Capabilities
Digital infrastructure,in section.
Five layers of one system. You can take any of them on their own, but they are designed to be operated together, and that is where the cost of running things actually drops.
read · plan · cut
Advisory
We read the stack, the invoices, and the contracts, then say plainly what to keep, what to move, and what to stop paying for.
Two or three sessions, read-only access to what exists, and a written document at the end. No slides. The output is a plan you could hand to another supplier and they would understand it.
Included
- Stack review: what runs where, and what it costs
- Spend audit across hosting, SaaS, and model usage
- Sequenced roadmap with dependencies made explicit
- Migration plan, including the parts that will hurt
Deliberately not
- Ongoing retainers with no defined output
- Vendor introductions we are paid for
Priced as a fixed piece of work. If the conclusion is that you should change nothing, that is a valid result and you still get the document.
models · agents · pipelines
Automation & AI
Models wired into the parts of a stack where they earn their cost. Document pipelines, triage, internal tooling. Every action logged and reversible by a person.
Language models are useful in a narrow set of places: reading unstructured text, drafting, classifying, and routing. We wire them into those places, log every action, and leave a person able to undo anything.
Included
- Retrieval over your own documents, hosted where the data allows
- Agents with tool access, scoped and rate-limited
- Cost modelling before the build, and spend monitoring after
- Local or on-premises models where data residency requires it
- An audit trail of every write, and a rollback path
Deliberately not
- Autonomous systems with no human in the loop
- Chatbots bolted onto a marketing site
- Training foundation models
If a rules engine would do the job, we will tell you that instead. It is cheaper to run and easier to debug at 3am.
next.js · apis · integrations
Systems & web
The application on top of the infrastructure. Built in vertical slices, shipped weekly, handed over with the source and the runbook that operates it.
Applications built on the infrastructure underneath them rather than dropped on top of it. Next.js and TypeScript by default, because they are what we operate well, not because they are fashionable.
Included
- Design through build to launch, in weekly slices
- APIs, third-party integration, and data migration
- Performance and accessibility budgets agreed before the build
- Source, CI, and runbooks handed over at the end
Deliberately not
- Rescue work on a codebase nobody will let us change
Every project ends with a handover, whether or not you keep us on afterwards. The repository is yours from the first commit.
postfix · dkim · s/mime
Mail transport
Mail that arrives and is verifiably yours. We issue S/MIME keys on your domain, install them, and rotate them on a schedule, with SPF, DKIM and DMARC aligned underneath.
Mail is the part of infrastructure that fails quietly: it does not go down, it goes to spam. We run Postfix with DKIM signing, aligned SPF and DMARC, and S/MIME certificates issued on your domain, so replies are verifiably from you and land where they should.
Included
- Postfix and OpenDKIM, configured and monitored
- SPF, DKIM and DMARC aligned, with reports going somewhere a person reads
- S/MIME certificates issued, installed on your devices, and rotated
- Bounce handling and reputation monitoring
- Dedicated sending domains and separate streams for transactional mail
Deliberately not
- Bulk marketing sending: use an ESP built for it
- Cold outreach infrastructure
- Anything that would put a shared IP at risk
If mail already goes to spam, the first deliverable is a diagnosis of which hop is failing, not a rebuild.
linux · tls · backups
Hosts
Linux machines we provision, patch, and answer for. Certificates that renew, backups that restore, and a person on the other end of the pager.
A machine, configured for what you actually run, with someone whose job it is to keep it running. Debian or AlmaLinux, nginx in front, TLS renewed automatically, and a weekly patch window you know about in advance.
Included
- Provisioning, hardening, and weekly patching
- nginx, TLS certificates, and renewal monitoring
- DNS under management, with the zone file in your account
- Encrypted daily backups held off-site, with restores tested
- Systemd units, log rotation, and a written runbook
Deliberately not
- Multi-region active-active failover
- 24/7 follow-the-sun cover: we are one time zone
One primary node at OVHcloud RBX9. Documented failover, not automatic failover. Ask us what happens when the building loses power and you will get a specific answer.
Not sure which layer you need?
Describe what you are running now. We will tell you which parts are worth changing and which are fine as they are.
Open a brief