IT Audit & Assurance Service
Thoropass · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
We support the following frameworks (with more being added every quarter): **SOC 1, SOC 2, PCI Level 1, PCI Level 2, PCI Level 3, PCI Level 4, HITRUST e1, HITRUST i1, HITRUST r2, HIPAA Security and Breach Notification, HIPAA Privacy Rule, GDPR, PIPEDA, CCPA, 23 NYCRR 500, ISO 27001 (2022), ISO 27018, ISO 42001, ISO 27701, ISO 9001 (QMS), NIST CSF 2.0, Cyber Essentials, CMMC Level 1, CMMC Level 2, NIS 2, and CIS v8.**
Custom frameworks coming soon :)
Show the rest of the publisher’s description (8 more lines)
**Trusted, World-Class Auditors:**
The tradeoff between rigor and efficiency is over. Thoropass’s in-house auditors bring deep expertise, extensive experience, and a modern approach to IT audits. Our rigorous standards ensure every report is accurate, reliable, and respected in the marketplace, giving you confidence in your compliance journey.**
**Auditor-Approved Integrations:**
Most software platforms help you collect evidence, but it often falls short of auditor expectations. Thoropass ensures automated evidence is programmatically verified and auditor-approved, streamlining the entire process to minimize rejections and re-work. From start to finish, audits become effortless and stress-free.
**AI-Enabled Evidence Verification:**
Submitting evidence without confidence risks delays and errors. Thoropass’s First Pass AI eliminates guesswork by instantly flagging missing, outdated, or incorrect evidence in one click. This ensures audit readiness, reduces hours of manual QA, and accelerates timelines by addressing most evidence acceptability issues before they reach the auditor.
**Powerful Audit Management:**
Managing audits with spreadsheets and endless email threads is inefficient and chaotic. Thoropass centralizes the entire audit process, allowing you to assign tasks, track evidence requests, add comments, and communicate directly with auditors—all in one platform. Stay organized, eliminate confusion, and drive your audit to completion seamlessly.
Highlights
Highlighted by the publisher on AWS Marketplace.
End-to-end compliance: seamless integration with Thoropass's GRC Platform
Built for scale: assessments for multiple frameworks with only one audit
Modernized audits: tech-enabled delivery, powered by AI
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Sources
Publisher resources
1 linkLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

