Thoropass
Thoropass is an end-to-end cybersecurity auditor combining an AICPA-licensed audit firm with an AI-powered compliance automation platform, serving 1,200+ healthcare, fintech, SaaS, and insurance customers across SOC 2, HITRUST, HIPAA, PCI DSS, and ISO 27001 frameworks.
- Company typePrivate
- Founded2019
- HeadquartersNew York, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Thoropass does
Thoropass is an end-to-end cybersecurity auditor that combines a licensed audit firm with an AI-powered compliance automation platform. Founded in 2019 and headquartered in New York with a regional office in London, the company delivers security audits and continuous compliance monitoring across SOC 2, HITRUST, HIPAA, PCI DSS, ISO 27001, GDPR, NIST CSF 2.0, and 30+ other frameworks. Its audit authority stems from Laika Compliance, LLC, acquired in 2022 and now operating as Thoropass Assurance, a licensed certified public accounting firm registered with the AICPA that operates under ISO/IEC 17021-1 accreditation requirements for certification decisions. The penetration testing service holds CREST accreditation.
The platform layer comprises Thoropass AI (built on Google Vertex AI and Azure OpenAI), Automated Evidence Collection and AI Validation, Access Review Automation, Security Questionnaire Automation, Risk Assessment and Management, a Trust Center, and Integrations with 100+ tools including AWS and GitHub. First Pass AI, introduced in December 2024, adds AI-driven evidence verification that validates audit evidence before formal audits. The combination positions Thoropass as a single vendor delivering both readiness software and audit delivery, in contrast to platform-only competitors that require third-party assessors.
Thoropass makes money through bundled annual subscriptions combining compliance automation software with integrated audit delivery, supplemented by CREST-accredited penetration testing services and vulnerability scanning. Pricing is quote-based, calibrated to frameworks pursued, audit scope, and customer size. Go-to-market combines enterprise field sales for large accounts, inside sales for mid-market, a self-serve Thoropass for Startups tier, an MSP Compliance-as-a-Service channel, and AWS co-sell distribution. The company serves 1,200+ customers across healthcare, fintech, SaaS, and insurance with 200+ employees in more than a dozen countries, and has raised approximately $98 million across four funding rounds led by investors including Fin Capital, J.P. Morgan Growth Equity Partners, Canapi Ventures, and Bain Capital Ventures.
Thoropass firmographics
Firmographics- Name
- Thoropass
- Legal name
- Thoropass, Inc.
- Website
- https://thoropass.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Thoropass is an end-to-end cybersecurity auditor combining an AICPA-licensed audit firm with an AI-powered compliance automation platform, serving 1,200+ healthcare, fintech, SaaS, and insurance customers across SOC 2, HITRUST, HIPAA, PCI DSS, and ISO 27001 frameworks.
- Ownership category
- akta.pro rank
Thoropass industry classification
Industry- Product category
- Compliance Automation Software
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519), Testing Laboratories and Services (54138)
- SIC
- Services-Prepackaged Software (7372), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Compliance, GRC Workflow & Audit Automation Platforms (HDAEAHAL)
- akta.pro secondary industries
- Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE), Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI), Responsible AI, AI Governance & Compliance Services (BPAEAHAJ)
Keywords
Where Thoropass is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Thoropass business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Infrastructure
Revenue model
- SaaS Subscription - Compliance Automation Platform: Thoropass offers a subscription-based compliance automation platform with bundled audit services. Pricing varies based on frameworks pursued, audit scope, company size, and required services. The platform combines software and audit delivery in a bundled approach that can be more cost-effective than managing separate vendors for readiness tooling and audit services.
- Professional Audit Services: Integrated audit services delivered by in-house expert auditors, including SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, GDPR certifications. Thoropass is a licensed auditor that delivers audits as a certified CPA firm registered with AICPA.
- Penetration Testing Services: CREST-accredited penetration testing services identifying vulnerabilities across different environments including network, application, and infrastructure testing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based pricing tailored to organization size, frameworks, and scope |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels9 records
Thoropass product offering
Product offeringCore offering
Thoropass operates an AI-powered compliance automation platform integrated with an in-house licensed audit firm to deliver end-to-end infosec compliance and certification. Customers subscribe to a SaaS platform that automates evidence collection, AI-driven validation, access reviews, security questionnaire responses, and risk management, while bundled audit services deliver formal certifications for SOC 2, HITRUST, HIPAA, PCI DSS, ISO 27001, GDPR, and 30+ additional frameworks.
Product overview
Thoropass is an end-to-end cybersecurity auditor combining a licensed audit firm with an AI-powered compliance automation platform. The portfolio consists of two interconnected components: (1) Audit Services delivered by in-house auditors for frameworks including SOC 2, HITRUST, HIPAA, PCI DSS, ISO 27001, GDPR, and NIST CSF 2.0; and (2) the Compliance Automation Platform featuring Thoropass AI for AI-driven evidence collection, Automated Evidence Collection & AI Validation, Access Review Automation, Security Questionnaire Automation, Risk Assessment & Management, and Trust Center. Additional services include Pentesting and Vulnerability Scanning. The platform integrates with AWS, GitHub, and other business tools to automate evidence collection and maintain continuous compliance monitoring, combining expert auditors with AI automation for faster, higher-quality audits.
Differentiator
Problem solved
Functional benefit
Products and services
- Thoropass Audit
- Compliance Automation Platform
- Pentesting
- Vulnerability Scanning
- Compliance as a Service for MSPs
Quantifiable outcome
- 91% of organizations must resubmit audit evidence at least sometimes due to miscommunication or shifting auditor expectations, highlighting the industry-wide challenge Thoropass addresses with its integrated platform approach
- +2 more outcomes
Companies that use Thoropass
Customer profileNamed customers22 records
Segments5 records
Ideal customer profiles4 records
Thoropass technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability4 records
Feature8 records
Thoropass partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and growth.
