Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
A great way to simplify your SOC2 certification process
What do you like best about the product?
As someone who has moved from just being a part of a SOC2 audit to someone responsible for it I really appreciate how easy Thoropass makes the process. Our Customer Success Manager walked us through every step of the process and was always just an email or phone call away if we had any questions. The built-in policy templates, questionnaires and integrations with cloud providers helped get us up and running quickly. The auditors have also been very responsive with the evidence requests, so we're not left wondering if things are progressing.
The UI gives a great overview of where you are in the process. You can easily track how much is done, how many steps are remaining and who is responsible for those tasks. It even has reminders to notify us of deadlines when certain requirements need to be done for Type 2. It's integrations with cloud providers also saves us time on some evidence collection as some items can be gathered automatically in a format that's audit approved.
The UI gives a great overview of where you are in the process. You can easily track how much is done, how many steps are remaining and who is responsible for those tasks. It even has reminders to notify us of deadlines when certain requirements need to be done for Type 2. It's integrations with cloud providers also saves us time on some evidence collection as some items can be gathered automatically in a format that's audit approved.
What do you dislike about the product?
There's not much to dislike, however, there have been instances of the integrated cloud connectors flagging issues on services we're not using. It's not a big deal to turn them off or label them as exclusions but it would be better if we didn't need to do that. There's also been instances where I've had to reconfigure the connectors if they stopped working, but that also only takes a couple minutes.
What problems is the product solving and how is that benefiting you?
Many of our customers are in the finanical industry and require SOC2 or equivilent certifications to do business with them. Thoropass is greatly simplifying the process of getting and keeping our SOC2 certifcations.
- Leave a Comment |
- Mark review as helpful
Significantly alleviates ambiguity for complex audits
What do you like best about the product?
Great customer experience and onboarding, they were really helpful in removing the ambiguity I had around SOC requirements. They give a lot of guidence on how we can create any new policies needed in a way that will pass the audit which also alleviated the anxiety I had around understanding what we need, how the audit process works, etc.
What do you dislike about the product?
I don't dislike anything but I think there's an opportunity to reduce duplicative work with third-party vendor assessments
What problems is the product solving and how is that benefiting you?
We have several large customers in heavily regulated industries, Thoropass helps us stay compliant so we can continue to service those contracts. As a small team and company, we're able to gain certifications that would take 2-3x the time and money without Thoropass.
Fast Type 1 result, if you put the effort in!
What do you like best about the product?
We are a small startup requiring SOC2 to bring in a particular segment of customers. Generally speaking, our pre-SOC2 behaviors were sound, and we weren't expecting to need to clean up too much to have a successful audit. We were matched with Allie as an account manager who was extremely patient and informative as she walked us through the process and the platform. She walked us through the integrations available so we could connect Thoropass to our systems of record. Honestly, it was very easy, even though we kind of slow rolled it a bit because we were working on other things.
Once we were ready, it took us only a month to get our Type 1 certification. We were in disbelief and wondered if we had mistakenly gotten approved, but Allie assured us it was just because we had done things properly the first time! We are now in our Type 2 phase, and Allie has continued to be helpful in letting us know what we have to do to have a successful Type 2 audit. We have to log in to the platform a couple times a quarter to upload evidence and that is it. Assuming that's really all there is to it, we're hoping to have our Type 2 in hand before the end of this year!
Once we were ready, it took us only a month to get our Type 1 certification. We were in disbelief and wondered if we had mistakenly gotten approved, but Allie assured us it was just because we had done things properly the first time! We are now in our Type 2 phase, and Allie has continued to be helpful in letting us know what we have to do to have a successful Type 2 audit. We have to log in to the platform a couple times a quarter to upload evidence and that is it. Assuming that's really all there is to it, we're hoping to have our Type 2 in hand before the end of this year!
What do you dislike about the product?
I am still unsure about how potential customers will scrutinize our SOC2 report. Because I don't have experience going through the end to end audit process before, it will take some time for me to trust that a Thoropass audit is equal in 'standing' to a traditional audit done by an external firm - and only our customers can tell us this.
I think their built in document editor is very clunky. I almost released some official documents with comments and squigglies built in. Rather than do a lot of work to build an editor in your website, may I suggest a Google Docs or Office 365 integration so the documents can be edited using tools we are already familiar with.
