Proof of Work Services Get in Touch

Infrastructure engineering
at the speed of AI.

One engineer. Autonomous AI systems. The output of an entire IT department.
We build, monitor, and operate your infrastructure so you don't have to.

17+ sites managed
24/7 automated monitoring
100% documentation coverage
live // completed work STREAMING
systems // operational status

Proof of Work

Production systems. Live right now. Built and operated by a single engineer.

Ops LIVE

Infrastructure Monitoring & Alerting

Automated health checks across storage, SSL cert expiry, disk space, Docker containers, RAM pressure, unexpected ports, and auth failures. Self-healing watchdog auto-restarts failed services. Crash notifications via systemd hooks. Deduplication with cooldown logic.

BashsystemdResend APIDockerPAM
Infrastructure LIVE

Multi-Site Enterprise Infrastructure

Sole administrator for 17+ site enterprise. Consolidated distributed VMware workloads into a centralized datacenter. Engineered 3-2-1 backup strategy with Veeam across multiple NAS targets. Deployed Zabbix monitoring for proactive management.

VMware vSphereVeeamZabbixActive DirectoryFortinet
Security LIVE

Multi-Layer Security Architecture

SSH login notifications via PAM exec with IP whitelisting. fail2ban jails for sshd, Authelia, and nginx bot scanning. Weekly rkhunter rootkit scans. AIDE file integrity monitoring with cryptographic checksums. Authelia 2FA with TOTP and session management. Full nginx security headers.

PAMfail2banAIDErkhunterAuthelia
Ops Automated Backup & Disaster Recovery

Nightly incremental backups to Backblaze B2 via rclone. Automated monthly restore tests that download the full backup, verify file integrity, import MariaDB databases, and parse YAML configs. Status API tracked on a dashboard with staleness alerts.

rcloneBackblaze B2MariaDBsystemd timers
Infrastructure Hybrid VPN & DNS Override System

Tailscale mesh VPN across distributed infrastructure with WireGuard tunneling and NAT traversal. Subnet routing for seamless cross-site connectivity without per-device agent installs. Technitium DNS overrides for internal service resolution. Context-aware Authelia bypass logic — trusted networks skip 2FA, external access requires TOTP.

TailscaleWireGuardTechnitium DNSiptables
Infrastructure Reverse Proxy with Dynamic Auth

Advanced nginx configuration routing to multiple Docker containers and services. auth_request pattern with Authelia integration — 302 redirect to login portal on 401. Service-specific proxy rules with server-side API key injection, WebSocket upgrade headers, and bind-mount persistence across image updates.

nginxAutheliaDockerLet's Encrypt
AI AI-Powered Update Management

Tiered update strategy: automatic security patches via unattended-upgrades, weekly changelog analysis via Claude LLM that assesses breaking changes before emailing recommendations. Zero auto-apply for non-security updates — every email includes exact manual commands. Covers apt, Docker images, and third-party binaries.

unattended-upgradesOpenRouterDockersystemd
AI AI-Augmented Financial Operations

Full-stack financial tracking system with automated bank sync, AI-powered transaction analysis, budget management, and real-time dashboards. Multi-institution integration with automated anomaly detection and category inference.

PythonSQLiteREST APIsNginxAI/LLM
Cloud Microsoft 365 & Endpoint Management

Full tenant administration for enterprise M365 environment. Migrated endpoint management from GPO to Intune with Win32 app deployment for vulnerability remediation. Entra ID, Purview compliance, and conditional access policies across the organization.

IntuneEntra IDAzurePowerShellGPO
Platform Self-Hosted Operations Hub

Cloud VPS infrastructure behind reverse proxy with SSO authentication, automated SSL, push notifications, CalDAV integration, and AI chat. Custom multi-panel dashboard with cost tracker, backup status, agent metrics, and operational views. Fully automated deployment and monitoring with zero-downtime operations.

NginxAuthelia SSOLet's EncryptsystemdTailscale

What We Do

Enterprise-grade infrastructure management for businesses that need reliability without the overhead of a full IT department.

Infrastructure & Continuity

Virtualization, server administration, network architecture, and datacenter operations across VMware, Hyper-V, and Proxmox. 3-2-1 backup strategy with Veeam, tested recovery procedures, and documented disaster recovery plans. Every system documented, every change logged.

Security & Compliance

Endpoint management via Intune and GPO, identity with Entra ID, vulnerability remediation, and policy enforcement. Defense-in-depth with fail2ban, file integrity monitoring, and 2FA. Security that works without slowing your people down.

Monitoring & Automation

Proactive monitoring with Zabbix, automated alerting, self-healing watchdogs, and AI-driven anomaly detection. We know about problems before your users do — and half the time, we've already fixed them.

Microsoft 365 & Cloud

Full M365 tenant administration, Entra ID, Intune MDM, Purview compliance, and Azure migration. Conditional access, Win32 app deployment, and GPO-to-Intune migration. Your cloud environment managed by someone who actually understands it.

Let's Talk

One skilled engineer with AI tooling can deliver the reliability, documentation discipline, and operational depth that used to require a team of five.

William Woody  //  Des Moines, Iowa  //  Founder

No commitment required. Just a conversation.