Home page

Operations Security (OpSec)

is a set of instruments facilitating privacy and security. Our approach to OpSec builds upon possibly high simplicity, ensured processing efficiency and cryptographic solutions of proven reliability.
Miniature environment

Secure work environments

Designing and deployment of secure work environments
Secure computer networksMacOS personal systems and workstationsiOS mobile devicesBSD Unix and Ubuntu Linux servers systemsVirtualisation and security of key services and applicationsPrivacy and data encryptionDevOps tasks
Miniature services

Production services and key server processes

Engineering, deployment, security and optimisation of key production services for Unix and Linux systems
Advanced secure work environmentsProductions services
  • Web servers — service providing content over the HTTP protocol for any tasks, including up to complex tasks in cloud and cluster environments — solutions for WebOps NginxCaddyrelayd
  • CGI environments — code execution environments closely cooperating with HTTP servers, usually providing logic for Web — solutions for PHP programming services and Go programming services PHPGo
  • Databases — systems of standard production databases offering a wide array of functions and access protocols MySQLPercona MySQLPostgreSQL
  • Specialised databases — specialised purpose database systems or databases working within blockchain architectures SQLiteBerkeley DBRocksDBMonero LMDB
  • Electronic mail servers — mail exchange systems, spam filtering and providing access to client applications OpenSMTPDPostfixRspamd
  • Secure communication systems — secure text, audio and video communication systems, usually deployed in closed-loop settings — solutions for privacy of personal and business communication SignalSimpleXMatrixIRC
  • Cluster and virtualisation production systems — deployments of microservice containerisation and virtualisation in essential clusters and load balancing — solutions for virtualisation of systems and services DockerDocker SwarmKVMbhyve
  • Git repositories — code repositories and version control systems with Web interfaces — solutions for GitOps GitGitLabGiteagitolite
  • Cloud frameworks — services enabling easy online data synchronisation and exchange — solutions for private and public clouds and secure online data sharing ownCloudSeafileSyncthingRclone
  • Data sharing servers — systems of efficient high volume data sharing using secure high-performance SFTP and SCP protocols — solutions for modern filesystems and advanced data storage ZFSBtrfsOpenSSH
Production and DevOps support services
  • Authentication servers — servers providing centralised system, user and process authentication, usually in DevOps environments SSSD
  • DNS servers — nameservers configured for efficient and secure work in secure environments and with DevOps instrumentation Unbound
  • SMB and NFS servers — services providing easy data sharing for local networks — solutions for advanced computer networks SambaNFS
Miniature Performance

Systems and services performance monitoring

Solutions for monitoring of code performance, infrastructre, network systems, virtualisation as well as services and processes
Performance monitoring with PrometheusPerformance visualisation and analysis
Miniature virtualisation

Virtualisation of systems and services

Engineering, deployment, management and optimisation of virtualisation provider systems and virtual machines
Engineering, deployment, specialised configuration, advanced security and optimisation of virtualisation systems and individual virtual machines
  • KVM/Qemu virtualisation for Linux systems
  • bhyve virtualisation for FreeBSD
  • vmm virtualisation for OpenBSD
  • VMWare virtualisation framework for multiple systems
  • VirtualBox virtualisation framework for multiple systems
  • UTM/Qemu virtualisation for MacOS and Apple ARM64
Virtualisation securitySpecial purpose virtualisation based toolset distributions
  • Whonix Linux system
Miniature infrastructure

Infrastructure of secure wired and wireless networks

Engineering, deployment, security and optimisation of network infrastructure
Advanced network infrastructure
  • Wired networks
    • Ethernet networks with throughput up to 10 Gbit/s
    • Local networks requiring secure access authentication
    • Ethernet encryption
  • Wired networks
    • Standard WiFi 6 and 7 wireless network
    • High performance wireless networks with throughput up to 2.5 Gbit/s
    • Multi-layered wireless network encryption
    • Wireless networks access authentication systems
  • Network peripherals
    • Ethernet oriented Network Attached Storage (NAS) disk resources
    • Printing servers and networked printers
  • Advanced solutions
    • Multi source and redundant power management for the whole networks
    • Advanced management of Internet access endpoints on own hardware and software
Secure work environmentNetworks delivering complete Ubiquiti Unifi functionality
  • Private surveillance
  • Advanced network automation
  • Local network and and video conferencing
  • User identity authentication and secure premise and building access
Miniature Cloud

