# Secureframe MCP connector

Connect Secureframe to Claude, ChatGPT, Cursor, or any MCP client through Elaichi, and your team can ask about controls, frameworks, evidence, devices, and cloud resources, then add comments or update scope, all inside each person's own Secureframe access.

Source: https://elaichi.ai/connectors/secureframe/

## Facts

| | |
| --- | --- |
| Application | Secureframe |
| Category | Compliance |
| AI tools | 57 |
| Authentication | Connects with an API key |
| Needs your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. 57 tools is past the 30-tool threshold, so clients use `search_tools` and `execute_tool` |

## What you can ask once Secureframe is connected

- List all Secureframe repositories missing a framework asset scope.
- Show cloud resources added to Secureframe this week.
- Summarize open comments on our SOC 2 framework scopes.

## Connect Secureframe in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Secureframe.
2. Optionally set Share with, then press Connect.
3. Paste a Secureframe API key. One person generates a token in Secureframe and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Secureframe tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Connect Secureframe to Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Connect Secureframe to ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Connect Secureframe to Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Secureframe to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Secureframe tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Secureframe through Elaichi

### Check control status before the audit call

Compliance. Ask which SOC 2 or ISO 27001 controls in Secureframe still need attention, pull the details on any one of them, and leave a comment for the owner without opening a tab.

### Find cloud resources missing from a framework

Security. List the cloud resources Secureframe knows about, spot the ones not yet in scope for a framework, and add them so the next test run covers everything it should.

### Review devices and bring them into scope

IT. See every laptop and workstation Secureframe is tracking, check which ones fall under a given framework, and put a new hire's machine in scope the same afternoon.

### Keep repositories tagged and in scope

Engineering. Look up how a code repository is recorded in Secureframe, update its details when a service is renamed, and confirm it counts toward the frameworks your customers ask about.

### Pull evidence details for a customer questionnaire

Risk. Ask for the evidence attached to a specific control in Secureframe and get a plain summary you can paste into a vendor security questionnaire answer.

### Get a readiness summary in plain language

Leadership. Ask how many controls are passing for each framework in Secureframe and where the gaps are, then record follow-up notes as comments so the team sees them where they already work.

## Frequently asked questions

### How do I connect Secureframe to Claude?

In Elaichi, choose Secureframe and paste in an API key from your Secureframe account. Secureframe connects with an API key, so there is no OAuth application to register and no client ID or secret to generate. Then in Claude, open Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Sign in with your Elaichi account and Secureframe is ready.

### Does Secureframe work with ChatGPT and Cursor as well as Claude?

Yes. Once Secureframe is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You connect Secureframe once and every client picks it up.

### What can an AI agent actually do with my Secureframe data?

An agent can look up frameworks, controls, and the evidence behind them in Secureframe, list the devices, cloud resources, and code repositories being monitored, and tell you which ones are in scope for a framework. It can also add or edit comments, update a repository or cloud resource, put an asset into scope, and record custom connection data. Because Secureframe exposes a lot of actions, short concrete asks such as 'list failing controls for SOC 2' work better than long paragraphs.

### Does connecting Secureframe give the AI access to everything in my compliance workspace?

No. Every request runs as the person who signed in, so an agent only sees the frameworks, controls, evidence, and assets that person can already see in Secureframe. Elaichi can narrow that further with restrictions per team or per action, and it can never grant more than the person's own Secureframe permissions allow.

### Can my team share one Secureframe connection?

Yes. One person connects Secureframe with an API key and shares the connection with a team in Elaichi, and nobody else ever handles the key. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person behind every read, comment, or update in Secureframe.

### Can I stop an agent from deleting or changing things in Secureframe?

Yes. Restrictions in Elaichi work per action, so you can allow reading controls and evidence in Secureframe while blocking comment deletion, scope changes, or updates to cloud resources and repositories. A blocked action is never shown to the AI client at all, so no prompt, however worded, can reach it.