I think their built in document editor is very clunky. I almost released some official documents with comments and squigglies built in. Rather than do a lot of work to build an editor in your website, may I suggest a Google Docs or Office 365 integration so the documents can be edited using tools we are already familiar with.
What problems is the product solving and how is that benefiting you?
Thoropass lets us streamline our SOC2 compliance and simplifies the process by not requiring us to retain an external auditor. In fact, they provide services for everything that would normally be serviced by different firms, so if you're starting from zero you probably can have Thoropass provide everything you need.
have had a great experience. Account manager is always helpful.
What do you like best about the product?
step by step guidance and support throughout the process.
What do you dislike about the product?
some of the materials harder to understand. more examples would be great.
What problems is the product solving and how is that benefiting you?
SOC 2 Compliance
On point service delivery
What do you like best about the product?
focuse on the service they were called out
What do you dislike about the product?
honestly nothing i can think of, there were no distractions along their service delivery
What problems is the product solving and how is that benefiting you?
Streamline the process of obtaining Security Compliance
Thoropass is flexible and supportive, helping our healthcare startup complete its SOC2 audit on time
What do you like best about the product?
Ease of use, generated policies, customer support
What do you dislike about the product?
Pricy but accommodating, flexible, login issues but quick resolution.
What problems is the product solving and how is that benefiting you?
Helps tackle SOC 2 compliance, guiding us to audit
A great product and a great team
What do you like best about the product?
The platform itself is intuitive and user-friendly, making the complex process of maintaining SOC 2 and ISO 27001 compliance much more manageable. The comprehensive dashboards provide clear insights and real-time updates, ensuring that we stay on top of our compliance requirements without any hassle. The automation features are a game-changer, significantly reducing the manual effort involved and allowing our team to focus on more strategic tasks.
What do you dislike about the product?
Don't have anything bad to say. It's a great product/team executing compliance practices curated to the needs of our company.
What problems is the product solving and how is that benefiting you?
With Thoropass, we feel assured that our compliance with SOC 2 standards is consistently maintained. This confidence is vital for gaining and retaining the trust of our customers and stakeholders.
The knowledgeable and supportive Thoropass team is always available to assist us. Their expertise and commitment to our success ensure that we are well-prepared to handle any compliance challenges that may arise.
The knowledgeable and supportive Thoropass team is always available to assist us. Their expertise and commitment to our success ensure that we are well-prepared to handle any compliance challenges that may arise.
SOC-2 Type 1 and Type 2 & GDPR Audit
What do you like best about the product?
Fantastic support which is crucial for the audit and especially when you go for it for the first time.
What do you dislike about the product?
Some minor inconveniences in the platform's user interface.
What problems is the product solving and how is that benefiting you?
Thoropass helped us to pass SOC-2 Type 1 and Type 2 + GDPR audits.
As a startup, we were not familiar with all the details of audit processes, where to start, and what we should focus on the most.
The platform has many templates for different security controls and a useful knowledge base.
It is amazing that we could enroll our staff through seamless SSO (Azure Active Directory) integration and integrate our cloud security provider to gather evidence automatically.
As a startup, we were not familiar with all the details of audit processes, where to start, and what we should focus on the most.
The platform has many templates for different security controls and a useful knowledge base.
It is amazing that we could enroll our staff through seamless SSO (Azure Active Directory) integration and integrate our cloud security provider to gather evidence automatically.
It gives me a peace of mind.
What do you like best about the product?
The well thoughtout templates, saving us a lot of time so we can focus on our core business. The experience with our CSM and auditors are great. They are helpful to get us through the process.
What do you dislike about the product?
Learning to navigate the system is not easy. The risk register is starting to have a good structure but needs more integration to be helpful.
What problems is the product solving and how is that benefiting you?
It helps us not having to reinvent the wheel, saving time and money to focus on our business.
Thoropass has been instrumental in getting to SOC2 - the tools and support have been first class.
What do you like best about the product?
Best part is definitely the dedicated support, keeping us on track. It's also very easy to assign and track the various tasks, and the prepackaged tools are a big help.
What do you dislike about the product?
Given how much better Thoropass is to the alternatives, I can't think of anything beyond minutiae I would change
What problems is the product solving and how is that benefiting you?
We need SOC2 to maximize our market opportunity, and while our practices are compliant, Thoropass has made it far simpler to generate the documentation and evidence.
showing 61 - 70