Caisson vs Thoropass
Thoropass bundles the software and the auditor in one place. Caisson is the controls in your codebase the audit examines. These compose: here is the honest line.
Which should you use?
Different layers, and a natural pairing. Thoropass is distinctive among GRC platforms: it bundles the compliance software AND the audit itself under one roof: in-house auditors plus AI-driven evidence collection across SOC 2, ISO 27001, HIPAA, PCI DSS, and HITRUST. Caisson is the code that implements the controls that audit examines: fail-closed Postgres RLS with isolation tests, a WORM + hash-chained audit trail, per-tenant field encryption, and OSCAL evidence packs, one-time, in your codebase. Thoropass gives you the audit path end to end; Caisson gives you the controls the auditor inspects.
What Thoropass is
Compliance platform + in-house auditor (GRC SaaS). Facts below were read from thoropass.com on 2026-07-07.
- A compliance platform trusted by 1,000+ organizations (verified 2026-07-07) that combines audit software with in-house audit experts: the auditor and the tooling under one roof.
- Covers SOC 2, ISO 27001, GDPR, PCI DSS, HITRUST, and HIPAA with real-time control views and automated validation.
- AI-powered evidence collection paired with an auditor-led model: the assurance team performs the audit, not just the prep.
- Runs the audit and collects evidence from your stack; it does not ship the application controls the audit examines.
An honest comparison
Where Thoropass has a capability, it is marked. Caisson is the compliance and tenant-isolation substrate; Thoropass wins the rows it wins.
| Detail | Caisson | Thoropass |
|---|---|---|
| Continuous stack/cloud monitoring + automated evidence collection | from your own app code | |
| In-house auditor / signed audit engagement | — | |
| Runs the audit workflow (evidence-for-auditor, questionnaires) | — | |
| Fail-closed Postgres RLS + automated cross-tenant isolation tests | — | |
| WORM evidence store + append-only hash-chained audit trail | — | |
| SOC 2 / HIPAA / EU AI Act evidence packs + OSCAL export | — | |
| Per-tenant field encryption (envelope, per-tenant key) | — | |
| Detached evidence signing (Ed25519 + RFC-3161) | — | |
| License model | One-time perpetual, own the source | Subscription + audit engagement |
What Thoropass is genuinely better at
A comparison that only flatters one side isn't worth reading. Here is what this kit does well.
Thoropass's differentiator is genuine: it bundles in-house auditors with the compliance tooling, so audit prep and the audit itself live under one roof. For a team that wants a single accountable path to a signed report, that is a real advantage no code library offers.
Experienced assurance partners plus AI-driven evidence collection reduce the lift on your team and shorten the cycle. That end-to-end audit service is real and is well outside what Caisson provides.
Where Caisson draws the line
The compliance and tenant-isolation substrate a launch kit leaves to you.
Its auditors and agents examine the systems you built. Caisson is those controls (fail-closed RLS with isolation tests, a hash-chained audit trail, WORM storage, and an evidence-pack generator) as source you own, CI-tested, emitting OSCAL evidence an auditor can review.
Thoropass sells the audit path and evidence collection as a service; Caisson ships the evidence pipeline itself (the code that produces byte-stable OSCAL packs) one-time and owned. It does not perform your audit or sign your report; it is the implemented layer the auditor inspects.
Which should you pick?
You want a single accountable path to a signed audit: the compliance software and the auditor bundled, with evidence collection handled for you.
You want the implemented controls and evidence pipeline (RLS with isolation tests, a WORM audit trail, and OSCAL evidence) as code you own and test in CI, one-time.
Implement the controls with Caisson and take the audit path with Thoropass: the OSCAL evidence Caisson emits is what Thoropass's auditors examine and validate.
One-time, own the source.
Caisson is a one-time perpetual license — the price never recurs, and it includes 12 months of updates from your purchase date, renewable per entitlement afterward at 40% of list per year. The Base substrate is Apache-2.0; the compliance modules are commercial.
Compliance bundle
$1,649, one-time. Fail-closed RLS, WORM, the audit chain, evidence packs, and the framework and signing carves — the whole substrate this comparison is about.
À la carte
Take a single module from $49 — audit-worm, field-crypto, or compliance-core on their own, onto your existing Postgres app.
Everything bundle
$2,259 covers every bundle and every à-la-carte module, plus the open base, in one purchase.
Common questions.
Is Caisson a Thoropass alternative?
Does Caisson replace the auditor Thoropass provides?
How do the two price?
Ship the compliant backend.
Explore the Compliance bundle, browse every module in the marketplace, or read another comparison.