
Secureframe
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Connect Secureframe to PostHog to sync your data into the PostHog data warehouse for analysis and modeling.
Enter your Secureframe API credentials to pull your compliance data (controls, tests, personnel, devices, vendors, and more) into the PostHog Data warehouse.
You can create an API key and secret in the Secureframe Console under Your Profile → Company settings → API keys. The key's role-based permissions govern which tables you can sync.
Configuration
| Option | Type | Required |
|---|---|---|
Region | select | Yes |
API key | password | Yes |
API secret | password | Yes |
Linking Secureframe to PostHog
- Go to the Data pipeline page in PostHog
- Click New source and select Secureframe
- Fill in the required configuration fields
- Click Next, select the tables you want to sync, and then press Import
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
controls | A security control the company maintains to satisfy framework requirements, with aggregated test-health counts. | Full refresh | — | — |
tests | A compliance test that continuously evaluates a control, with pass/fail health status and evidence timing. | Full refresh | — | — |
users | A person (employee, contractor, or other personnel) tracked for compliance, onboarding, and audit scope. | Full refresh | — | — |
user_accounts | An account discovered on a connected vendor (e.g. a SaaS login), optionally linked to a Secureframe user. | Full refresh | — | — |
devices | A managed device reporting security posture such as disk encryption, firewall, and antivirus status. | Full refresh | — | — |
vendors | A third-party vendor tracked in the legacy vendor register, with risk and review metadata. | Full refresh | — | — |
tprm_vendors | A vendor tracked in Third Party Risk Management, with risk level, status, and subassessment responses. | Full refresh | — | — |
frameworks | A compliance framework (e.g. SOC 2, ISO 27001) with aggregate control and test counts. | Full refresh | — | — |
framework_requirements | A single requirement within a compliance framework and its overall health. | Full refresh | — | — |
risks | A risk register entry with impact, likelihood, treatment, and ownership details. | Full refresh | — | — |
repositories | A source-code repository discovered from a connected vendor, with audit-scope status. | Full refresh | — | — |
integration_connections | A connection to an integrated vendor and its current sync status. | Full refresh | — | — |
cloud_resources | A cloud infrastructure resource discovered from a connected vendor, with audit-scope status. | Full refresh | — | — |