Private and public clouds and secure online data sharing

Engineering, deployment and management of private and public cloud services
Private cloudsPublic clouds
Miniature DeepWeb

Engineering of non-public and anonymous networks

Engineering, deployment, security and optimisation of services for the non-public Internet (deep web) and the hidden Internet (darkweb)
Deep web networksAnonymous networks
Miniature norms

Operational compliance with cybersecurity norms

Engineering and development of solutions by default compliant with current cybersecurity norms
Compliance with Polish and European policy
  • The General Data Protection Regulation (GDPR), EU Regulation 2016/679
  • The Network Information and Security (NIS2), EU Directive 2022/2557, with the novelization of the Act on the National Cybersecurity System, a preview published on 23 april 2024, implementing NIS2 requirements
  • The Act on the National Cybersecurity System, published on 5 june 2018.
Compliance with the ISO international standards on cybersecurity and data privacy
  • Norm ISO/IEC 27001:2022 — an outline norm on Information Security Management Systems, with key extensions
    • Norm ISO/IEC 27002:2022 — Information security
    • Norm ISO/IEC 27701:2019 — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management
  • Norm ISO/IEC 27017:2015 — Information security for cloud services
  • Norm ISO/IEC 27018:2019 — Protection of personal data in public clouds
  • Norms ISO/IEC 27033-1|2|3|4|5|6|7 — Network security
  • Norms ISO/IEC 27034-1|2|3|5|5-1 — Application security
  • Norm ISO/IEC 27040:2024 — Storage security
  • Norm ISO/IEC 27100:2020 — Cybersecurity
Miniature servers

Secure server systems

Advanced server systems delivering security and stability suitable for handling of virtually any task
FreeBSD server systems

Advanced BSD Unix offering unique features. Server dedicated.

OpenBSD server systems

A legendarily secure system with a group of trusted daemons. Special purpose use.

Ubuntu Server server systems

Easy to use and versatile Linux. Universal use.


Advanced management of other systems
  • Oracle Solaris 11 server systems
  • Debian GNU/Linux server systems
Server solutions consultancy
  • Advisory services for purchasing, expansions and configuration of server systems and hardware
  • Advisory services for peering analysis and datacenter choice
Miniature service isolation

Isolation of services and processes

Engineering, deployment, security nad optimisation of advanced containerisation and isolation of server services
Cluster and microservices containerisation
  • Docker i Docker Swarm systems for Linux and MacOS
  • Secondary containerisation services for Linux systems
Advanced isolation of productions services and secure networks
  • VNET and Netgraph enabled jail isolation system for FreeBSD
  • Kernel Zones isolation system for Oracle Solaris 11
  • Secondary isolation systems for FreeBSD and OpenBSD
Deep virtualisation of server servicesSpecial purpose isolation and virtualisation based toolset distributions
  • Whonix i Tails Linux systems
Miniature networks

Advanced computer networks

Engineering, deployment, security and optimisation of secure high performance computer networks
Local networksNetwork virtualisationAdvanced server solutions and specialised network servicesSecure networks
Miniature VPN

Virtual Private Networks and secure data transport systems

Solutions ensuring secure communication between secure severs systems and networks
High performance secure IPSec linksWireguard protocol based virtual private network
  • Optimisation, configuration and multiplex operation of access servers
  • Wireguard links for secure networks and mobile clients
  • Asymmetric cryptography based anonymous (or blind) wireguard links
  • Special purpose wireguard solutions for secure servers systems
  • Solutions preventing wireguard protocol blacklisting
  • Solutions for advanced computer networks and privacy of personal and business communication
Ssh (OpenSSH) protocol based virtual private network
  • Virtualisation and ssh deployment as special purpose VPNs
  • Secure data transport for server systems and specialised networking hardware
  • Ssh as a secure authentication system for network resources
Secondary VPN solutions
  • OpenVPN based virtual private networks and links
  • Cisco AnyConnect based virtual private networks and links
Miniature privacy

