Skip to content

Integration · Developer tools

Connect Claude & ChatGPT to Secureframe

Ask your AI which compliance tests are failing, how a control is doing, or what is in your risk register. It can search tests, controls, policies, risks, tasks, vendors, devices and personnel in Secureframe. It can also update tests and people, attach evidence, add comments, and create and update POA&M items.

Connect Secureframe free

Free plan, no credit card. Takes about a minute.

Try asking

  • “Which tests are failing right now?”

    The AI searches your compliance tests and reads the failing ones with owner, due date and remediation steps.

  • “Which frameworks are we working on?”

    It lists your compliance frameworks, for example SOC 2 or ISO 27001.

  • “Which employee devices have security issues?”

    It searches devices and shows their security status.

What your AI can do

Tests and controls

Search tests and controls, read status, owner and remediation steps, update tests and attach evidence.

Risks and POA&M

Search the risk register, read risk scores and treatment, and create or update POA&M items.

Vendors, people and devices

Look up vendors and third-party risk vendors, search personnel and devices, and update a person's status or audit scope.

  • “Show the high risks in our risk register.”

    It searches the risk register and reads each risk with its score, owner and treatment.

  • “Add a note to the access review test that this quarter's review is done.”

    It finds the test and attaches evidence as an activity completion note.

  • “Create a POA&M item for missing MFA on the build server, owned by Anna, due 30 June.”

    It creates the item with issue, owner, due date and remediation plan.

29 tools for Secureframe

These tools are switched on when you connect. You can switch any of them off, or require your approval before it runs.

  • add_commentChanges dataAdd a comment with `content` to a record by `commentable_type` and `commentable_id`.
  • add_test_evidenceChanges dataAttach evidence to a test by `test_id`, using an `upload_id` or an `activity_completion` note.
  • create_poam_itemChanges dataCreate a POA&M item with an `issue` and `owner_id`, plus status, risk level, due date and remediation plan.
  • get_controlGet one control by `control_id`, with its linked tests and policies when `relationships` is true.
  • get_personGet one person by `user_id`, including onboarding status and audit scope.
  • get_policyGet one policy by `policy_id`.
  • get_riskGet one risk by `risk_id`, with its score, owner and treatment.
  • get_taskGet one task by `task_id`.
  • get_testGet one test by `test_id`, including status, owner, due date and remediation steps.
  • get_tprm_vendorGet one third-party risk management vendor by `supplier_id` (the vendor ID).
  • get_vendorGet one vendor by `supplier_id` (the vendor ID).
  • list_frameworksList the compliance frameworks you are working on (e.g. SOC 2, ISO 27001).
  • list_tprm_vendorsList vendors in third-party risk management, searchable with `q`.
  • list_vendorsList vendors in your vendor inventory, searchable with `q`.
  • search_commentsSearch comments by `q`.
  • search_controlsSearch controls by `q`. Use to find a control's ID and its health.
  • search_devicesSearch employee devices by `q`, with their security status.
  • search_evidenceSearch uploaded evidence by `q`.
  • search_framework_requirementsSearch framework requirements by `q`.
  • search_personnelSearch personnel by `q` (name or email).
  • search_poam_itemsSearch POA&M items (plan of action and milestones) by `q`.
  • search_policiesSearch policies by `q`.
  • search_risksSearch the risk register by `q`.
  • search_tasksSearch compliance tasks by `q`.
  • search_testsSearch compliance tests by `q`, with paging and sorting. Use to find failing tests and their IDs.
  • search_trust_center_requestsSearch Trust Center access requests by `q`.
  • update_personChanges dataUpdate a person by `user_id`: active, employee type, start or end date, or audit scope.
  • update_poam_itemChanges dataUpdate a POA&M item by `product_id` (the item ID): status, risk level, due date, owner or remediation plan.
  • update_testChanges dataUpdate a test by `test_id`: owner, enabled, next due date, interval or justifications.

Set up in three steps

  1. 1

    Pick the app

    Create a free PipMCP account and choose Secureframe from the app list.

  2. 2

    Paste your key

    Choose your Secureframe API address (https://api.secureframe.com for US or https://api-uk.secureframe.com for UK) and paste your API key and secret as one value: the key, a space, then the secret. Create the key in the Secureframe console under Your Profile > Company settings > API keys. Only certain roles can do this, and the secret is shown once.

  3. 3

    Add the link to your AI

    You get a personal MCP link. Add it to Claude, ChatGPT or Cursor:

    1. Click your name, then Settings › Connectors › Add custom connector.
    2. Paste your link as the Remote MCP server URL.
    3. Switch it on from the + menu in a chat.

Questions

What can the AI do in Secureframe?

The AI can search and read tests, controls, frameworks, framework requirements, policies, risks, tasks, evidence, comments, POA&M items, vendors, third-party risk vendors, devices, personnel and Trust Center requests. It can update tests and people, attach evidence to tests, add comments, and create and update POA&M items.

Does the AI see my Secureframe credentials?

No. Your Secureframe API key and secret are encrypted at rest and never shown to the AI. After you save them, they are not shown again, not even to you. The AI only sees the results of the tools it calls.

Can I control what the AI is allowed to do?

Yes. You choose which tools are switched on, so you can start read-only. Updating tests, people and POA&M items changes your compliance records, so these can require your approval before they run. Every tool call is logged.

Does it work with ChatGPT?

Yes. In ChatGPT go to Settings › Apps & Connectors › Advanced and turn on Developer mode, then add your PipMCP link. Developer mode needs a paid ChatGPT plan: Plus, Pro, Business or Enterprise. The same link also works in Claude (Settings › Connectors › Add custom connector), Cursor and other MCP clients.

What does it cost?

PipMCP has a free plan with no credit card required. Paid plans bill per completed task. You also need your own Secureframe account.

Why do I paste the key and secret together?

Secureframe authenticates with an API key plus a secret. PipMCP takes them as one value: the key, a space, then the secret. You also pick the API address that matches your Secureframe region, US or UK.

Let your AI work in Secureframe today.

Start free. Your key stays encrypted, and you decide what the AI may do.

Connect Secureframe free

PipMCP is not affiliated with Secureframe. Product names are trademarks of their owners.