The End-to-End Cybersecurity Auditor
In-house audit experts for every framework, powered by AI-driven evidence collection.
One Platform, Every Framework
Audit smarter across frameworks—centralized evidence, automated validation, and in-house auditor support.
Auditor-Led.
AI-Powered.

Combine AI automation with expert auditors—faster audits, higher quality, and less lift for your team.










Audit Experts, So You Don't Have to Be
Leith Khanafseh
Audit Managing Partner
|
Formerly: KPMG, EY, Coalfire
Leith founded and currently oversees the Assurance offering at Thoropass. Before Thoropass, Leith’s career spanned across a couple of the Big 4 accounting firms and Coalfire, where he performed and led information security audits for some of the world’s largest cloud service providers and SaaS platforms.
Matt Udicious
Director of Infosec Assurance
|
Formerly: Accenture, Coalfire, KPMG
With a decade of IT consulting experience, Matt has made substantial contributions across renowned organizations such as Accenture, KPMG, and Coalfire, including the implementation of robust security measures and compliance frameworks to safeguard the information assets of a diverse clientele.
Cristina Bartolacci
Head of Sales Engineering
|
Formerly: RSM
Cristina has contributed to defining the services and solutions offered by Thoropass, including being integral in building out Thoropass’ seamless audit experience and comprehensive solutions.
Eva Pittas
President & Co-founder
|
Formerly: Citigroup
Eva is a co-founder, as well as the President and Chief Customer Officer of Thoropass, leading customer experience and internal operations at the company. Before Thoropass, Eva founded BRCG, a boutique consulting firm after a 20+ year career at Citigroup where she was a Managing Director leading IT control, compliance, and vendor management.
Chris Beiro
Senior Director of Infosec
|
Formerly: KPMG, Coalfire
Chris is a seasoned cybersecurity executive with a strong track record in Governance, Risk, and Compliance (GRC). With over a decade of experience, he has helped organizations—from high-growth startups to Fortune 500 enterprises—strengthen their cybersecurity programs, meet rigorous compliance standards, and mitigate risk.
Bruce Edwards
Senior Manager, PCI Assurance
Bruce is a seasoned professional with 14 years of experience holding both CISA and CISM certifications. His experience spans various sectors including penetration testing, PCI QSA, ASV, and Cloud Security. In his previous role as a security director, Bruce lead PCI DSS assessments for Fortune 500 companies in the FinTech and healthcare sectors, both in the U.S. and around the world.
Lucas Baiocchi
Manager, HITRUST InfoSec Assurance
With 7+ years of experience in information security audits and assessments, Lucas leads and executes HITRUST assessments, working closely with organizations to evaluate their security posture, validate control effectiveness, and deliver clear, actionable insights that align compliance objectives with broader business goals.
Sam Li
CEO & Co-founder
|
Formerly: Bain Capital Ventures
A co-founder of Thoropass, Sam serves as the CEO. Before Thoropass, Sam was an EIR at Bain Capital Ventures after running Zinc Platform, a YC-backed InsurTech startup as co-founder and CTO. He studied CS at the University of Virginia and holds an MBA from Harvard Business School.
Austin Ogilvie
Executive Chairperson & Co-founder
Before Thoropass, Austin was CEO of Yhat, a data science company acquired by Alteryx (NYSE: AYX) in 2017. At Alteryx, Austin oversaw machine learning products. Austin is a graduate of the University of Virginia.



Delivering Modern Audits For Modern Companies

"What I like best about Thoropass is how it simplifies and operationalizes complex compliance processes like SOC 2, ISO 27001, and HIPAA. The platform integrates seamlessly with our cloud infrastructure (AWS), version control systems (like GitHub), and ticketing tools, enabling automated evidence collection and real-time visibility into our audit readiness."
.png)
Their expertise allowed us to make intelligent decisions around how we approach each control in line with our existing policies and procedures. It's been three years since we started leveraging Thoropass and they've helped immensely!

"Having both a caring and attentive account manager as well as reviewers made the whole annual SOC 2 compliance process easy to go through. What was originally met with anxiousness and angst turned into a good experience. Their site makes it easy to track the things that need to be updated, uploaded, and addressed for the review."

"The in-tool audit experience was a massive benefit. I could just log in, answer the open evidence requests, and I knew that I had checked off everything I needed to keep the audit process going."


"Thoropass was our complete compliance solution. The best part about working with Thoropass was that it’s the perfect blend of technology and people to take a complicated process and make it accessible and easy."


"Thoropass’ integration with MyCSF was a deciding factor. We didn’t have to upload evidence twice, just once into Thoropass. It saved quite a bit of time."


"Think of how many sleepless nights it’s going to cost you, versus paying someone who will provide you with really clear guidance. You will save so much time and so much money if you find a partner like Thoropass to help you."