Privacy of personal and business communication

Solutions ensuring privacy of digital communication — from authenticated electronic mail to deniable videoconferencing
Secure communication for computer and mobile systemsSecure communication in environments with specialised security requirements
Miniature environment

Secure work environments

Designing and deployment of secure work environments
Secure computer networksMacOS personal systems and workstationsiOS mobile devicesBSD Unix and Ubuntu Linux servers systemsVirtualisation and security of key services and applicationsPrivacy and data encryptionDevOps tasks
Miniature Performance

Systems and services performance monitoring

Solutions for monitoring of code performance, infrastructre, network systems, virtualisation as well as services and processes
Performance monitoring with PrometheusPerformance visualisation and analysis
Miniature service isolation

Isolation of services and processes

Engineering, deployment, security nad optimisation of advanced containerisation and isolation of server services
Cluster and microservices containerisation
  • Docker i Docker Swarm systems for Linux and MacOS
  • Secondary containerisation services for Linux systems
Advanced isolation of productions services and secure networks
  • VNET and Netgraph enabled jail isolation system for FreeBSD
  • Kernel Zones isolation system for Oracle Solaris 11
  • Secondary isolation systems for FreeBSD and OpenBSD
Deep virtualisation of server servicesSpecial purpose isolation and virtualisation based toolset distributions
  • Whonix i Tails Linux systems
Miniature infrastructure

Infrastructure of secure wired and wireless networks

Engineering, deployment, security and optimisation of network infrastructure
Advanced network infrastructure
  • Wired networks
    • Ethernet networks with throughput up to 10 Gbit/s
    • Local networks requiring secure access authentication
    • Ethernet encryption
  • Wired networks
    • Standard WiFi 6 and 7 wireless network
    • High performance wireless networks with throughput up to 2.5 Gbit/s
    • Multi-layered wireless network encryption
    • Wireless networks access authentication systems
  • Network peripherals
    • Ethernet oriented Network Attached Storage (NAS) disk resources
    • Printing servers and networked printers
  • Advanced solutions
    • Multi source and redundant power management for the whole networks
    • Advanced management of Internet access endpoints on own hardware and software
Secure work environmentNetworks delivering complete Ubiquiti Unifi functionality
  • Private surveillance
  • Advanced network automation
  • Local network and and video conferencing
  • User identity authentication and secure premise and building access
Miniature privacy

Privacy of personal and business communication

Solutions ensuring privacy of digital communication — from authenticated electronic mail to deniable videoconferencing
Secure communication for computer and mobile systemsSecure communication in environments with specialised security requirements
Miniature norms

Operational compliance with cybersecurity norms

Engineering and development of solutions by default compliant with current cybersecurity norms
Compliance with Polish and European policy
  • The General Data Protection Regulation (GDPR), EU Regulation 2016/679
  • The Network Information and Security (NIS2), EU Directive 2022/2557, with the novelization of the Act on the National Cybersecurity System, a preview published on 23 april 2024, implementing NIS2 requirements
  • The Act on the National Cybersecurity System, published on 5 june 2018.
Compliance with the ISO international standards on cybersecurity and data privacy
  • Norm ISO/IEC 27001:2022 — an outline norm on Information Security Management Systems, with key extensions
    • Norm ISO/IEC 27002:2022 — Information security
    • Norm ISO/IEC 27701:2019 — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management
  • Norm ISO/IEC 27017:2015 — Information security for cloud services
  • Norm ISO/IEC 27018:2019 — Protection of personal data in public clouds
  • Norms ISO/IEC 27033-1|2|3|4|5|6|7 — Network security
  • Norms ISO/IEC 27034-1|2|3|5|5-1 — Application security
  • Norm ISO/IEC 27040:2024 — Storage security
  • Norm ISO/IEC 27100:2020 — Cybersecurity
Miniature services

