Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Significantly alleviates ambiguity for complex audits
What do you like best about the product?
Great customer experience and onboarding, they were really helpful in removing the ambiguity I had around SOC requirements. They give a lot of guidence on how we can create any new policies needed in a way that will pass the audit which also alleviated the anxiety I had around understanding what we need, how the audit process works, etc.
What do you dislike about the product?
I don't dislike anything but I think there's an opportunity to reduce duplicative work with third-party vendor assessments
What problems is the product solving and how is that benefiting you?
We have several large customers in heavily regulated industries, Thoropass helps us stay compliant so we can continue to service those contracts. As a small team and company, we're able to gain certifications that would take 2-3x the time and money without Thoropass.
- Leave a Comment |
- Mark review as helpful
Fast Type 1 result, if you put the effort in!
What do you like best about the product?
We are a small startup requiring SOC2 to bring in a particular segment of customers. Generally speaking, our pre-SOC2 behaviors were sound, and we weren't expecting to need to clean up too much to have a successful audit. We were matched with Allie as an account manager who was extremely patient and informative as she walked us through the process and the platform. She walked us through the integrations available so we could connect Thoropass to our systems of record. Honestly, it was very easy, even though we kind of slow rolled it a bit because we were working on other things.
Once we were ready, it took us only a month to get our Type 1 certification. We were in disbelief and wondered if we had mistakenly gotten approved, but Allie assured us it was just because we had done things properly the first time! We are now in our Type 2 phase, and Allie has continued to be helpful in letting us know what we have to do to have a successful Type 2 audit. We have to log in to the platform a couple times a quarter to upload evidence and that is it. Assuming that's really all there is to it, we're hoping to have our Type 2 in hand before the end of this year!
Once we were ready, it took us only a month to get our Type 1 certification. We were in disbelief and wondered if we had mistakenly gotten approved, but Allie assured us it was just because we had done things properly the first time! We are now in our Type 2 phase, and Allie has continued to be helpful in letting us know what we have to do to have a successful Type 2 audit. We have to log in to the platform a couple times a quarter to upload evidence and that is it. Assuming that's really all there is to it, we're hoping to have our Type 2 in hand before the end of this year!
What do you dislike about the product?
I am still unsure about how potential customers will scrutinize our SOC2 report. Because I don't have experience going through the end to end audit process before, it will take some time for me to trust that a Thoropass audit is equal in 'standing' to a traditional audit done by an external firm - and only our customers can tell us this.
I think their built in document editor is very clunky. I almost released some official documents with comments and squigglies built in. Rather than do a lot of work to build an editor in your website, may I suggest a Google Docs or Office 365 integration so the documents can be edited using tools we are already familiar with.
I think their built in document editor is very clunky. I almost released some official documents with comments and squigglies built in. Rather than do a lot of work to build an editor in your website, may I suggest a Google Docs or Office 365 integration so the documents can be edited using tools we are already familiar with.
What problems is the product solving and how is that benefiting you?
Thoropass lets us streamline our SOC2 compliance and simplifies the process by not requiring us to retain an external auditor. In fact, they provide services for everything that would normally be serviced by different firms, so if you're starting from zero you probably can have Thoropass provide everything you need.
have had a great experience. Account manager is always helpful.
What do you like best about the product?
step by step guidance and support throughout the process.
What do you dislike about the product?
some of the materials harder to understand. more examples would be great.
What problems is the product solving and how is that benefiting you?
SOC 2 Compliance
On point service delivery
What do you like best about the product?
focuse on the service they were called out
What do you dislike about the product?
honestly nothing i can think of, there were no distractions along their service delivery
What problems is the product solving and how is that benefiting you?
Streamline the process of obtaining Security Compliance
Thoropass is flexible and supportive, helping our healthcare startup complete its SOC2 audit on time
What do you like best about the product?
Ease of use, generated policies, customer support
What do you dislike about the product?
Pricy but accommodating, flexible, login issues but quick resolution.
