The End-to-End Cybersecurity Auditor
Powered by the Audit Lifecycle Platform, no handoffs, rework, or last-minute surprises.
One Platform, Every Framework
Audit smarter across frameworks—centralized evidence, automated validation, and in-house auditor support.



Delivering Modern Audits For Modern Companies

"Thoropass was our complete compliance solution. The best part about working with Thoropass was that it’s the perfect blend of technology and people to take a complicated process and make it accessible and easy."


"The in-tool audit experience was a massive benefit. I could just log in, answer the open evidence requests, and I knew that I had checked off everything I needed to keep the audit process going."


"We needed a security compliance partner we could rely on for the entire preparation and audit process. That included understanding the scope, putting processes in place, creating documentation, using the right tools and implementing the right controls."

.png)
Overall, Thoropass provides an efficient, supportive platform for meeting compliance requirements, substantially aided by its thoughtful design and supportive customer service.

"Partnering with Thoropass as our single source of truth enables us to streamline our compliance programming while focusing on what we do best: building secure, trustworthy products and solutions that our users love."


“Go with a platform like Thoropass that supports multiple frameworks, includes strong efficiency-driven features, and is your auditor —so you’re not left to manage the entire audit process yourself.”
.png)
Their expertise allowed us to make intelligent decisions around how we approach each control in line with our existing policies and procedures. It's been three years since we started leveraging Thoropass and they've helped immensely!
"The process of achieving HIPAA compliance was incredibly smooth, thanks to the collaboration between Thoropass and their service partner, Muscatek."

"The platform is really helpful for us. When one certification is done, we just push one button and it pulls all the evidence and policies that we need for the other one—saving us so much time."
.png)
"Relatively easy to use. Auditors are there to guide, not castigate. Pentest team is terrific and easy to work with too."
.png)
"Thoropass is a smart solution to tedious tasks. If you use it as a manager, it allows to track learning/policy readiness of your team, as well as have a document version control for your policies. It comprehends a lot of functions such as facility control, vendor management, inventory control...Very user-friendly and intuitive."

"We were engaging with the auditor on Slack, managing things in two places, and having to duplicate evidence collection to align between the two. There was so much potential to do things better and more effectively. That’s when we switched to Thoropass."


"Thoropass not only told us what the vulnerabilities are, but they were also very communicative when it came to how to reproduce the vulnerabilities."

.png)
"Every single interaction we have had with a Thoropass representative has been friendly, engaging, and understandable. As a non-technical person, they helped guide me to make informed decisions about what priorities needed to be focused on, how they could support those priorities, and they were exceptionally priced to do business with."

"What I like best about Thoropass is how it simplifies and operationalizes complex compliance processes like SOC 2, ISO 27001, and HIPAA. The platform integrates seamlessly with our cloud infrastructure (AWS), version control systems (like GitHub), and ticketing tools, enabling automated evidence collection and real-time visibility into our audit readiness."

"Think of how many sleepless nights it’s going to cost you, versus paying someone who will provide you with really clear guidance. You will save so much time and so much money if you find a partner like Thoropass to help you."


“We picked Thoropass because it provides an assessor and a platform. A lot of other companies have only a platform and bring in a third-party assessor. Thoropass is a one-stop shop, which makes things much easier.”


“We thoroughly enjoy working with Thoropass. They come with the software, they come with the people, and it really mirrors the culture that we have at Access of wanting to make things as easy as possible and help our customers, and it’s been great working with them."


"Having someone like Thoropass on board who is saying, ‘Yes, you’re doing things right,’ or, ‘Yes, you need to change that bit over there, and then you’d be doing things right’: as a CEO, that makes you sleep well at night.”

"Having both a caring and attentive account manager as well as reviewers made the whole annual SOC 2 compliance process easy to go through. What was originally met with anxiousness and angst turned into a good experience. Their site makes it easy to track the things that need to be updated, uploaded, and addressed for the review."

