From compliance automation through audit, the Thoropass compliance delivery platform helps you get and stay compliant.
Modern audits delivered by expert auditors
Maintain compliance with real-time monitoring and alerts
Identify vulnerabilities with CREST-accredited pentest experts
Leverage AI for smarter compliance solutions
Streamline audits and improve accuracy with evidence automation
Simplify user reviews to enhance security
Automate responses to security questionnaires
Track and mitigate security risks in one place
Build trust with a professional, public-facing portal
Seamlessly connect your tools for streamlined compliance
Audits done the modern way. Leverage AI-powered compliance solutions with expert guidance for seamless, scalable audits.
From controls to audit, rapidly achieve infosec compliance with a single vendor
Manage your risk and streamline compliance
Meet your auditor on day 1 and eliminate any surprises
Discover proven compliance outcomes in the words of our customers.
Catch up on the latest industry trends and expert insights
Watch the latest webinar or meet us in person
Expert-curated resources for your compliance journey
A "true crime" styled podcast for anyone in the compliance industry
Actionable tools for your compliance journey
Implement audit-ready compliance solutions for friction-free infosec compliance outcomes.
Go beyond readiness with unmatched expertise
Stay updated with the latest Thoropass news and insights
Join the team that's reimagining compliance
Let's make compliance easier—together
We're committed to unbiased audits and superior service
Customer Stories / Berkshire Grey
Berkshire Grey combines AI and robotics to automate pick, pack and sort operations for retail, eCommerce, and logistics enterprises.
Brian McCarthy, VP of Engineering, DevOps and Infrastructure at Berkshire Grey, was looking to streamline internal processes and shorten the sales cycle. Customers had high security expectations, and the team was spending increasing amounts of time responding to questionnaires with up to 700 questions. Based on customer demand, he decided to pursue SOC 2 compliance.
In his previous experience with audits, auditors had a one-size-fits all approach. But Brian and his team were looking for a compliance partner who could not only conduct a SOC 2 audit, but also guide them through the process, automate evidence collection, and scope the project to their needs.
Brian shared, “we were looking for a match with our philosophy and approach.”
The Customer Success Managers (CSMs) at Thoropass made the experience completely different from the traditional audit firms the team had worked with in the past. From onboarding through their audit and beyond, Berkshire Grey’s dedicated CSM held weekly calls to answer questions and keep their audit preparation process on track.
Aaron Branham, IT Director at Berkshire Grey, said their CSM always showed up to the calls prepared.
He explained, “they’d done their homework, and they had already read the documents. We were able to get answers in real time and move forward.”
The CSM was also instrumental in helping the team to tailor and scope policy templates in a way that met their needs within the compliance framework.
Along with the CSM, the easy-to-use Thoropass platform simplified the process. The evidence requirements were clearly communicated, and the platform kept all documents in one place and maintained version control. Thoropass collected evidence automatically through integrations with the platform such as GitHub and BambooHR, and automated the access review process.
Speaking to this, Austin explained: “the integrations with the various cloud platforms have been absolutely monumental in reducing the amount of time that we have to spend in spreadsheets.”
When it came time for their audit, the Berkshire Grey team found Thoropass’ in-house auditors easier to work with than expected and committed to understanding their business and specific needs.
Multi-framework compliance made easy with control mapping
After completing their SOC 2 audit, the Berkshire Grey team was ready to tackle additional frameworks. In order to grow its business in Europe, where they have staff in 13 countries, the team began pursuing GDPR compliance. The Thoropass platform eliminated redundant work by mapping the overlapping controls between the two frameworks.
“Once we had our policies nailed down, we had a lot of the evidence already taken care of, and we’re able to map it from SOC 2 over to the GDPR-specific controls,” explained Austin.
Berkshire Grey successfully completed its first SOC 2 Type 2 audit in about six months, resulting in an improved security posture and increased customer trust.
However, the benefits compounded as Berkshire Grey maintained compliance with Thoropass. The following year, with muscle memory and integrations in place, the team completed their SOC 2 renewal in only 25% of the time.
Berkshire Grey plans to maintain SOC 2 and GDPR with Thoropass, and is currently working on SOC 3.
The team was relieved to find that although the company has grown, it has not impacted the scope or resources required for compliance. They intend to expand to other frameworks depending on customer needs, knowing that Thoropass makes multi-framework compliance manageable.
Aaron shared, “we’re not scared about the next one. We feel like we have the right nimble team and the right partner to get that done.”
Talk with one of our experts to build your custom path to compliance and take advantage of Thoropass’s thoughtful automation, expert guidance, and security audit experience.
HIPAA
CCPA, GDPR, ISO 27001, PIPEDA, SOC 2, SOC 3