From compliance automation through audit, the Thoropass compliance delivery platform helps you get and stay compliant.
Modern audits delivered by expert auditors
Maintain compliance with real-time monitoring and alerts
Identify vulnerabilities with CREST-accredited pentest experts
Leverage AI for smarter compliance solutions
Streamline audits and improve accuracy with evidence automation
Simplify user reviews to enhance security
Automate responses to security questionnaires
Track and mitigate security risks in one place
Build trust with a professional, public-facing portal
Seamlessly connect your tools for streamlined compliance
Audits done the modern way. Leverage AI-powered compliance solutions with expert guidance for seamless, scalable audits.
From controls to audit, rapidly achieve infosec compliance with a single vendor
Manage your risk and streamline compliance
Meet your auditor on day 1 and eliminate any surprises
Discover proven compliance outcomes in the words of our customers.
Catch up on the latest industry trends and expert insights
Watch the latest webinar or meet us in person
Expert-curated resources for your compliance journey
A "true crime" styled podcast for anyone in the compliance industry
Actionable tools for your compliance journey
Implement audit-ready compliance solutions for friction-free infosec compliance outcomes.
Go beyond readiness with unmatched expertise
Stay updated with the latest Thoropass news and insights
Join the team that's reimagining compliance
Let's make compliance easier—together
We're committed to unbiased audits and superior service
Lucas Baiocchi (he/him)
Lucas Baiocchi is a seasoned cybersecurity leader with over seven years of experience in information security audits and assessments. He brings deep expertise across a broad spectrum of industry-recognized frameworks and standards, including HITRUST, NIST CSF, NIST 800-53, HIPAA, PCI, SOC 1 & 2, and ISO 27001.
As the HITRUST InfoSec Assurance Manager at Thoropass, Lucas leads and executes HITRUST assessments, working closely with organizations to evaluate their security posture, validate control effectiveness, and deliver clear, actionable insights that align compliance objectives with broader business goals. His approach ensures not only regulatory and standards-based compliance, but also the adoption of efficient, scalable, and realistic security solutions.
Lucas holds a Bachelor’s degree in Information Systems from San Diego State University and is certified as a Certified CSF Practitioner (CCSFP), Certified HITRUST Quality Professional (CHQP), and Healthcare Information Security and Privacy Practitioner (HCISPP).
He has successfully guided a diverse range of clients—from agile, cloud-native startups to complex, on-premises global enterprises—through the process of achieving and maintaining HITRUST certification.
7+ Years
HITRUST, HIPAA, NIST CSF, NIST 800-53 Rev. 5, PCI-DSS, SOC 1, SOC 2, ISO 27001
San Diego State University