.png)
Overall, Thoropass provides an efficient, supportive platform for meeting compliance requirements, substantially aided by its thoughtful design and supportive customer service.
.png)
"I appreciate Thoropass for its quick onboarding process and friendly pricing, which made the transition from our previous system smooth and cost-effective. I find the customer service exceptional, with ultra-fast responses to emails. The compliance-focused training features are invaluable, ensuring all our team members are properly trained and certified. Lastly, Thoropass is constantly ahead of the curve in compliance, acting as a comprehensive solution that meets all my company's needs."

“Go with a platform like Thoropass that supports multiple frameworks, includes strong efficiency-driven features, and is your auditor —so you’re not left to manage the entire audit process yourself.”

"Feature-wise, Thoropass covers everything needed for SOC 2 in one place, including control management, evidence tracking, policies, vendor risk, and audit coordination. Overall, Thoropass makes SOC 2 far more manageable and repeatable. I’d highly recommend it to any company pursuing or maintaining SOC 2 compliance."
.png)
"With Thoropass, it is simple and easy to monitor compliance. I like the way that Thoropass has an easy to use task based interface that you can easily see what you need to remedy in your cloud platforms to maintain your SOC 2 compliance. It also has automated monitors that work with to monitor the environment and if anything goes out of compliance it will immediately flag it and give you a task to remediate it."

“Thoropass has been nothing short of a small miracle. They've made compliance something that helps us grow, instead of something that holds us back.”

"The process of achieving HIPAA compliance was incredibly smooth, thanks to the collaboration between Thoropass and their service partner, Muscatek."

"We needed a security compliance partner we could rely on for the entire preparation and audit process. That included understanding the scope, putting processes in place, creating documentation, using the right tools and implementing the right controls."


“We picked Thoropass because it provides an assessor and a platform. A lot of other companies have only a platform and bring in a third-party assessor. Thoropass is a one-stop shop, which makes things much easier.”

.png)
"Relatively easy to use. Auditors are there to guide, not castigate. Pentest team is terrific and easy to work with too."
.png)
"Very thorough and the tool made the process very easy. The account manager is very responsive and explained the entire process very well. With regards to the Pentest, the tool helped us identify a few issues ahead of the actual pentest, saving time for us and the pen-testers."
.png)
"Every single interaction we have had with a Thoropass representative has been friendly, engaging, and understandable. As a non-technical person, they helped guide me to make informed decisions about what priorities needed to be focused on, how they could support those priorities, and they were exceptionally priced to do business with."

"Working with Thoropass has not only made compliance achievable. It’s made it a strategic advantage."


“We thoroughly enjoy working with Thoropass. They come with the software, they come with the people, and it really mirrors the culture that we have at Access of wanting to make things as easy as possible and help our customers, and it’s been great working with them."

.png)
"Thoropass is a smart solution to tedious tasks. If you use it as a manager, it allows to track learning/policy readiness of your team, as well as have a document version control for your policies. It comprehends a lot of functions such as facility control, vendor management, inventory control...Very user-friendly and intuitive."

"Our account manager provides exceptional service, ensuring smooth interaction and assistance, which significantly enhances our overall experience with the platform. In addition to this, the pen test team is truly exceptional, offering expert insights and reliable performance in conducting penetration tests."

"There will always be benefits to having an automation platform, but having a strong audit partner, like the one we found with Thoropass, is invaluable."


"Partnering with Thoropass as our single source of truth enables us to streamline our compliance programming while focusing on what we do best: building secure, trustworthy products and solutions that our users love."


"We were engaging with the auditor on Slack, managing things in two places, and having to duplicate evidence collection to align between the two. There was so much potential to do things better and more effectively. That’s when we switched to Thoropass."


"It made it really easy to see both frameworks at a glance, and to have different pieces of evidence apply to both HITRUST and SOC 2. It didn’t feel like a huge chore, and was a big help in efficiency."

.png)
Thoropass combines readiness, evidence management, and auditor interaction in a single platform. This helps Roark maintain an organized audit trail, critical for a firm that documents every control, ticket, and policy for SOC 2 evidence. The ability to collaborate with the auditor directly in-platform reduces friction and prevents duplicative work.

"Thoropass not only told us what the vulnerabilities are, but they were also very communicative when it came to how to reproduce the vulnerabilities."

.png)
"Thoropass has been instrumental in simplifying our journey through complex healthcare SaaS compliance requirements, like SOC 2, HIPAA, and HITRUST. Their expertise not only clarifies these challenging processes but also ensures we adhere to the highest standards, significantly benefiting our operational efficiency and data security."

"Having someone like Thoropass on board who is saying, ‘Yes, you’re doing things right,’ or, ‘Yes, you need to change that bit over there, and then you’d be doing things right’: as a CEO, that makes you sleep well at night.”
"Thoropass saved us significant time and resources. We have a small team and were able to handle all of the policies, controls, activities, monitoring, and audit activities efficiently because of Thoropass’ platform and expert support."