What problems is the product solving and how is that benefiting you?
Helps tackle SOC 2 compliance, guiding us to audit
A great product and a great team
What do you like best about the product?
The platform itself is intuitive and user-friendly, making the complex process of maintaining SOC 2 and ISO 27001 compliance much more manageable. The comprehensive dashboards provide clear insights and real-time updates, ensuring that we stay on top of our compliance requirements without any hassle. The automation features are a game-changer, significantly reducing the manual effort involved and allowing our team to focus on more strategic tasks.
What do you dislike about the product?
Don't have anything bad to say. It's a great product/team executing compliance practices curated to the needs of our company.
What problems is the product solving and how is that benefiting you?
With Thoropass, we feel assured that our compliance with SOC 2 standards is consistently maintained. This confidence is vital for gaining and retaining the trust of our customers and stakeholders.
The knowledgeable and supportive Thoropass team is always available to assist us. Their expertise and commitment to our success ensure that we are well-prepared to handle any compliance challenges that may arise.
The knowledgeable and supportive Thoropass team is always available to assist us. Their expertise and commitment to our success ensure that we are well-prepared to handle any compliance challenges that may arise.
SOC-2 Type 1 and Type 2 & GDPR Audit
What do you like best about the product?
Fantastic support which is crucial for the audit and especially when you go for it for the first time.
What do you dislike about the product?
Some minor inconveniences in the platform's user interface.
What problems is the product solving and how is that benefiting you?
Thoropass helped us to pass SOC-2 Type 1 and Type 2 + GDPR audits.
As a startup, we were not familiar with all the details of audit processes, where to start, and what we should focus on the most.
The platform has many templates for different security controls and a useful knowledge base.
It is amazing that we could enroll our staff through seamless SSO (Azure Active Directory) integration and integrate our cloud security provider to gather evidence automatically.
As a startup, we were not familiar with all the details of audit processes, where to start, and what we should focus on the most.
The platform has many templates for different security controls and a useful knowledge base.
It is amazing that we could enroll our staff through seamless SSO (Azure Active Directory) integration and integrate our cloud security provider to gather evidence automatically.
It gives me a peace of mind.
What do you like best about the product?
The well thoughtout templates, saving us a lot of time so we can focus on our core business. The experience with our CSM and auditors are great. They are helpful to get us through the process.
What do you dislike about the product?
Learning to navigate the system is not easy. The risk register is starting to have a good structure but needs more integration to be helpful.
What problems is the product solving and how is that benefiting you?
It helps us not having to reinvent the wheel, saving time and money to focus on our business.
Thoropass has been instrumental in getting to SOC2 - the tools and support have been first class.
What do you like best about the product?
Best part is definitely the dedicated support, keeping us on track. It's also very easy to assign and track the various tasks, and the prepackaged tools are a big help.
What do you dislike about the product?
Given how much better Thoropass is to the alternatives, I can't think of anything beyond minutiae I would change
What problems is the product solving and how is that benefiting you?
We need SOC2 to maximize our market opportunity, and while our practices are compliant, Thoropass has made it far simpler to generate the documentation and evidence.
The experience was overall positive.
What do you like best about the product?
The auditors and account managers were very responsive and helpful guiding us through our first SOC 2 TYPE II certification. There was always quick to reply to questions and help us focus on what mattered most durring the process.
What do you dislike about the product?
The website, although better than when we first joined, is still a bit confusing to use. Deep links to really work. There isn't a clear way to know how to get arround the site without having someone walk you through or setting aside time to explore the website in detail. Uploading evidence prooved to be more difficult than necessary as files would end up being corrupted somewhere between uploading and viewing on the platform. Files in the evidence section don't always load for some reason. There was also a lot of ambiguity of what "evidence" meant on a case per case basis. We assumed it meant screenshots, but it would have been nice to see an example of what "evidence" meant for different types of spotchecks.
What problems is the product solving and how is that benefiting you?
Audit management, Vendor security assessments and documetation.
showing 51 - 60