Reviews from AWS customer
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
1,166 reviews
from
External reviews are not included in the AWS star rating for the product.
A great maangement tool to take away the pain
What do you like best about the product?
Its just one place to store all of the artefacts, results, tools and tasks to take care of our security and compliance needs. Integrations make life super easy - I can't imagine a world where we would have to go and fetch all this data independently. It must have saved use hundreds of expensive hours!
What do you dislike about the product?
Not too much. It provides enough value to not dislike it.
What problems is the product solving and how is that benefiting you?
Compliance and security monitoring.
Simplifies Compliance Without Sacrificing Depth
What do you like best about the product?
I am a Managing Director (Not a security expert anyhow) and Secureframe is cool as it can pull compliance docs for prospects. The “Shared Evidence” functionality allows me to provide limited access to auditors or clients without exposing my internal systems. Powerful — making enterprise buyers who are otherwise hesitant believe in them to the point that they have been doing demos over calls with their customer support team explaining controls.
What do you dislike about the product?
It even offers some sales-facing features (e.g. it can respond to RFPs automatically), but the set-up cost is high. Smaller sales teams may find the time difficult to dedicate to set up.
What problems is the product solving and how is that benefiting you?
One of the biggest benefits of Secureframe is it allows you to get through the security theater in sales conversations. I can share timely compliance status results rather than nebulous promises. It also has cut down on how many times I go back and forth with our security team—I can now answer about 80% of prospect inquiries on the fly.
The Backbone of Our Compliance Strategy
What do you like best about the product?
As an Admin at a financial service, I use Secureframe for dealing with redundant regulation: (SOC 2, GDPR, NYDFS). It is one example of how the Platform can statically map controls against frameworks, avoiding duplication (1 AWS config check for multiple requirements). I love the audit schedule, it is a great way to track deadlines in bite size pieces so you don't miss anything.
What do you dislike about the product?
Additional customizability with reporting exports I use them for board meetings and find I have to manually format the data in order to focus on certain risks or progress metrics.
What problems is the product solving and how is that benefiting you?
By using Secureframe, compliance became a competitive edge in our company instead of just a cost center. We have gone through audits with 0 findings, cut our external consultant fees by 75%, and even leveraged our compliance posture when negotiating better cyber insurance rates.
Efficiency Boost for IT and Sales Teams Alike
What do you like best about the product?
I love that Secureframe is one of the few security tools designed as a bridge between the world of security and sales for an IT Director. Our sales support team now spends less time on security questionnaires and the automated compliance reports (e.g. for RFPs) have been a blessing Remediation tasks are tracked across integrations with software like Jira and Slack, and auditors laud the presentation of evidence in their workflow.
What do you dislike about the product?
These little clusters of quirks, such as the need to manually re-upload some controls over and over — bunch up into clutter. And I wish there were more controls around task assignment — the DevOps sub-team vs. HR can't cleanly separate out their compliance workloads).
What problems is the product solving and how is that benefiting you?
Compliance is now a differentiator, instead of a sales blocker. We now sign deals faster because our prospects believe our SOC 2 reports, and IT does not need to chase its tail gathering screenshots or policy signatures. Very few tools will make both tech and business teams happy, but this does that.
Simplifies all aspects of gaining and maintaining SOC2 compliance
What do you like best about the product?
Secureframe provides complete coverage of SOC2 compliance controls making compliance and auditing super easy. There are loads of integrations with software platforms (we use GCP and Atlassian) that help with data collection. The employee onboarding and continuous monitoring are extremely easy to set up and the annual employee security training keep our staff up to date with security threats and how to spot them. Any time we need support, Secureframe is extremely quick to get back to us with helpful responses.
What do you dislike about the product?
I cant think of anything to dislike about Secureframe, it has made our SOC2 compliance super easy.
What problems is the product solving and how is that benefiting you?
Secureframe reduces the time for our security team to maintain compliance allowing them to get on with other tasks and never having to fret over anything come audit time.
A Solid Platform with Room for Growth
What do you like best about the product?
Integrations with our tech stack (Jira, Okta) have been smooth and evidence collection automation is a significant time-saver. Secureframe's team is fantastic at listening to customer feedback; we put in requests (MFA for the dashboard, etc) and they're implemented within months.
