Solutions
Everything you cancommission.
The capabilities page is how the work is organised. This is the menu: the individual things a client can actually ask for, each one a real thing we operate on Linux and can point to. If what you need is not here, ask. The turned-down list is short, and it is honest.
debian · nginx · tls
Managed Linux hosts
A server configured for what you actually run, not a generic box with your site parked on it. We provision it, harden it, patch it weekly, and a named person answers for it when it misbehaves.
Included
- Debian or AlmaLinux, hardened and patched weekly
- nginx in front, certificates renewed automatically
- DNS under management, the zone file in your account
- Encrypted daily backups held off-site, with restores tested
Multi-region active-active is usually a different shop's job. We will point you to the right one, and if you genuinely need it we will scope and build it.
postfix · dkim · s/mime
Mail that lands
Mail is the part that fails without warning: it does not go down, it goes to spam. We run Postfix with DKIM, aligned SPF and DMARC, and S/MIME keys issued on your domain, so a reply is verifiably from you.
Included
- Postfix and OpenDKIM, configured and monitored
- SPF, DKIM and DMARC aligned, with reports a person actually reads
- S/MIME keys issued, installed on your devices, and rotated
- Bounce handling and reputation monitoring
Bulk marketing sending and cold outreach. Those need an ESP built for it.
next.js · typescript · apis
Web applications
The application on top of the infrastructure, built in weekly slices and shipped as working pieces rather than a diagram. You get the source, the CI, and the runbook that operates it.
Included
- Design through build to launch, in weekly slices
- APIs, third-party integration, and data migration
- Performance and accessibility budgets set before the build
- Source, CI and runbooks handed over at the end
Rescue work on a codebase nobody will let us change.
postgres · redis · backups
Databases and data
The data your app depends on, set up properly rather than bolted on. PostgreSQL or MariaDB, caching in Redis, migrations that can be rolled back, and backups you can actually restore from.
Included
- PostgreSQL or MariaDB, tuned for your workload
- Redis for caching and queues where it earns its place
- Schema migrations with a rollback path
- Point-in-time backups and restores that are tested
A shared public database for other tenants. Yours, and only yours.
nftables · tls · audit
Hardening and security
The unglamorous work that keeps a server honest. A firewall with a small, known open surface, current TLS with HSTS, security headers, patching on a schedule, and logs that go somewhere a person looks.
Included
- nftables or UFW, with the fewest open ports that still work
- TLS with HSTS and a strict security-header set
- fail2ban and account hardening
- Patching on a schedule, with a written audit trail
A security audit signed off by an external firm. We harden; we point you to who certifies.
prometheus · grafana · status
Monitoring and on-call
If it is running, it is being watched. Metrics, logs, and uptime go to dashboards and alerts, and the state of it is published on a status page you can link to instead of emailing us to ask.
Included
- Prometheus and Grafana for metrics and dashboards
- Uptime checks with a public status page and feed
- Log aggregation you can read back later
- Alerts to a named person, not a dead mailing list
24/7 follow-the-sun cover. We are one time zone, and we will tell you when we are asleep.
docker · podman · jobs
Containers and services
The services around your app: a search index, a worker, a scheduler. We package them as containers with health checks, run them on a single well-understood host, and keep the images rebuildable from source.
Included
- Docker or Podman, with stacks described in a file you can read
- Health checks and automatic restarts
- Scheduled jobs and queue workers that survive a reboot
- Image builds you can reproduce from source
Kubernetes at multi-node scale. For what we run, one host and a good runbook is the honest tool.
meilisearch · rag · embeddings
Search and retrieval
Find things in your own data, on your own hardware where the data requires it. A search index over your content, or retrieval wired to a model, with results you can audit rather than a black box. Your data is never used to train a model, ours or anyone else's.
Included
- Meilisearch or Typesense for fast, filterable search
- Retrieval over your own documents, hosted where it is allowed
- Embeddings and reranking, tuned to your corpus
- Local or on-premises models where residency requires it
Training foundation models. We retrieve and route; we do not train base models.
cutover · runbooks · keys
Migrations and handover
Leaving shared hosting or another provider without a surprise. We plan the cutover in writing, move the domain and the data, and hand over everything so you are never locked to the person who built it.
Included
- A written migration plan with the cutover window
- Domain, DNS, data and certificates moved without loss
- Runbooks and credentials handed over, yours from day one
- A read-only review of your current stack before we touch it
Ongoing retainers with no defined output. A plan is a deliverable; a body is a different contract.
Not sure what you need?
Describe what you are running now. We will tell you which of these you actually need, and which ones you can skip.