Product
Jentic OSThe workplace. An in-house AI platform for every employeeJentic OneSafe access. Agents reach your systems without holding keysJentic AIRThe foundation. Gets your existing platforms ready for AI
Pricing
Developers

GET STARTED

API DirectoryBrowse 10,000+ APIs Ready For AI Agent IntegrationDocumentationGuides and API reference

TOOLS

API ScoringCheck your AI Readiness using our scorecardArazzo UIVisualize Arazzo Workflows As Interactive DocumentationArazzo EditorBuild And Edit Multi-Step API Workflows Visually

COMMUNITY

GitHubOpen source projects and examplesOpen StandardsBuilt on open specs. Never locked in.
Resources
Company
About UsOur mission and teamCareersJoin our teamContactGet in touch
Try it now
Jentic OSJentic OneJentic AIR
Pricing
API DirectoryDocumentationAPI ScoringArazzo UIArazzo EditorGitHubOpen Standards
Resources
About UsCareersContact
Try it now
JenticJentic
Products
  • Jentic OS
  • Jentic One
  • Jentic AIR
For Developers
  • API Directory
  • Documentation
  • GitHub
Company
  • About Jentic
  • Careers
  • Contact Us
  • Trust Centre
ISO/IEC 27001:2022 certification badge issued by Prescient SecurityISO/IEC 27001:2022 certification badge issued by Prescient Security

Information Security Management System

Certified to ISO/IEC 27001:2022 by Prescient Security

Terms & Conditions•Privacy Policy•
© 2026 Jentic Technology Ltd. All rights reserved.
Switch to light modeSwitch to dark mode
APIs / Security / Secureframe API
Secureframe API logo

Secureframe API

Official vendor OpenAPI document · agent-readySecurityCompliancebearer10 EndpointsREST

For Agents

Programmatically list users, list compliance frameworks. Covers 10 operations with bearer authentication.

Use for: I need to users, I want to compliance frameworks, Search for controls, Find all control

Not supported: Does not handle payments, communications, or crm - use for security only.

Secureframe API for compliance automation, risk management, and security posture monitoring. Manage compliance frameworks, audits, and security controls. The API exposes 10 endpoints secured with bearer authentication.

Jentic One on GithubView OpenAPI Document

Install Jentic One Beta

Connect the Secureframe API to your agent

Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Secureframe API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.

Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.

1

Step 1: Jentic One Host machine

# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fsecureframe.com%2Fsecureframe" | sh
2

Step 2: Agent machine

# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fsecureframe.com%2Fsecureframe" | sh
jentic register       # connects your agent to your Jentic One instance

Jentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.

Capabilities

What an agent can do with Secureframe API.

List Users

Get Control

Create Vendor

Query and filter Secureframe API records by parameters

Monitor Secureframe API operational status and events

Use Cases

Patterns agents use Secureframe API for, with concrete tasks.

★ Security Operations

Use the Secureframe API to perform security operations programmatically. The API provides 10 endpoints covering core functionality including list users, list compliance frameworks, list controls.

Call GET /users to list users

Automated Audits Management

Automate audits operations by combining multiple Secureframe API endpoints. Agents can list compliance frameworks and then list controls in a single workflow.

Call GET /compliance-frameworks to list compliance frameworks, then verify the result

AI Agent Integration via Jentic

AI agents discover and call Secureframe API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.

Search Jentic for 'list users', load the operation schema, and execute with Jentic-managed credentials

Key Endpoints

10 endpoints — secureframe api for compliance automation, risk management, and security posture monitoring.

METHOD

PATH

DESCRIPTION

GET

/users

List Users

GET

/compliance-frameworks

List Compliance Frameworks

GET

/controls

List Controls

GET

/controls/{control_id}

Get Control

GET

/audits

List Audits

POST

/vendors

Create Vendor

GET

/vendors

List Vendors

POST

/evidence

Upload Evidence

GET

/users

List Users

GET

/compliance-frameworks

List Compliance Frameworks

GET

/controls

List Controls

GET

/controls/{control_id}

Get Control

GET

/audits

List Audits

POST

/vendors

Create Vendor

GET

/vendors

List Vendors

POST

/evidence

Upload Evidence

Why Jentic?

What agents get from Jentic-routed access to this vendor.

Setup

Setup

Wiring the Secureframe API by hand means obtaining its bearer token, threading it onto every call, and building each users, controls, and evidence request yourself. Through Jentic you install once, import Secureframe from the API Directory, store the token once, and your agent calls it.

Permission scoping

Permission scoping

The Secureframe API mixes read lists with creates like adding a vendor or evidence, and its writes take their target in the request body, so scope by operation: limit the agent to the operations it needs, such as listing controls or reading users, and leave vendor or evidence creation out unless you add them.

Credential management

Credential isolation

Your Secureframe token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.

Intent-based discovery

Intent-based discovery

Agents search Jentic by intent such as 'list compliance controls' or 'look up a control', and Jentic returns the matching Secureframe operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

Related APIs

Alternatives and complements available in the Jentic catalogue.

Alternative

Snyk

Alternative security API

Choose Snyk when you need a different approach to security operations

Alternative

Crowdstrike

→

Alternative security API

Choose Crowdstrike when you need a different approach to security operations

FAQs

Specific to using Secureframe API through Jentic.

What authentication does the Secureframe API use?

The Secureframe API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

Can I list users with the Secureframe API?

Yes. Use the GET /users endpoint. The API returns structured JSON responses that agents can parse and act on directly.

What are the rate limits for the Secureframe API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

How do I list users through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'list users'. Jentic returns the matching Secureframe API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

How many endpoints does the Secureframe API have?

The Secureframe API exposes 10 endpoints covering audits, compliance, controls operations.

Can I limit what my agent is allowed to do with the Secureframe API?

Yes. Because you run Jentic One yourself, you decide which Secureframe operations your agent may call, so you can allow read-only calls like listing controls (GET /controls) and reading users (GET /users) while leaving out the write operations that create vendors (POST /vendors) or upload evidence (POST /evidence). Since those writes take their target in the request body, keeping them off the allowed list stops the agent from adding vendors or evidence unless you explicitly grant it. Your Secureframe bearer token is stored encrypted by your own instance and injected only for the operations you permit.

GET STARTED

Start building with Secureframe API

Explore with Jentic One
View OpenAPI Document