Logo Menu

By Peter Korpak · Reviewed against our methodology · Last updated

Thoropass Logo

Thoropass

Specialist Verified New York, NY, USA

Last verified · how we verify

Type II Cost
$25K–$70K
Timeline
4–10 months
Founded
2019
Team Size
200-250

Thoropass is a specialist SOC 2 audit firm in New York, NY, USA that charges $25K–$70K for Type II audits with 4–10 month timelines. Founded in 2019, they hold 8 accreditations and specialize in B2B SaaS, FinTech, HealthTech, and 2 more. Their pricing is above average compared to the specialist average of $18.491K–$52.655K.

Or compare with similar firms ↓

Free. Anonymous until you pick.

How Much Does Thoropass Charge for SOC 2?

Type I Cost
$15K–$50K
Type II Cost
$25K–$70K
Timeline
4–10 months
Team Size
200-250
Report Delivery
Weeks, not quarters (62% faster than traditional process)
Response Time
In-platform same-day collaboration with dedicated auditor

Type II Pricing Position

$10K $450K
Thoropass: $25K–$70K Specialist avg: $18.491K–$52.655K

Note: Pricing shown is estimated based on typical engagements. Use our SOC 2 cost calculator for a personalized estimate.

4%

of Specialist firms charge more for Type II

7%

of Specialist firms have longer minimum timelines

8

certifications (tier avg: 4)

Compare Thoropass with Similar Specialist Firms

Side-by-side pricing, timeline, and certification counts for the 5 closest-priced peers in the specialist tier.

Thoropass Prescient Security Moore Kingston Smith Accedere Audit Advantage Group CAS Assurance
Type II Cost $25K–$70K $20K–$75K$25K–$70K$25K–$70K$25K–$70K$25K–$70K
Type I Cost $15K–$50K $12K–$35K$15K–$50K$15K–$50K$15K–$50K$15K–$50K
Timeline 4–10 mo 3–9 mo3–9 mo4–10 mo4–10 mo4–10 mo
Team Size 200-250 300–4005–1520–20020–20020–200
Certifications 8 173312
Founded 2019 20182016201720152018

Thoropass Industry Fit

For buyers in B2B SaaS and FinTech, Thoropass fits the specialist profile when timeline (4–10 months) and Type II pricing ($25K–$70K) align with what specialist firms typically deliver. Their 8 active accreditations — including CPA Firm (Laika Compliance LLC dba Thoropass Assurance), PCI DSS QSAC, HITRUST Authorized External Assessor — extend that fit beyond pure SOC 2 into adjacent compliance frameworks.

Who Should Hire Thoropass?

First-time SOC 2 / ISO 27001 / HIPAA / PCI / HITRUST seekers (under 200 employees) who want one vendor handling both the GRC platform and the audit, eliminating the handoff between Vanta/Drata-style automation and a separate CPA firm. Companies pursuing multiple frameworks who want shared evidence across SOC 2 + ISO 27001 + HITRUST + PCI in a single audit cycle. Mid-market SaaS, fintech, and healthtech seeking 25-50% savings vs. traditional audit firms with fixed pricing.

What Makes Thoropass Different?

The only end-to-end cybersecurity auditor. Bundles a proprietary GRC platform with in-house CPA, PCI QSAC, and HITRUST assessor under one roof. Same auditor from Day 1 through report issuance (no handoff between readiness vendor and audit firm). First Pass AI pre-screens evidence, cutting secondary auditor requests up to 80%. 1,000+ customers, 500+ audits annually, $98M raised through Series C (Fin Capital led). AICPA Peer Review 'Pass' rating (achieved twice, most recently December 2025). Inc. 5000 honoree for 2nd consecutive year (351% three-year growth). Founded 2019; rebranded from Laika in March 2023.

Is Thoropass Right for You?

  • You need HITRUST + SOC 2 bundled in a single engagement
  • You handle payment data and need PCI DSS + SOC 2 together
  • You're a SaaS company going through SOC 2 for the first time
  • You already use Thoropass (proprietary) and want an auditor who integrates with it
  • You want a firm that focuses primarily on SOC 2 and compliance audits

About Thoropass

Thoropass is the rare compliance vendor that owns both ends of the SOC 2 problem: the GRC platform you use to prepare for the audit, AND the licensed CPA firm that signs the audit report. Most of the market splits these roles (Vanta/Drata/Secureframe handle automation and refer you to a separate auditor like Schellman or A-LIGN). Thoropass argues that handoff is the friction.

