# Fyzno — everything in one file > Everything digital is physical somewhere. Fyzno runs the machines your product sits on, the path your mail takes to reach an inbox, and the code on top of both. Managed hosting, SMTP with S/MIME, web builds, and automation, run from the Netherlands. This is the long form of https://fyzno.com/llms.txt. It inlines the copy from every page except the two binding legal documents and the live status data, both of which are linked because a stale copy of either would be worse than none. - Map: https://fyzno.com/llms.txt - Live status, machine-readable: https://fyzno.com/api/status - Binding terms: https://fyzno.com/legal/terms/full - Privacy policy: https://fyzno.com/legal/privacy ## The argument Your website lives in a building in Gravelines, France. We can name the facility, the upstream, and the last thing that went wrong with it. On 22 February 2026 that was OVH rerouting our gateway during scheduled backbone maintenance; the host was unreachable for four minutes. Most providers describe infrastructure in the abstract. Abstraction holds up right until something breaks, and then it is worth nothing to you. ## What we run Five layers of one system. You can take any of them on their own, but they are designed to be operated together, and that is where the cost of running things actually drops. ### Hosts — linux · tls · backups A machine, configured for what you actually run, with someone whose job it is to keep it running. Debian or AlmaLinux, nginx in front, TLS renewed automatically, and a weekly patch window you know about in advance. Includes: - Provisioning, hardening, and weekly patching - nginx, TLS certificates, and renewal monitoring - DNS under management, with the zone file in your account - Encrypted daily backups held off-site, with restores tested - Systemd units, log rotation, and a written runbook Does not include: - Multi-region active-active failover - 24/7 follow-the-sun cover: we are one time zone Note: One primary node at OVHcloud RBX9. Documented failover, not automatic failover. Ask us what happens when the building loses power and you will get a specific answer. ### Mail transport — postfix · dkim · s/mime Mail is the part of infrastructure that fails quietly: it does not go down, it goes to spam. We run Postfix with DKIM signing, aligned SPF and DMARC, and S/MIME certificates issued on your domain, so replies are verifiably from you and land where they should. Includes: - Postfix and OpenDKIM, configured and monitored - SPF, DKIM and DMARC aligned, with reports going somewhere a person reads - S/MIME certificates issued, installed on your devices, and rotated - Bounce handling and reputation monitoring - Dedicated sending domains and separate streams for transactional mail Does not include: - Bulk marketing sending: use an ESP built for it - Cold outreach infrastructure - Anything that would put a shared IP at risk Note: If mail already goes to spam, the first deliverable is a diagnosis of which hop is failing, not a rebuild. ### Systems & web — next.js · apis · integrations Applications built on the infrastructure underneath them rather than dropped on top of it. Next.js and TypeScript by default, because they are what we operate well, not because they are fashionable. Includes: - Design through build to launch, in weekly slices - APIs, third-party integration, and data migration - Performance and accessibility budgets agreed before the build - Source, CI, and runbooks handed over at the end Does not include: - Rescue work on a codebase nobody will let us change Note: Every project ends with a handover, whether or not you keep us on afterwards. The repository is yours from the first commit. ### Automation & AI — models · agents · pipelines Language models are useful in a narrow set of places: reading unstructured text, drafting, classifying, and routing. We wire them into those places, log every action, and leave a person able to undo anything. Includes: - Retrieval over your own documents, hosted where the data allows - Agents with tool access, scoped and rate-limited - Cost modelling before the build, and spend monitoring after - Local or on-premises models where data residency requires it - An audit trail of every write, and a rollback path Does not include: - Autonomous systems with no human in the loop - Chatbots bolted onto a marketing site - Training foundation models Note: If a rules engine would do the job, we will tell you that instead. It is cheaper to run and easier to debug at 3am. ### Advisory — read · plan · cut Two or three sessions, read-only access to what exists, and a written document at the end. No slides. The output is a plan you could hand to another supplier and they would understand it. Includes: - Stack review: what runs where, and what it costs - Spend audit across hosting, SaaS, and model usage - Sequenced roadmap with dependencies made explicit - Migration plan, including the parts that will hurt Does not include: - Ongoing retainers with no defined output - Vendor introductions we are paid for Note: Priced as a fixed piece of work. If the conclusion is that you should change nothing, that is a valid result and you still get the document. ## How the work is run The person who answers your mail is the person with root. That is the whole pitch, and it is the reason the rest of this site can be specific. ### One primary, documented There is no multi-region failover cluster here. There is one well-understood machine at OVHcloud in Gravelines, a written failover design, and encrypted daily backups held in Strasbourg. Knowing exactly where your single point of failure is beats not knowing where six of them are. ### Written before built Hosts, mail routing, certificates, models, and backups are laid out in writing before anything is provisioned. If the plan cannot survive a read-through, it will not survive production. ### You keep the keys Source, runbooks, DNS, and the accounts stay yours throughout. Ending an engagement is a handover, not an extraction. ### We say no in writing If something is outside what we can operate well, we will say so and point you somewhere better. A referral costs less than a bad quarter. ## On the record 22 February 2026. OVH rerouted the Gravelines gateway during scheduled backbone maintenance and the host was unreachable for four minutes. We called every affected customer inside a day and confirmed nothing was lost. The cause was upstream. The write-up is public anyway. Every incident since is published at https://fyzno.com/status, whether or not the cause was ours. ## link.in-my.bio A single link that holds everything you point people at. Built by hand, hosted on the same infrastructure as everything else here, and yours to change whenever you want. - **Built, not generated**: You describe it; we build it. No