# Secureframe: -17 point Door Gap
- Site: secureframe.com
- Scanned: 2026-09-08
- Scan type: Basic scan
- Business type: b2b_saas
- Report: https://www.seconddoor.io/r/secureframe-u5rcyv
- Scanner version: 12
Secureframe publishes pricing and API specs but routes all buyers through sales conversations, blocking self-serve access.
## Scores
| Measure | Score |
| --- | --- |
| Humans | 40/100 |
| Agents | 57/100 |
| Composite | 49/100 |
| Door Gap | -17 points |
| Percentile | 12th |
The human score is the mean of the four human dimensions, the agent score the mean of the six agent dimensions, and the Door Gap the difference between them.
## What the machine actually did
The agent got through 10 of 15 requests, but could not find a contact route for machines. It came up empty on 4 other checks too.
- ok      reach the site at all
- ok      find out whether machines are welcome
- ok      ask whether the door opens for requests carrying the AI crawlers' names
- ok      read the site's own guide for language models
- ok      find out what pages exist
- missing find a contact route for machines
- missing find a published agent interface
- missing find an agent plugin manifest
- missing find out whether verified agents are recognised
- ok      read the homepage as data rather than as a page
- ok      find a machine readable API spec
- ok      read the developer documentation
- ok      read the prices without running JavaScript
- ok      find a comparison page worth citing
- missing walk the way a visitor would, to a signup form or a product
## Top issues
1. **No MCP manifest was found at the 3 standard paths checked, so an agent has no published machine door to this site.** (agent_aware_instrumentation)
2. **No security.txt is published, preventing agents and security researchers from reporting vulnerabilities or contacting the security team.** (machine_fetchable_trust)
3. **The only route to an account is a sales conversation, so nobody signs up without talking to a person.** (steps_to_first_value)
The evidence and the recommended fix for each are on the report page: https://www.seconddoor.io/r/secureframe-u5rcyv
## Files generated from this scan
- **Pricing as Offer structured data** at `pricing page`, 20 minutes, developer. Verify: The next scan reads Offer structured data with a price and currency on the pricing page, and the pricing check credits it.
- **Machine interfaces: where you stand** at `notes`, 10 minutes, no developer needed. Verify: The next scan finds the interface you published answering at its well-known path, and that check passes.
- **security.txt** at `/.well-known/security.txt`, 10 minutes, no developer needed. Verify: The next scan fetches /.well-known/security.txt as text and the security.txt check passes.
Each file is written from what this scan found on the site. The content is in the JSON once the evidence is opened: https://www.seconddoor.io/api/reports/secureframe-u5rcyv
## The agent door
- **machine_discoverability** 100/100. Robots.txt explicitly names and allows 3 AI crawlers (oai-searchbot, claude-searchbot, perplexitybot), a real browser is served normally, key pages render without JavaScript, sitemap lists 1666 URLs, homepage includes Organization and.
- **programmatic_onboarding** 35/100. An OpenAPI spec is published at developer.secureframe.com/openapi.json, enabling client generation. However, the only entry point is a sales form requiring a human conversation.
- **pricing_legibility** 85/100. One price, $7,000, is readable in the homepage HTML without JavaScript. The pricing page publishes this figure without gating it behind a demo request or JavaScript execution. No tier is routed to sales.
- **agent_aware_instrumentation** 50/100. Robots.txt names 3 AI crawlers and allows them, pricing.md publishes prices in machine-readable form, and an OpenAPI spec is published. No MCP manifest exists at the 3 standard paths checked.
- **machine_fetchable_trust** 40/100. The homepage answers automated requests normally. No security.txt is published at /.well-known/security.txt. An agent can verify the site is reachable but cannot fetch security contact information, incident reporting procedures, or.
- **commercial_rails** 32/100. Prices are published in raw HTML ($7,000), pricing.md is machine-readable, and an OpenAPI spec exists. The only route to purchase or trial is a sales conversation initiated from a form.
## The human door
- **steps_to_first_value** 20/100. The primary call to action is 'Request a demo', a sales form 2 steps from the homepage. No trial signup, no free tier, and no self-serve product access exist.
- **required_fields** 25/100. The entry point is a sales form. The form was not walked to completion, so the full field count is unobserved. The sales-only route means no self-serve signup path exists to measure.
- **verification_walls** 65/100. No verification requirement appears on the sales form entry point. Email confirmation, phone verification, or identity checks are not visible at the initial contact stage.
- **error_recovery** 50/100. No typed input fields with validation constraints were found on the entry point. The sales form was not walked to completion, so validation behavior and error messages are unobserved.
---
Scored by SecondDoor. Method: https://www.seconddoor.io/methodology
Scan another site: https://www.seconddoor.io
Rate an issue or this report: POST https://www.seconddoor.io/api/feedback, or the rate_fix tool on https://www.seconddoor.io/api/mcp
