Presumably legal, but morally gray.
I can rob people one at a time or I can go rob the bank. I can break into your clients one at a time or I can break into your "security" company.
Where is the product that keeps that data, your infrastructure safe? Why arent you selling that. Oh wait there is no such thing as it does not exist.
You are a compromise by a state level actor waiting to happen. In fact if you were compromised by a state level actor it is in your companies best interest to cover it up rather than disclose it (as that would be the end of your organization).
It's the fox guarding the hen house.
At some point were going to find out that a government, China, Russia, India.... used you, or one of your peers doing the same. This is taking off my shoes at the airport levels of stupid and ineffective.
I spend a fair bit of time talking to C-levels. The bulk of them use your services not because they think they are effective but because they know that they can point the finger at you when the shit hits the fan.