drag-and-drop editor to fight, no template you have to bend into shape, no watermark at the bottom. - **A real address**: link.in-my.bio/yourname, live on a certificate that renews itself. Bring your own domain instead if you would rather. - **Fast, and nothing tracking you**: Static pages, no cookie banner, no analytics scripts, no third-party fonts. It loads before a visitor notices it was loading. - **Changes are a message**: New link, new photo, different colour: send a note and it is live the same day. No dashboard to remember the password for. Four starting points: Each one is a real template, not a mockup. Pick the closest and we adjust it to you: type, spacing, and colour all move. What it costs: Quoted in the reply, once we have seen what you want. It is a small, fixed price for the build and a small one per year for hosting. You will have both numbers in writing before anything starts. Product site: https://link.in-my.bio ## Engagement terms, plain language (last updated 3 July 2026) Quoted verbatim from https://fyzno.com/legal/terms. The binding document is at https://fyzno.com/legal/terms/full and it governs. ### 01 · Provider — Who you're engaging fyzno is a digital infrastructure studio based in the Netherlands. We provide managed web hosting, managed SMTP, web development, AI integrations and AI workflows. Anything we call a sub-processor or partner in the written scope of your engagement is part of fyzno for the purposes of these terms. ### 02 · Engagement — How a project begins Every project begins with a written scope and a written price. The scope names the deliverables, the timeline, the assumptions and the boundary of what is out of scope. A signed scope fixes its price for that scope; list prices for new work can change. Work begins only after both parties have signed. Verbal agreements are not engagements. ### 03 · Uptime & SLA — Quarterly 99.9% target, missed = contacted For managed hosting and managed SMTP we commit to a quarterly uptime SLA of 99.9% on managed infrastructure. If we miss the threshold in any given quarter, we contact you on the same business day with a written post-mortem. We don't bury incidents behind auto-credit or marketing copy. See § 06 for the operational reality behind this number. ### 04 · Confidentiality — What we keep Anything you share in the course of an engagement, including source, credentials, customer data and contracts, stays confidential. We sign your NDA if you have one. If you don't, ours is in the default scope and binds every named partner and sub-processor. ### 05 · Data & hosting — Where the work lives Production workloads run in the EU by default. AI workloads involving personal data can be run on private infrastructure on request. We don't sell or trade customer data. Backups are encrypted at rest and held for at least thirty days, with encrypted daily backups retained in Strasbourg off the primary site. You remain responsible for keeping your own copies of your data. ### 06 · Operational honesty (SLI) — One primary node. Zero pretending. We run a single primary node today, in OVHcloud's Gravelines site, with a documented failover design and encrypted off-site backups. We are actively implementing a second operational node plus a separate backup node; the migration plan is written and progress is public on /status. We don't claim multi-region high availability we haven't shipped, and we don't sell uptime we can't measure. When something is wrong, we contact you as soon as we know, usually within minutes, and we figure out the next step together: a prorated refund for the affected period, a free extension of the term, or hands-on help getting your environment back on track. If we miss the bar, we make it right. ### 07 · Payment & renewal — Invoices, subscriptions, and what happens if one goes unpaid Project work is invoiced monthly in arrears and payable within fourteen days. Managed services (hosting, SMTP) run per term and renew automatically unless cancelled before the renewal date; you manage the cancellation, we don't make it hard. Late payment pauses non-critical project work first. Sustained non-payment can suspend or, ultimately, terminate managed services; the full document spells that power out bluntly, but we will always contact you before anything is switched off. ### 08 · Termination — Leaving cleanly Either party may end an engagement with thirty days' written notice. On termination we hand back source, credentials, runbooks and a written export of any data we held. After thirty days we delete our copies and send you the deletion certificate. Separately, access to the public Services themselves can be ended as described in § 15 of the full document: that clause protects the platform; your engagement deliverables are governed by the signed scope. ### 09 · Disclaimer & Liability — Maximum legal exclusion We provide our services on an "AS IS" basis and exclude all liability to the absolute maximum extent permitted by mandatory EU and Dutch law. Where liability fundamentally cannot be waived (such as willful misconduct, gross negligence under Burgerlijk Wetboek art. 6:75, or death), our aggregate liability is strictly capped at the fees paid to us in the six months preceding the claim. You also indemnify us against third-party claims arising from your use of the services. ### 10 · Governing law — Dutch law, Dutch courts These terms are governed by the laws of the Netherlands. Disputes are settled first by good-faith discussion; if that fails, exclusively in the competent Dutch courts. Claims must be brought within one year of the cause arising. ## Where it runs OVHcloud RBX9, Gravelines, France (51.01°N 2.13°E). Encrypted daily backups are held in Strasbourg, off the primary site. Single primary node today. A second operational node and a separate backup node are being implemented; the failover design and the migration plan are written down and progressively being rolled out. Sub-processors, complete (GDPR art. 28): - OVHcloud — Hosting. The physical machine the site, the contact ledger and the mail server run on. Gravelines, France (RBX9). GDPR art. 28 data processing agreement. EEA only. - OVHcloud — Backup storage. Encrypted daily snapshots of the same machine. Strasbourg, France. GDPR art. 28 data processing agreement. EEA only. There is no CDN, no analytics, no third-party fonts, and no third-party scripts of any kind. ## How to reach a person Tell us what you are running now and what you want it to do. No form letters back. The person who replies is the person who would do the work. - Brief: https://fyzno.com/brief - Email: info@fyzno.com. Reply within 48 hours, S/MIME-signed. - Phone: +31 9700 859 9562. Inbound only. The caller pays. - Hours: Mon–Fri · 09:00–18:00 CET. Generated at build time from the same content that renders https://fyzno.com.