Founded in 2019 and rebranded from Laika in March 2023, Thoropass is headquartered in New York with an EMEA hub in London. The firm has raised $98M across four rounds (most recently a $50M Series C led by Fin Capital in November 2022, with J.P. Morgan Growth Equity, Centana, and Canapi participating). It now serves 1,000+ organizations, completes 500+ audits annually, and was named to the Inc. 5000 for a second consecutive year in 2025 with 351% three-year growth.

The licensed audit firm is Laika Compliance, LLC dba Thoropass Assurance, registered with the AICPA and recently the recipient of an AICPA Peer Review “Pass” rating for the second time (December 2025). Thoropass is also a PCI QSA Company (QSAC) and an AICPA Authorized HITRUST External Assessor, claiming to be the first automated compliance solution to earn HITRUST assessor status.

The Platform + Audit Bundle

This is the core of Thoropass’s positioning. Three things follow from owning both sides:

Same auditor from Day 1 to the stamp. No transition meeting from your readiness vendor to a separate audit firm. The auditor who scopes your environment is the same one signing the report.

First Pass AI pre-screens evidence. Launched in January 2025, this AI layer programmatically checks evidence completeness and accuracy before it reaches the auditor. Thoropass claims this cuts secondary auditor requests up to 80% and reduces manual QA time by 95%.

Shared evidence across frameworks. SOC 2 + ISO 27001 + PCI + HITRUST use the same control set with one collection cycle. For companies pursuing two or more frameworks, this eliminates redundant evidence work.

The platform also supports companies who don’t want to switch GRC tools. Since 2025, the audit module is available standalone for customers already on Vanta, Drata, or Secureframe, and the platform offers “Our GRC or yours” interop.

Platform Capabilities (2025-2026 builds)

  • First Pass AI (Jan 2025), automated evidence pre-screening
  • Head Start for Access Reviews (Jan 2025), reuses prior review data, cuts review work by ~95%
  • GenAI Security Questionnaire Automation, answers due-diligence questionnaires
  • Multi-Product Workspace, manage multiple products/divisions with auto-mapped controls
  • Trust Center (Sept 2025), public-facing compliance posture portal
  • Risk Register and Risk Assessment
  • Penetration Testing built into the platform
  • 100+ auditor-approved integrations spanning AWS, Azure, GCP, Snowflake, GitHub, Jira, Okta, Slack, M365, and more

The Independence Question

The AICPA issued a Peer Reviewer Alert in December 2022 about self-review threats when compliance automation platforms also have audit affiliates. Thoropass has addressed this publicly: evidence flows through standardized APIs reviewed and approved by auditors before deployment, and the licensed CPA firm operates under AICPA Code of Professional Conduct standards. They’ve now passed two AICPA peer reviews with the “Pass” rating, the highest available.

This matters because the rest of the market sometimes raises independence concerns about platform-plus-audit firms. Two peer review passes (2022 and 2025) is the strongest counter-evidence available.

Compliance Frameworks

Direct audits Thoropass conducts:

  • SOC 1 (SSAE 18 financial controls)
  • SOC 2 Type I and Type II
  • SOC 3
  • HITRUST (i1 and r2 Validated Assessment & Certification, plus MyCSF authorized reseller)
  • PCI DSS (RoC, AoC, SAQ via QSAC accreditation)
  • HIPAA / HITECH assessments

Frameworks supported via platform + partner CB:

  • ISO 27001, ISO 27018, ISO 42001
  • CMMC Level 1, NIST CSF 2.0, NIST 800-53
  • GDPR, CCPA, 23 NYCRR 500 (NYDFS Cybersecurity Requirements)

Thoropass markets coverage across 30+ frameworks total with control-mapping that lets a single evidence set satisfy several reports.

Worth noting what’s missing: no FedRAMP capability, no StateRAMP, no CMMC Level 2 C3PAO status. Companies targeting federal authorizations will need a 3PAO partner.

Leadership

Sam Li, Co-Founder & CEO. UVA Computer Science, Harvard MBA. Previously co-founder and CTO of Zinc Platform (YC-backed insurtech), with stints at Google, Goldman Sachs, and Cambridge Associates. Named a 2026 EY Entrepreneur Of The Year New York finalist.

Eva Pittas, Co-Founder, President & COO. Spent 20+ years at Citigroup as Managing Director of IT Risk & Control and Vendor Management for the Institutional Clients Group. Founded BRCG, a boutique fintech compliance consultancy, before Laika/Thoropass. NYU Stern.

Austin Ogilvie, Co-Founder & Executive Chairman. Background in data science and ML, previously at Alteryx.

Dicken Chaplin, CFO. Joined December 2022. Previously CFO at Turbonomic, where he grew revenue from $20M to $200M+, leading to a $2B acquisition by IBM.

