thingsrecon PRICING

Get pricing that fits your attack surface.

Our flexible pricing is tailored to your environment, whether you're monitoring one domain or hundreds of suppliers. No hidden costs, just a clear model based on real usage.

Attack Surface Discovery

Uncover exposed assets across your digital footprint. Enrich findings with business, financial, and geopolitical context to prioritize the risks.

  • Automate mapping via digital footprints (domains, IPs, scripts)
  • Measure cyber hygiene and quantify risk to drive smarter security investments
  • Meet regulatory requirements (NIS2, DORA)

Supply Chain Intelligence

Understand how vendors connect to your digital ecosystem. Continuously monitor supplier exposure and focus on the risks closest to your core systems.

  • Assess supplier cyber risk with transparent scoring
  • Understand proximity—their level of integration into your digital surface
  • Continuously monitor your supply chain

Find the right plan for your recon.

When you reach out, we'll help with:

  • A breakdown of our pricing structure based on domains and suppliers
  • Help estimating your usage and what coverage you need
  • Guidance on scaling as your needs grow
Thank you! We’ll be in touch soon.
In the meantime, explore our Resource Center. It’s packed with insights, videos, and practical guides on attack surface discovery and supply chain risk.
Oops! Something went wrong while submitting the form.

Frequently asked questions

Does ThingsRecon require software installation?

No. ThingsRecon performs discovery externally and does not require software agents to be installed across the organisation or its suppliers. The platform analyses publicly observable technical signals and conducts non-intrusive scanning from outside the environment, which reduces deployment effort and avoids depending on each supplier to participate. Agentless discovery is especially useful for unknown, unmanaged or third-party assets where the organisation may not have administrative access. It does not remove the value of internal telemetry, asset management or endpoint tools; those sources can provide additional context. ThingsRecon’s role is to show what is visible and connected from an external perspective, attach evidence to the findings and monitor the surface as it changes. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert.

How is ThingsRecon priced?

You pay per domain for Attack Surface Asset Discovery and per supplier for Supply Chain Discovery. Plans scale based on your actual usage and monitoring frequency.

What is ThingsRecon?

ThingsRecon is a cybersecurity platform that maps your external attack surface, across your own assets and your supply chain. We show you what attackers see, so you can fix what matters most.

How does ThingsRecon work?

We scan the public internet like an attacker would: continuously, without agents or integrations, to uncover exposed assets, misconfigurations, and vulnerable third-party connections.

Can I use ThingsRecon for compliance?

Yes. We support security and compliance leaders working toward NIS2, DORA, and SEC compliance by delivering real-time visibility and third-party risk insights aligned to key requirements.

Is ThingsRecon white-label or partner-friendly?

Yes. We support custom reporting, co-branded outreach, and joint value delivery. We have flexible plans designed for MSSPs and service providers.

Can I integrate ThingsRecon into my existing service?

Absolutely. Use our dashboards, exports, or API to enrich your existing SIEM, vulnerability management, GRC platform, or risk monitoring programs with external discovery.