Thoropass SOC 2 compliance software
Thoropass does not publish a complete rate card; the concrete public numbers are AWS Marketplace's starting prices of $8,700/year for the platform subscription and $5,800/year for the SOC 2 audit subscription (about $14,500/year combined at the floor), while buyer-side deal data (Vendr, SmartSuite) reports typical real-world contracts running $20,000-$45,000/year once company size and scope are added.
The company operated as Laika from its 2019 founding until it rebranded to Thoropass on March 29, 2023 (announced via PR Newswire and the company's own newsroom); the underlying CPA entity is still legally named Laika Compliance, LLC, doing business as Thoropass Assurance.
By Peter Korpak, Lead Editor · independently researched · Methodology
- Pricing
- Quote-based (reported from $15K/yr)
- Source-checked frameworks
- 10
- Integrations
- 200+
- G2 (2026-07-24)
- 4.7 · 600 reviews
AWS presents the platform and audit as separate subscription dimensions that bill independently, even though they run through one provider workflow. The tradeoff worth weighing is the scope of the relationship rather than audit quality, which the AICPA peer review is the mechanism for: one provider covering both software and attestation removes a vendor handoff, while the buyer still needs the proposal to separate platform, examination, implementation, renewal, and additional-framework fees. A buyer who wants the audit without that consolidation can take the audit-first path and keep the GRC platform already in place.
Thoropass (as Laika) has raised $98M total across four rounds, most recently a $50M Series C led by Fin Capital with Centana Growth and existing investors J.P. Morgan Growth Equity Partners, Canapi, and ThirdPrime, which closed and was announced November 8, 2022 per PR Newswire and TechCrunch.
What Thoropass does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | "Integrations and monitors vetted by auditors, that automatically satisfies evidence requests while powering transparent continuous compliance monitors." Source |
| Auditor workspace | Yes | The audit runs inside the same platform end to end ("from evidence to report, your entire audit is finally connected"); this is Thoropass's core differentiator versus software-only platforms. Source |
| Trust center | Yes | "Trust Center" is listed as a standing product module in the site's main navigation. Source |
| Security questionnaire answering | Yes | "Security Questionnaires" is listed as a standing product module in the site's main navigation. Source |
| Enterprise admin (SSO, SCIM, RBAC) | Yes | Thoropass documents SSO, SCIM provisioning, and roles/permissions. Multi-entity support is not confirmed either way; SCIM IdP limitations are recorded in the separate capability row. Source |
| SCIM 2.0 provisioning | Yes | Thoropass documents SCIM 2.0 provisioning through Entra and Okta, with SSO as a prerequisite. Google Workspace is unsupported. For Okta, the current article warns that SCIM-installed apps work but catalog-installed apps do not while Thoropass and Okta resolve the issue. No public tier is named. Source |
| Continuous control testing | Yes | Vendor markets "proactive monitoring capabilities" that flag issues ahead of audit windows, framed as continuous rather than point-in-time. Source |
| Native multi-framework support | Yes | Each framework (SOC 1, SOC 2, ISO 27001, HITRUST, etc.) has its own dedicated framework page and audit type; the vendor separately advertises "up to 90% crossover between frameworks" as a control-reuse efficiency feature layered on top of, not instead of, natively built controls. Source |
10 frameworks checked individually, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Core named product line; audit is performed by the affiliated CPA entity, Thoropass Assurance. Source |
| SOC 1 | Vendor-claimed | Source |
| ISO 27001 | Vendor-claimed | Source |
| HIPAA | Vendor-claimed | Source |
| HITRUST | Vendor-claimed | Thoropass is a HITRUST-authorized external assessor per its own independence page. Source |
| PCI DSS | Vendor-claimed | Source |
| GDPR | Vendor-claimed | Source |
| NIST CSF | Vendor-claimed | Source |
| CMMC | Vendor-claimed | Source |
| Cyber Essentials | Vendor-claimed | Source |
Thoropass uses quote-based pricing.
Getting a direct number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.
- Disclosure model
- Quote-based (reported from $15K/yr)
- Sourced annual price (reported)
- USD 14,500 / year
- Basis
- Estimate, 2026-08-24
Software pricing alone does not establish the audit fee. A licensed CPA firm issues the SOC 2 report. A commercial offer may package coordination or the fee, so get the legal provider, deliverable, and amount in writing. See the SOC 2 audit cost guide for scope and budget context.
Read the Thoropass pricing guide for the current source table and quote checklist.
Who actually issues the report.
