Our MCP Server Is Thoropass’ Most Popular New Product Launch Ever. Why Is That?

September 22, 2026

Launching a new product is always exciting, but it's also one of those moments when you realize how much you’re guessing. You can spend months looking at what is happening in the market, talking to customers about what they need, working with your engineering team to build something you believe will be valuable, and then you launch it and wait to see whether customers agree with you.

We did that a couple of months ago when we beta launched the Thoropass MCP server. We started with a small group of customers because we wanted to see how they would use it and whether it would actually make a difference in the audit process.

The response has been remarkable. In its first 60 days, more than 50 customers adopted the MCP server, making it the most popular new product launch in Thoropass history – in fact, the beta group was oversubscribed. The pace of adoption has exceeded what we expected, and, more importantly, the feedback from customers has been very consistent. They immediately understand what it can do for their teams.

I have spent most of my career in IT risk and controls, so I have a pretty good sense of where the friction in an audit really comes from. It's not usually that a company doesn't have the information. In most cases, the information is sitting somewhere in the organization. The problem is getting the right information, from the right system, for the right population, in front of the right person at the right time.

A GRC team can have years of investment in technology that manages its controls and stores evidence, and yet when an audit starts, there’s still an enormous amount of manual work involved in connecting the auditor's request to the systems and people that actually have the information. Someone has to understand what the auditor is asking for, determine which system contains the relevant information, identify the right population, and pull the data, review it, upload it and answer the inevitable follow-up questions.

Of course, the larger the company, the more complicated this becomes. There may be different systems across business units, different owners and different populations that need to be considered. The GRC team ends up spending a tremendous amount of time coordinating all of it, and this is where the MCP server gets particularly interesting.

Learn more: Building an MCP Layer to Streamline AI-Native Audits

The difference is the auditor behind the MCP

There’s an important difference between what we're doing with our MCP beyond simply connecting an AI agent to a compliance platform. At the most basic level, a compliance platform can give an AI agent access to controls, policies, documents and evidence that a company has collected. While that can certainly make some tasks easier, an audit is different.

At Thoropass, an evidence request comes from an auditor who understands the audit scope, the applicable framework and the specific control being tested. The auditor has already made decisions about what is relevant to the engagement, including which systems and populations need to be considered.

When an AI agent connects to Thoropass through MCP, it isn't starting with a blank page and asking, "Where can I find something that looks like evidence for this control?" It has the context of the auditor's request and the scope behind it. It knows what the auditor is looking for and, importantly, why that information is relevant to the audit – context which can change what the agent can do.

Take an access control as an example. A compliance platform might know that a company has an access control, and perhaps has access to an identity system. But our agent can start with the auditor's evidence request, which reflects the framework, the audit scope and the systems and populations the auditor has determined are relevant. It can then use that context to help retrieve the right information from the customer's connected systems.

The difference is subtle, but it's fundamental, in that we aren't just connecting AI to compliance data. We're connecting AI to the audit itself.

The audit brings something that a generic compliance workflow does not: professional judgment about what needs to be tested, what is in scope, and what constitutes relevant evidence. This is what makes the MCP server so powerful for an audit – the technology isn’t simply making it easier to move information. It's allowing an AI agent to work within the context that an auditor has already established.

The value isn’t just automation - it's better context.

There has been a lot of discussion about AI making work faster. While that’s certainly part of what we're trying to accomplish, the bigger opportunity in auditing is giving AI enough context to make the work it's doing more relevant. This is a challenge I’ve seen many times throughout my career in risk management: an export can be completely accurate and still not be the right evidence.

For example, an access review might include every employee in a particular identity system, but leave out a recently acquired business that’s also relevant to the control. So while the data itself isn't wrong, the population is incomplete.

An experienced auditor knows to ask that type of question, which is why scope and judgment are so important to what we're building at Thoropass. We're not trying to remove judgment from the audit process. We're trying to make the technology much better at understanding and applying the context that surrounds the work, while keeping the auditor responsible for evaluating the evidence and reaching the conclusion.

