Logo Menu

Thoropass SOC 2 compliance software

SOC 2 compliance automation platform with an affiliated in-house audit practice, sold bundled or audit-first Last updated

Thoropass does not publish a complete rate card; the concrete public numbers are AWS Marketplace's starting prices of $8,700/year for the platform subscription and $5,800/year for the SOC 2 audit subscription (about $14,500/year combined at the floor), while buyer-side deal data (Vendr, SmartSuite) reports typical real-world contracts running $20,000-$45,000/year once company size and scope are added.

By , Lead Editor ยท independently researched ยท Methodology

Pricing
Quote-based (reported from $15K/yr)
Source-checked frameworks
10
Integrations
200+
G2 (2026-07-24)
4.7 ยท 600 reviews
What the evidence says

AWS presents the platform and audit as separate subscription dimensions that bill independently, even though they run through one provider workflow. The tradeoff worth weighing is the scope of the relationship rather than audit quality, which the AICPA peer review is the mechanism for: one provider covering both software and attestation removes a vendor handoff, while the buyer still needs the proposal to separate platform, examination, implementation, renewal, and additional-framework fees. A buyer who wants the audit without that consolidation can take the audit-first path and keep the GRC platform already in place.

Company context

Thoropass (as Laika) has raised $98M total across four rounds, most recently a $50M Series C led by Fin Capital with Centana Growth and existing investors J.P. Morgan Growth Equity Partners, Canapi, and ThirdPrime, which closed and was announced November 8, 2022 per PR Newswire and TechCrunch.

Capabilities

What Thoropass does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes "Integrations and monitors vetted by auditors, that automatically satisfies evidence requests while powering transparent continuous compliance monitors." Source
Auditor workspace Yes The audit runs inside the same platform end to end ("from evidence to report, your entire audit is finally connected"); this is Thoropass's core differentiator versus software-only platforms. Source
Trust center Yes "Trust Center" is listed as a standing product module in the site's main navigation. Source
Security questionnaire answering Yes "Security Questionnaires" is listed as a standing product module in the site's main navigation. Source
Enterprise admin (SSO, SCIM, RBAC) Yes Thoropass documents SSO, SCIM provisioning, and roles/permissions. Multi-entity support is not confirmed either way; SCIM IdP limitations are recorded in the separate capability row. Source
SCIM 2.0 provisioning Yes Thoropass documents SCIM 2.0 provisioning through Entra and Okta, with SSO as a prerequisite. Google Workspace is unsupported. For Okta, the current article warns that SCIM-installed apps work but catalog-installed apps do not while Thoropass and Okta resolve the issue. No public tier is named. Source
Continuous control testing Yes Vendor markets "proactive monitoring capabilities" that flag issues ahead of audit windows, framed as continuous rather than point-in-time. Source
Native multi-framework support Yes Each framework (SOC 1, SOC 2, ISO 27001, HITRUST, etc.) has its own dedicated framework page and audit type; the vendor separately advertises "up to 90% crossover between frameworks" as a control-reuse efficiency feature layered on top of, not instead of, natively built controls. Source
Source-checked frameworks

10 frameworks checked individually, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed Core named product line; audit is performed by the affiliated CPA entity, Thoropass Assurance. Source
SOC 1 Vendor-claimed Vendor markets connected readiness, evidence collection, and audit for SOC 1. Does not establish one contract covering software and examination. Source
ISO 27001 Vendor-claimed Source
HIPAA Vendor-claimed Vendor-claimed HIPAA framework program. Confirm the risk-analysis deliverables and implementation support in the quoted scope. Source
HITRUST Vendor-claimed Thoropass is a HITRUST-authorized external assessor per its own independence page. Source
PCI DSS Vendor-claimed Source
GDPR Vendor-claimed Source
NIST CSF Vendor-claimed Source
CMMC Vendor-claimed Source
Cyber Essentials Vendor-claimed Source
Pricing

Thoropass uses quote-based pricing.

Getting a direct number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.

Disclosure model
Quote-based (reported from $15K/yr)
Sourced annual price (reported)
USD 14,500 / year
Basis
Estimate, 2026-08-24

Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.

Read the Thoropass pricing guide for the current source table and quote checklist.

Auditor handoff

Who actually issues the report.

The SOC 2 report is issued by Thoropass Assurance, the trade name of Laika Compliance, LLC, a licensed CPA firm registered with the AICPA; Thoropass, Inc. (the software company) is a separate legal entity under the same corporate umbrella, per the company's own /company/legal page. That two-entity structure is what AICPA rules require of any firm selling both technology and attestation services, and it is externally checked rather than self-declared: we read the AICPA's public peer review file directly, and it records Laika Compliance, LLC with a report rating of pass, accepted 12 December 2025, covering the period to 31 January 2025. Thoropass's own /independence-and-excellence page describes the people and process separation (Customer Success on one side, auditors on the other) that sits behind it. Two purchase paths exist and most comparisons in this category describe only the first. Bundled, the platform and the audit come from the same provider relationship and run in one connected workflow; AWS Marketplace lists the platform and audit as separate subscription dimensions that bill independently, so buyers should confirm the Order Forms and renewal terms rather than assume a single contract. Audit-first, you keep the GRC platform you already run and engage Thoropass Assurance as the independent auditor: Thoropass states its Audit Lifecycle Platform works with any GRC platform and system of record, and its Smart Sort AI feature, announced 29 January 2026, turns an export from any GRC tool into audit-ready evidence with no integration to build. Both of those are the vendor's own claims and we have not tested them. The constraint runs the other way: Thoropass's materials describe the audit being performed by Thoropass Assurance and do not document bringing an outside CPA firm into the workspace, so a buyer who wants to keep the software and rotate audit firms should ask about that directly. We do not carry that limit as an established fact, because the pages stating it outright are published by vendors selling competing platforms.