“Thoropass has been nothing short of a small miracle. They've made compliance something that helps us grow, instead of something that holds us back.”

.png)
"Very thorough and the tool made the process very easy. The account manager is very responsive and explained the entire process very well. With regards to the Pentest, the tool helped us identify a few issues ahead of the actual pentest, saving time for us and the pen-testers."
.png)
"I appreciate Thoropass for its quick onboarding process and friendly pricing, which made the transition from our previous system smooth and cost-effective. I find the customer service exceptional, with ultra-fast responses to emails. The compliance-focused training features are invaluable, ensuring all our team members are properly trained and certified. Lastly, Thoropass is constantly ahead of the curve in compliance, acting as a comprehensive solution that meets all my company's needs."
.png)
Thoropass combines readiness, evidence management, and auditor interaction in a single platform. This helps Roark maintain an organized audit trail, critical for a firm that documents every control, ticket, and policy for SOC 2 evidence. The ability to collaborate with the auditor directly in-platform reduces friction and prevents duplicative work.
.png)
"Thoropass has been instrumental in simplifying our journey through complex healthcare SaaS compliance requirements, like SOC 2, HIPAA, and HITRUST. Their expertise not only clarifies these challenging processes but also ensures we adhere to the highest standards, significantly benefiting our operational efficiency and data security."
.png)
"With Thoropass, it is simple and easy to monitor compliance. I like the way that Thoropass has an easy to use task based interface that you can easily see what you need to remedy in your cloud platforms to maintain your SOC 2 compliance. It also has automated monitors that work with to monitor the environment and if anything goes out of compliance it will immediately flag it and give you a task to remediate it."

"It made it really easy to see both frameworks at a glance, and to have different pieces of evidence apply to both HITRUST and SOC 2. It didn’t feel like a huge chore, and was a big help in efficiency."


"Thoropass’ integration with MyCSF was a deciding factor. We didn’t have to upload evidence twice, just once into Thoropass. It saved quite a bit of time."


"Feature-wise, Thoropass covers everything needed for SOC 2 in one place, including control management, evidence tracking, policies, vendor risk, and audit coordination. Overall, Thoropass makes SOC 2 far more manageable and repeatable. I’d highly recommend it to any company pursuing or maintaining SOC 2 compliance."

"Our account manager provides exceptional service, ensuring smooth interaction and assistance, which significantly enhances our overall experience with the platform. In addition to this, the pen test team is truly exceptional, offering expert insights and reliable performance in conducting penetration tests."

"There will always be benefits to having an automation platform, but having a strong audit partner, like the one we found with Thoropass, is invaluable."


"Working with Thoropass has not only made compliance achievable. It’s made it a strategic advantage."

"Thoropass saved us significant time and resources. We have a small team and were able to handle all of the policies, controls, activities, monitoring, and audit activities efficiently because of Thoropass’ platform and expert support."










