DevOps · OpSec · SIGINT · Anonymity

Stop renting
your infrastructure.
Own the whole thing.

Monitoring, detection, identity, and perimeter — running on metal you control, configured by people who actually read the docs. The whole baseline is free and public. Bring your tinfoil hat; we wear ours too.

Always watching. Never seen.

opsfox — monitor
live
infra/prod-cluster
active sessions: 3
Endpoint Monitoring
14 nodes
Log Correlation
2.3k/min
Identity Audit
clean
Config Drift Check
0 changes
Threat Detection
analyzing…
> correlating events from edge nodes…
> no lateral movement detected
> baseline established
0 critical0 high1 notice4 info
opsfox monitor
1.2s
All Clear
01 · The Creed

Six things we're annoying about.

OpsFox is a place for people who take digital sovereignty seriously and still enjoy it. Not a vendor pitch, not a fear campaign. Here's the stance — read it before you decide whether you belong here.

01–02Ownership
03–04Custody
05–06Practice
01

If you can't see it leave, you don't own it.

Every box should tell you what it's talking to and why. Most of them are built specifically not to. That's a design decision someone made about you.

02

Convenience is sold at the price of visibility.

The frictionless version of anything is frictionless because a layer you can't inspect is making decisions for you. Sometimes that trade is fine. You should be the one making it.

03

Your data on someone else's disk is someone else's asset.

Not a conspiracy — a balance sheet. It gets indexed, trained on, subpoenaed, breached, or repriced, and none of those events require anyone to be evil.

04

Hygiene beats heroics.

A password manager, hardware 2FA, real backups, and patches that actually get applied will out-defend any product you can buy. It isn't glamorous and it works.

05

Tinfoil hats welcome.

Being right about surveillance capitalism a decade early isn't a personality disorder. Threat-model out loud here. Nobody's going to tell you you're overthinking it.

06

This is supposed to be fun.

Racking up thin clients from corporate e-waste, giving a Pi Zero a face, watching your own dashboards light up — the joy is the retention mechanism. Security that feels like a chore doesn't get done.

02 · The Stakes

The window where you’re undefended.

Three numbers we built the practice around. Every retainer exists to close one of these gaps.

Verizon DBIR · 2025
0%

of attacks target small business

Small teams and contractors are actively targeted precisely because they lack the dedicated security staff that larger enterprises maintain.

IBM Cost of a Breach · 2025
0 days

average breach detection gap

Without active monitoring, most small organizations don't know they've been compromised until damage is done. Attackers have months to move laterally.

0days unseen
ENISA Threat Landscape · 2025
0%

of breaches exploit misconfig

Exposed APIs, default credentials, unpatched containers, firewall gaps. These aren't sophisticated attacks — they're preventable infrastructure problems.

cleanmisconfig
03 · The Catalogue

Pick your pieces. Run them yourself.

Ten components in three bundles. Every one of them runs on infrastructure you control, and nothing here phones home to us.

4 partsWATCHTOWER
3 partsBURROW
3 partsDEEP COVER

The operations centre.

The four that answer the questions that matter at 2am: what is running, what changed, who got in, and what left. All of it fits on one box.

Worth knowing

SENTINELNo host to measure on managed containers, so platform metrics replace host metrics.

CHECKPOINTIn your cloud, filtering uses the platform DNS firewall — one container as the whole VPC resolver is a blast radius nobody wants.

SENTINELObservability

Metrics, logs, and dashboards you'll actually open. Warns before a disk fills.

FreeMetalInstancesContainers
NIGHTWATCHSecurity event intelligence

Watches every host for the events that matter, tuned until an alert means something.

FreeMetalInstances
SENTRYIdentity & access gateway

One front door. Single sign-on and MFA in front of everything behind it.

FreeMetalInstancesContainers
CHECKPOINTPerimeter & traffic control

DNS filtering, TLS, and egress default-deny. Decides what gets to leave.

FreeMetalInstancesContainers

Your code, your files, your photos.

The things you are currently renting from somebody who reads them. Pull them back onto hardware you own, behind your own front door.

Worth knowing

DARKROOMNot sold managed. Four upstream auth and sharing flaws in fourteen months, and family photos are the wrong place to find the fifth. Free baseline only.

ARSENALNewSource forge & pipelines

Your repositories, reviews, and build history on your own metal.

MetalInstances
CACHENewFiles & sync

Sync and share behind your own identity gateway. Files only, not groupware.

