Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Thoropass

Thoropass

Reviews from AWS customer

0 AWS reviews
  • 5 star
    0
  • 4 star
    0
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

563 reviews
from

External reviews are not included in the AWS star rating for the product.


    Isaac C.

Great experience

  • July 31, 2025
  • Review provided by G2

What do you like best about the product?
Thoropass is very fast with updates, responses, and giving feedback on pentest remediation info.
What do you dislike about the product?
Nothing! The entire process was a smooth experience.
What problems is the product solving and how is that benefiting you?
Thoropass detects and analyzes various security risks that our applications may face, allowing us to develop more secure services to protect our workflow and sensitive information.


    Mark E.

A strong focus on compliance automation and audit management

  • July 31, 2025
  • Review provided by G2

What do you like best about the product?
Structured Compliance Frameworks – Thoropass provides pre-mapped controls for SOC 2, ISO 27001, and other frameworks, significantly reducing time spent on manual control mapping and cross-referencing.
Integrated Evidence Collection – The automated integrations with tools like AWS, Google Workspace, and HRIS systems streamline evidence gathering, helping maintain audit readiness year-round.
Guided Audit Experience – The platform not only organizes compliance work but also connects directly with experienced auditors, ensuring a seamless transition from preparation to certification.
Clear Task Management & Tracking – Its dashboard and workflow tools allow for easy assignment, monitoring, and closure of tasks, which keeps teams accountable and eliminates confusion.
Responsive Support Team – Thoropass provides prompt, informed support and advisory guidance, which is invaluable when navigating complex compliance requirements.
What do you dislike about the product?
Limited Customization for Unique Controls – While the platform covers major frameworks well, adding company-specific controls or tailoring workflows sometimes requires workarounds or external documentation.
Occasional Integration Gaps – Some integrations (e.g., niche HRIS or ticketing systems) are not fully supported, which means certain evidence must still be uploaded manually.
Reporting Limitations – Standard reports are functional but could benefit from more flexibility and export options for board-level or regulator presentations.
Learning Curve for First-Time Users – Although intuitive once familiar, the platform’s terminology and structure can initially feel overwhelming to teams new to compliance automation.
Audit Coordination Bottlenecks – Scheduling and coordination with auditors through the platform is efficient most of the time, but peak periods can result in slower response times.
What problems is the product solving and how is that benefiting you?
Manual Compliance Burden – Thoropass automates evidence collection from systems like AWS, Google Workspace, and HR tools, removing the need for repetitive manual screenshots, exports, and spreadsheets.
Benefit: Saves significant time for the compliance team and ensures evidence is always up to date.

Audit Readiness Stress – Preparing for SOC 2 or ISO 27001 audits can be chaotic; Thoropass provides a structured framework, pre‑mapped controls, and direct auditor connections.
Benefit: Audits become predictable and less disruptive to day‑to‑day operations.

Task Ownership Confusion – In many organizations, compliance tasks fall through the cracks. Thoropass assigns, tracks, and monitors each task.
Benefit: Everyone knows their responsibilities, deadlines are met, and accountability is maintained.

Continuous Monitoring Gaps – Many companies only focus on compliance at audit time. Thoropass maintains integrations and automated checks year‑round.
Benefit: The organization remains compliant continuously rather than scrambling once a year.


    Hospital & Health Care

Penetration testing using Thoropass

  • July 31, 2025
  • Review provided by G2

What do you like best about the product?
- The process was very easy.
- Very clear instructions about what was required
- Wonderful people who were very helpful in answering questions and proactive in helping out
- Pentest report was thorough and included what I should do to remediate the findings
- Retesting after fixing the findings was easy to request and get done.
What do you dislike about the product?
Nothing to add here. May be the cost could have been a little lower.
What problems is the product solving and how is that benefiting you?
Thoropass is helping me get certification including SOC2 Type 2 and HiTrust. This is critical for me since we are in Healthcare industry and these compliance controls are a must-have.


    Hospital & Health Care

Great value, great team

  • July 17, 2025
  • Review provided by G2

What do you like best about the product?
I really enjoyed working with Thoropass specifcally on our penetration test, SOC 1 Type 1 and HITRUST audits. They are super responsive when there are problems and helped us get across the finish line ahead of schedule. The penetration testers were very competent and gave great detailed reports of their findings and remediations.
What do you dislike about the product?
Occasionally there are issue with certain evidence requests having very vague requirements, which required some recycle. I know there isn't always a 'one size fits all' answer to every problem, but it would be great to incorporate some of the results of our conversations into the requirements generated for each certification path.
What problems is the product solving and how is that benefiting you?
Thoropass offers a lot of compliance roadmap items for getting certifications such as HITRUST and SOC2. We also leveraged them for penetration testing. We use their new "trust center" feature, which greatly aids in our due diligence process and cuts down on a lot of the time spent filling out vendor questionnaires.