Production services and key server processes

Engineering, deployment, security and optimisation of key production services for Unix and Linux systems
Advanced secure work environmentsProductions services
  • Web servers — service providing content over the HTTP protocol for any tasks, including up to complex tasks in cloud and cluster environments — solutions for WebOps NginxCaddyrelayd
  • CGI environments — code execution environments closely cooperating with HTTP servers, usually providing logic for Web — solutions for PHP programming services and Go programming services PHPGo
  • Databases — systems of standard production databases offering a wide array of functions and access protocols MySQLPercona MySQLPostgreSQL
  • Specialised databases — specialised purpose database systems or databases working within blockchain architectures SQLiteBerkeley DBRocksDBMonero LMDB
  • Electronic mail servers — mail exchange systems, spam filtering and providing access to client applications OpenSMTPDPostfixRspamd
  • Secure communication systems — secure text, audio and video communication systems, usually deployed in closed-loop settings — solutions for privacy of personal and business communication SignalSimpleXMatrixIRC
  • Cluster and virtualisation production systems — deployments of microservice containerisation and virtualisation in essential clusters and load balancing — solutions for virtualisation of systems and services DockerDocker SwarmKVMbhyve
  • Git repositories — code repositories and version control systems with Web interfaces — solutions for GitOps GitGitLabGiteagitolite
  • Cloud frameworks — services enabling easy online data synchronisation and exchange — solutions for private and public clouds and secure online data sharing ownCloudSeafileSyncthingRclone
  • Data sharing servers — systems of efficient high volume data sharing using secure high-performance SFTP and SCP protocols — solutions for modern filesystems and advanced data storage ZFSBtrfsOpenSSH
Production and DevOps support services
  • Authentication servers — servers providing centralised system, user and process authentication, usually in DevOps environments SSSD
  • DNS servers — nameservers configured for efficient and secure work in secure environments and with DevOps instrumentation Unbound
  • SMB and NFS servers — services providing easy data sharing for local networks — solutions for advanced computer networks SambaNFS
Miniature virtualisation

Virtualisation of systems and services

Engineering, deployment, management and optimisation of virtualisation provider systems and virtual machines
Engineering, deployment, specialised configuration, advanced security and optimisation of virtualisation systems and individual virtual machines
  • KVM/Qemu virtualisation for Linux systems
  • bhyve virtualisation for FreeBSD
  • vmm virtualisation for OpenBSD
  • VMWare virtualisation framework for multiple systems
  • VirtualBox virtualisation framework for multiple systems
  • UTM/Qemu virtualisation for MacOS and Apple ARM64
Virtualisation securitySpecial purpose virtualisation based toolset distributions
  • Whonix Linux system
Miniature VPN

Virtual Private Networks and secure data transport systems

Solutions ensuring secure communication between secure severs systems and networks
High performance secure IPSec linksWireguard protocol based virtual private network
  • Optimisation, configuration and multiplex operation of access servers
  • Wireguard links for secure networks and mobile clients
  • Asymmetric cryptography based anonymous (or blind) wireguard links
  • Special purpose wireguard solutions for secure servers systems
  • Solutions preventing wireguard protocol blacklisting
  • Solutions for advanced computer networks and privacy of personal and business communication
Ssh (OpenSSH) protocol based virtual private network
  • Virtualisation and ssh deployment as special purpose VPNs
  • Secure data transport for server systems and specialised networking hardware
  • Ssh as a secure authentication system for network resources
Secondary VPN solutions
  • OpenVPN based virtual private networks and links
  • Cisco AnyConnect based virtual private networks and links
Miniature DeepWeb

Engineering of non-public and anonymous networks

Engineering, deployment, security and optimisation of services for the non-public Internet (deep web) and the hidden Internet (darkweb)
Deep web networksAnonymous networks
Miniature servers

Secure server systems

Advanced server systems delivering security and stability suitable for handling of virtually any task
FreeBSD server systems

Advanced BSD Unix offering unique features. Server dedicated.

OpenBSD server systems

A legendarily secure system with a group of trusted daemons. Special purpose use.

Ubuntu Server server systems

Easy to use and versatile Linux. Universal use.


Advanced management of other systems
  • Oracle Solaris 11 server systems
  • Debian GNU/Linux server systems
Server solutions consultancy
  • Advisory services for purchasing, expansions and configuration of server systems and hardware
  • Advisory services for peering analysis and datacenter choice
Miniature networks

Advanced computer networks

Engineering, deployment, security and optimisation of secure high performance computer networks
Local networksNetwork virtualisationAdvanced server solutions and specialised network servicesSecure networks
Miniature Cloud

Private and public clouds and secure online data sharing

Engineering, deployment and management of private and public cloud services
Private cloudsPublic clouds