Service
OSINT Assessment
Authorised OSINT exposure assessment for UK organisations — public information attackers reuse for phishing, impersonation and targeting.
An OSINT Assessment maps authorised public exposure — brand, domains, staff-facing footprints and leaked clues attackers reuse for phishing and recon. It is structured tidy-up work, not stalking and not a licence to look at any company.
At BoundaryProof, OSINT is one of four focused services with Web, External Infrastructure and Firewall. It exists because many SME incidents start with what was already public: email patterns, old documents, staff role maps, abandoned domains, and metadata that makes social engineering easy.
What it is
Structured review of domains, emails and metadata; staff and company exposure that is already online; and public breach or leak indicators relevant to your authorised scope. The deliverable is a prioritised picture of what to remove, monitor, train against or fold into technical follow-up.
We translate public facts into business risk. A forgotten PDF that lists internal naming conventions is not gossip — it is a mapping aid. A clear org chart plus a predictable mailbox format is not “just LinkedIn” — it is phishing fuel. Treating those as out-of-scope soft issues is how teams over-invest in tools and under-invest in exposure hygiene.
Who it is for
UK businesses worried about impersonation and phishing. Agencies protecting brands. SaaS teams preparing for customer due diligence. Founders who want a sober read on what the internet already knows before a funding or enterprise sales cycle.
It is not for individuals seeking personal investigations. It is not for requests to profile another company without authority. If that is the ask, we refuse.
What we need
Authorisation to assess your brand and domain footprint. Primary domains and known trade names. Notes on brands you are retiring or launching. Contacts for marketing and IT if takedowns will be needed. Any known past leak events you want considered.
Because sources are public, people sometimes skip authorisation. We do not. The engagement is still for a client who can act on findings and who owns the footprint in question.
What you get
Prioritised exposure findings, context for how someone hostile might use them, and practical recommendations: removals, monitoring, process changes, staff verification hardening, and pointers to Web or Infrastructure follow-ups where technical exposure overlaps. Debrief included. Retest optional when you have cleaned the highest-impact items.
What we will not do
We will not conduct personal investigations. We will not accept unauthorised third-party OSINT. We will not claim OSINT replaces technical testing. We will not hide behind the word research to excuse poor boundaries. No CE+ product. No “we look at any company” positioning.
How it pairs with other services
OSINT explains targeting. External Infrastructure shows reachability. Web shows application weakness. Firewall shows permit paths. Many clients start with one, then add another once the first report makes the next question obvious. The free intro call is where we choose the order with you.
Example starting scenarios
Your staff are being targeted with convincing invoice fraud. Your brand shows up in lookalike domains. Old PDFs still rank on search engines. A customer asks how you manage public exposure and phishing risk. OSINT gives you a structured answer rooted in what is already out there — then pairs with technical services when reachability or application issues show up too.
We keep the work professional and bounded. If a request slides toward investigating private individuals or unauthorised third parties, we stop and reset scope.
Fit with the rest of the site
OSINT is frequently underestimated because it does not always look like “technical testing”. It still produces prioritised, actionable output. It also often changes how leadership talks about phishing and brand abuse — moving from vague worry to a list of concrete clean-ups.
When OSINT points at technical exposure, we will say whether Web, External Infrastructure or Firewall is the logical follow-up. When the main work is takedown, process and monitoring, we will say that too. Honesty about what OSINT can and cannot fix is part of the service.
If your concern is public exposure and social-engineering fuel, book the free intro call. Confirm you can authorise the brand and domain footprint. We will keep boundaries clean and refuse requests that slide into unauthorised third-party investigation.
What “good enough” looks like after OSINT
High-impact public artefacts should be removed or mitigated. Brand impersonation risks should be visible to marketing and ops. Staff-facing processes that rely on weak verification should be tightened. Leadership should understand which exposures are cosmetic and which enable convincing fraud.
You should also have a short monitoring habit: periodic checks for lookalike domains, leftover documents and unexpected public mentions of internal system names. OSINT is not only a one-off clean-up; it is a way to install a lighter ongoing awareness without pretending you need a giant intelligence team.
When public findings point back to reachable systems or weak applications, we will recommend External Infrastructure or Web with clear reasons. That handoff is deliberate and authorised — never a slide into unscoped work.
Authorised scope and inbound buying
Even when sources are public, the engagement belongs to a client who can act on findings about their brand and domains. We will not run OSINT against competitors or random companies on request. Inbound only; no CE+ product; free intro ≠ free OSINT report.
Ready to talk it through?
Book a free intro call to confirm fit, authorisation and scope. Prefer the form? Use the contact section on the main site.
Also see: Web Assessment · External Infrastructure · Firewall Review · Start here
Out of scope for OSINT
OSINT here is authorised company-exposure mapping for brands and domains you own or control. It is not personal investigations, not stalking staff, not “looking someone up”, and not profiling competitors or random companies without authority. Even when sources are public, the engagement stays authorised.