Leith Khanafseh, Managing Partner, Assurance & Compliance Products. Previously led infosec audits at Coalfire for major cloud service providers, plus Big 4 experience.

Chris Biero, Senior Director, Head of SOC. 10+ years in GRC across startups and Fortune 500 firms.

Pricing

Thoropass does not publish a rate card. Aggregated third-party data:

  • Vendr median annual contract value: ~$30,728 (range $20,930 to $52,675)
  • Small companies (under 50 employees, single framework): $20K to $40K/year subscription
  • Mid-sized (50 to 200 employees): $40K to $90K/year
  • Stated savings vs. traditional audit firms: 25-50%
  • Marketing claim: “Zero cost overruns with fixed pricing”

Pricing model is annual subscription, custom-quoted, tiered by frameworks pursued, company size/complexity, and support level. The platform-plus-audit bundle is the most common engagement, but the audit module is also sold standalone for companies already on a different GRC tool.

Timeline

Thoropass markets “SOC 2 in weeks, not quarters” with 62% faster time to audit completion vs. traditional process. Customer-reported timelines back this up:

  • Benefix: SOC 2 Type I and Type II within 8 days post-kickoff
  • Cinchy: ISO 27001 in 4 weeks, SOC 2 in 2 weeks
  • Capitalize: up and running in 2 weeks, audit “in a fraction of the time”
  • Stylo: SOC 2 Type 1 from scratch in roughly 2 to 3 months

The firm reports 80%+ of technical control evidence is auto-collected via integrations, and the First Pass AI layer reduces audit overhead by ~80%.

Client Base & Testimonials

Named customers from public case studies:

  • Capitalize (FinTech, retirement account rollovers)
  • Benefix (health insurance / benefits platform)
  • Cinchy (data integration / data fabric)
  • Stylo (AI customer support)
  • Wayleadr (workplace management)
  • AcuityMD (medical device sales platform)
  • Fundraise Up (nonprofit fundraising)
  • dealcloser (legal tech)
  • Kado (crypto on/off-ramp)

G2 rating: 4.7/5 across 435+ reviews, with 74.7% in the Small-Business segment.

Critical feedback from G2 reviews surfaces a recurring set of complaints: UI can be clunky, limited bulk-edit options, occasional integration breakage, and slower performance at scale. Buyers weighing Thoropass should pressure-test the workflow against their specific cloud stack before committing.

Who Should Choose Thoropass

Best fit:

  • First-time SOC 2 / ISO 27001 / HIPAA / PCI seekers (under 200 employees) who want one vendor handling both the GRC platform and the audit
  • Companies pursuing multiple frameworks who want shared evidence across SOC 2 + ISO 27001 + HITRUST + PCI in a single audit cycle
  • Mid-market SaaS, fintech, and healthtech seeking 25-50% savings vs. traditional audit firms with fixed pricing
  • Teams with limited compliance resources that benefit from the auditor-built scoping roadmap and policy templates
  • Companies wanting HITRUST + SOC 2 together (Thoropass’s HITRUST accreditation is a real moat at this price point)

Not ideal for:

  • Public companies or IPO candidates that need Big-4 brand on the audit report
  • Companies pursuing FedRAMP, StateRAMP, or CMMC Level 2 (Thoropass does not have these capabilities)
  • Enterprises with deep GRC customization needs at scale (platform feature set is narrower than Vanta or Drata)
  • Buyers who want fully transparent published pricing before scoping

Recent Milestones

  • Dec 2025: Thoropass Assurance earns AICPA Peer Review “Pass” rating for the second time
  • Sept 2025: Trust Center launches as a public-facing compliance posture product
  • Sept 2025: Named to Inc. 5000 for second consecutive year (351% three-year growth, ranked #1,246)
  • Jan 2025: First Pass AI launches (AI-driven evidence pre-screening); audit module made available standalone for non-Thoropass GRC users
  • Sept 2024: Expanded HITRUST partnership as MyCSF Authorized Reseller; launched ISO 42001, NIST CSF 2.0, 23 NYCRR 500 support
  • 2024: Established London office for EMEA expansion
  • March 2023: Rebranded from Laika to Thoropass
  • Nov 2022: Series C of $50M led by Fin Capital

Bottom Line

Thoropass occupies a category of one in the SOC 2 market: the only company that ships a GRC platform AND signs the audit report. For first-time buyers pursuing multiple frameworks who value speed and fixed pricing over brand prestige, the bundle is compelling and the AICPA Peer Review track record answers the obvious independence question.