- Amazon Web Services (AWS)coreAWS partnership with new initiatives at re:Invent 2024 including expanding co-sell benefits, migration incentives, and new AWS Specializations. Focus on helping partners leverage AI technologies and grow revenue with startups, SMBs, and security solutions.
- CREST (Council of Registered Ethical Security Testers)coreCREST accreditation for Thoropass penetration testing service - internationally recognized accreditation body for cybersecurity professionals and organizations. CREST certification indicates that a penetration testing provider meets rigorous standards for technical capability, methodology, and ethical conduct.
- Managed Services Providers (MSPs)growthThoropass launched 'Compliance as a Service' offering for managed services providers to gain a competitive edge. MSPs can resell or embed Thoropass compliance services to their customer base.
- 100+ Integration PartnerscoreThoropass integrates with wide range of common business and infrastructure tools including cloud providers, identity and access management systems, HR platforms, and ticketing tools to automate evidence collection and reduce manual work.
Scale indicators6 records
Recent moves7 records
Expansion highlights6 records
Thoropass competitors and assessment
Company assessmentDirect peers
- Vanta: Vanta is the most direct competitor: an AI-powered compliance automation platform for SOC 2, ISO 27001, HIPAA, and 30+ frameworks, serving a similar startup and mid-market customer base with a software-only model (no in-house audit delivery).
- Drata: Drata is a direct competitor offering continuous compliance automation across SOC 2, ISO 27001, HIPAA, and other frameworks, targeting the same startup, mid-market, and SaaS segments as Thoropass.
- Schellman: Schellman is a niche cybersecurity assessment and compliance firm offering SOC 2, ISO 27001, HITRUST, and PCI DSS services with a tech-enabled delivery model—comparable to Thoropass Assurance in combining audit expertise with proprietary tooling.
- Hyperproof: Hyperproof is a GRC and compliance operations platform supporting SOC 2, ISO 27001, and multi-framework programs—competing with Thoropass in mid-market GRC and evidence management categories.
- A-LIGN: A-LIGN is a cybersecurity and compliance audit firm delivering SOC 2, ISO 27001, HITRUST, and PCI DSS assessments combined with a technology platform—closely mirroring Thoropass's bundled auditor-plus-platform model.
- Coalfire: Coalfire is a cybersecurity advisory and assessment firm specializing in SOC 2, ISO 27001, HITRUST, and FedRAMP audits—the same framework breadth and healthcare/regulated-industry focus that Thoropass's audit practice targets.
- Secureframe: Secureframe provides compliance automation for SOC 2, ISO 27001, HIPAA, PCI DSS, and other frameworks with a similar AI-assisted approach, competing for the same startup and SMB customers as Thoropass.
- Sprinto: Sprinto is a compliance automation platform focused on SOC 2, ISO 27001, and HIPAA for fast-growing B2B SaaS companies, directly overlapping Thoropass's SaaS primary vertical and automated evidence collection capabilities.
- AuditBoard: AuditBoard is a leading audit, risk, and compliance management platform (SOC 2, ISO 27001, SOX) recognized as a G2 leader in Audit Management—directly comparable to Thoropass's audit management and GRC platform.
Broad incumbents
- OneTrust: OneTrust is a broad privacy, GRC, and ethics-and-compliance platform incumbent with overlapping SOC 2, ISO 27001, and risk management capabilities as part of a much larger portfolio serving enterprise and mid-market customers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Thoropass social profiles
Digital presenceThoropass compliance and trust
Trust signalCompliance6 records
Thoropass financial estimates
Financial estimateRevenue estimate
Valuation estimate
Thoropass leadership team
Management profileNumber of profiles
Profiles5 records
Thoropass subsidiaries and ownership
Company hierarchySubsidiaries1 record
Thoropass funding detail
Funding detailFunding overview
Funding rounds4 records
Investors11 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Thoropass M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Thoropass
What does Thoropass do?
Thoropass operates an AI-powered compliance automation platform integrated with an in-house licensed audit firm to deliver end-to-end infosec compliance and certification. Customers subscribe to a SaaS platform that automates evidence collection, AI-driven validation, access reviews, security questionnaire responses, and risk management, while bundled audit services deliver formal certifications for SOC 2, HITRUST, HIPAA, PCI DSS, ISO 27001, GDPR, and 30+ additional frameworks.
Is Thoropass a public or private company?
Thoropass is a private company. It is classified as venture growth investor backed and is currently operating.
When was Thoropass founded?
Thoropass was founded in 2019. It employs 101 to 250 people.
Where is Thoropass based?
Thoropass is headquartered in New York, United States, in the North America region.
How does Thoropass make money?
Three revenue lines are on record. SaaS Subscription - Compliance Automation Platform is the primary driver. The others are professional Audit Services and penetration Testing Services.
Who are Thoropass's main competitors?
Direct peers on record are Vanta, Drata, Schellman, Hyperproof, A-LIGN, Coalfire, Secureframe, Sprinto and AuditBoard. OneTrust is listed as a broad incumbent.
Does Thoropass have an API?
No public API is recorded for Thoropass.
What industry is Thoropass in?
Thoropass's product category is Compliance Automation Software. Its primary akta.pro industry code is HDAEAHAL, Compliance, GRC Workflow & Audit Automation Platforms, with a secondary code of HDAEANAE, Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies). Its NAICS code is 5415 and its SIC code is 7372.