SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Secureframe launches hosted AI server for compliance

Secureframe launches hosted AI server for compliance

Fri, 7th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Secureframe has launched a hosted Model Context Protocol server for its compliance platform, giving users direct access to live compliance data through AI assistants.

The launch adds a hosted option for teams using tools such as Claude Desktop, Claude Code, Cursor and other assistants that support the protocol. Customers do not need to run or maintain the underlying infrastructure themselves.

The product is aimed at security, IT and engineering teams that want to query compliance records in natural language and take action within existing workflows. Those actions include identifying failing controls, updating test statuses and creating Plan of Action and Milestones items.

The system can be used across frameworks including CMMC, NIST 800-171, FedRAMP and SOC 2. Teams can also review vendor risks, inspect System Security Plan sections, check policies and assessment objectives, and handle evidence requests.

The move reflects a broader push to make governance, risk and compliance work more accessible through familiar software tools. One focus area is software development, where engineers can use AI assistants in an integrated development environment or terminal instead of switching to a separate compliance system.

"This is a powerful step forward for our customers. We're helping them tap into their compliance data with the AI tools they already use, without requiring them to host, monitor, or update any infrastructure themselves," said Shrav Mehta, Founder and Chief Executive Officer of Secureframe. "It's all about making compliance easier, more accessible, and more integrated with your daily workflow."

Federal focus

Alongside the product launch, Secureframe introduced three free tools for defence contractors navigating federal cybersecurity requirements: a contract requirements lookup tool, a CMMC readiness assessment and a CMMC return on investment calculator.

The lookup tool uses a five-question assessment to identify which federal frameworks apply to a contractor's work, including CMMC, NIST and FedRAMP.

The readiness assessment offers a short review across key NIST 800-171 domains and generates an estimated SPRS score with a prioritised gap analysis. The calculator compares estimated three-year compliance costs with contract value at risk using Department of Defence and industry data.

Secureframe tied the new tools to findings from its federal cybersecurity report, which surveyed nearly 900 defence contractors, prime contractors, C3PAOs and practitioners. Fewer than 2% of organisations that require CMMC Level 2 had fully achieved it, while 44% cited uncertainty over how compliance would be evaluated and 51% described overall compliance costs as prohibitive.

Those figures point to a market where regulation is expanding but implementation remains uneven. For suppliers in the defence industrial base, that creates a need for tools that clarify which rules apply, how far they are from compliance and what the financial exposure may be.

Continuous checks

The broader theme of the announcement is a shift away from point-in-time audit preparation toward continuous monitoring. Secureframe said its hosted server lets users surface issues across multiple frameworks and address them in real time through connected assistants.

That approach mirrors a wider change in cyber governance, with companies expected to maintain evidence, controls and remediation records on an ongoing basis rather than assemble them only when an audit approaches. In heavily regulated sectors, this can shape operational decisions as much as compliance work.

Katie Arrington, Chief Information Officer of IonQ and former Department of Defence Chief Information Security Officer, outlined that view in remarks cited by Secureframe.

"We have to realize this is not a compliance issue. This is about business survivability and national security," said Arrington. "What the government is using CMMC for is an insurance policy that you have the right cybersecurity culture and posture. It's not a checklist. It never was. It's to create a mindset around what you need to do to protect your environment continuously."