One specialist for every part of your IT.
Security, everyday support, networks, websites and private AI — designed, built and run in-house by the person you actually talk to.
sd@tech-solutions:~# systemctl status sd-tech-solutions.service
● sd-tech-solutions.service — one specialist, every layer of your IT Loaded: loaded (/etc/systemd/system/sd.service; enabled) Active: active (running) — racking servers since the first box on a shelf Tasks: security · managed-it · networks · web · private-ai Status: "accepting new clients"
services
Pick what you need.
Private AI, running on your own hardware
An assistant that reads your documents and drafts your paperwork — without any of it leaving the building.
portfolio
Work I've shipped.
See everything →Sneakers Sports Lounge
Sports bar — events, menus and match listings.
Visit the site → DemoElectrical King
Contractor site with quoting, invoicing, jobs and payroll behind it.
Open the demo → DemoOne Stop Mechanical
Trades company site with a booking form that reaches someone.
Open the demo →under-the-hood
Under the hood.
# not your thing? skip it — this part is for the people who ask# architecture only — no addresses, no secrets. $ systemctl list-units --type=service --state=running edr-platform › self-built EDR + email gateway [hosted in Canada] private-cloud › files, VPN, backups on my own hardware llm-runtime › self-hosted models, 7B–14B, air-gapped option web-frontends › client sites + portals, hand-coded $ uptime --since first box racked years ago. rebuilt more times than I'd admit. still running.
drwxr-x--- security/ what's actually running on your endpoints ▸
- 1,200+ detection rules in production, Sigma-based
- 23,000+ threat indicators, refreshed every 6 hours from 5 live feeds
- Behavioural detection — process lineage, credential access, mass-encryption patterns; no prior signature required
- Tamper-evident audit log, Canadian-hosted, per-tenant isolated
- Secure email gateway in front of the mailbox, not bolted on after
drwxr-xr-x ai/ how the private models are actually kept safe ▸
- Self-hosted 7B–14B models on local hardware — prompts and documents never leave the network
- Read-only first. The agent queries and drafts; it changes nothing by default
- Approval gate on every write and every outbound email
- Scoped, least-privilege database credentials — never a shared admin login
- Vendor-agnostic: self-hosted, Claude or OpenAI, your call
drwxr-xr-x infrastructure/ the layer everything else depends on ▸
- AD / Entra ID, hybrid identity, group policy, tiered admin separation
- VLAN segmentation, Wi-Fi design, point-to-point links between sites
- WireGuard site-to-site and remote access — admin services off the public internet entirely
- Versioned, encrypted, off-site backups — and restores actually tested
- Everything documented and reproducible, so your team can own it
get-in-touch
Book a free check-up.
An hour of my time. No cost, no obligation.
- Where you're exposed right now
- What's quietly costing you money
- One thing you can fix this week
One person, start to finish — I build it, I run it, and I answer the phone.
Prefer email? info@sd-techsolutions.com — I reply within one business day.