Logo Menu

SOC 2 compliance automation platform with an affiliated in-house audit practice Β· verified

Thoropass

The company operated as Laika from its 2019 founding until it rebranded to Thoropass on March 29, 2023 (announced via PR Newswire and the company's own newsroom); the underlying CPA entity is still legally named Laika Compliance, LLC, doing business as Thoropass Assurance.

Thoropass does not publish a price list; the only concrete public numbers are AWS Marketplace's starting prices of $8,700/year for the platform subscription and $5,800/year for the SOC 2 audit subscription (about $14,500/year combined at the floor), while independent buyer-side write-ups (Vendr, SmartSuite, ComplyJet) report typical real-world contracts running $20,000-$45,000/year once company size and scope are added.

The bundled software-plus-audit model is the main tradeoff buyers should weigh: it can reduce back-and-forth during the audit itself, but it also means the entity that built your evidence workflow is commercially tied to the entity opining on it, and switching software vendors later likely means switching auditors too.

Desk research against public sources. Every figure below carries its source and the date we retrieved it.

Capabilities

What Thoropass does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes "Integrations and monitors vetted by auditors, that automatically satisfies evidence requests while powering transparent continuous compliance monitors." Source
Auditor workspace Yes The audit runs inside the same platform end to end ("from evidence to report, your entire audit is finally connected"); this is Thoropass's core differentiator versus software-only platforms. Source
Trust center Yes "Trust Center" is listed as a standing product module in the site's main navigation. Source
Security questionnaire answering Yes "Security Questionnaires" is listed as a standing product module in the site's main navigation. Source
Enterprise admin (SSO, SCIM, RBAC) Yes Thoropass's own help center documents SSO + SCIM provisioning configuration and a separate "Roles & Permissions" article; multi-entity support is not confirmed either way. Source
SCIM 2.0 provisioning Yes Thoropass documents a SCIM 2.0 API with Okta and Entra setup guides. No tier is named; the only stated requirement is asking customer success for an API key, which suggests broad availability rather than a gate. Google Workspace cannot use it, which is an identity-provider limitation rather than a Thoropass one. Source
Continuous control testing Yes Vendor markets "proactive monitoring capabilities" that flag issues ahead of audit windows, framed as continuous rather than point-in-time. Source
Native multi-framework support Yes Each framework (SOC 1, SOC 2, ISO 27001, HITRUST, etc.) has its own dedicated framework page and audit type; the vendor separately advertises "up to 90% crossover between frameworks" as a control-reuse efficiency feature layered on top of, not instead of, natively built controls. Source
Frameworks

10 frameworks, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed Core named product line; audit is performed by the affiliated CPA entity, Thoropass Assurance. Source
SOC 1 Vendor-claimed Source
ISO 27001 Vendor-claimed Source
HIPAA Vendor-claimed Source
HITRUST Vendor-claimed Thoropass is a HITRUST-authorized external assessor per its own independence page. Source
PCI DSS Vendor-claimed Source
GDPR Vendor-claimed Source
NIST CSF Vendor-claimed Source
CMMC Vendor-claimed Source
Cyber Essentials Vendor-claimed Source
Pricing

Thoropass does not publish a price.

Getting a number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.

Disclosure model
Quote-based (reported from $15K/yr)
Observed price (reported)
USD 14,500 / year
Basis
Estimate, 2026-07-24

Auditor fees are separate from all of these. See the SOC 2 audit cost guide for what the audit itself runs.

Auditor handoff

Who actually issues the report.

The SOC 2 report is issued by Thoropass Assurance, the trade name of Laika Compliance, LLC, a licensed CPA firm registered with the AICPA; Thoropass, Inc. (the software company) is a separate legal entity under the same corporate umbrella (per the company's own /company/legal page). Thoropass's own /independence-and-excellence page explicitly calls this 'our affiliated audit entity' and describes a people/process separation (Customer Success vs. Auditors) intended to satisfy AICPA independence rules; the audit arm passed its most recent AICPA peer review in 2025 with the top rating. In practice this means the platform vendor and the auditor are commercially affiliated rather than a customer-chosen, arm's-length third party: multiple independent buyer-comparison sources (Sprinto, Smartsuite, trycomp.ai) describe Thoropass as bundled 'by design' and note you cannot bring your own independent auditor onto the platform, which limits workspace portability if a buyer later wants to keep the software but switch audit firms.

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who Thoropass is for, and who it is not.

Good fit

A company pursuing multiple related certifications (e.g. SOC 2 plus ISO 27001 or HITRUST) that wants one connected audit process and is willing to pay a bundled software-plus-audit price instead of shopping the audit separately.

Poor fit

A company that wants to choose its own independent CPA firm, keep the freedom to switch auditors while retaining the software, or that specifically wants to avoid any appearance of the platform vendor and the auditor being under common ownership.

Typical buyer: A growth-stage or regulated company that wants the entire audit (not just readiness) to happen inside one platform with in-house auditors, and is comfortable with the audit firm being affiliated with the software vendor..

Source ledger

Where every figure on this page came from.

9 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.

← All SOC 2 compliance software Β· Thoropass review Β· How we verify

Some links to compliance platforms on this page are affiliate links: if you sign up through one, the vendor may pay us a commission at no cost to you. It never changes our ranking, our review, or which platform we recommend.

For Thoropass

Something here out of date?

Every figure above carries a source and the date we read it. If one has moved, send us the current source and we will update the record.

Verification is free and always will be. It does not change where Thoropass appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.

Correct this record