecurity and privacy protection

FedRAMP

FedRAMP

FedRAMP 20x Low Authorized

CMMC

CMMC

CMMC Level 2 Authorized. CMMC is a U.S. Department of Defense framework verifying contractors have implemented required cybersecurity practices to protect sensitive government data.

TX-RAMP

TX-RAMP

TX-RAMP provides a standardized approach for assessment and certification of cloud computing services that process the data of Texas state agencies.

GDPR

GDPR

Protect the personal data and privacy of EU citizens for transactions that occur within EU member states

CPRA

CPRA

California Consumer Privacy / Privacy Rights Act, is legislation designed to improve the data privacy of California residents

Resources

Get our latest security and compliance resources and reports

SOC 2 Type 2 report

Period July 1, 2024 to June 30, 2025

ISO 27001 certificate

ISO 27001:2022 certificate (January)

TX-RAMP Certification

Level 1 Valid until March 6, 2028

Pen Test Executive Summary

An executive summary of Secureframe's most recent penetration test

CMMC Level 2 Certification

CMMC Level 2 Certification from the Cyber AB, valid until 9/9/2028

CMMC Level 2 Summary Report

CMMC Level 2 Summary Report from audit with C3PAO Redspin

CMMC Shared Responsibility Matrix

Secureframe's CMMC Shared Customer Responsibility Matrix for the 110 controls of NIST 800-171 rev.2 & CMMC Level 2.

FedRAMP 20x Low Authorization Letter

Secureframe's FedRAMP 20x Low Authorization Letter, valid until 8/20/2026

FedRAMP 20x 3PAO Coalfire Validated Assessment Methodology

FedRAMP 20x KSI Validation - Human Readable - Public

View all

Subprocessors

AWS

Cloud Hosting Services

Data location: United States / London

Catamorphic Co. (Launch Darkly)

Catamorphic Co. (Launch Darkly)

Feature Flag Management

Data location: United States

DataDog

DataDog

Cloud-based monitoring and analytics platform

Data location: United States

Functional Software, Inc. (Sentry)

Functional Software, Inc. (Sentry)

Error tracking

Data location: United States

OneSchema

OneSchema

Data Import Structuring

Data location: United States

OpenAI

AI platform and large language model capability.

Data location: United States

Twilio, Inc.

Twilio, Inc.

Email Communications and Product Notifications

Data location: United States

Cloudflare

Cloudflare

Email Communications and Product Notifications

Data location: United States

Intercom (Fin)

Intercom (Fin)

Email Communications and Product Notifications

Data location: United States

View all

FedRAMP 20x Authorized Resources

Coalfire FedRAMP 20x Moderate Audit Methodology

Coalfire FedRAMP 20x Moderate Audit Report (Human Readable)

Coalfire FedRAMP 20x Moderate Audit Report (Machine Readable)

Secureframe POAM (as of 3-12-26)

Secureframe KSI Implementation Summaries

Secureframe FedRAMP 20x Schema

Secureframe FedRAMP 20x Controls Test (Human and Machine Readable) 3-31-26

FedRAMP 20x Authorization

Testing Methodology (CNA Example)

Read the original on trust.secureframe.com ↗