ThreadFusion
SERVICES & PRICING

Priced by scope, not by hours you can't verify.

Every engagement states the assets in scope, the deliverable and the price before it starts. If the scope grows, we re-quote in writing rather than letting the invoice drift. Above $25,000 I stop quoting from a table and we talk — a scope that size deserves a conversation, not a form.

Three ways to buy

Attack Surface Probe
one-off · your whole public footprint$4,500
  • Automated discovery, manually verified
  • 6-8 page report and a 45-minute call
  • The cheapest way to find out if you have a problem
Specialized Assessment
AI/LLM · supply chain · cloud$12,000
  • One scope of your choice
  • The areas most pentests leave out
  • Same deliverable and same retest

Assessments — fixed price per scope

SCOPETYPICAL SIZEDURATIONFROM
Attack Surface Probe1 organization · all public assets3 days$4,500
Annual Pentest — base1 app · 1 API · 3 roles · 1 cloud account5 days$15,000 / yr
· each additional web appadd-on—+$2,500
· each additional cloud accountadd-on—+$2,000
· internal networkadd-on—+$4,000
Specialized Assessment — AI / LLM1 assistant or agent4 days$12,000
Specialized Assessment — supply chain1 org · up to 30 repos4 days$12,000
Specialized Assessment — cloud / AD posture1 account or forest4 days$12,000

Every engagement includes one retest within 30 days, at no extra cost, to confirm the fixes landed.

What I don't do

Remediation is executed by the teams that own the asset. What you get from me is the finding, the reproduction, the recommendation and the retest — not a change pushed into your production systems by an outsider.

Saying this out loud is the point. An external tester with write access to your infrastructure is a risk you are adding, not removing.

Same reason I don't sell continuous monitoring: running a platform around the clock is a different business with different economics, and pretending otherwise would mean charging you for a dashboard instead of for judgement. What you buy here is a person looking at your exposure at the moments when it actually changed.

  • Continuous 24/7 monitoring — that is a platform, and good cheap ones already exist
  • Incident response and forensics
  • Executing fixes inside your environment
  • Issuing compliance certifications
  • Physical intrusion and social engineering
  • Reselling anyone else's scanning platform

Not sure which one you need?

Start with the free snapshot. It usually answers the question by itself.

Get a free exposure snapshot