Register now

Live webinar series
Audit advice you won't find in a checklist.
Every session combines a focused discussion with live audience Q&A, giving you direct access to the people who review evidence every day.
You'll leave with:
- Practical guidance from experienced auditors
- Answers to your toughest audit questions
- Tips you can immediately apply to your compliance program
- A better understanding of what auditors actually look for



Upcoming sessions
Join the conversations most relevant to your audit program.
September 23
What Actually Makes Evidence SOC 2 Ready?
Understand how lengthy audit timelines impact enterprise sales, pipeline velocity, and market expansion.

october 7
Preparing for HITRUST Without Overbuilding
Avoid wasted effort by focusing on what auditors actually expect.

October 21
ISO 27001: What Changes Beyond SOC 2?
Understand the key differences before adding another framework.

November 4
Can You Reuse Evidence Across Frameworks?
Learn when evidence can be reused, when it can't, and how to reduce duplicate work across audits.

November 18
What Should AI Companies Prepare to Prove?
Understand the controls, documentation, and governance auditors increasingly expect from AI companies.

december 2
What Do Healthcare and Healthtech Teams Get Wrong About HIPAA?
Learn the most common audit pitfalls and how to avoid them before they become findings.

december 9
What Should You Fix Before Your Next Audit Cycle?
Identify the biggest gaps to address now so your next audit is smoother, faster, and more predictable.

Meet the auditors

They've seen late-night evidence hunts, endless follow-ups, and last-minute surprises. Now they're here to answer your questions before your next audit turns into Audit Hell.







Leith Khanafseh
Audit Managing Partner
|
Formerly: KPMG, EY, Coalfire
Leith founded and currently oversees the Assurance offering at Thoropass. Before Thoropass, Leith’s career spanned across a couple of the Big 4 accounting firms and Coalfire, where he performed and led information security audits for some of the world’s largest cloud service providers and SaaS platforms.
Matt Udicious
Director of Infosec Assurance
|
Formerly: Accenture, Coalfire, KPMG
With a decade of IT consulting experience, Matt has made substantial contributions across renowned organizations such as Accenture, KPMG, and Coalfire, including the implementation of robust security measures and compliance frameworks to safeguard the information assets of a diverse clientele.
David Haviley
Senior Manager, InfoSec Solutions
David is a leader within Thoropass’ InfoSec Assurance practice, where he plays a pivotal role in managing and overseeing a range of offerings, including SOC 1, SOC 2, SOC 3, and HIPAA compliance. His expertise lies in the comprehensive review and support of SOC audit processes and HIPAA attestations for businesses of varying sizes and industries.
Bennett Stamper
Compliance Engineer
Bennett has been working in compliance since 2020, beginning his career as an external auditor at Coalfire. There, he specialized in ISO audits, while also gaining broad experience across frameworks like SOC 2, PCI-DSS, and more. In 2025, Bennett joined Thoropass as a Sales Engineer, where he helps ensure accurate deal scoping, provides expert guidance to both customers and internal stakeholders, and supports other team members cross-functionally.
Chris Beiro
Senior Director of Infosec
|
Formerly: KPMG, Coalfire
Chris is a seasoned cybersecurity executive with a strong track record in Governance, Risk, and Compliance (GRC). With over a decade of experience, he has helped organizations—from high-growth startups to Fortune 500 enterprises—strengthen their cybersecurity programs, meet rigorous compliance standards, and mitigate risk.
Bruce Edwards
Senior Manager, PCI Assurance
Bruce is a seasoned professional with 14 years of experience holding both CISA and CISM certifications. His experience spans various sectors including penetration testing, PCI QSA, ASV, and Cloud Security. In his previous role as a security director, Bruce lead PCI DSS assessments for Fortune 500 companies in the FinTech and healthcare sectors, both in the U.S. and around the world.
Lucas Baiocchi
Manager, HITRUST InfoSec Assurance
With 7+ years of experience in information security audits and assessments, Lucas leads and executes HITRUST assessments, working closely with organizations to evaluate their security posture, validate control effectiveness, and deliver clear, actionable insights that align compliance objectives with broader business goals.
Why Thoropass?
Built by auditors. Backed by Thoropass.
Thoropass helps organizations move from evidence collection to final report with experienced auditors, AI-enabled evidence validation, and purpose-built audit workflows that reduce rework, improve visibility, and keep audits moving forward.










.png)