BoundaryProof Blog
The 3-call process: intro, scope, debrief
Intro, scope, debrief — three calls that keep founder-led assessments fast and free of account-manager fog.
Agency-style security buying often means many meetings and few decisions. BoundaryProof uses three calls: a free intro, a scope and prerequisites call, then a report debrief. The rhythm keeps founder-led work accountable without account-manager fog.
The design matches how SMEs actually buy. You want to know if there is a fit, what will be tested, what you will receive, and how to fix what matters. You do not want a theatre of steercos before anyone has looked at a single authorised asset.
Call 1 — Free intro
We discuss your business, concerns and exposed assets at a high level. We decide whether a focused Web, External Infrastructure, OSINT or Firewall review is the right first move. You should leave with a clearer path, not a pressure close. If we are not the right help, we say so.
Call 2 — Scope and prerequisites
Before work starts, we confirm authorisation, assets, access requirements, testing windows and safety constraints. This is where “authorised only” becomes concrete. Third-party targets without permission are refused. Ambiguous ownership is resolved. You know what is in and out of scope, and what we need from you to work efficiently.
Call 3 — Report debrief
You receive a clear report, then we walk through findings, business impact, recommended fixes and sensible next steps. Prioritised issues first. Evidence where appropriate. Practical remediation, not vague advice. Optional retest can follow once your team has had time to change things.
Why this converts better than a black box
Buyers trust what they can see. Direct access to the assessor reduces the fear that findings will arrive as an unread PDF from someone who never met you. The process also protects delivery quality: scoping is tighter, expectations are shared, and debrief time is reserved rather than bolted on.
Services stay within the four focused reviews. There is no CE+ product and no claim that we assess any company. The calls exist to make Web, Infra, OSINT and Firewall work accountable and usable for UK startups, SMEs, agencies and SaaS teams.
If that sounds like how you prefer to buy, book the free intro call or use the contact form. Bring a short description of what you run and what you want reviewed. We will take it from there — carefully, and only with authorisation.
Scheduling without losing momentum
Intro to scope should not take months. If assets and authorisation are ready, the process moves. If they are not, the gap is usually organisational, not technical — finding who can say yes. Use the intro call to identify that person. Use the scope call to lock details. Keep assessment dates realistic around releases and peak trading.
The debrief should land close enough to delivery that context is fresh, but not so rushed that remediations cannot be discussed with the people who will implement them. We plan that with you rather than forcing a generic timeline.
What each call is not
The intro is not a free assessment. The scope call is not a place to renegotiate ethics around third-party targets. The debrief is not a sales pitch disguised as findings. Keeping those distinctions clean is how trust compounds across engagements and referrals.
If your organisation needs procurement paperwork between calls, say so early. We can work with that reality without turning the process into six unnecessary meetings. The three calls are the spine; documents can sit around them without replacing them.
Ready to talk it through?
Book a free intro call to see whether a focused Web, External Infrastructure, OSINT or Firewall review is the right first step. Authorised scope only.