Fyzno

Capabilities

Digital infrastructure,in section.

Five layers of one system. You can take any of them on their own, but they are designed to be operated together, and that is where the cost of running things actually drops.

read · plan · cut

Advisory

We read the stack, the invoices, and the contracts, then say plainly what to keep, what to move, and what to stop paying for.

Two or three sessions, read-only access to what exists, and a written document at the end. No slides. The output is a plan you could hand to another supplier and they would understand it.

Included

  • Stack review: what runs where, and what it costs
  • Spend audit across hosting, SaaS, and model usage
  • Sequenced roadmap with dependencies made explicit
  • Migration plan, including the parts that will hurt

Deliberately not

  • Ongoing retainers with no defined output
  • Vendor introductions we are paid for

Priced as a fixed piece of work. If the conclusion is that you should change nothing, that is a valid result and you still get the document.

models · agents · pipelines

Automation & AI

Models wired into the parts of a stack where they earn their cost. Document pipelines, triage, internal tooling. Every action logged and reversible by a person.

Language models are useful in a narrow set of places: reading unstructured text, drafting, classifying, and routing. We wire them into those places, log every action, and leave a person able to undo anything.

Included

  • Retrieval over your own documents, hosted where the data allows
  • Agents with tool access, scoped and rate-limited
  • Cost modelling before the build, and spend monitoring after
  • Local or on-premises models where data residency requires it
  • An audit trail of every write, and a rollback path

Deliberately not

  • Autonomous systems with no human in the loop
  • Chatbots bolted onto a marketing site
  • Training foundation models

If a rules engine would do the job, we will tell you that instead. It is cheaper to run and easier to debug at 3am.

next.js · apis · integrations

Systems & web

The application on top of the infrastructure. Built in vertical slices, shipped weekly, handed over with the source and the runbook that operates it.

Applications built on the infrastructure underneath them rather than dropped on top of it. Next.js and TypeScript by default, because they are what we operate well, not because they are fashionable.

Included

  • Design through build to launch, in weekly slices
  • APIs, third-party integration, and data migration
  • Performance and accessibility budgets agreed before the build
  • Source, CI, and runbooks handed over at the end

Deliberately not

  • Rescue work on a codebase nobody will let us change

Every project ends with a handover, whether or not you keep us on afterwards. The repository is yours from the first commit.

postfix · dkim · s/mime

Mail transport

Mail that arrives and is verifiably yours. We issue S/MIME keys on your domain, install them, and rotate them on a schedule, with SPF, DKIM and DMARC aligned underneath.

Mail is the part of infrastructure that fails quietly: it does not go down, it goes to spam. We run Postfix with DKIM signing, aligned SPF and DMARC, and S/MIME certificates issued on your domain, so replies are verifiably from you and land where they should.

Included

  • Postfix and OpenDKIM, configured and monitored
  • SPF, DKIM and DMARC aligned, with reports going somewhere a person reads
  • S/MIME certificates issued, installed on your devices, and rotated
  • Bounce handling and reputation monitoring
  • Dedicated sending domains and separate streams for transactional mail

Deliberately not

  • Bulk marketing sending: use an ESP built for it
  • Cold outreach infrastructure
  • Anything that would put a shared IP at risk

If mail already goes to spam, the first deliverable is a diagnosis of which hop is failing, not a rebuild.

linux · tls · backups

Hosts

Linux machines we provision, patch, and answer for. Certificates that renew, backups that restore, and a person on the other end of the pager.

A machine, configured for what you actually run, with someone whose job it is to keep it running. Debian or AlmaLinux, nginx in front, TLS renewed automatically, and a weekly patch window you know about in advance.

Included

  • Provisioning, hardening, and weekly patching
  • nginx, TLS certificates, and renewal monitoring
  • DNS under management, with the zone file in your account
  • Encrypted daily backups held off-site, with restores tested
  • Systemd units, log rotation, and a written runbook

Deliberately not

  • Multi-region active-active failover
  • 24/7 follow-the-sun cover: we are one time zone

One primary node at OVHcloud RBX9. Documented failover, not automatic failover. Ask us what happens when the building loses power and you will get a specific answer.

Not sure which layer you need?

Describe what you are running now. We will tell you which parts are worth changing and which are fine as they are.

Open a brief