// EXPERTISE

Our expertise
Open Source by choice

The main areas we work in and what we can do in each of them for your organization. Not an exhaustive list, but expertise built up over time to deliver secure, stable and maintainable systems, always prioritizing Free Software where possible.

Infrastructure and Virtualization

Where systems live

We work directly on physical machines (servers, workstations, network equipment) when performance or predictability requires it: no intermediate hypervisors, minimal latency, full control over the hardware.

For virtualization we use mature open source platforms: stable, isolated environments that are easily migratable between hosts or replicable across sites. Snapshot management, backups and live migrations all happen from the same interface, without third-party tools.

Where we need lightweight containers and application isolation, we containerize, evaluating requirements and security implications case by case.

Operating Systems

The systems we use most

Our declared preference is a stable, security-oriented GNU/Linux distribution: long-term support, a release cycle geared toward stability, and no non-free packages in the standard configuration. It's the foundation of nearly every server we install.

For contexts requiring strong isolation and security by design, we use an Open Source system that compartmentalizes each application or working context in separate virtual machines: the browser, email, sensitive documents never share the same memory space.

We also manage mixed environments, adapting to whatever operating systems the client already uses, without insisting that Free Software is always the only practical answer.

Network and Perimeter Security

What protects and connects everything

The network perimeter is protected by dedicated firewalls on purpose-built hardware, with rules actively managed over time and not abandoned after initial installation.

Private networks are extended with VPN tunnels, choosing the protocol best suited to the performance and compatibility required.

Unwanted access is automatically blocked by system- and kernel-level filtering rules. TLS certificates are managed with automatic renewal, zero manual intervention. Incoming email is filtered upstream to block spam and malware before they reach internal servers.

Vulnerability Assessment and Security Monitoring

Finding weaknesses, before anyone else does

We run periodic audits that identify misconfigurations, outdated software versions and known CVEs present in the client's environment, before they can be exploited by anyone else.

A continuous monitoring system handles endpoint monitoring, security event correlation and real-time anomaly detection: an Open Source SIEM approach that makes anomalous behaviors visible across servers and workstations.

Network reconnaissance is done with dedicated tools and essential for understanding exactly what is actually exposed to the outside before proceeding to secure it.

Self-Hosting and Private Cloud Services

The alternative to commercial cloud services, managed locally

We install and maintain self-hosted platforms as an alternative to commercial cloud services: files, calendars, contacts and real-time collaboration under direct client control, on their own hardware, without passing through third-party infrastructure.

Email can be managed internally with full sovereignty over messages, without any external provider in between, and with the ability to integrate anti-spam and encryption directly into the delivery chain.

Backup and Disaster Recovery

Because data is only lost if you haven't protected it

For virtual machines we use a backup system integrated with the virtualization platform: incremental backups with client-side deduplication, integrated encryption and automatic verification of archived data integrity.

For filesystem data, we adopt tools with deduplication and end-to-end encryption, with support for remote destinations via SSH or S3-compatible object storage. The choice depends on context and the client's operational preferences.

Synchronization between systems is done with tools universally proven over decades, simple to integrate into scripts and cronjobs.

Automation and Scripting

The glue that holds everything together

We write shell scripts for daily system operations: automated backups, process monitoring, notifications, log rotation, orchestration of repetitive tasks and glue between tools that otherwise wouldn't talk to each other. We follow defensive practices to avoid the classic silent errors of shell scripts.

When logic becomes more complex (parsing structured data, generating reports, integrating with REST APIs, custom tools for the client) we move to a high-level programming language: readable, testable, with an ecosystem of libraries that covers almost every need without exotic dependencies.

Web and Backend Development

When the sysadmin also becomes a developer

Backend is mainly built on pragmatic languages widely supported on shared hosting, with no dependencies on complex runtimes or mandatory containers.

Frontend is semantic markup, modern stylesheets and client-side scripting without unnecessary frameworks when complexity doesn't justify it. Accessibility to international standards, mobile-first, no external resources: everything self-hosted.

Web servers are manually configured and hardened with security headers, modern TLS and structured logging. For relational data we choose the engine best suited to scalability requirements and project preferences. Version control is always tracked with an industry-standard tool.

Artificial Intelligence

Adopting it or doing without, always in control

Many organizations have adopted AI quickly, often reducing human oversight of their processes. The risk is not AI itself, but errors that spread without anyone noticing. We help companies and professionals take back control of AI governance: understanding where it is already in use, deciding what to automate and where human verification remains essential, and defining checkpoints and fallback procedures for when AI gets it wrong.

We support migration in both directions.
• Towards AI, introducing it only where the benefit justifies the costs, including the resources and energy it consumes, and with an exit plan from day one.
• From AI back to traditional management, when automation has gone further than needed: we rebuild knowledge of the systems, document procedures and put critical decisions back in people’s hands, without interrupting service.

We have been managing systems since 1993, long before AI: experience that also helps run them without it.

It is the same approach we have always applied to security and business continuity: anticipating what can go wrong and staying able to step in. We can also support staff with guidelines and training for an informed use of AI, including in light of the European AI Act.

AI is one of many tools available, not the starting point: an option to be assessed case by case and adopted only if it brings a concrete benefit, with the consent of those we work for. It can help, for example, with code review, analysis of logs and configurations or writing technical documentation, including comparing multiple models for a second opinion. If the choice is not to use it, we work without it.

In all cases, output is verified by an expert human operator before being deployed to production.
AI accelerates, it doesn't replace human judgment.

Tools

Some of the products behind the expertise above

Here is a selection of some of the products and tools we use: Debian GNU/Linux, Ubuntu, LinuxMint, LMDE, QubesOS, GrapheneOS, LineageOS, eOS, OPNsense, WireGuard, OpenVPN, Proxmox, LXC, Docker, Podman, Let's Encrypt, nftables, Nextcloud, Postfix, Dovecot, Nessus, Wazuh, nmap, Borg, restic, rsync, git, Bash, Python, PHP, HTML, CSS, JavaScript, Nginx, Apache, MariaDB, MySQL, PostgreSQL.