The rigor your investors demand. The language your engineers speak.
Penetration testing and attack surface management against NIST SP 800-115: the report your investors and enterprise customers in the United States ask for. Delivered with direct communication in your engineers’ own language, so findings get fixed instead of filed.
US-registered company · Reports in English or Spanish · Remote delivery
EXPOSURE SNAPSHOTsample.acme.com
api-staging.acme.comAdmin panel reachable from the internet
CRITICAL
backups-acmeCloud bucket allows public listing
HIGH
legacy.acme.comLive host, absent from the asset inventory
NEW
mail.acme.comDMARC published but not enforced
MEDIUM
Illustrative sample. Your snapshot uses your own domains.
15+Years in enterprise cybersecurity
30 daysRetest included after every report
3 daysFrom signed scope to first snapshot
WHO IT'S FOR
When someone in the United States asks you for security evidence.
Spanish-speaking companies that sell to, or raise from, the US. They usually arrive at one of these four moments:
A security questionnaire landed
An enterprise customer wants a recent pentest before signing. You get the report and the attestation letter that questionnaire asks for.
Due diligence is coming
Your round or an acquisition goes through technical review. You show up with findings fixed and the retest that proves it, instead of explaining why you have nothing.
You are preparing SOC 2 or ISO 27001
Your auditor will ask for a penetration test with a named methodology. You have one, aligned with NIST SP 800-115, inside your audit window.
You shipped AI or changed clouds
An agent with tool access, a migration or an acquisition moved your surface. The review covers exactly what changed.
SERVICES
Three ways in: map what's exposed, test in depth, or go where scanners don't.
START HERE
Attack Surface Probe
Everything your organization exposes to the internet, mapped in one pass and ranked by what an attacker reaches first.
Domains, subdomains, IPs, certificates, cloud storage and exposed services
Shadow IT: live hosts that never made it into your inventory
Each exposure named with the asset behind it, not a generic category
Repeat it when something changes — a migration, an acquisition, a new product — not every month out of habit
YOU RECEIVEA report with prioritized exposure, plus the full asset inventory as a spreadsheet your team can keep working from.$4,500, one-off
ANNUAL
Annual Pentest
A bounded, authorized test of what matters, with findings your engineers can actually reproduce.
External perimeter, web applications and APIs
Cloud configuration review, read-only by default
Severity ranked by reachability, not by CVSS alone
Retest within 30 days, plus a short second pass at 6 months
YOU RECEIVEA findings report with a reproducible proof of concept and a remediation recommendation per finding, plus an executive summary that survives a board meeting.$15,000 / year, per application
SPECIALIZED
Specialized Assessment
Three areas most testers skip, scoped and priced like everything else.
AI and LLM systems: indirect prompt injection, agent actions, exposed MCP servers
Software supply chain: dependencies, build pipelines and CI workflows
Internal posture without handing over credentials — you run read-only commands, I read the output
Detection rules written for the gaps the assessment actually finds
YOU RECEIVEThe same deliverable as any other engagement: reproducible findings ranked by what is reachable, with the recommendation next to each one.$12,000 per assessment
An autonomous scanner is cheap and hands you two hundred findings with no context. A traditional firm is slow and expensive. Here the automation does what it is good at — covering everything, fast — and a human does the part you are actually paying for: deciding what is real, proving it, and telling you what to fix first.
01
Scope
Rules of engagement in writing: what is in, what is out, when, and who to call if something breaks.
02
Cover
Automated discovery across the whole surface, because a person alone misses assets and a machine does not get tired. Passive first, active only where the scope allows.
03
Verify by hand
Every finding that matters is reproduced manually before it reaches your report. No scanner output pasted into a template, and no CVSS score without an exploit path behind it.
04
Say what was not measured
If something could not be tested — a host behind a bot wall, a flow that needed credentials I did not have — the report says so. A gap you know about is worth more than a clean page you cannot trust.
05
Hand off
A recommendation the owning team can execute on its own terms, and a retest to confirm it landed.
ThreadFusion delivers attack surface work under contract through ThreadFusion LLC. Fifteen years in cybersecurity, and daily practice doing exactly this: reviewing the external attack surface of an enterprise the size where forgetting an asset is the normal failure mode, not the rare one.
Every engagement is led and signed by a senior practitioner — the person whose name is on the report is the person who did the work and will defend it on a call. No scanner output pasted into a template, no finding you cannot reproduce from the report alone.
BACKGROUND
Security leadership in a large regulated enterprise
Recognized researcher in public vulnerability disclosure programs
Contracted and delivered under ThreadFusion LLC, registered in Florida, USA
Reporting delivered in English and Spanish
Questions people ask first.
Do you need access to our systems?
Not for attack surface management — it works entirely from outside, from data that is already public. Pentest access is agreed in the scope, and nothing beyond it is touched.
How is authorization handled?
Signed rules of engagement before anything starts, naming the assets in scope, the testing window and the escalation contact on your side.
Who reads the report?
Both audiences get their section: an executive summary in plain language, and a technical body with reproduction steps your engineers can follow line by line.
Do the internal assessments need credentials in my environment?
No. For Active Directory, cloud and container work I send read-only commands, your team runs them, and I analyze the output. None of them modify anything, and I never hold credentials to your environment.
Why is there no name on this site?
Because I hold a full-time security role at a large enterprise and keep the two separate. You contract with a US-registered LLC, scope and liability are in writing, and the name of the person who signs goes in the contract and on the report. Testing runs in the window we agree, and during an engagement every message gets an answer within one business day.
FREE SNAPSHOT
Start by finding out what's already exposed.
Give me one domain. You get back a one-page summary of what is reachable from the internet under your name, at no cost and with no obligation. If it looks boring, you have learned something useful.