### What happens to a Secureframe connection when someone leaves?

Offboarding a person in Elaichi ends their access to Secureframe through every client at once, with nothing to revoke in Claude, ChatGPT, or Cursor separately. A Secureframe connection they shared keeps working for everyone else on the team. If you want to remove Secureframe entirely, disconnecting it once in Elaichi removes it from every client.

## All 57 Secureframe tools

Every tool below is callable through https://api.elaichi.ai/mcp once Secureframe is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all Secureframe repository framework asset scopes** (List). List Framework Asset Scopes for a secureframe repository. The absence of a Framework Asset Scope indicates the asset is not in scope for the Framework. Returns: id, active, framework_id, manually_scoped_reason, created_at. Required: repository_id.
- **Create a Secureframe repository framework asset scope** (Create). Create a Framework Asset Scope for a secureframe repository. Framework Asset Scopes are immutable — once created they cannot be modified; create a new scope to update. Returns: id, active, framework_id, manually_scoped_reason, created_at. Required: repository_id.
- **Update a Secureframe repository by ID** (Update). Update a Secureframe repository by id. Returns: id, created_at, updated_at. Required: id.
- **List all Secureframe repositories** (List). List repositories in Secureframe. Returns: id, created_at, updated_at. Supports Lucene syntax filtering via the q parameter and optional relationship sideloading via include and relationships.
- **Get single Secureframe repository by ID** (Get). Get a single Secureframe repository by id. Returns: id, created_at, updated_at. Required: id.
- **List all Secureframe cloud resources** (List). List Secureframe cloud resources. Returns: id, cloud_resource_type, vendor_name, region, third_party_id, in_audit_scope, owner_id, created_at, updated_at. Use `q` for Lucene-syntax filtering and `include` to embed related data.
- **Get single Secureframe cloud resource by ID** (Get). Get a single Secureframe cloud resource by id. Returns: id, cloud_resource_type, vendor_name, region, third_party_id, in_audit_scope, owner_id, created_at, updated_at. Required: id.
- **Update a Secureframe cloud resource by ID** (Update). Update a Secureframe cloud resource by id. Returns: id, cloud_resource_type, vendor_name, region, third_party_id, in_audit_scope, owner_id, created_at, updated_at. Required: id.
- **List all Secureframe cloud resource framework asset scopes** (List). List framework asset scopes for a Secureframe cloud resource. Returns: id, in_audit_scope, out_of_audit_scope_reason for each scope record associated with the specified cloud resource. Required: cloud_resource_id.
- **Create a Secureframe cloud resource framework asset scope** (Create). Create a framework asset scope for a Secureframe cloud resource, setting its audit scope status for a given framework. Returns: id, in_audit_scope, out_of_audit_scope_reason. Required: cloud_resource_id.
- **List all Secureframe comments** (List). List Secureframe comments with optional filtering and full-text search. Returns: id, content, commentable_type, commentable_id, company_id, conversation_id. Use q for Lucene-syntax filtering and include to sideload related resources.
- **Get single Secureframe comment by ID** (Get). Get a single Secureframe comment by id. Returns: id, content, commentable_type, commentable_id, company_id, conversation_id. Required: id.
- **Create a Secureframe comment** (Create). Create a new comment in Secureframe attached to a commentable resource. Returns: id, content, commentable_type, commentable_id, company_id, conversation_id.
- **Update a Secureframe comment by ID** (Update). Update an existing Secureframe comment's content by id. Returns: id, content, commentable_type, commentable_id, company_id, conversation_id. Required: id.
- **Delete a Secureframe comment by ID** (Delete). Delete a Secureframe comment by id. Returns an empty 204 response on success. Required: id.
- **List all Secureframe controls** (List). List Controls in Secureframe. Returns: id, name, key, health_status, enabled, custom, owner_name, frameworks, created_at, updated_at. Filter using Lucene syntax via the q parameter, or include related objects (author, company, owner) via include.
- **Get single Secureframe control by ID** (Get). Get a single Secureframe Control by id. Returns: id, name, key, health_status, enabled, custom, owner_name, frameworks, created_at, updated_at. Required: id.
