The Landing Page— One conversion-focused landing page, designed and built, with your form or CTA wired to your CRM and a Lighthouse baseline to prove it.
The Marketing Site— A five-page marketing site — home, about, services, contact, blog index — built on a modern stack with a headless CMS, deployed with your DNS cut over.
The Dedicated Designer— One day, per week or per month, where a named designer works exclusively through your design queue — same designer every time.
The Site Facelift— A per-page front-end refresh that modernizes the look of an existing page without touching your backend or content.
The Hero Section Rocket— A ground-up rebuild of your homepage hero section — layout, imagery, motion and messaging — while the rest of the page stays as-is.
The Responsiveness Fix— A targeted fix for broken mobile and tablet rendering — layout overflow, touch targets, viewport bugs — on a site that already works on desktop.
The Accessibility Alignment— A per-page audit and remediation to WCAG 2.2 AA, backed by axe-core and Lighthouse evidence — scoped to the pages you name, not a full-site sweep.
The Headless CMS Setup— Connect an existing or new site to a headless CMS — schemas configured, content migrated, your team trained — so content edits stop needing a developer.
The Own Your Data Pack— Swap the data-harvesting defaults on your site — reCAPTCHA, Google Analytics, Google Maps, Google Fonts — for privacy-respecting alternatives.
The Multi-Language Setup— Retrofit internationalization into your existing web app — string extraction, routing, language switcher, and AI translation into three languages.
The Framework Facelift— A per-page, component-level restyle for existing HTML, React, Svelte or Vue pages — a modern look applied without touching your business logic.
The Visual Assurance— Continuous visual monitoring of your site with Playwright — screenshots of your key pages across desktop, tablet and mobile, diffed on every check and reviewed by a human before you are alerted.
The Customer Portal (Tandemity)— An authenticated customer-facing portal built on your existing Tandemity work hub, with three features included and its chat and task tooling already in place.
The Customer Portal (non-Tandemity)— A standalone, authenticated customer-facing portal built on your own stack, with three features included and a fixed screen count to keep scope contained.
The Admin Panel— An authenticated internal admin panel covering ten entities — customers, orders, products, users, settings and the like — with CRUD screens, integrations and audit logging.
The AI Portal— A custom AI workbench with 5–10 task-specific forms wired to your chosen AI providers, with role-based access and per-user spend caps built in.
The AI Form— One new task-specific form added to an existing AI Portal — prompt design, model selection and role-based access — without touching the rest of the platform.
The Document Extraction Pipeline— Automated extraction of structured data from one document type — invoices, contracts, forms or receipts — into your system, with a human review queue for anything the model is unsure about.
The Scheduled AI Agent— A single-purpose agent that runs on a schedule — cron or a workflow trigger — executes one defined job, and delivers the result to Slack, email or your database.
The Custom Tandemity Tool— A bespoke tool built inside your existing Tandemity work hub — a custom intake form, staff dashboard or automation panel — scoped to one named tool per engagement.
The MCP Server Build— A custom MCP (Model Context Protocol) server exposing your chosen tools to AI assistants like Claude or Cursor, built and deployed as a running service.
The API Integration— Your app or portal connected to one external API — HubSpot, Salesforce, QuickBooks, Xero, Shopify or similar — with sync, error handling and an admin view of status.
The Workflow Hosted Agent (n8n, Make)— An AI agent built inside n8n or Make following a trigger → LLM → tool calls → output pattern, covering jobs like lead routing, support triage or form processing.
The Guacamole Gateway— A self-hosted Apache Guacamole gateway giving browser-based access to your existing servers and desktops over RDP, VNC or SSH — no per-seat licensing.
The Guacamole & Zero Trust Network— The Guacamole gateway build extended with a zero-trust network layer — Tailscale or Cloudflare Access, device posture checks and session recording for audited environments.
The Developer Workstation Setup— Spec'd remote Linux development workstations for engineering teams — full toolchains, containers and IDE access, hosted so code never has to leave your environment.
The Linux Remote Desktop Pilot Program— A 5-user pilot of Proxmox-hosted Linux desktops accessed through Guacamole — a low-commitment way to prove the model before committing to a full rollout.
The Linux Remote Desktop Rollout— Full production Linux desktop deployment for 10–50 users — golden images, automated provisioning, SSO, backups and monitoring, replacing costly Windows VDI.
The Managed Remote Desktop Service— Ongoing management of an existing remote desktop fleet — patching, backups, monitoring, user provisioning and L1/L2 support, billed monthly for a roughly 10-user environment.
The Custom Linux ISO— A distributable Linux ISO built to your app stack, with a custom-designed desktop background and lockscreen instead of a stock wallpaper — you hand it to your own users to install.
The Bulk Onboarding Sprint (Migration Day)— A coordinated rollout onboarding 10–50 staff onto Linux desktops in scheduled waves, with a defined cutover day and a two-week hypercare period afterward.
The Linux Pilot Program— A managed 30-day Linux pilot for 3–5 of your staff, with unlimited live support and a final technical report — built to give you real data before a full rollout decision.
The Linux Endpoint Onboarding— A new starter fully working on a Linux endpoint in one engagement — machine provisioned and accounts live, then a live role-tuned training session ending with a personalized cheat sheet.
The Walk-Through Support— Live screen-share support where the technician guides your user verbally and the user does the clicking — the technician never takes remote control of the device.
The Linux Help Desk— An ongoing monthly Linux help desk retainer, staffed by Linux-fluent technicians, for customers running Linux as their daily-driver desktop OS.
The End-User Training Pack— Branded, reusable training materials for your staff — recorded video walkthroughs, a written quick-start guide, an FAQ document, and a live Q&A session.
