Loading
Xavier Boone

How the work runs

Same three stages, either practice

Scope first, so nobody is surprised by the invoice or the findings. Then the work. Then a handover that survives my leaving.

  1. Stage 01

    Scope and agree

    What's in, what's out, what success looks like, and what it costs. For security work this includes written authorization and testing windows.

  2. Stage 02

    Build or test

    Regular check-ins with something real to look at — a staging URL, or an interim list of findings ranked by what would actually hurt.

  3. Stage 03

    Hand over

    Source, credentials, and plain-language docs. For assessments, a remediation list your developers can work straight from, plus a retest.

Background

Short version

I started at a small community college, coding in Python and studying systems and workflows, and I kept ending up in the same place: small businesses buy a plethora of productivity services without the know-how to optimize them for their use case.

As time has passed, AI has matured and those businesses have grown. I help them scale — without scaling their attack surface.

Currently

Open to: freelance design builds, security assessments, and part-time contract work.

Based in: the NJ–NY–DE–PA corridor — on-site across the region, remote anywhere.

Typical turnaround: two to six weeks depending on scope.

Blog & Thoughts

Latest pieces

Notes from both practices, written for the person who has to act on them.

Part one of a build series: pfSense on a two-port mini PC, for roughly what a Netgate 1100 costs but with considerably more compute behind it. Parts list with prices, the install, interface assignment, and the two kernel panics I hit on the way through.

Read it · The pfSense series · All posts

Enterprise security stacks are dense, costly, and staffed. At home, the three things everyone actually needs are usually already bundled into a carrier plan or a credit card. There are a number of steps an individual can take to lock down their home environment without paying for the same protection twice.

Read it · All posts

Contact

Tell me what you're working on

A sentence or two about the project and your timeline is enough to start. If it's a security engagement, mention what you own and who can authorize testing.