Thoropass
Thoropass is an auditor-led, AI-powered compliance and audit automation platform that combines software with expert auditor services. Its products span continuous compliance monitoring and alerting, automated evidence collection, a global control library, vulnerability scanning, and CREST-accredited penetration testing, helping companies achieve and maintain SOC 2, ISO 27001, HIPAA, PCI DSS and HITRUST. For developers and integration partners, Thoropass exposes a Partner API secured with OAuth 2.0 (Authorization Code + PKCE, refresh tokens, and RFC 7591 dynamic client registration) and a hosted, OAuth-protected Model Context Protocol (MCP) server for AI-agent access to audits, evidence requests, controls, alerts, devices and vulnerability data. Thoropass (formerly Laika) is backed by Bain Capital Ventures.
Thoropass publishes 1 API on the APIs.io network. Tagged areas include Company, Fintech, Compliance, Compliance Automation, and Audit.
Thoropass’ developer surface includes documentation, API reference, support, engineering blog, pricing, authentication, and 14 more developer resources.
Kin Score
APIs 1
Individual APIs this provider publishes, each with its own machine-readable definition.
Thoropass Partner API
OAuth 2.0-secured Partner API for programmatic access to Thoropass audits, evidence requests, controls, monitoring alerts, devices, change requests, training records and vulnera...
MCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
thoropass-mcp.yml
MCP SERVERSecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes governing access to this provider's APIs.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 3
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 3
Pagination, idempotency, versioning, errors, and events
Access & Security 4
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API