- **Create a Secureframe custom connection datum** (Create). Submit resource data to a Secureframe custom connection for asynchronous processing. Accepts an array of resource objects conforming to a specified schema and vendor slug. Returns a 202 Accepted response with no body indicating the data is enqueued for processing. Required: id, resource_data, schema_slug, vendor_slug.
- **List all Secureframe devices** (List). List Secureframe devices. Returns: id, device_name, os, make, model, serial_number, mac_address, owner_name, hard_drive_encrypted, local_firewall_enabled, created_at, updated_at. Supports Lucene-syntax search and filtering via the q parameter.
- **Get single Secureframe device by ID** (Get). Get a single Secureframe device by id. Returns: id, device_name, os, make, model, serial_number, mac_address, owner_name, hard_drive_encrypted, local_firewall_enabled, created_at, updated_at. Required: id.
- **List all Secureframe device framework asset scopes** (List). List Framework Asset Scopes for a Secureframe device. The absence of a scope indicates the device is not in scope for the given Framework. Returns: id, device_id, framework_id, active, manually_scoped_reason. Required: device_id.
- **Create a Secureframe device framework asset scope** (Create). Create a Framework Asset Scope for a Secureframe device. Scopes are immutable once created; to change scope, create a new record. Returns: id, device_id, framework_id, active, manually_scoped_reason. Required: device_id.
- **Get single Secureframe evidence by ID** (Get). Get a single Evidence record from Secureframe by id. Returns: id. Required: id.
- **List all Secureframe frameworks** (List). List Secureframe frameworks. Returns: id, title, created_at, updated_at. Supports full-text search via q (Lucene syntax) and optional relationship includes via include.
- **Get single Secureframe framework by ID** (Get). Get a single Secureframe framework by id. Returns: id, title, created_at, updated_at. Required: id.
- **List all Secureframe framework requirements** (List). List Secureframe Framework Requirements. Returns: id, name, key, enabled, health_status. Filter by enabled, health_status, id, key, or name using Lucene syntax via the q parameter.
- **Get single Secureframe framework requirement by ID** (Get). Get a single Secureframe Framework Requirement by id. Returns: id, name, key, enabled, health_status. Required: id.
- **List all Secureframe integration connections** (List). List Secureframe integration connections. Returns: id, name, status, updated_at, vendor_name. Supports Lucene-syntax filtering via q, and relationship sideloading via include or relationships.
- **Get single Secureframe integration connection by ID** (Get). Get a single Secureframe integration connection by id. Returns: id, name, status, updated_at, vendor_name. Required: id.
- **Secureframe integration connections archive** (Archive). Archive a Secureframe integration connection by id. Returns the updated connection record including id, name, status, updated_at, and vendor_name. Required: id.
- **Get single Secureframe knowledge base answer by ID** (Get). Get a single Secureframe Knowledge Base Answer by id. Returns: id, content, type, primary_answer, knowledge_base_question_id. Required: id.
- **Create a Secureframe knowledge base answer** (Create). Create a new Secureframe Knowledge Base Answer linked to an existing Knowledge Base Question. Returns: id, content, type, primary_answer, knowledge_base_question_id. Required: content, knowledge_base_question_id, type.
- **Update a Secureframe knowledge base answer by ID** (Update). Update an existing Secureframe Knowledge Base Answer by id. Returns: id, content, type, primary_answer, knowledge_base_question_id. Required: id.
- **Delete a Secureframe knowledge base answer by ID** (Delete). Delete a Secureframe Knowledge Base Answer by id. Returns an empty 200 response on success. Required: id.
- **List all Secureframe risks** (List). List risks in Secureframe. Returns: id, custom_risk_id, description, owner_name, archived. Filter results using Lucene syntax via the q parameter, or include the related owner object via the include parameter.
- **Get single Secureframe risk by ID** (Get). Get a single Secureframe risk by id. Returns: id, custom_risk_id, description, owner_name, archived. Required: id.
