Services

Do you need my passwords or access to my accounts?

No.

We do not need passwords, one-time codes, recovery credentials or private account access for our services.

If anyone claiming to represent Principia Works asks you for one of those things, do not provide it.

Is an Exposure Assessment a penetration test?

No.

A penetration test actively evaluates technical systems for vulnerabilities.

An Exposure Assessment looks from the outside at publicly accessible information and what that information reveals when connected.

The two services can complement each other, but they answer different questions.

Do you fix everything you find in an Exposure Assessment?

The assessment includes recommendations for reducing relevant exposure.

Where something can be addressed externally and falls within the agreed scope, we may be able to assist.

Changes requiring access to your accounts or systems remain under your control.

We are not positioning Principia Works as a general device-hardening or IT-support service.

What makes this different from Googling myself?

Searching your own name can be useful.

An assessment goes further by examining multiple sources, documenting evidence, connecting related findings and considering what the combined information could make possible.

The risk often sits in the relationship between several ordinary details rather than one dramatic discovery.

What makes Principia Intelligence different from an automated OSINT tool?

Automation is useful for searching and organising information.

It is not enough on its own.

Principia Intelligence combines technology with analyst review.

Significant findings are checked, evidence is documented and conclusions are separated from assumptions.

Security awareness

Is your training just phishing awareness?

No.

Phishing is part of the problem, but social engineering can involve WhatsApp, phone calls, payment requests, voice cloning, compromised communication channels and other forms of impersonation.

Training is adapted to the audience and the organisation's needs.

Can you tailor the training to our organisation?

Yes.

Where appropriate, we review relevant public information and organisational context before building the session.

The exact depth depends on the agreed scope.

Do you run phishing simulations?

They can be included where appropriate.

The purpose is to improve behaviour and understand patterns, not embarrass individual employees.

How results are handled and reported is agreed before the simulation begins.

Do you cover AI voice clones and deepfakes?

Yes.

Synthetic voice, video and AI-generated messages are relevant to modern impersonation.

The important lesson is not that nothing can be trusted.

It is that sensitive instructions should not depend on appearance or voice alone.

OSINT and investigations

Can Principia Intelligence investigate anyone?

No.

We require a legitimate purpose and an appropriate basis for investigative work.

The research must have a defined scope.

We do not provide unrestricted personal investigations simply because somebody is curious about another person.

Can you investigate job candidates?

Employment-related research may be possible where it is lawful, proportionate, appropriately authorised and relevant to a legitimate hiring or risk question.

We do not support indiscriminate digging into somebody's private life.

The scope must match the reason for the research.

Can you help law enforcement?

Principia Intelligence is designed to be capable of supporting authorised investigative work where the engagement falls within our competence and appropriate authority exists.

The fact that a request comes from an institution does not remove the need for scope, evidence handling and clear purpose.

Can you locate someone?

Public information may sometimes help establish a timeline, location history or relevant activity.

Principia Works does not offer unrestricted real-time tracking of people as a general service.

Any location-related research requires an appropriate purpose, authority and scope.

Can you access private social media accounts?

No.

We do not bypass account privacy controls or use stolen credentials.

Do you impersonate people during investigations?

Not as part of the services described on this site.

Our work is based primarily on public or otherwise appropriately authorised information.

Can you guarantee that OSINT findings are complete?

No.

Public information changes constantly.

Content can be removed, hidden, misreported, duplicated or unavailable to us.

A report describes what we were able to establish from the sources and scope available at the time.

What happens if two sources disagree?

We document the conflict rather than silently choosing the version we prefer.

Where possible, we look for additional sources.

If the conflict cannot be resolved reliably, the uncertainty remains part of the finding.

Privacy and scope

Is everything you research already public?

Our standard research is based on information that is publicly accessible or otherwise lawfully provided or authorised for the engagement.

We do not bypass technical controls to obtain information.

Does public mean harmless?

No.

A collection of public information can become significantly more sensitive when it is brought together and analysed.

We treat resulting reports and case material accordingly.

When does research begin?

After the engagement has been scoped and the required authority, approval or consent has been established.

We do not conduct speculative investigations on potential clients simply to demonstrate what we can find.

What happens to the information you collect?

Retention and handling depend on the engagement and are defined in the relevant agreement.

We aim to retain sensitive research material only for as long as it is needed for the purpose for which it was collected.

Practicalities

Why are there no fixed prices on the website?

The work depends heavily on scope.

A single-person exposure assessment, a leadership workshop and an investigation involving several organisations require very different amounts of research and analysis.

We therefore define the work first and provide the fee in writing before it begins.

How long does an engagement take?

It depends on the scope.

The proposal sets out the expected timeline before you commit.

Do you work outside Windhoek?

Yes.

Research and briefings can be carried out remotely.

In-person training outside Windhoek can be arranged where practical.

Do you work outside Namibia?

Potentially.

Remote OSINT and advisory work can cross borders, but legal, privacy and data-handling requirements may affect what we can accept.

Something is happening right now. Can you help?

Principia Works is not an emergency incident-response service.

If money is actively at risk, contact the relevant financial institution immediately.

If systems are actively compromised, contact your IT or incident-response provider.

Where criminal conduct may be involved, contact the appropriate authorities.

We may be able to help investigate the social-engineering or public-information component after the immediate incident has been contained.

Question not answered?info@principiaworks.net

Start with the problem, not the service.

You do not need to know exactly what you need before contacting us.

Tell us what happened, what concerns you or what you are trying to understand.

We will tell you whether Principia Works is the right fit and what the next step would involve.