BoundaryProof Blog

Authorised only: why we refuse third-party targets

UK founder notes ← All posts

If you cannot authorise the assets, we will not test them. That boundary protects you, us and everyone else.

Security work without authorisation is not clever. It is a problem. BoundaryProof only assesses systems and public footprints you own or are explicitly authorised to have reviewed — and we refuse third-party targets without owner permission.

That stance is not marketing fluff. It keeps engagements legal, insurance-sensible and professionally clean. It also keeps the free intro call honest: we are here to help UK businesses reduce their own exposure through Web, External Infrastructure, OSINT and Firewall reviews — not to weaponise curiosity.

What “authorised” looks like in practice

Before testing starts, we run a scope and prerequisites call. We confirm assets, permission, access requirements, testing windows and safety constraints. Written clarity beats verbal assumptions. If ownership is murky — shared hosting, client environments, reseller setups — we pause until the right party signs off.

OSINT still needs authorisation in our model. Even though sources are public, the engagement is for a client who can act on findings about their brand, domains and staff-facing footprint. We do not run OSINT “against anyone”. We do not look at any company on speculative request.

Why buyers sometimes push the wrong ask

Sometimes the ask comes from a good place: worry about a vendor, frustration with a partner, or fear after reading a breach story. The answer is still the same. Assess what you control. Improve your own perimeter, applications, public exposure and firewall posture. Use contracts and due diligence for suppliers — not unauthorised scanning.

Sometimes the ask is simply out of scope for a focused SME practice. We are not a private investigation firm. We are not a team for hire against arbitrary internet targets. Staying narrow is how we stay useful.

How this helps you as a client

When we refuse third-party work, you get a clearer partner. Reports stay tied to assets you can remediate. Debriefs stay practical. Retests validate your fixes, not someone else’s drama. Founder-led delivery means the same person who refuses the bad ask is the person accountable for the good work.

If you have authority over the systems that worry you, book the free intro call. If you do not, the helpful next step is to get that authority — not to shop for someone willing to ignore it.

Edge cases we still handle carefully

Holding companies, franchises, white-label platforms and agencies running client infrastructure create edge cases. The rule does not change: identifiable authorising party, clear asset list, written scope. If a client asks you to arrange a review of their estate, they need to authorise it — we can work through you as the delivery partner when the paperwork says so.

This is also why the contact form includes an authorised-enquiries note. It is a filter that saves everyone time and keeps BoundaryProof aligned with the kind of work we are willing to put a name on.

What good authorisation looks like on paper

A short written confirmation covering who owns the assets, which domains or ranges are included, which environments are excluded, and who can pause testing is usually enough for SME work. Fancy legalese is less important than unambiguous ownership. If two directors disagree about what “our systems” means, fix that before day one of assessment.

Agencies should treat client estates as client-authorised work, not as an implied right that comes with a reseller login. The intro call is a good place to map who signs what. Getting this right protects your reputation as much as ours.

Ready to talk it through?

Book a free intro call to see whether a focused Web, External Infrastructure, OSINT or Firewall review is the right first step. Authorised scope only.

← Back to blog index · Home