BoundaryProof Blog

OSINT assessment vs “looking someone up”

UK founder notes ← All posts

OSINT here means authorised company-exposure mapping — not stalking staff or digging into private lives.

People hear “OSINT” and imagine someone trawling social media for gossip. That is not what an OSINT assessment means at BoundaryProof. It is structured, authorised company-exposure work — public sources, practical tidy-up, no stalking.

Looking someone up casually is not a service offering. We do not investigate private individuals for curiosity, disputes or third-party fishing trips. If you ask us to profile a person or company you do not have authority to assess, we refuse. Authorised-only is not a slogan; it is how the work stays legal and professional.

What company OSINT actually covers

Typical scope includes domains and email patterns, public metadata, staff and company exposure that is already online, and public breach or leak indicators that might affect your users or admins. The question is: what can an attacker learn without breaking into anything, and how would that help them craft a convincing attack?

That might include forgotten subdomains, exposed documents, reused branding that enables impersonation, or staff details that make password resets and helpdesk social engineering easier. It is about business risk, not sensational personal dossiers.

Why SMEs underestimate public exposure

Smaller teams move fast. Marketing publishes, developers leave staging clues, old microsites linger, and LinkedIn profiles quietly map your org chart. None of that requires exotic tooling to abuse. A structured OSINT review turns scattered public facts into a prioritised picture: what to remove, what to monitor, what to train staff about, and what to fold into Web or Infrastructure follow-up.

OSINT also complements the other three services. External Infrastructure finds what is reachable. Web assessment finds what is weak on applications. Firewall review finds what your perimeter allows. OSINT finds what the internet already knows about you — which often explains how an attacker would choose targets in the first place.

Boundaries that matter

We will not claim we look at any company. We work with clients who own or are authorised to review the brand, domains and public footprint in scope. We will not sell OSINT as a way to surveil competitors’ staff. We will not mix OSINT with unauthorised access. If your concern is better framed as a Web or Infrastructure review, we will say so rather than stretch the label.

If you are unsure whether your public footprint is helping attackers, book the free intro call. Bring your domains and a plain description of what you are worried about. We will decide together whether OSINT is the right first step, or whether another focused service gets you clearer value faster.

Outputs you can give to non-security people

A good OSINT report should be readable by a founder, an ops lead and a marketing owner without a translator. Public exposure often cuts across those roles: take down this document, change this process, monitor this brand abuse pattern, tighten this helpdesk verification step. That cross-functional clarity is why OSINT belongs beside technical reviews rather than in a shadowy corner.

If your worry is purely application bugs, we may steer you to Web first. If your worry is open services, External Infrastructure may lead. OSINT is for the public-knowledge problem. Naming the problem correctly prevents buying the wrong work and calling it research.

Ready to talk it through?

Book a free intro call to see whether a focused Web, External Infrastructure, OSINT or Firewall review is the right first step. Authorised scope only.

← Back to blog index · Home