Process
A 3-call process built for trust, speed and clear scope.
Every engagement is handled directly by the person doing the assessment. No account manager handoff, no inflated agency language and no unclear scope.
Agency-style security buying often means many meetings and few decisions. BoundaryProof uses three calls: a free intro, a scope and prerequisites call, then a report debrief. The rhythm keeps founder-led work accountable without account-manager fog.
The design matches how SMEs actually buy. You want to know if there is a fit, what will be tested, what you will receive, and how to fix what matters. You do not want a theatre of steercos before anyone has looked at a single authorised asset.
Call 1 — Free intro
We discuss your business, concerns and exposed assets at a high level. We decide whether a focused Web, External Infrastructure, OSINT or Firewall review is the right first move. You should leave with a clearer path, not a pressure close. If we are not the right help, we say so.
The intro is a conversation only — not a free report, free scan, free OSINT, or permission to test. Book via Calendly or use the contact form.
Call 2 — Scope and prerequisites
Before work starts, we confirm authorisation, assets, access requirements, testing windows and safety constraints. This is where “authorised only” becomes concrete. Third-party targets without permission are refused. Ambiguous ownership is resolved. You know what is in and out of scope, and what we need from you to work efficiently.
Typical prerequisites include named authorising party, listed domains/URLs/hosts (or firewall rule exports), production versus staging clarity, emergency contact, and any fragile areas or rate limits we should respect.
Call 3 — Report debrief
You receive a clear report, then we walk through findings, business impact, recommended fixes and sensible next steps. Prioritised issues first. Evidence where appropriate. Practical remediation, not vague advice. Optional retest can follow once your team has had time to change things.
What sits between the calls
After a good intro: proposal and statement of work if it is a fit. Written authorisation for listed assets before any assessment work. Work against agreed scope. Report delivery. Invoice on the terms agreed. Optional fixed-item retest after you remediate.
What each call is not
The intro is not a free assessment. The scope call is not a place to renegotiate ethics around third-party targets. The debrief is not a sales pitch disguised as findings. Keeping those distinctions clean is how trust compounds.
More detail: Authorised only · What you get · Blog: the 3-call process · Start here
Ready to talk it through?
Book a free intro call to confirm fit, authorisation and scope. Prefer the form? Use the contact section on the main site.