Register now

Join us for an upcoming session for What the audit?! Wednesdays
Loading...
We collect your contact information to provide updates about our products and services. Privacy Policy.
X Streamline Icon: https://streamlinehq.com

Live webinar series

Audit advice you won't find in a checklist.

Every session combines a focused discussion with live audience Q&A, giving you direct access to the people who review evidence every day.

You'll leave with:

  • Practical guidance from experienced auditors
  • Answers to your toughest audit questions
  • Tips you can immediately apply to your compliance program
  • A better understanding of what auditors actually look for
Register now

Upcoming sessions

Join the conversations most relevant to your audit program.

September 23

What Actually Makes Evidence SOC 2 Ready?

Understand how lengthy audit timelines impact enterprise sales, pipeline velocity, and market expansion.

Register now

october 7

Preparing for HITRUST Without Overbuilding

Avoid wasted effort by focusing on what auditors actually expect.

Register now

October 21

ISO 27001: What Changes Beyond SOC 2?

Understand the key differences before adding another framework.

Register now

November 4

Can You Reuse Evidence Across Frameworks?

Learn when evidence can be reused, when it can't, and how to reduce duplicate work across audits.

Register now

November 18

What Should AI Companies Prepare to Prove?

Understand the controls, documentation, and governance auditors increasingly expect from AI companies.

Register now

december 2

What Do Healthcare and Healthtech Teams Get Wrong About HIPAA?

Learn the most common audit pitfalls and how to avoid them before they become findings.

Register now

december 9

What Should You Fix Before Your Next Audit Cycle?

Identify the biggest gaps to address now so your next audit is smoother, faster, and more predictable.

Register now

Meet the auditors

They've seen late-night evidence hunts, endless follow-ups, and last-minute surprises. Now they're here to answer your questions before your next audit turns into Audit Hell.

Smiling woman with long dark hair wearing a striped shirt with green, white, and yellow colors.

Leith Khanafseh

Audit Managing Partner

|

Formerly: KPMG, EY, Coalfire

Leith founded and currently oversees the Assurance offering at Thoropass. Before Thoropass, Leith’s career spanned across a couple of the Big 4 accounting firms and Coalfire, where he performed and led information security audits for some of the world’s largest cloud service providers and SaaS platforms.

Matt Udicious

Director of Infosec Assurance

|

Formerly: Accenture, Coalfire, KPMG

With a decade of IT consulting experience, Matt has made substantial contributions across renowned organizations such as Accenture, KPMG, and Coalfire, including the implementation of robust security measures and compliance frameworks to safeguard the information assets of a diverse clientele.

David Haviley

Senior Manager, InfoSec Solutions

David is a leader within Thoropass’ InfoSec Assurance practice, where he plays a pivotal role in managing and overseeing a range of offerings, including SOC 1, SOC 2, SOC 3, and HIPAA compliance. His expertise lies in the comprehensive review and support of SOC audit processes and HIPAA attestations for businesses of varying sizes and industries.

Bennett Stamper

Compliance Engineer

Bennett has been working in compliance since 2020, beginning his career as an external auditor at Coalfire. There, he specialized in ISO audits, while also gaining broad experience across frameworks like SOC 2, PCI-DSS, and more. In 2025, Bennett joined Thoropass as a Sales Engineer, where he helps ensure accurate deal scoping, provides expert guidance to both customers and internal stakeholders, and supports other team members cross-functionally.

Chris Beiro

Senior Director of Infosec

|

Formerly: KPMG, Coalfire

Chris is a seasoned cybersecurity executive with a strong track record in Governance, Risk, and Compliance (GRC). With over a decade of experience, he has helped organizations—from high-growth startups to Fortune 500 enterprises—strengthen their cybersecurity programs, meet rigorous compliance standards, and mitigate risk.

Bruce Edwards

Senior Manager, PCI Assurance

Bruce is a seasoned professional with 14 years of experience holding both CISA and CISM certifications. His experience spans various sectors including penetration testing, PCI QSA, ASV, and Cloud Security. In his previous role as a security director, Bruce lead PCI DSS assessments for Fortune 500 companies in the FinTech and healthcare sectors, both in the U.S. and around the world.

Lucas Baiocchi

Manager, HITRUST InfoSec Assurance

With 7+ years of experience in information security audits and assessments, Lucas leads and executes HITRUST assessments, working closely with organizations to evaluate their security posture, validate control effectiveness, and deliver clear, actionable insights that align compliance objectives with broader business goals.

Why Thoropass?

Built by auditors. Backed by Thoropass.

Thoropass helps organizations move from evidence collection to final report with experienced auditors, AI-enabled evidence validation, and purpose-built audit workflows that reduce rework, improve visibility, and keep audits moving forward.