Infrastructure agentization
One gateway in front of every model, a key per project, a budget per project, an audit log. Then agents that read freely and write only on confirmation. The kind that notices the disk is filling up.
More →…it’s just not very evenly distributed (William Gibson)
It runs here. Agents that operate the infrastructure. Applications we built and use every day. A boundary sensitive data does not cross. We only sell what we have run on ourselves first.
Twenty-five years keeping production systems alive. Agents now run part of ours — and we know exactly where they can be trusted and where they cannot.
References
A short list, and it is meant to be. What exactly we did for whom we will happily tell you; some of it is theirs to disclose rather than ours, and we leave it that way.
The question everyone actually asks
Aggregates go to the cloud model. Anything sensitive — raw records, identifiers, location, health data — never leaves the network. It runs on a local model, on your hardware. This is not a promise on a slide; it is the boundary we run our own systems on, because some of our own data is the kind you do not hand to anyone.
Here is how it is built. Every model call goes through LiteLLM, so there is exactly one place where "what may go where" gets decided. Sensitive routes are pinned in that config to an Ollama instance on your own GPU — including the embeddings behind document search, which are computed on your own hardware. Everything else is allowed out. The boundary is therefore a line of configuration: you can read it, change it, and audit it the same way you audit any other rule on your network.
We are two people. That is why the list is short — and why it is what we can actually deliver alongside the work we already carry.
One gateway in front of every model, a key per project, a budget per project, an audit log. Then agents that read freely and write only on confirmation. The kind that notices the disk is filling up.
More →An application with a defined edge — shipped and handed over, not rented back to you. We run four of them and use all four daily, so we can also tell you what breaks on them a year in.
More →Your people already use AI. The question is whether they use it well and whether you can see it. A day on site, on your real workflows, with agentic tasks — not a slide deck about prompts.
More →Home Assistant deployed through its API as code — reviewable, revertable, rebuildable. It survives the vendor rewriting their API. Households or offices — the same engineering either way.
More →one alert rule per backup job, each with a threshold matched to its own schedule. A backup nobody checks is a work of fiction.
every model behind one door, a key per project, a budget per project. Swapping provider is a one-line change in the gateway.
router, DNS, DHCP and VPN migrated while everything kept running. The only outage was the few seconds it took to move a cable — there was no way around that one.
our own server at home, an offsite receiver in another town, a VPS in the cloud. Alerts arrive in Signal — because the first responder is an agent.
These are numbers from our own infrastructure, verified on the day this page was last rewritten. Not a client list — a lab. It is where we test what we would propose to you, and it is why we can show you the scars instead of the slides.
Every one of them is ours, in production, and still running this morning.
Custom software · in production
Three legal entities, three sets of books, and a person retyping bank statements into accounting software every month. The bank has an API. Nobody uses it, because open banking is sold to banks, not to the companies that bank there.
Custom software · four apps in production
Each of them came out of a problem of our own, not a brief. Nobody paid us for them, so nothing in them was built merely because it was in the spec — and nobody took delivery either, so there is no getting rid of them. That is exactly what makes them a useful reference: an application you have to use every day will tell you within a year the truth a customer never would.
Agentization · in production
Models from four different providers, several applications wanting them, and the default outcome: keys copied into whatever needed them, no budget, no audit, no idea what leaves the building.
No deck, no discovery workshop, no invoice. One hour, and you will get a straight answer: this is what I would do, this is what it costs — or, you do not need us for this.