canonical: https://jentic.com/apis/secureframe.com/secureframe

# Secureframe API

Secureframe API for compliance automation, risk management, and security posture monitoring. Manage compliance frameworks, audits, and security controls. The API exposes 10 endpoints secured with bearer authentication.

## For AI agents

Programmatically list users, list compliance frameworks. Covers 10 operations with bearer authentication.

## Scope

Does not handle payments, communications, or crm - use for security only.

## Capabilities

- List Users
- Get Control
- Create Vendor
- Query and filter Secureframe API records by parameters
- Monitor Secureframe API operational status and events

## Use cases

### Security Operations

Use the Secureframe API to perform security operations programmatically. The API provides 10 endpoints covering core functionality including list users, list compliance frameworks, list controls.

Example prompt: Call GET /users to list users

### Automated Audits Management

Automate audits operations by combining multiple Secureframe API endpoints. Agents can list compliance frameworks and then list controls in a single workflow.

Example prompt: Call GET /compliance-frameworks to list compliance frameworks, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Secureframe API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.

Example prompt: Search Jentic for 'list users', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | /users | List Users |
| GET | /compliance-frameworks | List Compliance Frameworks |
| GET | /controls | List Controls |
| GET | /controls/{control_id} | Get Control |
| GET | /audits | List Audits |
| POST | /vendors | Create Vendor |
| GET | /vendors | List Vendors |
| POST | /evidence | Upload Evidence |

## Key resources

- **Audits** — Operations related to Audits
- **Compliance** — Operations related to Compliance
- **Controls** — Operations related to Controls
- **Evidence** — Operations related to Evidence
- **Integrations** — Operations related to Integrations

## Why Jentic

- **Setup:** Wiring the Secureframe API by hand means obtaining its bearer token, threading it onto every call, and building each users, controls, and evidence request yourself. Through Jentic you install once, import Secureframe from the API Directory, store the token once, and your agent calls it.
- **Permission scoping:** The Secureframe API mixes read lists with creates like adding a vendor or evidence, and its writes take their target in the request body, so scope by operation: limit the agent to the operations it needs, such as listing controls or reading users, and leave vendor or evidence creation out unless you add them.
- **Credential handling:** Your Secureframe token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'list compliance controls' or 'look up a control', and Jentic returns the matching Secureframe operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Snyk** — Alternative security API
- **Crowdstrike** — Alternative security API

## FAQ

### What authentication does the Secureframe API use?

The Secureframe API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I list users with the Secureframe API?

Yes. Use the GET /users endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Secureframe API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I list users through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'list users'. Jentic returns the matching Secureframe API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Secureframe API have?

The Secureframe API exposes 10 endpoints covering audits, compliance, controls operations.

### Can I limit what my agent is allowed to do with the Secureframe API?

Yes. Because you run Jentic One yourself, you decide which Secureframe operations your agent may call, so you can allow read-only calls like listing controls (GET /controls) and reading users (GET /users) while leaving out the write operations that create vendors (POST /vendors) or upload evidence (POST /evidence). Since those writes take their target in the request body, keeping them off the allowed list stops the agent from adding vendors or evidence unless you explicitly grant it. Your Secureframe bearer token is stored encrypted by your own instance and injected only for the operations you permit.
