A bounded 30–60 day technical pilot designed around your data, detection question and acceptance criteria—not an open-ended trial.
Representative telemetry and agreed detection scenarios are in scope.
Detection packs are deployed and their evidence output is reviewed.
False-positive behavior is characterized rather than hidden.
Evidence quality and analyst workflow are evaluated by the customer team.
Required integration and deployment boundaries are validated.
A written enterprise decision is made at the end of the pilot.
Set objectives, data sources, baseline controls and the decision date.
Deploy the agreed ThreatFade boundary and validate operational prerequisites.
Review detections, evidence, analyst workflow, latency and false-positive behavior.
Produce a quantified outcome and choose Enterprise, iterate, or stop.
The pilot is intentionally not a free proof-of-concept. It reserves engineering capacity, creates a shared acceptance framework and gives both sides an evidence-backed decision point.
Technical intake
Minimal qualification only. Security telemetry, credentials and sensitive incident details are not requested here.