- **Create a Secureframe security questionnaire** (Create). Create a new Security Questionnaire in Secureframe by uploading a questionnaire file with associated metadata. Returns the created questionnaire object including its id, owner_id, and company_name. Required: owner_id, file.
- **List all Secureframe tests** (List). List tests in Secureframe. Returns: id.
- **Get single Secureframe test by ID** (Get). Get a single Secureframe test by id. Returns: id. Required: id.
- **Update a Secureframe test by ID** (Update). Update a Secureframe test by id. Returns: id. Required: id.
- **Create a Secureframe test export** (Create). Create a Test Export for a Secureframe test. Returns: id, test_id. Required: test_id.
- **Get single Secureframe test export by ID** (Get). Get a Secureframe Test Export by id. Returns: id, test_id. Required: id.
- **List all Secureframe trust center requests** (List). List Trust Center Requests in Secureframe. Returns: id, email, requester_name, reviewed, created_at. Use q to filter with Lucene syntax; use include to sideload trust_center_resource_requests.
- **Get single Secureframe trust center request by ID** (Get). Get a single Secureframe Trust Center Request by id. Returns: id, email, requester_name, reviewed, created_at, document_security. Required: id.
- **Update a Secureframe trust center request by ID** (Update). Update a Secureframe Trust Center Request by id, including approving or rejecting resource requests and setting document security. Returns: id, email, requester_name, reviewed, created_at, document_security. Required: id.
- **Get single Secureframe user security setting by ID** (Get). Get user security settings in Secureframe for the authenticated company and user. Returns the UserSecuritySetting object including id and security configuration fields specific to the company and user; consult Secureframe API documentation for the full field breakdown.
- **List all Secureframe vendors** (List). List Secureframe vendors. Returns: id, name, archived, owner_name, risk_level, updated_at. Supports Lucene-syntax search and filtering via q. Deprecated — prefer the Third Party Risk Management Vendor endpoint.
- **Get single Secureframe vendor by ID** (Get). Get a single Secureframe vendor by id. Returns: id, name, archived, owner_name, risk_level, updated_at. Required: id. Deprecated — prefer the Third Party Risk Management Vendor endpoint.
- **Secureframe vendors archive** (Archive). Archive a Secureframe vendor by id. Returns the updated vendor record including id, name, archived, owner_name, risk_level, and updated_at. Required: id. Deprecated — prefer the Third Party Risk Management Vendor endpoint.
- **Get single Secureframe knowledge base question by ID** (Get). Get a Secureframe Knowledge Base Question by id. Returns: id, content, owner_id, review_frequency, manual_review_requested. Required: id.
- **Create a Secureframe knowledge base question** (Create). Create a new Secureframe Knowledge Base Question. Returns the created question including id, content, owner_id, review_frequency, and manual_review_requested. Required: content.
- **Update a Secureframe knowledge base question by ID** (Update). Update a Secureframe Knowledge Base Question by id. Returns the updated question including id, content, owner_id, review_frequency, and manual_review_requested. Required: id.
- **Delete a Secureframe knowledge base question by ID** (Delete). Delete a Secureframe Knowledge Base Question by id. Returns an empty 200 OK response with no body on success. Required: id.
- **List all Secureframe tprm vendors** (List). List Third Party Risk Management Vendors in Secureframe. Returns: id, name, risk_level, archived, owner_name, updated_at, created_at. Filter results with Lucene syntax via q; optionally include related data using include or relationships.
- **Get single Secureframe tprm vendor by ID** (Get). Get a single Third Party Risk Management Vendor in Secureframe by id. Returns: id, name, risk_level, archived, owner_name, updated_at, created_at. Required: id.
- **Secureframe tprm vendors archive** (Archive). Archive a Third Party Risk Management Vendor in Secureframe by id. Returns: id, name, archived, risk_level, owner_name, updated_at, created_at. Required: id.
- **Create a Secureframe test evidence** (Create). Upload evidence to a test in Secureframe by attaching a file via multipart form. Returns: id. Required: test_id, file. Optionally supply activity_completion to record the date the activity was completed.
