BoundaryProof Blog

Why the free intro call is the best first step

UK founder notes ← All posts

Skip the glossy proposal. A 30-minute intro tells you what is exposed and which focused review comes first.

Security buying for UK SMEs often feels like a trap: a glossy full-pentest proposal, or silence until someone “qualifies” you. Neither answers the real question — what should we look at first, and is it worth doing now?

That is why BoundaryProof starts with a free intro call. It is not a sales theatre piece. It is a practical conversation between you and the person who would actually do the work. You explain what you run, what you are worried about, and any deadlines you are working toward. I explain which of the four focused services — Web, External Infrastructure, OSINT or Firewall — is the quickest route to useful findings.

What the call is for

The intro call exists to reduce risk on both sides. You should leave knowing whether a focused review makes sense, roughly what authorisation and assets we would need, and what a report would look like. I should leave knowing whether I can help without stretching scope into something you did not ask for.

We will talk about internet-facing reality, not buzzwords. That might mean a customer portal that has grown beyond the original design, a firewall rule base that nobody wants to own, public company data that could feed phishing, or a set of cloud hosts you are not sure are locked down. The goal is clarity, not a hard close.

What we will not do on the call

I will not push a productised “everything scan”. There is no CE+ offering here, and I will not claim we look at any company without proper authorisation. If you ask me to assess a third-party target you do not control, I will refuse. Authorised scope is non-negotiable, and it is better we establish that early.

I also will not pretend every business needs a full penetration test as the first move. Many teams need visibility into exposure first: what is reachable, what is misconfigured, and what is publicly useful to an attacker. A focused assessment can prove value quickly without locking you into a large consultancy process.

How to get value in 30 minutes

Come with a short list. What does the business do? Which domains or systems matter? Is there a known worry — admin panels, remote access, messy firewall changes, staff data online? Any compliance or customer pressure? That is enough. You do not need a perfect asset inventory before booking.

If the fit is good, we move to a scope and prerequisites call before any testing starts. If it is not a fit, you still leave with a clearer sense of what “exposed” means for your setup and what a sensible next step looks like — even if that next step is internal work rather than hiring anyone.

Founder-led delivery means the person on the intro call is the same person scoping, assessing and debriefing. No junior handoff, no inflated agency language. Just a direct conversation about Web, External Infrastructure, OSINT or Firewall reviews for authorised UK businesses.

A note on tone

The intro call should feel like a technical discovery chat, not a demo. You can ask uncomfortable questions: what you will not find, how noisy testing might be, what happens if production is fragile, and how findings are prioritised. Direct answers are part of the product. If a vendor dodges those questions, that is useful signal before you spend money.

For agencies and SaaS teams, bring constraints about client data and multi-tenant realities. For startups, bring the launch date and what “good enough before sales calls” means. For established SMEs, bring the legacy bits you are embarrassed about — those are usually where exposure hides. The more honest the input, the more precise the recommendation across Web, External Infrastructure, OSINT and Firewall.

Ready to talk it through?

Book a free intro call to see whether a focused Web, External Infrastructure, OSINT or Firewall review is the right first step. Authorised scope only.

← Back to blog index · Home