Four services. Fixed scope. Nothing you cannot take over yourself.
Every engagement is delivered as code, documented in runbooks and handed to you in your own accounts and repositories. If you replace us next year, everything still works.
Self-Hosted AI
Run open-weight models on hardware you control — no per-token bill, no data leaving your perimeter.
See what this costsWhat is included
- vLLM, Ollama and llama.cpp inference servers, tuned for your GPUs
- Open WebUI / API gateway with SSO, per-user quotas and audit logs
- Retrieval-augmented generation over your own documents and databases
- Whisper transcription, embeddings and image models on the same stack
- GPU sizing, procurement guidance and thermal/power planning
Cloud Foundation
The boring layer done properly: networking, identity, environments and deploys that survive an audit.
See what this costsWhat is included
- AWS, Hetzner, OVH, Proxmox or bare metal — chosen on cost, not habit
- Infrastructure as code in Terraform/OpenTofu with reviewed state
- Docker Compose or Kubernetes, sized to the team that has to run it
- CI/CD pipelines with staged rollouts and one-command rollback
- Zero-trust remote access over WireGuard or Tailscale
Migration & Cost Rescue
Move off the meter. Most workloads leave hyperscalers 40–70% cheaper without losing reliability.
See what this costsWhat is included
- Workload inventory, dependency mapping and a costed target design
- Rehost or re-platform with a tested cutover and rollback window
- Database migration with replication and verified data integrity
- Egress, storage-tier and reserved-capacity cost modelling
- Post-move FinOps dashboard so savings stay visible
Security, Backup & DR
Backups you have actually restored from, and a recovery plan someone else can follow at 3am.
See what this costsWhat is included
- CIS-aligned hardening baseline applied through code
- 3-2-1 backups with immutable off-site copies and restore drills
- Documented RPO/RTO targets with a rehearsed failover runbook
- Centralised logging, metrics and on-call alerting that pages a human
- Secrets management, certificate automation and patch pipelines
Tooling
Open, standard, and boring on purpose.
No proprietary agents, no bespoke framework only we understand. Every tool below is open source or an industry default, which is what makes handover — and replacing us — genuinely possible.
Cloud & metal
- AWS
- Hetzner
- OVHcloud
- DigitalOcean
- Proxmox VE
- Bare metal & colocation
Infrastructure
- Terraform / OpenTofu
- Ansible
- Docker & Compose
- Kubernetes (k3s, EKS)
- Traefik / Caddy / NGINX
- WireGuard & Tailscale
AI serving
- vLLM
- Ollama
- llama.cpp
- Open WebUI
- LiteLLM gateway
- Qdrant / pgvector
- Whisper
- ComfyUI
Operations
- Prometheus & Grafana
- Loki / OpenSearch
- Restic & Borg
- Vault / SOPS
- GitHub Actions & GitLab CI
- Uptime Kuma / Alertmanager
Delivery
How an engagement actually runs.
Weekly demos, a shared board you can read at any time, and a written definition of done agreed before we invoice anything.
Discovery call
45 minutes, free
We map what you run today, what it costs, what has to keep working and what "done" looks like.
Fixed-price proposal
Within 3 business days
A written scope, architecture sketch, timeline and a single number. No hourly surprises.
Build
1–10 weeks
Everything provisioned as code in your accounts, with weekly demos and a shared progress board.
Cutover & proof
Scheduled window
Rehearsed migration, a live restore test and load verification before we call it live.
Handover
On completion
Runbooks, architecture diagrams, credentials in your vault and training for the people on call.
Care (optional)
Monthly
Patching, monitoring, restore drills and capacity reviews — or a clean exit with full documentation.