Six disciplines, one accountable operator
Every service below is delivered by our own engineers on our own network — not resold, not outsourced. Each one is documented here in full: what it includes, how it’s delivered, and which plan tier it sits on. Jump to any of them below.
VPN server lease
Dedicated and shared VPN gateways provisioned across our 312-node global footprint, on WireGuard and OpenVPN, with static or rotating dedicated IPs. Nodes are leased by the port, the region, or the whole fleet — sized for a five-person remote team or a multinational workforce.
Every gateway sits behind the same zero-log policy described on our trust & security page: no connection logs, no traffic logs, no DNS query retention. Encryption keys rotate automatically, dead nodes fail over to the nearest healthy node in the same region within seconds, and access can be gated behind your existing SSO provider so leaving employees lose VPN access the moment they’re offboarded — not whenever someone remembers to revoke a shared credential.
- Dedicated or shared gateway nodes
- WireGuard & OpenVPN protocols
- Static dedicated IP options (IPv4 & IPv6)
- Per-region or global bandwidth pools
- Split-tunnel and full-tunnel policies
- SLA-backed uptime with automatic failover routing
- Automatic encryption key rotation every 90 days
- Kill-switch and DNS-leak protection by default
- Multi-hop routing available for sensitive traffic
- SSO/SAML-gated access provisioning and offboarding
- Site-to-site tunnels for connecting branch offices
- Bandwidth usage reporting by team or cost center
Cloud-based AI predictive models
Predictive models trained on network, endpoint and identity telemetry surface anomalies before they become incidents — unusual authentication patterns, lateral movement, data exfiltration shape, and infrastructure drift. Models run on elastic cloud compute and re-score continuously, not on a nightly batch.
We combine unsupervised anomaly detection with supervised classifiers trained on labeled incident data, retrained on your own telemetry roughly every 30 days so the model keeps adapting to how your team actually works. Every alert ships with a plain-language explanation of why it fired — not just a risk score — and routes into whatever SOC or SIEM you already run through a webhook or REST API. Telemetry stays within your agreed region; nothing leaves for model training without a separate data-processing agreement.
- Behavioural anomaly detection
- Continuous risk-scoring, not nightly batches
- Exfiltration and lateral-movement modelling
- Custom model tuning for your environment
- Alert routing into your existing SOC/SIEM
- Monthly model performance reporting
- Explainable alerts — why a score fired, not just the number
- Webhook & REST API integration
- Configurable false-positive suppression rules
- Model retraining roughly every 30 days on your telemetry
- Regional data residency options
- Model changelog for audit and compliance review
GrapheneOS system deployments
Fleet imaging and provisioning of GrapheneOS-hardened devices for executives, field staff and high-risk personnel — de-googled, sandboxed, remotely attestable, and managed through mobile device management policies your IT team already understands. We handle procurement, imaging, enrolment and lifecycle refresh.
We can source Pixel-class hardware directly or image devices you already own. Every unit ships with a tamper-evident seal that’s checked against a photo log on receipt, per-app network and permission policies configured before handoff, and an optional sandboxed Play compatibility layer for teams that need specific consumer apps without giving up the hardened base OS. Lost or stolen devices go through a documented remote-lock-and-wipe workflow, and every unit gets a quarterly firmware and security-patch verification pass for as long as it’s in the fleet.
- Fleet imaging & bulk provisioning
- Remote attestation and integrity checks
- MDM policy design and enrolment
- Sandboxed Play compatibility layer (optional)
- Executive and field-team device tiers
- Lifecycle refresh and secure decommission
- Hardware sourcing & procurement support
- Per-app network and permission policies
- Tamper-evident seal with photo-logged receipt audit
- Encrypted backup and rapid re-provisioning
- Documented loss/theft remote-lock and wipe workflow
- Quarterly firmware and security-patch verification
Corporate privacy protection
We reduce what the outside world can learn about your company and your people: data-broker and OSINT exposure audits, employee digital-footprint reduction, breach and credential-leak monitoring, and data-minimization reviews across the vendors already holding your information.
An exposure audit covers public records, social media, data-broker listings, breach databases, and credential mentions on dark-web forums — for named executives or your whole staff directory. Where we find listings we can act on, we file broker opt-out and removal requests and re-check on a recurring schedule, since brokers routinely re-list people months later. On the vendor side, we review the data-processing agreements and consent flows of the third parties already holding your company’s data and flag where you’re sharing more than the relationship requires.
- Executive & employee OSINT exposure audits
- Data-broker removal coordination
- Credential and breach-leak monitoring
- Third-party data-minimization reviews
- Privacy policy and consent-flow review
- Quarterly exposure reporting
- Dark-web credential and mention monitoring
- Physical address and property-record scrubbing support
- Social media exposure assessment for executives
- Vendor data-processing agreement (DPA) review
- Employee privacy-hygiene training session
- Annual re-audit included on Professional & Sovereign
Digital risk architecture analysis
A structural review of how your systems, identities, vendors and data actually connect — attack-surface mapping, trust-boundary analysis, and architecture recommendations that hold up under a real red-team exercise, not just a compliance checklist. We map findings directly to ISO 27001, SOC 2 and GDPR control families.
The review runs through structured interviews with your engineering leads, live network and cloud-configuration review through read-only API access (AWS, Azure or GCP), and an identity and access management audit across your core systems. Findings are ranked by exploitability and business impact, not just severity score, and delivered as a written report plus a working session with your team to walk through the remediation roadmap. Sovereign clients get this refreshed annually as their environment changes.
- Attack-surface & trust-boundary mapping
- Cloud and identity architecture review
- Red-team informed recommendations
- Compliance control mapping (ISO 27001, SOC 2, GDPR)
- Prioritized remediation roadmap
- Board-ready risk briefing
- Read-only cloud configuration review (AWS/Azure/GCP)
- Identity & access management (IAM) audit
- Third-party and vendor risk assessment
- Findings ranked by exploitability and business impact
- Follow-up working session with your engineering leads
- Annual refresh included on Sovereign plan
Security & infrastructure consulting
Fractional CISO time, vendor and architecture reviews, incident tabletop exercises, and hands-on guidance for teams standing up a security function for the first time or scaling an existing one past what a single in-house lead can cover.
A fractional CISO engagement runs on a weekly or biweekly cadence, with board-level reporting and policy drafting included. Tabletop exercises are run as a half-day scenario with your incident-response team and a written after-action report. Staff augmentation can slot a senior engineer into your existing team for a defined project, and engagements can be structured hourly, as a monthly retainer, or as a fixed-scope project — whichever fits how your budget actually works.
- Fractional CISO engagements
- Vendor & architecture due diligence
- Incident response tabletop exercises
- Security roadmap & budget planning
- Staff augmentation for security teams
- Board and investor security briefings
- Security policy & procedure drafting
- Vendor security questionnaire response support
- New-hire security onboarding sessions
- M&A security due diligence
- Cyber-insurance readiness review
- Flexible engagement: hourly, retainer, or fixed-scope project
Not sure which services you need?
Tell us your team size and current setup — we’ll recommend a scope, not sell you all six.