Video Reviews
427 Thoropass Reviews
Overall Review Sentiment for Thoropass
Log in to view review sentiment.

First thing that comes to mind is communication. Thoropass Customer Success Manager is always there for you and constantly checkes up on you if you need any help.
Software itself is easy to use and implement across your company, as well as provides a lot of templates for anything new you want to adopt. Constant updates and quality of life changes.
The range of services Thoropass provides is also company's strong suit, providing full support for those, who want to be compliant. Together we have successfully went through several cruical compliance audits.
Overall Fundraise Up is happy that Thoropass continues to strive for excellense and we are looking forward to having Thoropass as our long term partner. Review collected by and hosted on G2.com.
There are some minor tweaks that could be implemented and it is taking some time to add those for us to use, but nothing critical, as those tweaks are more quality of life featues, rather than missing pieces of core functionality Review collected by and hosted on G2.com.
We were not very knowledgeable about cybersecurity, and as a startup, we could not afford to hire an expensive employee just to guide us through the SOC-2 Type 1 journey. Thoropass is incredibly comprehensive. It clearly outlines what needs to be done, provides live feedback along with comments in the app, and reduces the time needed to become compliant. We have improved our operation because of Thoropass. We intend to continue using their services, as their app stores all the information needed for audits, reminds us of due dates and timeframes to be met, and keeps track of everything in their vault. They are a valuable partner to our business.
The customer support team was very knowledgeable -- and what they didn't know - they knew who to go to in the organization to make sure we were compliant. Review collected by and hosted on G2.com.
I can't think of any downsides. No one particularly likes the SOC-2 process development as it takes away from doing our startup work. So it is a necessary evil -- and Thoropass increased our velocity vs. slowing us down. Review collected by and hosted on G2.com.

All company policies and procedures are centralized in a unique single, great customer support, very easy to integrate with other vendors such as AWS and Google Workspace. A lot of tools that support our company to help our customers and also the employees, such as the data room and the training controls.
There is also a set of compliance frameworks available, which can lead our company to an incremental improvement of our compliance portfolio. For example, right now we only have HIPAA, but soon we'll start implementing SOC Type 2 using as a base what we already have in place. Review collected by and hosted on G2.com.
Once Thoropass is fast growing company, a lot of major changes in the platform are performed and some time leads us to be lost over the new interface and location of most used items.
Even if all changes are presented in a step-by-step guide, sometimes can be a little "boring" experience. Review collected by and hosted on G2.com.
I think the support has been great during our rollout of Thoropass. Vareity of little questions that were easily answered. I really do like the interface as well and some of the features that I think added more value than other vendors, like the risk management/register section. I already had this manually created on my end BUT it looks so much better in Thoropass and makes it easier to go through and share with the team on a regular basis. Overall though, really happy I chose Thoropass over similar vendors.. Review collected by and hosted on G2.com.
I have had some integration issues along the way, where the integrations need to be redone due to changes made to the integration itself. I don't have admin access to all the integrated sources so I have to reach out to all those admins and reset the integration backup. Very easy setup though, just a hassle to reach out to other admins to reintegrate. Review collected by and hosted on G2.com.

Thoropass has helped our small business to understand how to become SOC2 compliant with ease. We are currently working through the process and have had consistent communication with Alex Scudellari. He has been able to answer all of our questions and has been helpful in understanding each of the processes we have to go through. Review collected by and hosted on G2.com.
The only thing I have disliked about Thoropass is the amount of work needed to become compliant. It is a long process that will take time. This is something that happens with most companies, but Thoropass has seemed to be helpful in moving us along as quickly as possible. Review collected by and hosted on G2.com.

I love how the platform brings everything about ISO27001 compliance together in a single place and makes it significantly less daunting to go through. Having access to a dedicated account manager is also incredibly useful, as they act as the single point of reference throughout the process and also getting answers from the knowledgeable team on more technical questions. Shoutout to Alex - thanks for all your help so far! Review collected by and hosted on G2.com.
The platform is US centric, which probably reflects the user base. There were some parts of the process that we needed to re-work or re-apply to UK legislation. Review collected by and hosted on G2.com.