    Melissa M. P.

Great Product, Great Partnership

  • July 08, 2025
  • Review provided by G2

What do you like best about the product?
The benefit of using Thoropass is it's integration to systems for auditing capabilities, it makes it much easier to provide evidence and to ensure needed corrections are addressed immediately. Our account manager, Nat, is super to work with, addresses all of our questions, provides guidance and is quick to respond. We have also used Thoropass for Pen testing which was pretty seamless and offered the same level of professionalism as we have come to know with Thoropass.
What do you dislike about the product?
There are some areas of the program that need enhancement or modifications, such as the risk register, and it would be ideal if some of the objects included sorting and filtering or the ability to customize and add our own fields
What problems is the product solving and how is that benefiting you?
x


    Jarom L.

Thoropass - Great experiece

  • July 07, 2025
  • Review provided by G2

What do you like best about the product?
I like that Thoropass has everything you need for audits included in their platform. It was very easy to use and is user friendly.
What do you dislike about the product?
Nothing. It was a great experience. I have nothing negative to say about them.
What problems is the product solving and how is that benefiting you?
SOC 2 compliance


    Jim B.

Best company for pentests and compliance!

  • July 01, 2025
  • Review provided by G2

What do you like best about the product?
Very efficient and powerful platform to track compliance tasks. Pentest process is also very efficient with good pricing.
What do you dislike about the product?
Nothing, I honestly have no complaints!!
What problems is the product solving and how is that benefiting you?
GDPR and SOC2 compliance


    Joan R.

PenTest Review

  • June 26, 2025
  • Review provided by G2

What do you like best about the product?
The comprehensive report is a must for us on addressing each of the findings
What do you dislike about the product?
Nothing outstanding to point out. I'm confortable with the customer service
What problems is the product solving and how is that benefiting you?
It highlights ours opportunities and suggest a path of how to resolve them


    Isaac P.

Thoropass Team is very professional

  • June 25, 2025
  • Review provided by G2

What do you like best about the product?
The Thoropass team is incredibly professional and organized. Nat Larson, our customer success manager, has been an outstanding guide throughout the entire process , always helping us focus on the next priority to stay on track with our SOC 2 controls and audit milestones 😎.

The platform itself is truly all-in-one , from policy templates to evidence collection and auditor collaboration, making it an ideal choice for companies pursuing both SOC 2 Type I and Type II compliance.

We also ran Penetration Testing through Thoropass and had a similarly great experience. Their team was efficient, communicative, and made the process smooth from start to finish.
What do you dislike about the product?
Nothing about Thoropass itself, it’s more that SOC 2 can be a bit overwhelming, especially if it’s your first time going through it. As someone more focused on execution than documentation, it was initially intimidating. But with Thoropass’ support, everything became manageable and far less stressful.
What problems is the product solving and how is that benefiting you?
Thoropass is helping us achieve and maintain SOC 2 compliance with confidence. Before using it, we didn’t have a clear structure for documentation, evidence collection, or audit readiness. Thoropass provided us with a clear roadmap, centralized platform, and expert guidance that made the entire process much smoother.

Thanks to their support, we’ve been able to stay organized, reduce time spent chasing documentation, and focus more on improving our security posture rather than just checking boxes.


    Simeon F.

Contantly improving tool with first class support

  • June 18, 2025
  • Review provided by G2

What do you like best about the product?
This is a big app that wraps around a large process. You need policies, training, monitoring of your infrastructure - and then you need to pass an audit that will include hundreds or thousands of pieces of evidence... And Thoropass can help with all of that!

I love the integrations (Thoropass can tell when my AWS infrastructure falls out of compliance), task reminders and when I'm using a new vendor who needs review) and the automations (I need reminders to stay on top of my compliance tasks).

Three quarters of the year I live in my Dashboard which keeps me up to date on what I need to be doing. And during audit season I live in the audit module which guides me through the audit evidence process.

I should also mention that the support I've gotten from Thoropass customer service reps has been outstanding and very responsive to questions about the product, reporting bugs, or helping me find best practices to improve. My background is not in compliance so the hand-holding with a personal touch has really made a positive difference in my comfort level doing the ongoing work needed to maintain our certification level.
What do you dislike about the product?
Lots of improvements and new features during my three years experience but the training module (assigning/tracking required course completions) still isn't great.
What problems is the product solving and how is that benefiting you?
As an enterprise SAAS vendor, SOC2 compliance is table stakes to even have a conversation. Thoropass helps us adopt the processes and policies needed to pass the SOC2 audit. It helps me stay organized and pay regular attention to all those "important but not urgent" things that otherwise might sometimes fall through the cracks.