The Zero Trust Network Setup— Replace a traditional VPN with an identity-based zero-trust network — platform selection, deployment, an initial ACL policy, and onboarding for up to 5 users and their primary devices.
The Zero Trust Device Addition— Add a single non-user-tied device — a server, printer, IoT device, or a second device for an existing user — to a zero-trust network that is already running.
The Zero Trust User Onboarding— Onboard one new user, including their primary device, onto a zero-trust network that's already running — account provisioning, ACL assignment, and a connectivity test.
The FleetDM/osquery Install— FleetDM server installed with osquery agents rolled out across Linux, macOS and Windows endpoints, plus base query packs and a compliance baseline.
The FleetDM Monitoring Pack— Ongoing monthly FleetDM monitoring — compliance reporting, vulnerability tracking, query writing and a monthly posture review — for a fleet already running FleetDM.
The Wazuh Server & Client Install— Wazuh SIEM installed — manager, indexer and dashboard — with agents rolled out across Linux, macOS and Windows hosts, base rule tuning and alert routing.
The Wazuh Monitoring Pack— Ongoing monthly Wazuh SIEM monitoring — alert triage, false-positive tuning, weekly reporting and incident escalation — for a stack already running Wazuh.
The Dedicated System Admin Day— One full day per week or per month with the same named admin working your queue — backlog clearing, improvement work, and a planning call.
The Brute Force Guardian— Standalone fail2ban install that watches your logs for repeated failed logins and bans offending IPs automatically, with your own IPs whitelisted first.
The Linux Patching Pack— Supervised OS updates run per VM inside a maintenance window you define — pre-update snapshot, apt/dnf/zypper execution, post-update verification and a change log.
The Web Server Install— Greenfield install of one web server — Caddy, Nginx, or Apache — on a fresh server, with automated HTTPS, security headers, and a basic reverse proxy configured.
The Web Server Migration— Migrate an existing web server configuration to a new server (e.g. Apache or Nginx to Caddy), covering up to 5 domains, with HTTPS auto-renewal and a tested rollback plan.
The Mail Stack Install— A full self-hosted mail server stack — Postfix, Dovecot, antivirus and anti-spam filtering — installed, DNS/TLS configured, and deliverability validated against test mailboxes.
The Reverse Proxy Setup— A properly configured reverse proxy in front of your application — TLS, rate limiting, WAF rules, logging, and geo-blocking if you need it.
The Database Install & Hardening— A fresh, hardened database install — your choice of PostgreSQL, MySQL/MariaDB, or MongoDB — with access control, TLS, backups, and a performance baseline configured.
The Linux Server Hardening— Existing Linux servers hardened to CIS Benchmark Level 1 (Level 2 on request) — SSH lockdown, fail2ban, automated patching, audit logging, and firewall rules — with a compliance report.
The Proxmox Web UI Hardening— Locks down the Proxmox web UI behind a hardened front door — reverse proxy with HTTPS, MFA, audit logging, and fail2ban — the fix for a data-center default install with nothing standing guard.
The Proxmox Cluster— A three-node Proxmox cluster built from scratch — shared storage, high availability, fencing, and tested live migration — enterprise virtualization without a VMware license.
The Cloud-Init Template Library— A set of reusable cloud-init templates — one per OS family — with your own defaults baked in, so every future VM provisions from a tested starting point instead of a manual install.
The Per-VM Setup— Per-VM provisioning from a cloud-init template — OS install, network and storage configuration, basic hardening, monitoring agent, and a documentation entry — priced per VM.
The Per-LXC Setup— Per-container LXC provisioning — template selection, network and storage configuration, optional app stack, hardening, and documentation — the lighter, denser alternative to a full VM.
The Proxmox Backup Setup— Proxmox Backup Server deployed and configured with jobs for every VM, a retention policy, off-site replication, and a tested restore — evidence backups actually work, not just that they run.
The Proxmox-to-Proxmox Migration— Move an existing Proxmox environment to new nodes — new hardware, a risky-in-place version upgrade, a datacenter move, or consolidating older hosts — with the old node left untouched until cutover is verified.
The VMware-to-Proxmox Migration— Move your VMware ESXi or vSphere VMs to Proxmox — configurations preserved, a parallel-run period, and a tested rollback plan — priced by VM count.
The Hyper-V-to-Proxmox Migration— Move VMs from Hyper-V to Proxmox using qemu-img conversion and VirtIO driver injection, with a parallel-run period and tested rollback before cutover.
The Proxmox Audit & Tune-up— A full audit of an existing Proxmox install — storage health, backup verification, update path, security posture — with the highest-priority fixes implemented, not just a findings document.
The Self-Hosted Git Setup— A self-hosted Git platform — Forgejo, Gitea, or GitLab CE — installed, configured, and handed over with an admin account ready to create users and repos.
The CI/CD Server Install— A self-hosted CI server — Jenkins, Woodpecker CI, or Drone — with build agents, secrets management, and one working sample pipeline for your main repo.
The Observability Stack— Prometheus, Loki, Tempo, and Grafana deployed and wired together, with a quoted number of starter dashboards and baseline alerting rules configured.
The Mail Relay Setup— Outbound mail rerouted through a transactional email service — AWS SES, Brevo, Postmark, Mailgun, SendGrid, or Resend — so it actually reaches inboxes.
The Sales Video— One scripted, voiced and edited 30-second sales video — visuals, motion graphics, music and your branding — built to sell a single offer, with up to two revision rounds.
The Course Video— One finished course video per unit — splash screen, video segments, screen recording and voice-over slides — produced from your outline and checked by your subject-matter expert.
The Animated Social Pack— One hook-first animated carousel of six to ten slides, designed to your brand and exported at platform-correct aspect ratios, with monthly bundles available.