MetalInstances
DARKROOMSelf-runMedia vault

Photo and video library with search and phone apps, on storage you own.

FreeMetal

For when the network can't be trusted.

Provenance for what you ship, backups nothing can delete, and inference that never leaves the building. Scoped per environment.

Worth knowing

GHOST PIPELINEVerification runs anywhere. The build side needs an instance to build on.

DEAD DROPIn your cloud this becomes truly immutable storage. The offline-mirror half is on-prem only.

GHOST PIPELINESupply chain integrity

Signed builds and dependency inventory. Prove what shipped and what was in it.

MetalInstancesContainers
DEAD DROPAir-gap & continuity

Append-only backups nothing can delete, and restores that get rehearsed.

MetalInstances
IRON DENPilotIn-boundary inference

Language models running inside your own network. Nothing leaves the building.

MetalInstances
04 · Where It Runs

Your hardware, or your cloud account.

Never ours. There's no OpsFox tenancy holding your data, because the whole point is that you can revoke us and still have everything.

Self-hostedMETAL
In your accountINSTANCES
In your accountCONTAINERS
Worth knowingProcurement

YOUR METAL

On hardware you can physically touch.

Compose and Ansible onto machines you own — a rack, a closet, a couple of mini PCs, or a plant-floor box that never sees the internet. Every component is available in this shape and this is the only shape that supports fully air-gapped work.

  • All components available, including air-gap and offline mirrors
  • No cloud bill and no third-party dependency
  • You own the hardware lifecycle — that's the trade

Anyone who wants the whole thing under their own roof

YOUR CLOUD · INSTANCES

Templated into your own AWS account.

A CloudFormation template stands the stack up on instances inside your account, your VPC, and your billing. You hold the root credentials and the data never leaves your tenancy. This is the shape for clients who want cloud convenience without a vendor holding their telemetry.

  • Deployed in your account, your VPC, under your own billing
  • Every component works in this shape, including host-level monitoring
  • Storage on your volumes, secrets in your own secret store

Commercial clients standardised on AWS

YOUR CLOUD · CONTAINERS

Managed containers, less to babysit.

The stateless parts of the stack run as managed container services in your account, with persistent data on your own volumes. Lower operational overhead, but a few components genuinely need to see the host they're watching and stay on instances instead. That split gets designed with you rather than pretended away.

  • Best fit for observability, identity, perimeter, and pipeline components
  • Host-visibility components stay on instances — an honest limit, not a gap
  • Usually deployed as a hybrid: containers where they fit, instances where they don't

Teams already running containers who want less to patch

Procurement

Cloud marketplace procurement is in progress, not live yet — nothing here is listed for purchase today. What is already true: if you run in AWS, that account is an approved vendor you have onboarded, so deploying there means no new vendor record, no fresh security questionnaire, and no new paperwork. To be clear about what it does not mean — services like these do not draw down a committed-spend agreement, though the infrastructure the stack runs on is ordinary usage that does.

05 · How The Work Gets Done

Machines draft. We sign.

Every vendor says AI now, most of them louder than is warranted. Here's our unglamorous version — including where we don't let the agents go.

01Dead Reckoning
02Nightwatch
03Silent Upgrade

A map of what you actually inherited.

Living document · updated monthly

Somebody set this up four years ago and left. Dead Reckoning is the written record of what's running, what talks to what, which box is load-bearing, and which service nobody can explain. Updated every month, so it stays true instead of rotting in a wiki.

What the agents do

Sweep the estate, diff this month against last, and draft the write-up. They work from inventory data and version strings — never credentials, never log contents.

What we do

We walk the environment, confirm what the sweep found, and write down the parts a scanner can't infer — why a decision was made, what breaks if you touch it.

The limit

We assert nothing we haven't verified against the actual host. Anything uncertain ships labelled uncertain, because a confident map that's wrong is worse than no map.

You hear about it before your client does.

Detection across the fleet · business-hours triage

Detection deployed on every environment you run, tuned until the alerts actually mean something. Most monitoring gets ignored within a month because it cries wolf. This gets tuned until it doesn't, then keeps getting tuned.

What the agents do

Correlate and cluster events, rank by what would actually hurt, and draft the first-pass write-up with the evidence attached.

What we do

We review every alert before it reaches you, write the recommendation, and own the call. Tuning decisions get made by someone who has actually seen your environment.