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who Thoropass is for, and who it is not.

Good fit

A company pursuing multiple related certifications (e.g. SOC 2 plus ISO 27001 or HITRUST) that wants one connected provider relationship instead of coordinating separate software and audit vendors. It also fits the opposite buyer: a team running Vanta, Drata or ServiceNow that wants an AI-assisted audit firm and does not want to move its GRC stack to get one.

Poor fit

A company whose procurement policy requires the audit firm to carry no common ownership with the software vendor, which is a stricter bar than the AICPA sets and a buyer-side policy choice rather than a finding against the firm. Also a poor fit for a team that wants to run the Thoropass platform while rotating audit firms year to year, since on the bundled path the audit side is Thoropass Assurance.

Typical buyer: A growth-stage or regulated company that wants the audit itself, not only readiness, run by the same team that runs the platform, or one that already has a GRC platform it likes and wants a faster audit rather than a second piece of software..

Related profiles

Compare Thoropass with three alternatives.

  • Comp AI

    Engineering-led teams want inspectable evidence automation across the scope.

  • The audit workflow should sit beside a broad connected evidence layer.

  • Guided support and auditor-facing remediation are equally important.

Sources

20 records ยท last read

If a claim on this page is out of date, this is the list to re-check.

20 sources for Thoropass, with what each established and when we read it
Establishes Source Retrieved
Confirms the Laika-to-Thoropass rebrand announcement dated March 29, 2023. PR Newswire Press
Confirms $50M Series C led by Fin Capital, closed November 8, 2022, bringing total funding to $98M. PR Newswire Press
Independent press confirmation of the $50M Series C and its date. TechCrunch Press
States that Laika Compliance, LLC dba Thoropass Assurance is the licensed AICPA-registered CPA firm, and Thoropass, Inc. dba Thoropass is the separate technology/professional-services entity. Thoropass (vendor) Vendor docs
Describes the audit arm as "our affiliated audit entity," explains the AICPA independence framework applied, and cites a 2025 AICPA peer review with the highest ("pass") rating. Thoropass (vendor) Vendor docs
Public File Search, firm name "Laika", returns Laika Compliance LLC (firm number 900255351244, Annandale VA): period covered 02/01/2024 to 01/31/2025, peer review acceptance date 12/12/2025, report rating Pass. Read from the AICPA's own public file rather than from the vendor's summary of it, which is why the peer review is graded independently confirmed rather than vendor-claimed. AICPA Peer Review Program Standards body
Published starting prices: $8,700/year platform subscription and $5,800/year SOC 2 audit subscription. AWS presents them as separate subscription dimensions that bill independently and work together. AWS Marketplace Marketplace
Vendor markets connected SOC 1 readiness, evidence collection, and audit with expert auditors. Does not establish one contract covering software and examination, or that every independence policy accepts the affiliated-auditor model. Thoropass (vendor) Vendor docs
Vendor markets a connected evidence-to-report audit workflow with expert auditors inside the platform. Speed and overhead percentages on the page are vendor claims and are not used as facts on the FinTech shortlist. Thoropass (vendor) Vendor docs
Announcement dated 29 January 2026 stating the Audit Lifecycle Platform "works seamlessly with any GRC platform and systems of record" and that Smart Sort AI lets customers "upload exported files from any vendor's GRC system with no integration required" and turn them into audit-ready evidence. Establishes the audit-first purchase path, where the customer keeps its existing GRC platform, as a vendor-stated capability. File upload rather than live sync, and untested by us. Thoropass (vendor newsroom) Vendor docs
Source of the audit-cycle figure: First Pass "helped to reduce audit timelines from 73 days, already an industry benchmark, to just 29 days, a 60% reduction." Vendor-measured, still published as of this retrieval. Thoropass (vendor) Vendor docs
4.7/5 rating across roughly 600 reviews (dated reading from G2's public listing). G2 Review platform
Current SSO/SCIM setup for Entra and Okta, including Google Workspace exclusion and the temporary Okta catalog-app limitation. Thoropass (vendor help center) Vendor docs
HIPAA framework support recorded as vendor-claimed. Thoropass Vendor docs
Vendor-claimed HIPAA framework program. Confirm the risk-analysis deliverables and implementation support in the quoted scope. Thoropass Vendor docs
Thoropass describes one connected evidence-to-report workflow with embedded audit expertise, while its public entity notice identifies Laika Compliance, LLC dba Thoropass Assurance as the AICPA-registered CPA firm and Thoropass, Inc. as the technology/professional-services firm. Use the existing independently checked peer-review record for any claim stronger than this vendor-described workflow. Thoropass Vendor docs
The MSA describes telephone, email, or online-chat assistance during the subscription term as set out in the applicable Order Form. Do not promise a particular support level without the buyer's Order Form. Thoropass Vendor docs
Thoropass says its pricing varies by framework, audit scope, company size, and required services, and buyers receive a tailored quote. Thoropass Vendor docs
The 12-month Marketplace dimensions list the Compliance Platform starting at $8,700 and the SOC 2 Audit Subscription starting at $5,800; the page says they bill independently and final cost varies by scope. AWS Marketplace Marketplace
Not established. The reviewed DPA covers customer personal data but does not establish a HIPAA BAA route or permission to upload PHI. SOC2Auditors.org Editorial

โ† All SOC 2 compliance software ยท Thoropass review ยท How we verify

For Thoropass

Something here out of date?

Every figure above carries a source and the date we read it. If one has moved, send us the current source and we will update the record.

Verification is free and always will be. It does not change where Thoropass appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the sources list above alongside the date.

Correct this record