Linking Secureframe as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Secureframe connector syncs controls, tests, users, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Enter your Secureframe API credentials to pull your compliance data (controls, tests, personnel, devices, vendors, and more).
You can create an API key and secret in the Secureframe Console under Your Profile → Company settings → API keys. The key's role-based permissions govern which tables you can sync.
You'll be asked for:
- Region: choose between US (api.secureframe.com) and UK (api-uk.secureframe.com).
- API key
- API secret
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
All Secureframe tables are full refresh. Each sync replaces the contents of the table.
Configuration
| Option | Type | Required |
|---|---|---|
Region | select | Yes |
API key | password | Yes |
API secret | password | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
controls | A security control the company maintains to satisfy framework requirements, with aggregated test-health counts. | Full refresh | — | — |
tests | A compliance test that continuously evaluates a control, with pass/fail health status and evidence timing. | Full refresh | — | — |
users | A person (employee, contractor, or other personnel) tracked for compliance, onboarding, and audit scope. | Full refresh | — | — |
user_accounts | An account discovered on a connected vendor (e.g. a SaaS login), optionally linked to a Secureframe user. | Full refresh | — | — |
devices | A managed device reporting security posture such as disk encryption, firewall, and antivirus status. | Full refresh | — | — |
vendors | A third-party vendor tracked in the legacy vendor register, with risk and review metadata. | Full refresh | — | — |
tprm_vendors | A vendor tracked in Third Party Risk Management, with risk level, status, and subassessment responses. | Full refresh | — | — |
frameworks | A compliance framework (e.g. SOC 2, ISO 27001) with aggregate control and test counts. | Full refresh | — | — |
framework_requirements | A single requirement within a compliance framework and its overall health. | Full refresh | — | — |
risks | A risk register entry with impact, likelihood, treatment, and ownership details. | Full refresh | — | — |
repositories | A source-code repository discovered from a connected vendor, with audit-scope status. | Full refresh | — | — |
integration_connections | A connection to an integrated vendor and its current sync status. | Full refresh | — | — |
cloud_resources | A cloud infrastructure resource discovered from a connected vendor, with audit-scope status. | Full refresh | — | — |
Troubleshooting
- If the connection fails with an authorization error, the API key is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.