Thoropass

Thoropass is an auditor-led, AI-powered compliance and audit automation platform that combines software with expert auditor services. Its products span continuous compliance monitoring and alerting, automated evidence collection, a global control library, vulnerability scanning, and CREST-accredited penetration testing, helping companies achieve and maintain SOC 2, ISO 27001, HIPAA, PCI DSS and HITRUST. For developers and integration partners, Thoropass exposes a Partner API secured with OAuth 2.0 (Authorization Code + PKCE, refresh tokens, and RFC 7591 dynamic client registration) and a hosted, OAuth-protected Model Context Protocol (MCP) server for AI-agent access to audits, evidence requests, controls, alerts, devices and vulnerability data. Thoropass (formerly Laika) is backed by Bain Capital Ventures.

Thoropass publishes 1 API on the APIs.io network. Tagged areas include Company, Fintech, Compliance, Compliance Automation, and Audit.

Thoropass’ developer surface includes documentation, API reference, support, engineering blog, pricing, authentication, and 14 more developer resources.

30.1/100 thin ▬ flat Agent 25/100 agent aware Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
1 APIs 1 MCP Servers
CompanyFintechComplianceCompliance AutomationAuditSecurityCybersecurityGRCSOC 2MCP

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 30.1/100 · thin
Contract Quality 0.0 / 25
Developer Ergonomics 8.3 / 20
Commercial Clarity 10.5 / 20
Operational Transparency 2.1 / 13
Governance 0.0 / 12
Discoverability 9.3 / 10
Agent readiness — 25/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/thoropass: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Thoropass Partner API

OAuth 2.0-secured Partner API for programmatic access to Thoropass audits, evidence requests, controls, monitoring alerts, devices, change requests, training records and vulnera...

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

thoropass-mcp.yml

MCP SERVER

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Thoropass Authentication

oauth2 · 1 scheme

SECURITY

Thoropass Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Thoropass Trust Center

trust center published

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Thoropass Scopes

24 scopes · authorizationCode

24 scopes

SCOPES

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Access & Security 4

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: thoropass
name: Thoropass
description: Thoropass is an auditor-led, AI-powered compliance and audit automation platform that combines software with
  expert auditor services. Its products span continuous compliance monitoring and alerting, automated evidence collection,
  a global control library, vulnerability scanning, and CREST-accredited penetration testing, helping companies achieve and
  maintain SOC 2, ISO 27001, HIPAA, PCI DSS and HITRUST. For developers and integration partners, Thoropass exposes a Partner
  API secured with OAuth 2.0 (Authorization Code + PKCE, refresh tokens, and RFC 7591 dynamic client registration) and a hosted,
  OAuth-protected Model Context Protocol (MCP) server for AI-agent access to audits, evidence requests, controls, alerts,
  devices and vulnerability data. Thoropass (formerly Laika) is backed by Bain Capital Ventures.
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://cdn.prod.website-files.com/6891db6efb3a962d3fcde7ae/689b377ec946ba9bb8d243f7_Thoropass_Website_OrO-Way-Hero-1.webp
url: https://raw.githubusercontent.com/api-evangelist/thoropass/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- bain-capital-ventures
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-21'
tags:
- Company
- Fintech
- Compliance
- Compliance Automation
- Audit
- Security
- Cybersecurity
- GRC
- SOC 2
- MCP
apis:
- name: Thoropass Partner API
  description: OAuth 2.0-secured Partner API for programmatic access to Thoropass audits, evidence requests, controls, monitoring
    alerts, devices, change requests, training records and vulnerability data, plus a hosted MCP server for agents.
  humanURL: https://www.thoropass.com/platform/integrations
  baseURL: https://api.thoropass.com
  tags:
  - Compliance
  - Audit
  - MCP
  properties:
  - type: Authentication
    url: authentication/thoropass-authentication.yml
  - type: OAuthScopes
    url: scopes/thoropass-scopes.yml
  - type: MCPServer
    url: mcp/thoropass-mcp.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://thoropass.com/
- type: Documentation
  url: https://help.thoropass.com/
- type: APIReference
  url: https://docs.thoropass.com/mcp
- type: Support
  url: https://help.thoropass.com/
- type: Blog
  url: https://www.thoropass.com/learn/blog
- type: Pricing
  url: https://www.thoropass.com/pricing
- type: Login
  url: https://app.thoropass.com
- type: TermsOfService
  url: https://thoropass.com/terms-and-conditions/
- type: PrivacyPolicy
  url: https://www.thoropass.com/privacy-policy
- type: StatusPage
  url: https://status.thoropass.com
- type: TrustCenter
  url: https://trust.thoropass.com/
- type: Authentication
  url: authentication/thoropass-authentication.yml
- type: OAuthScopes
  url: scopes/thoropass-scopes.yml
- type: MCPServer
  url: mcp/thoropass-mcp.yml
- type: WellKnown
  url: well-known/thoropass-well-known.yml
- type: Conventions
  url: conventions/thoropass-conventions.yml
- type: Conformance
  url: conformance/thoropass-conformance.yml
- type: Lifecycle
  url: lifecycle/thoropass-lifecycle.yml
- type: DomainSecurity
  url: security/thoropass-domain-security.yml
- type: LLMsTxt
  url: llms/thoropass-llms.txt
x-enrichment:
  date: '2026-07-21'
  status: enriched
  artifacts_added: 10
  pass: local-v1