Stop renting
your infrastructure.
Own the whole thing.
Monitoring, detection, identity, and perimeter — running on metal you control, configured by people who actually read the docs. The whole baseline is free and public. Bring your tinfoil hat; we wear ours too.
Always watching. Never seen.
Six things we're annoying about.
OpsFox is a place for people who take digital sovereignty seriously and still enjoy it. Not a vendor pitch, not a fear campaign. Here's the stance — read it before you decide whether you belong here.
If you can't see it leave, you don't own it.
Every box should tell you what it's talking to and why. Most of them are built specifically not to. That's a design decision someone made about you.
Convenience is sold at the price of visibility.
The frictionless version of anything is frictionless because a layer you can't inspect is making decisions for you. Sometimes that trade is fine. You should be the one making it.
Your data on someone else's disk is someone else's asset.
Not a conspiracy — a balance sheet. It gets indexed, trained on, subpoenaed, breached, or repriced, and none of those events require anyone to be evil.
Hygiene beats heroics.
A password manager, hardware 2FA, real backups, and patches that actually get applied will out-defend any product you can buy. It isn't glamorous and it works.
Tinfoil hats welcome.
Being right about surveillance capitalism a decade early isn't a personality disorder. Threat-model out loud here. Nobody's going to tell you you're overthinking it.
This is supposed to be fun.
Racking up thin clients from corporate e-waste, giving a Pi Zero a face, watching your own dashboards light up — the joy is the retention mechanism. Security that feels like a chore doesn't get done.
The window where you’re undefended.
Three numbers we built the practice around. Every retainer exists to close one of these gaps.
of attacks target small business
Small teams and contractors are actively targeted precisely because they lack the dedicated security staff that larger enterprises maintain.
average breach detection gap
Without active monitoring, most small organizations don't know they've been compromised until damage is done. Attackers have months to move laterally.
of breaches exploit misconfig
Exposed APIs, default credentials, unpatched containers, firewall gaps. These aren't sophisticated attacks — they're preventable infrastructure problems.
Pick your pieces. Run them yourself.
Ten components in three bundles. Every one of them runs on infrastructure you control, and nothing here phones home to us.
The operations centre.
The four that answer the questions that matter at 2am: what is running, what changed, who got in, and what left. All of it fits on one box.
SENTINELNo host to measure on managed containers, so platform metrics replace host metrics.
CHECKPOINTIn your cloud, filtering uses the platform DNS firewall — one container as the whole VPC resolver is a blast radius nobody wants.
Metrics, logs, and dashboards you'll actually open. Warns before a disk fills.
FreeMetalInstancesContainersWatches every host for the events that matter, tuned until an alert means something.
FreeMetalInstancesOne front door. Single sign-on and MFA in front of everything behind it.
FreeMetalInstancesContainersDNS filtering, TLS, and egress default-deny. Decides what gets to leave.
FreeMetalInstancesContainersYour code, your files, your photos.
The things you are currently renting from somebody who reads them. Pull them back onto hardware you own, behind your own front door.
DARKROOMNot sold managed. Four upstream auth and sharing flaws in fourteen months, and family photos are the wrong place to find the fifth. Free baseline only.
Your repositories, reviews, and build history on your own metal.
MetalInstancesSync and share behind your own identity gateway. Files only, not groupware.
MetalInstancesPhoto and video library with search and phone apps, on storage you own.
FreeMetalFor when the network can't be trusted.
Provenance for what you ship, backups nothing can delete, and inference that never leaves the building. Scoped per environment.
GHOST PIPELINEVerification runs anywhere. The build side needs an instance to build on.
DEAD DROPIn your cloud this becomes truly immutable storage. The offline-mirror half is on-prem only.
Signed builds and dependency inventory. Prove what shipped and what was in it.
MetalInstancesContainersAppend-only backups nothing can delete, and restores that get rehearsed.
MetalInstancesLanguage models running inside your own network. Nothing leaves the building.
MetalInstancesYour hardware, or your cloud account.
Never ours. There's no OpsFox tenancy holding your data, because the whole point is that you can revoke us and still have everything.
YOUR METAL
On hardware you can physically touch.
Compose and Ansible onto machines you own — a rack, a closet, a couple of mini PCs, or a plant-floor box that never sees the internet. Every component is available in this shape and this is the only shape that supports fully air-gapped work.
- All components available, including air-gap and offline mirrors
- No cloud bill and no third-party dependency
- You own the hardware lifecycle — that's the trade
Anyone who wants the whole thing under their own roof
YOUR CLOUD · INSTANCES
Templated into your own AWS account.
