I build the infrastructure
your business runs on.

Email, the website, the file server, the network and the security on top — built properly, then kept that way. On the Microsoft 365 licences you already pay for, on Sophos, or on open source you own outright. I do the build. Then I stay and run it.

services

What I build.

01

Infrastructure, from scratch or rebuilt

Servers, networks, Wi-Fi, file storage, email and backups that actually get restore-tested. On your premises, in the cloud, or a mix of both.

02

Websites and business systems

Start with the site your customers see. Then the web apps behind it — booking, quoting, invoicing — and the internal systems: point of sale, stock and inventory, CRM and ERP. Off-the-shelf where it fits, custom where it doesn't.

03

Microsoft 365, set up properly

Email, Teams, OneDrive and SharePoint, the accounts your staff sign in with and the computers they sign in from. Migrated, configured and locked down — not left on the defaults it shipped with.

04

Managed security

Security on every computer and every mailbox — using what's already included in your Microsoft 365 subscription, Sophos where your insurer wants a named vendor, or my own open-source tools. Set up, tuned to how your office works, then watched. The industry calls this EDR & MSP

05

Migrations and upgrades

Moving off ageing hardware, a host you've outgrown, or a setup someone else left behind — planned, staged and reversible.

06

Looking after it once it's live

Updates, patching, monitoring and remote fixes, so faults are found and fixed before they interrupt your day. The industry calls this RMM

AI integration, enterprise or open-source

Wired into the systems you already run — or self-hosted on your own hardware, so none of it leaves the building.

How that works →
Priced per engagement. Every job is quoted in writing after the check-up — a new website, an email migration, a file server, or the whole office. The open-source tooling is free; what I charge for is designing, building and running your infrastructure. Book a free check-up →

who you get

Everything I sell, I run.

More about me →

The mission. SD Tech Solutions exists to build the infrastructure a business runs on, and to keep it running. Sometimes that is an open-source stack I provision, configure and maintain myself. Sometimes it is Sophos, Microsoft 365 and the other enterprise systems you already pay for, onboarded properly and looked after. Either way the aim is the same: a resilient setup, a straight answer, and a solution that pays for itself.

I manage Windows Server, SharePoint and Microsoft 365 estates professionally — that is the day job, and it is where the standards come from. The consulting is that same work, at a scale a small business can actually afford.

What is hard to fake is a system that has been running in production for a year and someone who can tell you exactly where it breaks. Every tool on this site — the security console, the private AI, the file storage, the password vault — runs on my own hardware first. If it is not good enough for my infrastructure, it does not go on yours.

I take on a small number of clients at a time, because the person who scopes your build is the person who racks it. Everything I build is documented and reproducible — addressing plans, identity design, runbooks, versioned configuration — so your own staff or another engineer can pick it up from the paperwork if I am ever unavailable. If what you need is a help desk staffed around the clock, I will say so at the check-up and point you somewhere better suited. If you want one engineer who knows your estate by heart, that is exactly what this is.

open source

My open-source projects.

All projects →

Security and management tooling I built for my own fleet, now open source. Read the source, run it on your own hardware, or have me set it up for you.

Download the source. 0.1.0-e3cbfe3 · AGPL-3.0 · 0.8 MB · no sign-up, no email address Download ↓

sd@tech-solutions:~# systemctl status sd-tech-solutions.service

 sd-tech-solutions.service — infrastructure design, build and operation
   Loaded: loaded (/etc/systemd/system/sd.service; enabled)
   Active: active (running) — running production systems since the first server I was trusted with
    Tasks: infrastructure · security · networks · web · private-ai · open-source
   Status: "taking on new clients"

under the hood

Under the hood.

# optional reading — for the people who like to see the workings
sd@lab — the stack behind the practice
# architecture only. Sanitised for publication.

$ systemctl list-units --type=service --state=running

  private-cloud       files, VPN, backups on my own hardware
  web-frontends       client sites + portals, hand-coded
  edr-platform        self-built EDR + email gateway  [hosted in Canada]
  llm-runtime         self-hosted models, 7B–14B, air-gapped option

$ uptime --since
  first rack years ago. rebuilt as the standards moved.
  still running.
01 infrastructure/ the layer everything else depends on
  • AD / Entra ID, hybrid identity, group policy, tiered admin separation
  • VLAN segmentation, Wi-Fi design, point-to-point links between sites
  • WireGuard site-to-site and remote access — admin services off the public internet entirely
  • Versioned, encrypted, off-site backups — and restores actually tested
  • Everything documented and reproducible, so your team can own it
02 security/ what's in the open-source security stack
  • 1,232 detection rules, built on the open SigmaHQ standard
  • 24,000+ threat indicators from 5 live feeds, refreshed on a schedule
  • Behavioural detection — process lineage, credential access, mass-encryption patterns; no prior signature required
  • Tamper-evident audit log, hash-chained and per-tenant isolated
  • Email gateway in front of the mailbox — Gmail live, Microsoft 365 in progress
  • Free and open source — with the limitations documented →
03 ai/ how the private models are actually kept safe
  • Self-hosted 7B–14B models on local hardware — prompts and documents never leave the network
  • Read-only first. The agent queries and drafts; it changes nothing by default
  • Approval gate on every write and every outbound email
  • Scoped, least-privilege database credentials — never a shared admin login
  • Vendor-agnostic: self-hosted, Claude or OpenAI, your call

what happens next

What happens after you get in touch.

Most people write to me when something has already started to hurt: the server is out of warranty and nobody wants to touch it, the backup has never been restored, email is unreliable, or the person who set everything up has left. From there the sequence is the same every time.

  1. The free check-up. An hour of my time, on-site or remote, looking at what you actually have. You get a straight assessment of what is exposed, what is costing you, and what to fix first — in a short write-up that is yours either way.
  2. Scope, in writing. What is in, what is out, what it costs, and what “done” looks like — agreed before anything is touched.
  3. Build alongside the old. New systems go up beside what you have, get tested, then swap in during a planned window. Reversible at every step.
  4. Handover. Documentation, credentials, and a walkthrough for whoever runs it day to day. It is yours to keep.
  5. Keep it running — if you want. Patching, monitoring, backups checked and faults fixed under a light retainer, or your own team takes it from here.
Book a free check-up →

get in touch

Book a free check-up.

An hour of my time, at no cost, on-site or remote. I change nothing on your systems during it, and you keep the write-up whether or not you hire me.

  • Where you're exposed right now
  • What's quietly costing you money
  • One thing you can fix this week

One person, start to finish — I build it, I run it, and I am the one who answers.

Or write directly: info@sd-techsolutions.com — I reply within one business day.

Goes straight to me, and nowhere else.

Book a free check-up →