I build the infrastructure
your business runs on.
Email, the website, the file server, the network and the security on top — built properly, then kept that way. On the Microsoft 365 licences you already pay for, on Sophos, or on open source you own outright. I do the build. Then I stay and run it.
services
What I build.
AI integration, enterprise or open-source
Wired into the systems you already run — or self-hosted on your own hardware, so none of it leaves the building.
who you get
Everything I sell, I run.
More about me →The mission. SD Tech Solutions exists to build the infrastructure a business runs on, and to keep it running. Sometimes that is an open-source stack I provision, configure and maintain myself. Sometimes it is Sophos, Microsoft 365 and the other enterprise systems you already pay for, onboarded properly and looked after. Either way the aim is the same: a resilient setup, a straight answer, and a solution that pays for itself.
I manage Windows Server, SharePoint and Microsoft 365 estates professionally — that is the day job, and it is where the standards come from. The consulting is that same work, at a scale a small business can actually afford.
What is hard to fake is a system that has been running in production for a year and someone who can tell you exactly where it breaks. Every tool on this site — the security console, the private AI, the file storage, the password vault — runs on my own hardware first. If it is not good enough for my infrastructure, it does not go on yours.
I take on a small number of clients at a time, because the person who scopes your build is the person who racks it. Everything I build is documented and reproducible — addressing plans, identity design, runbooks, versioned configuration — so your own staff or another engineer can pick it up from the paperwork if I am ever unavailable. If what you need is a help desk staffed around the clock, I will say so at the check-up and point you somewhere better suited. If you want one engineer who knows your estate by heart, that is exactly what this is.
selected work
Work I've shipped.
See everything →Office move with no internet
An acquired business relocated on short notice, with no documentation and no internet at the new site — a wireless link between buildings first, then the firewall, the servers and backups, all online before close of business.
Read the case study → Microsoft 365File server to SharePoint
300 GB+ of shared files moved off an office server into SharePoint Online, checked file by file until nothing was missing, with permissions rebuilt so staff see only what they should.
Read the case study → Live client siteSneakers Sports Lounge
Sports bar — events, menus and match listings, in production.
Visit the site →open source
My open-source projects.
All projects →Security and management tooling I built for my own fleet, now open source. Read the source, run it on your own hardware, or have me set it up for you.
EDR & email security
1,232 Sigma detection rules, five live threat-intel feeds, and a mail gateway — self-hosted or on my instance.
See what it does → Open source · freeRMM & remote management
Patching, monitoring, inventory, click-to-SSH and remote desktop from one Go agent. No seat count.
See what it does →sd@tech-solutions:~# systemctl status sd-tech-solutions.service
● sd-tech-solutions.service — infrastructure design, build and operation Loaded: loaded (/etc/systemd/system/sd.service; enabled) Active: active (running) — running production systems since the first server I was trusted with Tasks: infrastructure · security · networks · web · private-ai · open-source Status: "taking on new clients"
under the hood
Under the hood.
# optional reading — for the people who like to see the workings# architecture only. Sanitised for publication. $ systemctl list-units --type=service --state=running private-cloud › files, VPN, backups on my own hardware web-frontends › client sites + portals, hand-coded edr-platform › self-built EDR + email gateway [hosted in Canada] llm-runtime › self-hosted models, 7B–14B, air-gapped option $ uptime --since first rack years ago. rebuilt as the standards moved. still running.
01 infrastructure/ the layer everything else depends on ▸
- AD / Entra ID, hybrid identity, group policy, tiered admin separation
- VLAN segmentation, Wi-Fi design, point-to-point links between sites
- WireGuard site-to-site and remote access — admin services off the public internet entirely
- Versioned, encrypted, off-site backups — and restores actually tested
- Everything documented and reproducible, so your team can own it
02 security/ what's in the open-source security stack ▸
- 1,232 detection rules, built on the open SigmaHQ standard
- 24,000+ threat indicators from 5 live feeds, refreshed on a schedule
- Behavioural detection — process lineage, credential access, mass-encryption patterns; no prior signature required
- Tamper-evident audit log, hash-chained and per-tenant isolated
- Email gateway in front of the mailbox — Gmail live, Microsoft 365 in progress
- Free and open source — with the limitations documented →
03 ai/ how the private models are actually kept safe ▸
- Self-hosted 7B–14B models on local hardware — prompts and documents never leave the network
- Read-only first. The agent queries and drafts; it changes nothing by default
- Approval gate on every write and every outbound email
- Scoped, least-privilege database credentials — never a shared admin login
- Vendor-agnostic: self-hosted, Claude or OpenAI, your call
what happens next
What happens after you get in touch.
Most people write to me when something has already started to hurt: the server is out of warranty and nobody wants to touch it, the backup has never been restored, email is unreliable, or the person who set everything up has left. From there the sequence is the same every time.
- The free check-up. An hour of my time, on-site or remote, looking at what you actually have. You get a straight assessment of what is exposed, what is costing you, and what to fix first — in a short write-up that is yours either way.
- Scope, in writing. What is in, what is out, what it costs, and what “done” looks like — agreed before anything is touched.
- Build alongside the old. New systems go up beside what you have, get tested, then swap in during a planned window. Reversible at every step.
- Handover. Documentation, credentials, and a walkthrough for whoever runs it day to day. It is yours to keep.
- Keep it running — if you want. Patching, monitoring, backups checked and faults fixed under a light retainer, or your own team takes it from here.
get in touch
Book a free check-up.
An hour of my time, at no cost, on-site or remote. I change nothing on your systems during it, and you keep the write-up whether or not you hire me.
- Where you're exposed right now
- What's quietly costing you money
- One thing you can fix this week
One person, start to finish — I build it, I run it, and I am the one who answers.
Or write directly: info@sd-techsolutions.com — I reply within one business day.