A CloudFormation template stands the stack up on instances inside your account, your VPC, and your billing. You hold the root credentials and the data never leaves your tenancy. This is the shape for clients who want cloud convenience without a vendor holding their telemetry.
- Deployed in your account, your VPC, under your own billing
- Every component works in this shape, including host-level monitoring
- Storage on your volumes, secrets in your own secret store
Commercial clients standardised on AWS
YOUR CLOUD · CONTAINERS
Managed containers, less to babysit.
The stateless parts of the stack run as managed container services in your account, with persistent data on your own volumes. Lower operational overhead, but a few components genuinely need to see the host they're watching and stay on instances instead. That split gets designed with you rather than pretended away.
- Best fit for observability, identity, perimeter, and pipeline components
- Host-visibility components stay on instances — an honest limit, not a gap
- Usually deployed as a hybrid: containers where they fit, instances where they don't
Teams already running containers who want less to patch
Cloud marketplace procurement is in progress, not live yet — nothing here is listed for purchase today. What is already true: if you run in AWS, that account is an approved vendor you have onboarded, so deploying there means no new vendor record, no fresh security questionnaire, and no new paperwork. To be clear about what it does not mean — services like these do not draw down a committed-spend agreement, though the infrastructure the stack runs on is ordinary usage that does.
Machines draft. We sign.
Every vendor says AI now, most of them louder than is warranted. Here's our unglamorous version — including where we don't let the agents go.
A map of what you actually inherited.
Somebody set this up four years ago and left. Dead Reckoning is the written record of what's running, what talks to what, which box is load-bearing, and which service nobody can explain. Updated every month, so it stays true instead of rotting in a wiki.
Sweep the estate, diff this month against last, and draft the write-up. They work from inventory data and version strings — never credentials, never log contents.
We walk the environment, confirm what the sweep found, and write down the parts a scanner can't infer — why a decision was made, what breaks if you touch it.
We assert nothing we haven't verified against the actual host. Anything uncertain ships labelled uncertain, because a confident map that's wrong is worse than no map.
You hear about it before your client does.
Detection deployed on every environment you run, tuned until the alerts actually mean something. Most monitoring gets ignored within a month because it cries wolf. This gets tuned until it doesn't, then keeps getting tuned.
Correlate and cluster events, rank by what would actually hurt, and draft the first-pass write-up with the evidence attached.
We review every alert before it reaches you, write the recommendation, and own the call. Tuning decisions get made by someone who has actually seen your environment.
Automated response only ever touches what you pre-approved in writing, and the rate limit fails to alert-only rather than acting. Anything ambiguous waits for a human — a wrong containment action during business hours is bad, at 3am unsupervised it's a catastrophe.
Your stack stops rotting.
One reviewed change set a month across every environment, run in a window you pick. You hear about the advisories that can actually reach you and nothing else — no vendor feed, no CVE firehose, no 40-page PDF.
Version matching is deterministic — no language model touches it. Thousands of monthly advisories collapse to the handful that match real inventory before a token gets spent. Agents then draft the patch and its rollback.
We approve the train, run the window with you, and own anything that breaks. Every decision not to patch something gets written down with the reason.
Staging first, always. Nothing auto-applies to production, ever. The only thing allowed to close itself is “not present in your inventory,” because that's a lookup rather than a judgment call.
Published prices. No call required.
Every engagement starts with RECON at $6,500, then scales by how many environments you're responsible for. Priced per environment, because that's the unit an agency actually thinks in. 2 retainers at a time.
One environment, run properly. The stack deployed, watched, patched, and documented — so the thing you inherited stops being a liability.
A handful of environments and no security person. Absorbed overhead against one avoided loss
3 environments · 30 hosts · +$750/environment
Every environment you run for someone else, on one invoice. Patched on the same train, watched by the same rules, documented to the same standard.
An agency holding other people's infrastructure. $750 per environment — resells at a normal care-plan markup
6 environments · 60 hosts · +$700/environment
Everything in ENCLAVE, plus the build pipeline and the weird stuff — air-gapped segments, plant networks, and the environments nobody else will touch.
A real fleet, or environments that get strange
12 environments · 120 hosts · +$650/environment
Three phases. Every engagement.
Whether it ends after the first or runs for years. Envision → Create → Maintain.
Map the landscape before you build on it. A full assessment of infrastructure posture, exposure points, and operational gaps produces a written plan with prioritized findings.
Build it right. Document everything. Security stack deployment, IaC pipelines, and runbooks authored alongside the build — to the point where someone else can operate it.
