ThreadFusion
ATTACK SURFACE MANAGEMENT · PENETRATION TESTING

The rigor your investors demand. The language your engineers speak.

Penetration testing and attack surface management against NIST SP 800-115: the report your investors and enterprise customers in the United States ask for. Delivered with direct communication in your engineers’ own language, so findings get fixed instead of filed.

Get a free exposure snapshotBook a 30-minute call

US-registered company · Reports in English or Spanish · Remote delivery

EXPOSURE SNAPSHOTsample.acme.com
  • api-staging.acme.comAdmin panel reachable from the internet
    CRITICAL
  • backups-acmeCloud bucket allows public listing
    HIGH
  • legacy.acme.comLive host, absent from the asset inventory
    NEW
  • mail.acme.comDMARC published but not enforced
    MEDIUM
Illustrative sample. Your snapshot uses your own domains.
15+Years in enterprise cybersecurity
30 daysRetest included after every report
3 daysFrom signed scope to first snapshot
WHO IT'S FOR

When someone in the United States asks you for security evidence.

Spanish-speaking companies that sell to, or raise from, the US. They usually arrive at one of these four moments:

A security questionnaire landed

An enterprise customer wants a recent pentest before signing. You get the report and the attestation letter that questionnaire asks for.

Due diligence is coming

Your round or an acquisition goes through technical review. You show up with findings fixed and the retest that proves it, instead of explaining why you have nothing.

You are preparing SOC 2 or ISO 27001

Your auditor will ask for a penetration test with a named methodology. You have one, aligned with NIST SP 800-115, inside your audit window.

You shipped AI or changed clouds

An agent with tool access, a migration or an acquisition moved your surface. The review covers exactly what changed.

SERVICES

Three ways in: map what's exposed, test in depth, or go where scanners don't.

ANNUAL

Annual Pentest

A bounded, authorized test of what matters, with findings your engineers can actually reproduce.

  • External perimeter, web applications and APIs
  • Cloud configuration review, read-only by default
  • Severity ranked by reachability, not by CVSS alone
  • Retest within 30 days, plus a short second pass at 6 months
YOU RECEIVEA findings report with a reproducible proof of concept and a remediation recommendation per finding, plus an executive summary that survives a board meeting.$15,000 / year, per application
SPECIALIZED

Specialized Assessment

Three areas most testers skip, scoped and priced like everything else.

  • AI and LLM systems: indirect prompt injection, agent actions, exposed MCP servers
  • Software supply chain: dependencies, build pipelines and CI workflows
  • Internal posture without handing over credentials — you run read-only commands, I read the output
  • Detection rules written for the gaps the assessment actually finds
YOU RECEIVEThe same deliverable as any other engagement: reproducible findings ranked by what is reachable, with the recommendation next to each one.$12,000 per assessment

SERVICES & PRICING →

APPROACH

The machine covers. A person decides.

An autonomous scanner is cheap and hands you two hundred findings with no context. A traditional firm is slow and expensive. Here the automation does what it is good at — covering everything, fast — and a human does the part you are actually paying for: deciding what is real, proving it, and telling you what to fix first.

01

Scope

Rules of engagement in writing: what is in, what is out, when, and who to call if something breaks.

02

Cover

Automated discovery across the whole surface, because a person alone misses assets and a machine does not get tired. Passive first, active only where the scope allows.

03

Verify by hand

Every finding that matters is reproduced manually before it reaches your report. No scanner output pasted into a template, and no CVSS score without an exploit path behind it.

04

Say what was not measured

If something could not be tested — a host behind a bot wall, a flow that needed credentials I did not have — the report says so. A gap you know about is worth more than a clean page you cannot trust.

05

Hand off

A recommendation the owning team can execute on its own terms, and a retest to confirm it landed.

Full methodology, aligned with NIST SP 800-115 →

ABOUT

A senior practitioner behind every report.

ThreadFusion delivers attack surface work under contract through ThreadFusion LLC. Fifteen years in cybersecurity, and daily practice doing exactly this: reviewing the external attack surface of an enterprise the size where forgetting an asset is the normal failure mode, not the rare one.

Every engagement is led and signed by a senior practitioner — the person whose name is on the report is the person who did the work and will defend it on a call. No scanner output pasted into a template, no finding you cannot reproduce from the report alone.

BACKGROUND
  • Security leadership in a large regulated enterprise
  • Recognized researcher in public vulnerability disclosure programs
  • Contracted and delivered under ThreadFusion LLC, registered in Florida, USA
  • Reporting delivered in English and Spanish

Questions people ask first.

Do you need access to our systems?

Not for attack surface management — it works entirely from outside, from data that is already public. Pentest access is agreed in the scope, and nothing beyond it is touched.

How is authorization handled?

Signed rules of engagement before anything starts, naming the assets in scope, the testing window and the escalation contact on your side.

Who reads the report?

Both audiences get their section: an executive summary in plain language, and a technical body with reproduction steps your engineers can follow line by line.

Do the internal assessments need credentials in my environment?

No. For Active Directory, cloud and container work I send read-only commands, your team runs them, and I analyze the output. None of them modify anything, and I never hold credentials to your environment.

Why is there no name on this site?

Because I hold a full-time security role at a large enterprise and keep the two separate. You contract with a US-registered LLC, scope and liability are in writing, and the name of the person who signs goes in the contract and on the report. Testing runs in the window we agree, and during an engagement every message gets an answer within one business day.

FREE SNAPSHOT

Start by finding out what's already exposed.

Give me one domain. You get back a one-page summary of what is reachable from the internet under your name, at no cost and with no obligation. If it looks boring, you have learned something useful.

Only public data is used. Nothing is scanned intrusively without a signed scope.