Logo Menu

Thoropass SOC 2 compliance software

SOC 2 compliance automation platform with an affiliated in-house audit practice, sold bundled or audit-first Last updated

Thoropass does not publish a complete rate card; the concrete public numbers are AWS Marketplace's starting prices of $8,700/year for the platform subscription and $5,800/year for the SOC 2 audit subscription (about $14,500/year combined at the floor), while buyer-side deal data (Vendr, SmartSuite) reports typical real-world contracts running $20,000-$45,000/year once company size and scope are added.

The company operated as Laika from its 2019 founding until it rebranded to Thoropass on March 29, 2023 (announced via PR Newswire and the company's own newsroom); the underlying CPA entity is still legally named Laika Compliance, LLC, doing business as Thoropass Assurance.

By , Lead Editor · independently researched · Methodology

Pricing
Quote-based (reported from $15K/yr)
Source-checked frameworks
10
Integrations
200+
G2 (2026-07-24)
4.7 · 600 reviews
What the evidence says

AWS presents the platform and audit as separate subscription dimensions that bill independently, even though they run through one provider workflow. The tradeoff worth weighing is the scope of the relationship rather than audit quality, which the AICPA peer review is the mechanism for: one provider covering both software and attestation removes a vendor handoff, while the buyer still needs the proposal to separate platform, examination, implementation, renewal, and additional-framework fees. A buyer who wants the audit without that consolidation can take the audit-first path and keep the GRC platform already in place.

Company context

Thoropass (as Laika) has raised $98M total across four rounds, most recently a $50M Series C led by Fin Capital with Centana Growth and existing investors J.P. Morgan Growth Equity Partners, Canapi, and ThirdPrime, which closed and was announced November 8, 2022 per PR Newswire and TechCrunch.

Capabilities

What Thoropass does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes "Integrations and monitors vetted by auditors, that automatically satisfies evidence requests while powering transparent continuous compliance monitors." Source
Auditor workspace Yes The audit runs inside the same platform end to end ("from evidence to report, your entire audit is finally connected"); this is Thoropass's core differentiator versus software-only platforms. Source
Trust center Yes "Trust Center" is listed as a standing product module in the site's main navigation. Source
Security questionnaire answering Yes "Security Questionnaires" is listed as a standing product module in the site's main navigation. Source
Enterprise admin (SSO, SCIM, RBAC) Yes Thoropass documents SSO, SCIM provisioning, and roles/permissions. Multi-entity support is not confirmed either way; SCIM IdP limitations are recorded in the separate capability row. Source
SCIM 2.0 provisioning Yes Thoropass documents SCIM 2.0 provisioning through Entra and Okta, with SSO as a prerequisite. Google Workspace is unsupported. For Okta, the current article warns that SCIM-installed apps work but catalog-installed apps do not while Thoropass and Okta resolve the issue. No public tier is named. Source
Continuous control testing Yes Vendor markets "proactive monitoring capabilities" that flag issues ahead of audit windows, framed as continuous rather than point-in-time. Source
Native multi-framework support Yes Each framework (SOC 1, SOC 2, ISO 27001, HITRUST, etc.) has its own dedicated framework page and audit type; the vendor separately advertises "up to 90% crossover between frameworks" as a control-reuse efficiency feature layered on top of, not instead of, natively built controls. Source
Source-checked frameworks

10 frameworks checked individually, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed Core named product line; audit is performed by the affiliated CPA entity, Thoropass Assurance. Source
SOC 1 Vendor-claimed Source
ISO 27001 Vendor-claimed Source
HIPAA Vendor-claimed Source
HITRUST Vendor-claimed Thoropass is a HITRUST-authorized external assessor per its own independence page. Source
PCI DSS Vendor-claimed Source
GDPR Vendor-claimed Source
NIST CSF Vendor-claimed Source
CMMC Vendor-claimed Source
Cyber Essentials Vendor-claimed Source
Pricing

Thoropass uses quote-based pricing.

Getting a direct number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.

Disclosure model
Quote-based (reported from $15K/yr)
Sourced annual price (reported)
USD 14,500 / year
Basis
Estimate, 2026-08-24

Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.

Read the Thoropass pricing guide for the current source table and quote checklist.

Auditor handoff

Who actually issues the report.

The SOC 2 report is issued by Thoropass Assurance, the trade name of Laika Compliance, LLC, a licensed CPA firm registered with the AICPA; Thoropass, Inc. (the software company) is a separate legal entity under the same corporate umbrella, per the company's own /company/legal page. That two-entity structure is what AICPA rules require of any firm selling both technology and attestation services, and it is externally checked rather than self-declared: we read the AICPA's public peer review file directly, and it records Laika Compliance, LLC with a report rating of pass, accepted 12 December 2025, covering the period to 31 January 2025. Thoropass's own /independence-and-excellence page describes the people and process separation (Customer Success on one side, auditors on the other) that sits behind it. Two purchase paths exist and most comparisons in this category describe only the first. Bundled, the platform and the audit come from the same provider relationship and run in one connected workflow; AWS Marketplace lists the platform and audit as separate subscription dimensions that bill independently, so buyers should confirm the Order Forms and renewal terms rather than assume a single contract. Audit-first, you keep the GRC platform you already run and engage Thoropass Assurance as the independent auditor: Thoropass states its Audit Lifecycle Platform works with any GRC platform and system of record, and its Smart Sort AI feature, announced 29 January 2026, turns an export from any GRC tool into audit-ready evidence with no integration to build. Both of those are the vendor's own claims and we have not tested them. The constraint runs the other way: Thoropass's materials describe the audit being performed by Thoropass Assurance and do not document bringing an outside CPA firm into the workspace, so a buyer who wants to keep the software and rotate audit firms should ask about that directly. We do not carry that limit as an established fact, because the pages stating it outright are published by vendors selling competing platforms.

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who Thoropass is for, and who it is not.

Good fit

A company pursuing multiple related certifications (e.g. SOC 2 plus ISO 27001 or HITRUST) that wants one connected provider relationship instead of coordinating separate software and audit vendors. It also fits the opposite buyer: a team running Vanta, Drata or ServiceNow that wants an AI-assisted audit firm and does not want to move its GRC stack to get one.

Poor fit

A company whose procurement policy requires the audit firm to carry no common ownership with the software vendor, which is a stricter bar than the AICPA sets and a buyer-side policy choice rather than a finding against the firm. Also a poor fit for a team that wants to run the Thoropass platform while rotating audit firms year to year, since on the bundled path the audit side is Thoropass Assurance.

Typical buyer: A growth-stage or regulated company that wants the audit itself, not only readiness, run by the same team that runs the platform, or one that already has a GRC platform it likes and wants a faster audit rather than a second piece of software..

Related profiles

Compare Thoropass with three alternatives.

  • Comp AI

    Engineering-led teams want inspectable evidence automation across the scope.

  • The audit workflow should sit beside a broad connected evidence layer.

  • Guided support and auditor-facing remediation are equally important.

Source ledger

Where every figure on this page came from.

11 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.

← All SOC 2 compliance software · Thoropass review · How we verify

For Thoropass

Something here out of date?

Every figure above carries a source and the date we read it. If one has moved, send us the current source and we will update the record.

Verification is free and always will be. It does not change where Thoropass appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.

Correct this record