Always watching. Never seen. Detection runs continuously and doesn't depend on anyone being awake. Triage happens during business hours, patches ride a tested monthly train, and the written record proves it — the ongoing function your team never had headcount for.
Two lists. Read both.
Everything above this line is free and always will be. This part is about the paid work. We take two clients at a time, which makes saying no the most useful thing we do — so the second list is as honest as the first.
- You run infrastructure for other people — an agency, a dev shop, a studio — and there's no security person on the payroll.
- You inherited a server, a cluster, or a whole environment that nobody left documentation for.
- You're maintaining the same stack across five client environments and patching has quietly become somebody's weekend.
- A client asked you a security question and you had to guess at the answer.
- One of your engineers holds the whole architecture in their head, and they could quit.
- You'd rather run your own metal than explain another surprise cloud bill.
- You want the person writing the fix to be the person who deploys it.
- You want a phone number staffed at 3am. Detection runs around the clock; we don't. We sell that honestly or not at all.
- You want a checkbox for $500 a month. The floor on retained work is $2,750, and below that the free repo is the honest answer.
- You need a vendor with its own audit report to clear procurement. We don't have one yet, and your risk team is right to care.
- You want someone to certify you. Nobody who implements a control gets to sign off on it, and that includes us.
- You want a report and then silence. That's the thing we exist to be the opposite of.
- You want the cheapest possible answer. Cheap infrastructure security is how the interesting incidents start.
Either list is a useful answer.
If the second list described you, no hard feelings — take the free baseline, it's genuinely good and it costs nothing to run.
If the first list described you, the prices are published, no call required to read them.
We're small. Verify us anyway.
No account manager, no juniors rotating onto your account, nobody pretending to be awake at 3am. Five things that make that survivable — none of which ask you to take our word for anything.
Everything ships as code, into your repo
Terraform, Ansible, Compose, and a runbook per system, on hardware you control. If we vanished tomorrow you'd still have a working, documented, auditable stack that any competent engineer can pick up on Monday.
That's an escrow clause that actually functions. A vendor with a proprietary agent can't write you one, because leaving them means losing your posture and starting over.
You can read our work before you buy any of it
The public baseline is the same shape as what we deploy for a paying client. Clone it. Hand it to your own engineer. Let them tell you whether it's any good.
Almost nobody in this market lets you inspect the product before the contract. That asymmetry is exactly why our repo is free.
Our response windows are in writing, and missing one costs us money
Detection runs continuously and doesn't depend on anyone being awake. Human acknowledgment is four business hours, 09:00 to 18:00 Eastern, Monday to Friday.
Miss it and a percentage of the month comes back to you against a published schedule. We don't sell round-the-clock human coverage, because we're small enough that we couldn't honour it and you'd find out at the worst possible moment.
Our answer to key-person risk is an envelope, not a promise
We're a small crew, not a call centre, and we'd rather you plan around that than discover it. So you get an encrypted envelope that you and your own lead both hold: the access inventory, the revocation commands, the current state of every system, and the escalation contacts.
Plus a written thirty-day transition plan, walked through with you on day one. That's a continuity story you can verify instead of a name on an org chart you can't.
Least privilege applies to us too
A named account you create, under your MFA, no shared credentials, no standing privileged access — just-in-time elevation you approve, time-boxed and logged. No domain admin, no data exports.
Every command run against your environment ships to a log store you control and we cannot delete. You can revoke us in one command, we'll demonstrate that command on day one, and we drill it once a quarter.
The baseline is free. Take it and go.
What's public, what isn't, and the line we don't move.
Everything worth running on a single box is public, Apache-2.0, and complete. Observability, detection, single sign-on, DNS filtering, TLS, MFA, egress default-deny, encrypted backups, and the runbooks that operate them. Clone it, run it, and never get in touch. It's safe that way on purpose.
What costs money isn't the safe part — it's the fleet part. High availability, multi-tenant, long retention, a restore that's actually been tested, and somebody keeping up with upstream across a dozen environments so you don't spend your weekends on it.
A fork gets you the files. It doesn't get you next month.
We don't paywall blast radius.
If gating something would make a non-paying adopter easier to breach, it doesn't get gated. These live in the free repo and they're staying there:
A security vendor that ships you the weaker config so the paid one looks better has told you what it thinks of you.
Not ready to book a call? Start with the repo.
Apache-2.0, complete for one host, and the audit tool runs on your machine and reports to you. Nothing is sent anywhere. If it tells you something useful, you know where to find us.