I honestly love working with Thoropass. Dealing with certifications has always been a major headache in my book - endless policy writing and control setups that drag on for months. Thoropass has significantly streamlined the compliance process for us. Their approach integrates with our operations, providing templates and questionnaires that are straightforward and easy to use. One of the standout features to me is the automated integration with our cloud accounts and SaaS services, which has eliminated much of the manual work required in the past.
Their "Employee Training" module contains security awareness training as well as secure coding training. Both are essentially online PDFs of around 20 and 80 or so pages, respectively. Both have been really high quality. Lots of good, in-depth info without being too high-level but also not too verbose.
I'd also like to point out that everyone at Thoropass I had contact with was a pleasure to work with. Very knowledgeable and super responsive. I used to do certifications in a large org of 110k people, and now I'm in a startup of 6. Our customers were asking for SOC2 and ISO27001 because we're handling some sensitive data. I didn't think that certification at our size could be so streamlined. If you're in a startup and need to obtain a certification, or if you're in the EU and need to comply with NIS2 beginning in October 2024, I can highly recommend doing it with Thoropass. Review collected by and hosted on G2.com.
There aren't many things I don't like about the app, but if I have to choose one it'd be the "Word" editor you're using to edit policy documents. Sometimes it doesn't load or it makes my browser hang. It's like a bad version of Google Docs and behaves like a sluggish Java applet in the early 2000s. That said you don't spend too much time in it and at the end of the day it gets the job done. Review collected by and hosted on G2.com.

Thoropass has been great to work with from their initial outreach through our most recent SOC 2 Type I and II audits. The journey to compliance can be feel imtimidating, but the Thoropass platform did a great job of managing steps and milestones. Even more helpful have been the individuals that helped us through the audits. The technical team was helpful and transparent, and our Customer Success Manager, Darren Zarandi, has done a terrific job supporting our team and guiding us along the way. The built-in integrations have also been a great help to streamline some of the work and evidence gathering. Review collected by and hosted on G2.com.
There have been a few small buggy issues in the platform's UI. Entering notes for evidence was touchy as well as updating documents. As we get through more audits, having an easy reference to our past evidence notes, etc. would be greatly beneficial and this has not been possible. The upside is that our Customer Success Manager has been great at communicating these issues and they have either been addressed or are considered for future product updates. Review collected by and hosted on G2.com.

I come from a DoD background and am used to a compliance management tool (eMASS) like what Thoropass has set-up. However, unlike eMASS, the Thoropass app has a much easier to navigate interface and contains links to templates and examples to show you what the auditors will be looking for in their review. If you get stuck on a particular control, the app makes it easy to leave a comment on the control itself, tag your Thoropass rep, and get a response back quickly. I love that I am teamed-up with a rep from the company that helps make sure we're not getting stuck on any part of the documentation process. Allie has made it so that I have never felt lost even when there have been language in controls that haven't made a lot on sense in our context.
I love the integrations with 3rd party applications that automatically collect evidence for your audit. This couldn't be easier when it's available for the tools you use.
Bugs are not really a thing you see in a positive review, but I feel like it speaks volumes to say that I've run into bugs, probably more than most people because I'm a digger, while using Thoropass. I've been able to email my findings to my customer rep and she almost always responds back the same day having reported it to the development team, giving me their feedback, and providing a timeframe of when it'll be fixed. I can't speak with authority, but I get the impression that their development team is running a tight Agile shop that prioritizes customer tickets in their sprint planning because the bugs I've reported are usually fixed within a couple of weeks at most. Review collected by and hosted on G2.com.
If I have to find something to dislike about Thoropass, I would say that when you have applications that can't be tied-in to the monitors/integrations that they have set-up, it can be time consuming to collect screenshots and confusing to know what to take screenshots of for the auditors. That said, that's not so much a dislike about Thoropass specifically and more a dislike of these audits in general. Review collected by and hosted on G2.com.

Last year, we had the opportunity to partner with Thoropass to ensure our company met HIPAA compliance standards. Their methodical breakdown of frameworks simplified task assignments across team members and provided clear visibility into the status of each control and policy, streamlining our navigation and execution. Weekly meetings with Grayson were particularly beneficial; his attentiveness and proactive communication about upcoming steps greatly enhanced our experience. Initially, the process appeared daunting for someone unfamiliar with the field, yet Thoropass masterfully simplified the complexities into manageable segments. At no point did they make us feel inexperienced or inadequate for lacking certain procedures. Review collected by and hosted on G2.com.
I do recall one cumbersome aspect: the multiple steps required to confirm that all team members had completed their trainings and policy acknowledgements. When I raised this issue with Thoropass, they promptly acknowledged it and assured me that it would be addressed in their next update. Review collected by and hosted on G2.com.