What do you dislike about the product?
UI also feels a little bit busy when trying to Dual Certify multiple frameworks (e.g SOC 2 + ISO 27001) It takes an absurd amount of clicks to switch between requirements.
What problems is the product solving and how is that benefiting you?
We have reduced audit prep time by 60% and eliminated the last minute fire drills! Built with transparency and real-time compliance status shared via read-only access links now brings more trust for clients about the platform.
Compliance Without the Headache
What do you like best about the product?
Our 12-person e-commerce business underwent a radical transformation after we implemented the employee training tracker. It even automatically notifies staff of what security training they need to complete and ensures everyone has signed their policies (previously it took me hours to chase people down!) Google Workspace integration server pulls in all our access logs automatically — we no longer have to take manual screenshots before audits. Our non-technical bookkeeper can check our compliance status in the dashboard.
What do you dislike about the product?
The alerting sometimes is too sensitive, and we get alerts from little changes in the systems that doesn´t even are changing compliance. When we started to include HIPAA requirements, the pricing shot up too high on our bootstrap budget.
What problems is the product solving and how is that benefiting you?
We had to be HIPAA compliant for our healthcare clients, but couldn't afford a full time compliance officer. We were able to get enterprise grade compliance and security at a fraction of the cost using Secureframe. Unexpected benefit? We were able to reduce our insurance premiums by presenting our Secureframe reports to our provider.
Not quite there, but getting better!
What do you like best about the product?
The account executive is very responsive and personable. A lot of my evidence was automatically uploaded via integrations. We were able to achieve SOC 2 on the first try.
What do you dislike about the product?
They don’t have as many popular integrations that other competitors have, so there is still some manual work involved to provide evidence. Customer support, especially the chat, is slow to respond to questions (not on demand). The software is clunky, buggy, and not very intuitive.
What problems is the product solving and how is that benefiting you?
It helps us collect evidence to supply to an auditor for SOC 2 compliance.
Game-Changer for Scaling Security Posture
What do you like best about the product?
I needed a solution, working as VP of Technology at a fast-growing startup, to handle an increased number of compliance requirements I was facing. We were able to draft thousands of lines of custom policies just by answering questions about our processes via Secureframe, rather than writing them ourselves. The vendor risk management module is another winner— it allows us to automate third-party assessments, which is local (Sweden) procurement.
What do you dislike about the product?
Initially, the onboarding process seems overwhelming, especially for teams who have little to no experience in compliance at all. I found the support, while responsive, I would have liked to see more in the way of self-service training. Also, the UI for tracking multiple frameworks (eg, SOC 2 + HIPAA simultaneously) could be more user-friendly.
What problems is the product solving and how is that benefiting you?
Pre-Secureframe, compliance had always been reacted to, as a mad dash before audits: And, we are now “audit-ready” all the time so that we were able to expedite enterprise client partnerships. It’s also helped us improve the security culture — employees read the auto-assigned training policies (since they are bite-sized and relevant).
Made SOC 2 Achievable for Our Tiny Team
What do you like best about the product?
Being a 7-person SaaS startup that needed SOC 2 compliance to secure enterprise clients (and with no history of any kind of compliance), I knew we were in for quite the ride. Writing secureframe's pre-built policies and automated evidence collection (esp. github and aws) saved us about 40 man-hours worth of work. The auditor matching service introduced us to an economical firm of auditors who mainly work with startups like our own. But the actual kicker was how far their customer service went — they responded to my panicked emails at 9pm when we were preparing for our audit!
What do you dislike about the product?
One of the shorter areas is vendor risk management( VRM) section. For example, we still manage third-party questionnaires in spreadsheets because that module of Secureframe's system isn't as intuitive as other components. The mobile experience is also lacking — I WANT to be able to see all new tasks that come in and approve them from my phone during commute times.
What problems is the product solving and how is that benefiting you?
Until Secureframe, compliance felt like it required expensive consultants to get done properly. Here we are, with SOC 2 Type 1 only in a short ten weeks and soon going to be transitioning into Type 2. The biggest benefit? Closed a $75k deal that required SOC 2 (client was super impressed we had everything documented in Secureframe)
showing 611 - 620