Ethics
Authorised testing only.
We only assess systems you own or are explicitly authorised to have assessed. These pages are not a licence to commission work against third parties or competitors.
Security work without authorisation is not clever. It is a problem. BoundaryProof only assesses systems and public footprints you own or are explicitly authorised to have reviewed — and we refuse third-party targets without owner permission.
What that means
- Before any testing or deep review starts, we agree in writing: assets in scope, authorising person, windows, and safety constraints.
- The free intro call is a conversation about fit. It is not permission to test and not a free report.
- We will refuse requests to target third parties, competitors, or systems without clear owner authorisation.
- During work we stay inside the agreed scope. Out-of-scope discoveries may be noted for discussion — not exploited beyond agreement.
Why we are strict
Unauthorised testing is unlawful and unsafe. Clear authorisation protects you, your customers, and us. It also keeps reports usable for remediation rather than drama.
How to start correctly
- Book a free intro: Calendly
- On the scope call, bring: domains/IPs/apps you want reviewed, who can authorise, and any change windows.
- We confirm prerequisites and only then schedule assessment work.
Agencies should treat client estates as client-authorised work, not as an implied right that comes with a reseller login. Shared environments need explicit permission from the owning party.
Questions: hello@boundaryproof.co.uk
Related: Why we refuse third-party targets · How we work · Not for
Ready to talk it through?
Book a free intro call to confirm fit, authorisation and scope. Prefer the form? Use the contact section on the main site.