Achieve infosec compliance without the headaches
Manage your risk and maintain compliance with ease
Evidence requests, questionnaires, penetration tests, all-in-one
Meet your auditor on day 1 and eliminate any surprises
Connect to the tools that matter most for your audit
See how our automated platform provides more than just readiness through clear roadmaps, transparent communication, and in-app audits
Get the recording icon-arrow
Stand out in a highly regulated industry
Minimize your risk while maximizing returns
Safeguard your data and close more deals
A bespoke solution for your unique business
Steve Heilenman | CIO, Benefix
Read More icon-arrow
Financial data security without the stress
Efficient SOC 2 compliance with no surprises
Enhance your security posture and build trust worldwide
Stay on top of data privacy regulations
Secure transactions,no matter your scale
Protect patient health data with confidence
Stand out in highly regulated industries
Many more standards including custom frameworks
Josh Horowitz | CTO, Stylo
Explore more success stories icon-arrow
Find out why the OrO Way is the best way to do compliance
See how we drive better outcomes through compliance
Go beyond readiness with unmatched expertise
Ensuring compliance is never a blocker to innovation
Join the team that's reimagining compliance
Let's make compliance easier—together
Your team of compliance experts is standing by. Meet your auditor on day 1 and get answers when you need them.
Get to know them icon-arrow
Catch up on the latest industry trends and expert insights
Attend the latest webinar or meet with us in person
Actionable tools for your compliance journey
Expert-curated resources for your compliance journey
A podcast for B2B CISOs
Customize and download your free information security policy and be well on your way to SOC 2 compliance.
Use our policy generator icon-arrow
Customer Stories / Medmo
Medmo is a healthcare platform for medical imaging, providing workflow solutions that simplify care for providers and patients. To gain customer confidence in handling patient health information, Medmo’s information security compliance needs to be top-notch.
Barak Poker, Medmo’s CTO, had big compliance requirements. As the business scaled to serve larger organizations, Barak needed proof that their product was secure.
In order to strengthen the company’s security posture, Barak needed to identify and remediate any potential security risks. He also needed all of their documentation organized to complete their SOC 2 audits and ongoing HIPAA compliance and be more prepared for audit requests. But Barak couldn’t do it alone.
Barak engaged Thoropass as a comprehensive compliance partner to conduct penetration testing and ensure readiness for both the SOC 2 and HIPAA frameworks. With a team of experts and an easy-to-use platform that streamlined the process, Barak found the support he needed to ensure the Medmo product was audit-ready.
“They fully understood what our application was, what our stacks were, what the breadth of each application was. I was really impressed by their organization and professionalism in terms of all their communications,” said Barak Poker, CTO at Medmo.
Thoropass’s experienced pentesters found several optimization opportunities, which were mostly focused on internal applications requiring high-level credentials. With Thoropass’s detailed reports and recommendations, Barak’s team was able to immediately run patches to optimize and further secure the Medmo platform.
Partnering with Thoropass allowed Barak to mitigate potential security risks and open the doors to new, larger customers. Now, when healthcare organizations ask for evidence of Medmo’s compliance, Barak has reports at the ready.
With ongoing compliance monitoring from Thoropass, Barak and his team know exactly what steps to take to keep risk at bay. Customers and stakeholders alike can have confidence in Medmo’s cybersecurity strategy.
Talk with one of our experts to build your custom path to compliance and take advantage of Thoropass’s thoughtful automation, expert guidance, and security audit experience.
ISO 27001, SOC 2