The SOC 2 report is issued by Thoropass Assurance, the trade name of Laika Compliance, LLC, a licensed CPA firm registered with the AICPA; Thoropass, Inc. (the software company) is a separate legal entity under the same corporate umbrella, per the company's own /company/legal page. That two-entity structure is what AICPA rules require of any firm selling both technology and attestation services, and it is externally checked rather than self-declared: we read the AICPA's public peer review file directly, and it records Laika Compliance, LLC with a report rating of pass, accepted 12 December 2025, covering the period to 31 January 2025. Thoropass's own /independence-and-excellence page describes the people and process separation (Customer Success on one side, auditors on the other) that sits behind it. Two purchase paths exist and most comparisons in this category describe only the first. Bundled, the platform and the audit come from the same provider relationship and run in one connected workflow; AWS Marketplace lists the platform and audit as separate subscription dimensions that bill independently, so buyers should confirm the Order Forms and renewal terms rather than assume a single contract. Audit-first, you keep the GRC platform you already run and engage Thoropass Assurance as the independent auditor: Thoropass states its Audit Lifecycle Platform works with any GRC platform and system of record, and its Smart Sort AI feature, announced 29 January 2026, turns an export from any GRC tool into audit-ready evidence with no integration to build. Both of those are the vendor's own claims and we have not tested them. The constraint runs the other way: Thoropass's materials describe the audit being performed by Thoropass Assurance and do not document bringing an outside CPA firm into the workspace, so a buyer who wants to keep the software and rotate audit firms should ask about that directly. We do not carry that limit as an established fact, because the pages stating it outright are published by vendors selling competing platforms.
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Thoropass is for, and who it is not.
Good fit
A company pursuing multiple related certifications (e.g. SOC 2 plus ISO 27001 or HITRUST) that wants one connected provider relationship instead of coordinating separate software and audit vendors. It also fits the opposite buyer: a team running Vanta, Drata or ServiceNow that wants an AI-assisted audit firm and does not want to move its GRC stack to get one.
Poor fit
A company whose procurement policy requires the audit firm to carry no common ownership with the software vendor, which is a stricter bar than the AICPA sets and a buyer-side policy choice rather than a finding against the firm. Also a poor fit for a team that wants to run the Thoropass platform while rotating audit firms year to year, since on the bundled path the audit side is Thoropass Assurance.
Typical buyer: A growth-stage or regulated company that wants the audit itself, not only readiness, run by the same team that runs the platform, or one that already has a GRC platform it likes and wants a faster audit rather than a second piece of software..
Compare Thoropass with three alternatives.
- Comp AI Sponsored
Engineering-led teams want inspectable evidence automation across the scope.
-
The audit workflow should sit beside a broad connected evidence layer.
-
Guided support and auditor-facing remediation are equally important.
Where every figure on this page came from.
11 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.
- Confirms the Laika-to-Thoropass rebrand announcement dated March 29, 2023. https://www.prnewswire.com/news-releases/laika-announces-rebrand-to-thoropass-301784518.html
- Confirms $50M Series C led by Fin Capital, closed November 8, 2022, bringing total funding to $98M. https://www.prnewswire.com/news-releases/laika-raises-50m-series-c-to-extend-market-leadership-in-end-to-end-continuous-compliance-and-audit-management-301671736.html
- Independent press confirmation of the $50M Series C and its date. https://techcrunch.com/2022/11/08/laika-laps-up-50m-for-its-automated-security-compliance-platform
- States that Laika Compliance, LLC dba Thoropass Assurance is the licensed AICPA-registered CPA firm, and Thoropass, Inc. dba Thoropass is the separate technology/professional-services entity. https://www.thoropass.com/company/legal
- Describes the audit arm as "our affiliated audit entity," explains the AICPA independence framework applied, and cites a 2025 AICPA peer review with the highest ("pass") rating. https://www.thoropass.com/independence-and-excellence
- Public File Search, firm name "Laika", returns Laika Compliance LLC (firm number 900255351244, Annandale VA): period covered 02/01/2024 to 01/31/2025, peer review acceptance date 12/12/2025, report rating Pass. Read from the AICPA's own public file rather than from the vendor's summary of it, which is why the peer review is graded independently confirmed rather than vendor-claimed. https://peerreview.aicpa.org/
- Published starting prices: $8,700/year platform subscription and $5,800/year SOC 2 audit subscription. AWS presents them as separate subscription dimensions that bill independently and work together. https://aws.amazon.com/marketplace/pp/prodview-3fqzxq4nazmgu
- Announcement dated 29 January 2026 stating the Audit Lifecycle Platform "works seamlessly with any GRC platform and systems of record" and that Smart Sort AI lets customers "upload exported files from any vendor's GRC system with no integration required" and turn them into audit-ready evidence. Establishes the audit-first purchase path, where the customer keeps its existing GRC platform, as a vendor-stated capability. File upload rather than live sync, and untested by us. https://www.thoropass.com/company/newsroom/thoropass-launches-smart-sort-ai-to-turn-any-grc-export-into-audit-ready-evidence
- Source of the audit-cycle figure: First Pass "helped to reduce audit timelines from 73 days, already an industry benchmark, to just 29 days, a 60% reduction." Vendor-measured, still published as of this retrieval. https://www.thoropass.com/blog/first-pass-ai
- 4.7/5 rating across roughly 600 reviews (read via search index; direct crawl blocked by G2's DataDome bot protection). https://www.g2.com/products/thoropass/reviews
- Current SSO/SCIM setup for Entra and Okta, including Google Workspace exclusion and the temporary Okta catalog-app limitation. https://help.thoropass.com/en/articles/9842849-sso-scim-provisioning-configuration-in-thoropass
← All SOC 2 compliance software · Thoropass review · How we verify
Something here out of date?
Every figure above carries a source and the date we read it. If one has moved, send us the current source and we will update the record.
Verification is free and always will be. It does not change where Thoropass appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.