Compliance Experts, So You Don't Have to Be
Leith Khanafseh
Audit Managing Partner
|
Formerly: KPMG, EY, Coalfire
Leith founded and currently oversees the Assurance offering at Thoropass. Before Thoropass, Leith’s career spanned across a couple of the Big 4 accounting firms and Coalfire, where he performed and led information security audits for some of the world’s largest cloud service providers and SaaS platforms.
Matt Udicious
Director of Infosec Assurance
|
Formerly: Accenture, Coalfire, KPMG
With a decade of IT consulting experience, Matt has made substantial contributions across renowned organizations such as Accenture, KPMG, and Coalfire, including the implementation of robust security measures and compliance frameworks to safeguard the information assets of a diverse clientele.
Cristina Bartolacci
Head of Sales Engineering
|
Formerly: RSM
Cristina has contributed to defining the services and solutions offered by Thoropass, including being integral in building out Thoropass’ seamless audit experience and comprehensive solutions.
Eva Pittas
President & Co-founder
|
Formerly: Citigroup
Eva is a co-founder, as well as the President and Chief Customer Officer of Thoropass, leading customer experience and internal operations at the company. Before Thoropass, Eva founded BRCG, a boutique consulting firm after a 20+ year career at Citigroup where she was a Managing Director leading IT control, compliance, and vendor management.
Chris Beiro
Senior Director of Infosec
|
Formerly: KPMG, Coalfire
Chris is a seasoned cybersecurity executive with a strong track record in Governance, Risk, and Compliance (GRC). With over a decade of experience, he has helped organizations—from high-growth startups to Fortune 500 enterprises—strengthen their cybersecurity programs, meet rigorous compliance standards, and mitigate risk.
Bruce Edwards
Senior Manager, PCI Assurance
Bruce is a seasoned professional with 14 years of experience holding both CISA and CISM certifications. His experience spans various sectors including penetration testing, PCI QSA, ASV, and Cloud Security. In his previous role as a security director, Bruce lead PCI DSS assessments for Fortune 500 companies in the FinTech and healthcare sectors, both in the U.S. and around the world.
Lucas Baiocchi
Manager, HITRUST InfoSec Assurance
With 7+ years of experience in information security audits and assessments, Lucas leads and executes HITRUST assessments, working closely with organizations to evaluate their security posture, validate control effectiveness, and deliver clear, actionable insights that align compliance objectives with broader business goals.
Sam Li
CEO & Co-founder
|
Formerly: Bain Capital Ventures
A co-founder of Thoropass, Sam serves as the CEO. Before Thoropass, Sam was an EIR at Bain Capital Ventures after running Zinc Platform, a YC-backed InsurTech startup as co-founder and CTO. He studied CS at the University of Virginia and holds an MBA from Harvard Business School.
Austin Ogilvie
Executive Chairperson & Co-founder
Before Thoropass, Austin was CEO of Yhat, a data science company acquired by Alteryx (NYSE: AYX) in 2017. At Alteryx, Austin oversaw machine learning products. Austin is a graduate of the University of Virginia.
The Modern Approach to IT Compliance
Get audit-ready with expertise embedded across Thoropass—from our auditors to our platform.
Frequently Asked Questions
At Thoropass, “AI-powered” means delivering speed and precision throughout the compliance process—so your team and our auditors can focus on the high-impact, value-driven work that really matters.
Today, we use AI in three key ways to make audits faster, more accurate, and less manual, with more enhancements on the way:
1. Evidence Quality Control: AI pre-screens evidence to catch common issues (like expired certificates, missing logs, or incomplete documentation) before your human auditor reviews it. This eliminates the back-and-forth cycles that slow down traditional audits.
2. Security Questionnaire Automation: AI generates consistent, accurate responses to vendor security questionnaires by scanning your compliance documentation and audit reports, saving hours of manual work.
3. Auditor Support: Behind the scenes, AI helps our auditors work more efficiently by flagging potential control gaps, suggesting relevant evidence requests, and identifying patterns across similar assessments.
Your audit is still conducted by top-tier, certified professionals – AI simply accelerates their workflow and helps surface potential issues earlier, so you can resolve them proactively and stay ahead of risk.
With Vanta/Drata: You get a compliance tool, then hand off to a separate auditor who may not understand your setup, leading to misaligned expectations, rejected evidence, and surprises.
With Thoropass: Your auditor works with you inside the platform from day one. No handoffs, no surprises.
Both.