The limit

Automated response only ever touches what you pre-approved in writing, and the rate limit fails to alert-only rather than acting. Anything ambiguous waits for a human — a wrong containment action during business hours is bad, at 3am unsupervised it's a catastrophe.

Your stack stops rotting.

One tested patch train a month

One reviewed change set a month across every environment, run in a window you pick. You hear about the advisories that can actually reach you and nothing else — no vendor feed, no CVE firehose, no 40-page PDF.

What the agents do

Version matching is deterministic — no language model touches it. Thousands of monthly advisories collapse to the handful that match real inventory before a token gets spent. Agents then draft the patch and its rollback.

What we do

We approve the train, run the window with you, and own anything that breaks. Every decision not to patch something gets written down with the reason.

The limit

Staging first, always. Nothing auto-applies to production, ever. The only thing allowed to close itself is “not present in your inventory,” because that's a lookup rather than a judgment call.

06 · What It Costs

Published prices. No call required.

Every engagement starts with RECON at $6,500, then scales by how many environments you're responsible for. Priced per environment, because that's the unit an agency actually thinks in. 2 retainers at a time.

$2,750OUTPOST
$4,500ENCLAVE
$7,500STRONGHOLD

One environment, run properly. The stack deployed, watched, patched, and documented — so the thing you inherited stops being a liability.

per month · 3-month minimum

A handful of environments and no security person. Absorbed overhead against one avoided loss

3 environments · 30 hosts · +$750/environment

DEAD RECKONING — the living map of what's running and why
SILENT UPGRADE — the tested monthly patch train
Detection deployed and tuned until the alerts mean something
Triage acknowledged within 4 business hours, 09:00–18:00 ET, Mon–Fri
Monthly 60-minute working session, recorded if you want it

Every environment you run for someone else, on one invoice. Patched on the same train, watched by the same rules, documented to the same standard.

per month · 3-month minimum · $45,000/yr prepaid

An agency holding other people's infrastructure. $750 per environment — resells at a normal care-plan markup

6 environments · 60 hosts · +$700/environment

Everything in OUTPOST, across up to 6 client environments
NIGHTWATCH — detection across the fleet, so you hear it before your client does
One patch train covering every environment, not five separate scrambles
Findings written so you can forward them to a client unedited
Answers for the security questions your clients ask you

Everything in ENCLAVE, plus the build pipeline and the weird stuff — air-gapped segments, plant networks, and the environments nobody else will touch.

per month · 6-month minimum · $75,000/yr prepaid

A real fleet, or environments that get strange

12 environments · 120 hosts · +$650/environment

Everything in ENCLAVE at double the environment and host cap
Signed builds, SBOM, secrets scanning, and policy gates in your pipeline
Network segmentation for air-gapped or industrial environments
Architecture documentation your clients can be shown directly
Framework mapping if a client demands one — capability, not identity
07 · The Process

Three phases. Every engagement.

Whether it ends after the first or runs for years. Envision → Create → Maintain.

01 / 03

Envision

2–4 weeks

Map the landscape before you build on it. A full assessment of infrastructure posture, exposure points, and operational gaps produces a written plan with prioritized findings.

deliverables
Audit report (PDF + markdown)
Evidence index
Risk register
Remediation roadmap
02 / 03

Create

4–12 weeks

Build it right. Document everything. Security stack deployment, IaC pipelines, and runbooks authored alongside the build — to the point where someone else can operate it.

deliverables
Infrastructure as code, in your repo
CI/CD with secrets scanning
Runbooks per system
Hardened baseline images
03 / 03

Maintain

Ongoing · monthly retainer

Always watching. Never seen. Detection runs continuously and doesn't depend on anyone being awake. Triage happens during business hours, patches ride a tested monthly train, and the written record proves it — the ongoing function your team never had headcount for.

deliverables
Detection deployed, tuned, maintained
Triage: 4 business hours, 09:00–18:00 ET
Monthly evidence pack
Quarterly drift audit
01Envision
02Create
03Maintain
08 · Before You Book

Two lists. Read both.

Everything above this line is free and always will be. This part is about the paid work. We take two clients at a time, which makes saying no the most useful thing we do — so the second list is as honest as the first.