Where it gets tighter: if you already love your current GRC tool, the standalone audit module is a viable path, but you lose the workflow advantages that justify the bundle. If your buyers demand a Big-4 brand on the audit report, Thoropass is the wrong choice. And if you’re heading toward FedRAMP or CMMC Level 2 in the next 12-18 months, you’ll need a different partner anyway.

For early-to-mid-stage SaaS, fintech, and healthtech with one vendor needed, fast turnaround required, and predictable fixed pricing preferred, Thoropass is one of the most differentiated options in the specialist auditor market.

Office Locations

New York, NY (HQ)
London, UK (EMEA hub)

Compliance Frameworks Offered

SOC 1 (SSAE 18) SOC 2 Type I & Type II SOC 3 HITRUST CSF (i1, r2 Validated Assessment & Certification) PCI DSS (Report on Compliance, AoC, SAQ) ISO 27001 ISO 27018 ISO 42001 (AI Management Systems) HIPAA / HITECH GDPR, CCPA NIST CSF 2.0, NIST 800-53 CMMC Level 1, 23 NYCRR 500

Platform Integrations

Thoropass Audit Lifecycle Platform (proprietary) AWS, Azure, Google Cloud, Snowflake, Digital Ocean, Heroku GitHub, GitLab, Jira, BitBucket Slack, Microsoft 365, Google Workspace, Okta 100+ auditor-approved integrations total

Client Testimonials

"Some of the best money I ever spent. Thoropass and being compliant ended up helping us close our second-largest customer."

Veronica Lim
CFO
Benefix

"Thoropass combines readiness, evidence management, and auditor interaction in a single platform. The ability to collaborate with the auditor directly in-platform reduces friction and prevents duplicative work."

Roark
Head of GRC

"For the past month, we've told our customers we're in the process of getting our SOC 2 and ISO 27001. Having the reports in our hands alleviates any concern from our customers."

Saskia
Cinchy

"With no prior knowledge, Thoropass laid out an easy-to-understand road map. Setting attainable goals with reasonable timetable made the process extremely easy with multiple team members."

Adam S.
VP of Operations

What Industries Does Thoropass Serve?

5 industries — Specialist average: 5

B2B SaaS FinTech HealthTech Insurtech Professional Services

What Certifications Does Thoropass Hold?

8 certifications — Specialist average: 4

AICPA CPA Firm (Laika Compliance LLC dba Thoropass Assurance) AICPA Peer Review Pass (Dec 2025) PCI DSS QSAC HITRUST Authorized External Assessor HITRUST MyCSF Authorized Reseller ISO 42001 (self-certified) HITRUST i1 (self-certified)

What Platforms Does Thoropass Integrate With?

Thoropass (proprietary)

Audit Platform

Thoropass Audit Lifecycle Platform (First Pass AI, Trust Center, Access Review Automation, 100+ integrations)

Thoropass SOC 2 Audit FAQ

Thoropass SOC 2 Type I audits typically range from $15K to $50K. Type II audits range from $25K to $70K. This is above average for specialist firms — the specialist tier average is $18.491K–$52.655K. Final pricing depends on your organization's scope, number of trust service criteria, and system complexity.

Questions to Ask Thoropass Before Hiring

A buyer-side checklist. Bring these to your first call — the answers separate firms that have run hundreds of SOC 2 engagements from firms that are bidding on them.

  1. Your team is sized at 200-250. How many auditors will be assigned to my engagement, and who is the engagement lead — a partner, a senior manager, or a staff auditor?
  2. You quote 4–10 months. What pushes a project to the longer end of that range, and what does "audit-ready on day one" look like to you?
  3. Your Type II range is $25K–$70K. What's included at each end, and what scope changes would push pricing above the top of that range?
  4. You integrate with Thoropass (proprietary). If our team uses a different GRC tool, what's the evidence-handoff process and does it change your fee?
  5. Who reviews and signs the report on your side — is that a partner-level CPA, and how involved are they during fieldwork versus only at sign-off?
  6. How do you handle subservice carve-outs (e.g., AWS, GCP, Azure) versus inclusive subservice organizations when defining our scope?
  7. When you find an issue mid-audit, what's your remediation cadence — same-day flagging, weekly checkpoints, or an end-of-fieldwork rollup?
  8. Do you have surge windows (e.g., Q4 financial-year close) when start dates slip, and how far in advance do we need to lock the engagement to avoid them?

Get a quote from Thoropass

Tell us your scope. Thoropass replies with a price, a timeline, and why they'd be a fit. Anonymous until you pick.

Want to compare first? See 55 similar specialist firms · or have us get 3 quotes instead

We email you the quotes. Auditors don't see your details until you pick.

Add more detail industry, frameworks, budget

No sales calls until you pick a firm.

Read by a human. Three quotes in 48 hours.