Thoropass’ platform helps you prepare and Thoropass is your auditor. Unlike platforms that just help you get organized, we’re the ones actually reviewing your evidence and issuing your certification. Though we provide many components for a full compliance and audit program (compliance automation, risk management, assessment, pentesting, etc.), you can use one or more components based on your needs.
We’re a trusted audit firm led by some of the world’s most experienced and respected auditors (AICPA peer-reviewed, PCI QSAC, HITRUST accredited) – not just software. And we take independence seriously–you can read more about our dedication to independence and excellence here.
Traditional auditing has an artificial tradeoff: you can have high quality or low cost, but not both. Technology changes that equation for us.
Our audit credentials:
- AICPA peer-reviewed CPA firm for SOC assessments
- PCI QSAC (Qualified Security Assessor Company)
- HITRUST accredited assessor
- 100+ years combined experience from Big 4 and top-tier audit firms (KPMG, EY, Coalfire, RSM)
Quality assurance:
- All audits follow the same rigorous standards as traditional firms
- Reports are widely accepted by customers, partners, and insurers
- Technology enhances (not replaces) auditor judgment and thoroughness
- Real-time collaboration prevents the quality gaps that cause audit failures
The difference: we use technology to eliminate the manual busywork that drives up costs at traditional firms, while maintaining the same professional standards and rigor. You get Big 4 quality without Big 4 overhead.
Yes, this is where we excel. Unlike traditional firms that treat each framework separately, we:
- Map shared controls across SOC 2, ISO 27001, PCI, HITRUST, etc.
- Single audit cycle for multiple certifications and products/regions
- Unified evidence collection – no duplicate work
- Multi-workspace support for different business units or regions
This synchronization significantly reduces audit overhead throughout the year.
It depends on the type of audit you’re preparing for, and the work you’ve done so far. Most customers are audit-ready 62% faster than traditional approaches, and our fastest customer was audit ready in just a few days. Ultimately, we’ll scope out the requirements for your audit.
Talk to us and get a quote in 24 hours.
Thoropass’ pricing depends on your audit scope, frameworks needed, and complexity of your environment. Most customers save 25-50% compared to traditional audit firms while getting both the platform and audit services included.
Every business measures ROI differently depending on their priorities. Some see audits as revenue enablers—unlocking deals with enterprise customers or access to new markets. Others focus on risk mitigation—identifying vulnerabilities before they become costly breaches or regulatory fines. Still others prioritize operational efficiency—reducing audit costs and freeing up internal teams from time-consuming compliance work.
Some ways our customers have seen ROI:
Revenue Unlock:
- Close enterprise deals requiring SOC 2/ISO certification
- Enter regulated markets (healthcare, finance, government)
- Accelerate sales cycles with Trust Center credibility
Risk Reduction:
- Identify vulnerabilities before they become breaches
- Avoid compliance fines and regulatory penalties
- Strengthen security posture with continuous monitoring
Cost & Time Savings:
- 62% faster time to audit completion
- 950+ hours of internal team time saved annually
- 25-50% cost savings vs. traditional audit firms
- Zero cost overruns with fixed pricing
Our customers see ROI within the first audit cycle, regardless of which benefits matter most to their business. See our case Studies to learn more.
Thoropass supports 100+ auditor-vetted integrations that automatically pull evidence that’s already audit-ready—no formatting or cleanup needed. Some examples include:
Cloud Providers: AWS, Azure, Google Cloud, Digital Ocean, Heroku, Snowflake
Business Apps: Slack, Microsoft 365, Google Workspace, Okta
Dev Tools: GitHub, GitLab, Jira
Security: CrowdStrike, Cloudflare, Splunk, Datadog, PagerDuty
HR/Finance: ADP, BambooHR, Workday, QuickBooks
Don’t see yours? We release new integrations regularly–it’s likely already in the works.
Our CREST-certified pentest offering is an Optional add-on service that integrates seamlessly with your compliance program. Our team goes beyond automated vulnerability scans to find the sophisticated attacks that actually threaten modern cloud environments.
What makes our pentesting different:
- Real-world attack simulation – We use actual attacker techniques, not just automated scanners
- Cloud-native focus – We test applications and APIs where real threats exist today
- Integrated findings – Results map directly to your compliance controls
- Single vendor – No juggling separate pentest and compliance teams
Our team delivers fast turnaround with minimal effort required from your team, while offering flexible scope expansion at minimal additional cost. We’re also a PCI Approved Scanning Vendor (ASV), and customers appreciate our clear, actionable reports designed for both technical and executive audiences.

















.png)