7 reasonsWorth a call
6 reasonsDon't bother
Either wayNo hard feelings
Worth a call if
  • You run infrastructure for other people — an agency, a dev shop, a studio — and there's no security person on the payroll.
  • You inherited a server, a cluster, or a whole environment that nobody left documentation for.
  • You're maintaining the same stack across five client environments and patching has quietly become somebody's weekend.
  • A client asked you a security question and you had to guess at the answer.
  • One of your engineers holds the whole architecture in their head, and they could quit.
  • You'd rather run your own metal than explain another surprise cloud bill.
  • You want the person writing the fix to be the person who deploys it.
Don't bother if
  • You want a phone number staffed at 3am. Detection runs around the clock; we don't. We sell that honestly or not at all.
  • You want a checkbox for $500 a month. The floor on retained work is $2,750, and below that the free repo is the honest answer.
  • You need a vendor with its own audit report to clear procurement. We don't have one yet, and your risk team is right to care.
  • You want someone to certify you. Nobody who implements a control gets to sign off on it, and that includes us.
  • You want a report and then silence. That's the thing we exist to be the opposite of.
  • You want the cheapest possible answer. Cheap infrastructure security is how the interesting incidents start.

Either list is a useful answer.

If the second list described you, no hard feelings — take the free baseline, it's genuinely good and it costs nothing to run.

If the first list described you, the prices are published, no call required to read them.

09 · Why Trust Us With It

We're small. Verify us anyway.

No account manager, no juniors rotating onto your account, nobody pretending to be awake at 3am. Five things that make that survivable — none of which ask you to take our word for anything.

01Code
02Read it
03Windows
04Continuity
05Access
01 / 05

Everything ships as code, into your repo

Terraform, Ansible, Compose, and a runbook per system, on hardware you control. If we vanished tomorrow you'd still have a working, documented, auditable stack that any competent engineer can pick up on Monday.

That's an escrow clause that actually functions. A vendor with a proprietary agent can't write you one, because leaving them means losing your posture and starting over.

02 / 05

You can read our work before you buy any of it

The public baseline is the same shape as what we deploy for a paying client. Clone it. Hand it to your own engineer. Let them tell you whether it's any good.

Almost nobody in this market lets you inspect the product before the contract. That asymmetry is exactly why our repo is free.

03 / 05

Our response windows are in writing, and missing one costs us money

Detection runs continuously and doesn't depend on anyone being awake. Human acknowledgment is four business hours, 09:00 to 18:00 Eastern, Monday to Friday.

Miss it and a percentage of the month comes back to you against a published schedule. We don't sell round-the-clock human coverage, because we're small enough that we couldn't honour it and you'd find out at the worst possible moment.

04 / 05

Our answer to key-person risk is an envelope, not a promise

We're a small crew, not a call centre, and we'd rather you plan around that than discover it. So you get an encrypted envelope that you and your own lead both hold: the access inventory, the revocation commands, the current state of every system, and the escalation contacts.

Plus a written thirty-day transition plan, walked through with you on day one. That's a continuity story you can verify instead of a name on an org chart you can't.

05 / 05

Least privilege applies to us too

A named account you create, under your MFA, no shared credentials, no standing privileged access — just-in-time elevation you approve, time-boxed and logged. No domain admin, no data exports.

Every command run against your environment ships to a log store you control and we cannot delete. You can revoke us in one command, we'll demonstrate that command on day one, and we drill it once a quarter.

10 · Open Core

The baseline is free. Take it and go.

What's public, what isn't, and the line we don't move.

Apache-2.0What's free
The lineWhat we won't gate

Everything worth running on a single box is public, Apache-2.0, and complete. Observability, detection, single sign-on, DNS filtering, TLS, MFA, egress default-deny, encrypted backups, and the runbooks that operate them. Clone it, run it, and never get in touch. It's safe that way on purpose.

What costs money isn't the safe part — it's the fleet part. High availability, multi-tenant, long retention, a restore that's actually been tested, and somebody keeping up with upstream across a dozen environments so you don't spend your weekends on it.

A fork gets you the files. It doesn't get you next month.

We don't paywall blast radius.

If gating something would make a non-paying adopter easier to breach, it doesn't get gated. These live in the free repo and they're staying there:

MFA enforcementTLS 1.2+ onlySecrets handlingAudit loggingLeast privilegeEgress default-denyTested backup

A security vendor that ships you the weaker config so the paid one looks better has told you what it thinks of you.

The open door

Not ready to book a call? Start with the repo.

Apache-2.0, complete for one host, and the audit tool runs on your machine and reports to you. Nothing is sent anywhere. If it tells you something useful, you know where to find us.