"The platform is really helpful for us. When one certification is done, we just push one button and it pulls all the evidence and policies that we need for the other one—saving us so much time."



.jpeg)




The Modern Approach to IT Compliance
Get audit-ready with expertise embedded across Thoropass—from our auditors to our platform.
Frequently Asked Questions
Thoropass is a licensed auditor that delivers audits, supported by purpose built software to streamline the process. Our platform helps you prepare by organizing evidence and readiness activities, while our audit team performs an independent assessment in accordance with professional standards. This approach allows you to manage preparation and audit execution in one place.
Thoropass reimagines the audit experience by combining a licensed audit firm with an AI-powered platform that automates and streamlines much of the process. Traditional firms often rely on manual evidence collection, spreadsheets, and fragmented communication. In contrast, Thoropass uses AI to map controls, identify gaps, and organize evidence in real time, reducing repetitive work and human error. This results in a more efficient, transparent, and predictable audit process, while still maintaining the rigor and oversight of experienced auditors.
Yes. Thoropass is a licensed audit firm and our audits are conducted according to established professional standards. Thoropass has received the highest AICPA peer review rating for its audit quality. The firm employs experienced auditors and follows rigorous methodologies to ensure accuracy and compliance. In addition, the platform enforces consistency in evidence collection and control validation. This combination of professional oversight and structured workflows helps ensure that audits meet the expectations of regulators, customers, and stakeholders.
Thoropass is designed to support multi-framework audits such as SOC 2, ISO 27001, PCI, GDPR, HITRUST, and others within a unified process. The platform maps overlapping controls across frameworks to reduce duplicate work, allowing organizations to pursue multiple certifications efficiently. It can also accommodate companies with multiple products or environments by organizing evidence and controls in a structured, scalable way, ensuring clarity and consistency across audits.
Organizations can typically get started with Thoropass quickly, often within days. The platform provides guided onboarding, integrations, and a centralized workspace where customers can document and manage their controls, helping accelerate evidence collection. Audit timelines vary depending on scope and readiness, but Thoropass is designed to shorten the overall process compared to traditional approaches. Many customers complete readiness and audit cycles in a matter of weeks to a few months, rather than extended multi-quarter timelines.
The Thoropass Audit Lifecycle Platform is a centralized system that manages the entire audit process from readiness through final reporting. It combines AI-powered workflow automation, evidence collection, control management, and auditor collaboration in one place. The platform is designed to replace fragmented tools like spreadsheets and email chains, providing a structured and transparent approach to compliance that scales with your organization.
“AI-powered” in the context of Thoropass refers to the use of automation and intelligent systems to streamline audit tasks. This includes suggesting relevant controls, identifying gaps, organizing evidence, and reducing manual effort in documentation. AI capabilities help teams prioritize work, improve accuracy, and accelerate readiness. Rather than replacing human judgment, these tools enhance both customer and auditor efficiency throughout the audit lifecycle.
Thoropass integrates with a wide range of common business and infrastructure tools to automate evidence collection and reduce manual work. These typically include cloud providers, identity and access management systems, HR platforms, and ticketing tools. By connecting directly to these systems, Thoropass can continuously gather and validate compliance data, minimizing the need for manual uploads and improving the reliability of audit evidence.
Thoropass pricing varies based on factors such as the frameworks pursued, audit scope, company size, and required services. Because the platform combines software and audit delivery, pricing typically reflects both components. Organizations receive a tailored quote to ensure alignment with their compliance goals. This bundled approach can often be more cost-effective than managing separate vendors for readiness tooling and audit services.
Yes! Thoropass can complement third-party GRC platforms by integrating into your broader compliance ecosystem. While we offer end-to-end audit lifecycle capabilities, organizations can continue using their preferred GRC tools. Thoropass focuses on streamlining audit readiness and execution, and its flexible approach allows teams to avoid duplicating work while maintaining their existing systems.
Thoropass offers a range of penetration testing services designed to identify vulnerabilities across different environments. These typically include network, application, and infrastructure testing, covering both internal and external attack surfaces. The goal is to simulate real-world threats and provide actionable insights to improve security posture. Testing is performed by qualified professionals and aligned with industry standards to support compliance and risk management efforts.
CREST is an internationally recognized accreditation body for cybersecurity professionals and organizations. CREST certification indicates that a penetration testing provider meets rigorous standards for technical capability, methodology, and ethical conduct. Working with CREST-certified testers provides assurance that testing is performed consistently and to a high professional standard, which is often important for regulatory compliance and customer trust.
In many cases, penetration testing is a requirement for cybersecurity frameworks such as SOC 2, HITRUST and others, particularly for demonstrating effective risk management. While requirements vary by framework and scope, a recent and properly conducted pentest is often expected as part of the evidence reviewed during an audit. Even when not strictly required, penetration testing is considered a best practice for identifying and addressing security weaknesses.




















.png)