BoundaryProof Blog

When you should not hire BoundaryProof

UK founder notes ← All posts

Good fit matters. Here is when we steer you away — and what that says about how we work.

A useful security partner tells you when not to buy. BoundaryProof focuses on Web, External Infrastructure, OSINT and Firewall reviews for authorised UK businesses. That narrowness is intentional — and it means we are the wrong choice in several situations.

You need unauthorised testing

If you want someone to probe a third-party target without permission, do not hire us. We refuse. Full stop. Get proper authorisation or use lawful channels. Curiosity is not a statement of work.

You need a huge multi-team programme on day one

If your requirement is a large consultancy circus with account managers, steercos and a dozen workstreams before anyone touches an asset, we are not trying to look like that. We are trying to deliver practical exposure reviews with direct access to the assessor.

You only want a certificate sticker

If the goal is a logo for a slide and no interest in fixing findings, we will be a frustrating partner. Reports are built for remediation and debrief, not theatre.

Your need sits outside the four services

We do not sell a CE+ product or claim we cover every security discipline. Malware labs, physical intrusion, assessing arbitrary internet companies, or indefinite retainer “hacking on demand” are not the offer. If your need is clearly something else, the intro call is where we say so.

You cannot identify who authorises scope

Shared environments and client systems need clear permission. If nobody can authorise, we cannot start. That protects everyone.

When we are a good fit, the opposite is true: you want focused reviews, clear reports, a 3-call process, and a specialist who will not inflate the engagement. Book the free intro call if that is you. If it is not, you have saved both of us time — which is also a successful outcome.

A quick self-check before you book

Can you authorise the assets? Do you want findings you will actually fix? Does your need map to Web, External Infrastructure, OSINT or Firewall? Are you comfortable with a direct specialist rather than a large account team? If you answered yes, it is worth a free intro call. If you answered no to authorisation or remediation intent, hiring anyone serious will feel uncomfortable — and it should.

Saying no to the wrong work is how we protect the quality of the right work. That is not gatekeeping for its own sake. It is how a small practice stays reliable.

What we will happily help you decide instead

Even when we are not the right delivery partner, a free intro call can still be useful. We can help you name the problem category, spot an authorisation gap, or confirm that your first move should be internal tidy-up rather than an external assessment. That honesty is part of founder-led sales.

If you need a large firm for contractual reasons, we will not pretend otherwise. If you need something outside Web, Infra, OSINT and Firewall, we will not invent a service name to win the work. Long-term reputation beats a short-term invoice.

The buyers we serve best are practical, authorised, and ready to remediate. If that is your posture, you are likely in the yes column.

Ready to talk it through?

Book a free intro call to see whether a focused Web, External Infrastructure, OSINT or Firewall review is the right first step. Authorised scope only.

← Back to blog index · Home