Related: Everyone Is Talking About AI in Audit. I Think We're Asking the Wrong Question.

So what exactly is an MCP?

The Model Context Protocol, or MCP, is an open standard for connecting AI applications to external tools and data. Our MCP server connects a customer's AI agents to the Thoropass Audit Lifecycle Platform, giving them access to the context they need to help with the audit, including Evidence Requests, audit scope and other information about the engagement. From there, an agent can interact with the customer's connected systems to help retrieve and prepare information for the auditor.

An access control request offers a practical example. An agent can use the auditor's request and the context around it to identify the relevant systems and information, retrieve supporting documentation or data, and prepare it for human review before it's submitted. The human does not disappear from the process, and the auditor still evaluates the evidence and determines whether it supports the control.

What changes with an MCP server is everything that happens before that judgment: instead of people spending their time translating requests, finding system owners, navigating different applications, downloading reports and moving evidence around, an agent can handle much more of that coordination. As a result, the customer spends less time getting information to the auditor and more time thinking about whether the information actually answers the question.

This is bigger than an MCP server.

The MCP server is one piece of a much larger architecture we’re building. We're creating an AI-native cybersecurity audit firm around our Audit Lifecycle Platform. The platform becomes the place where the context of the audit lives: the scope, the controls, the evidence requests and the information that moves through the engagement.

Once that context is available, we can apply AI to different parts of the audit lifecycle:

  • Our First Pass AI can review evidence before it gets to an auditor and identify potential issues earlier. 
  • Audit Copilot helps auditors with evidence evaluation and control testing. 
  • Our Audit Agents can take on repeatable parts of the audit process so that our auditors can spend more of their time applying judgment and talking with customers about what the evidence actually means.

The MCP server extends that architecture into the customer's own environment by connecting to their own AI agents, enabling them to interact directly with the audit process. This combination is really exciting, because we're not simply automating tasks that happen to be part of an audit – we're giving AI the context of the audit, so that it can help move the engagement forward in a way that is grounded in the auditor's understanding of the business, the controls and the systems that are actually in scope.

Why customers are embracing it

The speed of the MCP server’s adoption has reinforced something we’ve believed for some time: companies are ready for their audit technology to work more like the rest of their technology stack. They’ve already invested in GRC platforms, identity systems, ticketing systems, cloud infrastructure and countless other systems that contain the information an auditor needs. What they don't want is to lose all of the efficiency that those investments created when the audit begins.

It’s important to remember that the goal isn’t to take people out of the audit. In fact, I think the opposite is true – if we can eliminate more of the repetitive coordination, our customers have more time to focus on the parts of the process that require their expertise, and as a result, our auditors have more time to focus on the parts of the audit that require professional judgment.

In short, MCP for compliance connects AI to your compliance program and MCP for audit connects AI to the auditor. A compliance platform can tell an AI agent where information lives. An auditor can provide the context for why that information matters, what needs to be tested, which systems and populations are relevant, and what the evidence request is actually asking the customer to demonstrate.

When you combine that context with access to the customer's own AI agent, the potential is much greater than simply automating evidence collection – you’re giving an AI agent the ability to work within the context of the audit itself.

The response to this launch has been an important validation for us. We believed there was a better way to connect the systems companies have already invested in with the audit process. We believed AI could do much more if it understood the context and scope of the audit, rather than simply being given access to data.

The MCP is now in general availability for all customers. Anybody interested in connecting their AI agents to Thoropass can speak with their Customer Success Manager or contact us here to speak with an expert.

In this post:

Stay Connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Eva Pittas

See all Posts

Related Posts

No items found.

Stay connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Want to join our team?

Help Thoropass ensure that compliance never gets in the way of innovation.

View Open Roles

Have any feedback?

Drop us a line and we’ll be in touch.

Contact us