Legal
Terms of Service
Last updated: 24 September 2026
BoundaryProof Security — https://boundaryproof.co.uk/ — enquiries@boundaryproof.co.uk
United Kingdom · Law of England and Wales
1. Who we are
Services only: web assessment, external infrastructure assessment, OSINT assessment, and firewall review. No Cyber Essentials / CE+ product, managed SOC, or unrelated product sales via this site.
2. Acceptance
Using the site, submitting the intro-call form, booking Calendly, or engaging us means you accept these Terms and the Privacy Policy. If acting for a company, you confirm authority to bind it.
3. Website use
Lawful inbound business enquiries only. Do not misuse the site, submit false content, or ask us to discuss or target systems you are not authorised to commission. Site content is general information, not assurance for your organisation until scope is agreed in writing.
4. Intro calls and forms
The free intro call (form, email, or Calendly) is a fit discussion only. It is not an assessment, free OSINT or report, price guarantee, or legal / CE+ advice.
5. Authorised testing
You must only request assessment of systems you own or are authorised to commission. We test only against agreed assets with written permission, defined scope, prerequisites, and safety constraints.
Free intro ≠ free report ≠ permission to test.
We may refuse or stop work that appears unlawful, unauthorised, or outside our four services — including third-party or competitor targets without owner authorisation. See also Authorised only.
6. Engagements
Paid work needs clear written scope (email or statement of work): assets, authorisation, timing, deliverables, fees, and rules of engagement. Until agreed, we need not start. Security testing and reviews are point-in-time and cannot prove absence of all weaknesses.
7. Client duties
Provide timely access and accurate scope; maintain appropriate backups and change control; pay agreed invoices; decide which fixes to implement. You remain responsible for ongoing security of your systems.
8. Our limits
We work with reasonable care and skill as a founder-led practice. No guarantee of finding every issue or of fitness for a certification, tender, or insurance requirement unless expressly agreed in writing. Residual risk of careful testing (alerts, rare availability impact) is accepted when you authorise work.
9. Fees
As quoted, in GBP. Quotes are valid 30 days unless stated. Late payment may pause delivery.
10. IP and confidentiality
We keep methodologies and templates. On full payment you may use the report internally. Do not resell it or present it as CE+ / Cyber Essentials certification, or as another vendor’s work. Mutual confidentiality applies to non-public engagement information.
11. Liability
Nothing excludes liability that English law does not allow to be excluded. Subject to that: no indirect or consequential loss; total liability for an engagement is limited to the fees paid for that engagement in the 12 months before the claim.
12. Third-party tools
Netlify (hosting / forms) and Calendly (scheduling) have their own terms. We are not liable for their outages beyond reasonable control.
13. Cancellation
Cancel intros via Calendly or email. Paid work: per quote / statement of work. Either party may stop for material breach or if continuing would be unlawful. Pay for work properly performed.
14. Governing law
England and Wales. Contact enquiries@boundaryproof.co.uk first to resolve disputes informally.