Fixed-price IT work, held to one standard.
Reviews, workshops, builds and care plans for UniFi networks, MCP servers and the code your business runs on, delivered remotely and mostly in writing. Every change arrives staged, as a pull request or a dry run, for you or your IT provider to apply.
The practices behind every package.
Eight practices, four in AI and four in IT, and every package further down draws on them. Open one to read what it covers.
What we sell.
Every package has a fixed scope and a fixed price, quoted in writing before work starts. We never hold write access to your systems: we work with read-only or test credentials you issue and can revoke, and every change arrives staged for you or your IT provider to apply.
Doors
Where you start: fixed price, read-only, paid in full before work starts.
Agent and MCP Security Review
- One server or agent setup
- Up to three, or one remote server with OAuth
You get a findings report in plain English, ranked by blast radius, a hardening pull request when the server is yours, and a 30-minute walkthrough, live or recorded.
AI Connection Blueprint
- A questionnaire, one 60-minute call, then a written plan
You get a written plan for connecting AI to your own systems: what each connection may read and do, the approvals and logs it needs, the monthly cost, and one first build at a fixed price.
AI for IT Teams Workshop
- Remote half day, up to 20 people
Your team learns how assistants reach real systems through MCP, which guardrails belong in code and how to vet a third-party server, and keeps the recording, the slides and a one-page rollout checklist.
Code Health Check
- One repo up to 25,000 lines
One pull request adds CI, tests on the code paths that matter, secret scanning across full git history, a dependency audit and pinned actions, with a health report scored before and after.
Builds
Every build ships with tests, CI, documentation and a one-hour handoff.
Agent Team
- Up to six Claude agents
Claude agents take on the work you repeat every week, each with its own job, behind guardrail hooks on anything risky and a validator that proves the setup works, on your own Claude plan.
Read-only MCP connector
- One system, up to 10 tools
Your assistant reads one of your systems through an MCP server that logs every call and has no way to write.
Governed MCP connector
- One or two systems, up to 25 tools
Your assistant can also make changes, but every write is previewed and approved before it runs, with rollback where the system’s API allows it and an append-only audit log.
Repo Fleet Hardening
- Up to 20 repos in one GitHub organization
We bring the gates we run on our own repos to yours, as pull requests you merge: shared CI templates, actions pinned to commit SHAs, dependency updates gated on required checks, secret scanning and signed releases, with a fleet health report.
Private AI Gateway
- With a blind model test on your prompts
Your team reaches every AI model through one front door on your own server, with a key per person, budgets per team, routing that includes local models, and usage logs.
AI for UniFi
- One UniFi controller
Our open source mcp-unifi, configured read-only on your controller, lets an assistant answer questions about your network and stage changes as dry runs you apply, and you get a written network review.
Care plans
Billed monthly in advance. Three-month minimum, then month to month.
Connector care
- Monthly, per connector
Dependency and security updates arrive as pull requests you merge, with fixes when the upstream API changes, a monthly health report and one small change a month.
Agent team or gateway care
- Monthly, per agent team or gateway
You get model and tool updates, a monthly check that every agent still passes its validator, a usage and cost report and one small change a month.
Code health plan
- Monthly, up to three repos
Dependency updates arrive triaged with plain-English summaries, plus CI upkeep, secret hygiene, review on up to 10 new pull requests a month and a monthly report.
Fleet care
- Monthly, up to 20 repos
You get the code health plan across your whole fleet, with a monthly fleet report.
UniFi care
- Monthly, per site
Each month we review configuration drift, firmware, firewall rules and new clients, and stage any fixes as dry runs you apply.
mcp-unifi support
- Monthly, per organization
Teams that run the open source mcp-unifi themselves get email support with a two-business-day response and priority on their issues, through GitHub Sponsors or by invoice.
Claude agents we built do the bulk of it, and Pete Stergion reviews every deliverable before you see it.
Doors are paid in full before work starts. Builds are half to book the start date, half on delivery. Care plans are billed monthly in advance.
Your AI seats, API keys and hosting stay in your name and on your card. We never resell them or mark them up.
For MSPs and IT firms.
When a client asks you for AI, we do the review or the build behind you, under your name. You keep the relationship, the credentials and the managed IT.
A partner rate on every door and build, delivered behind you.
- You keep the client relationship and first-line support
- Your team reviews and applies every staged change
- Read-only or test credentials that you or your client issue and can revoke
- Care plans at the standard rate
- We never resell AI seats, API keys or hosting
- No help desk, monitoring or on-site work: we never compete for your managed IT
How it starts
Write to us about your firm and the client work you have in mind. Each partnership starts with a one-page agreement that sets your partner rate. The usual first step is the AI for IT Teams Workshop for your own staff.
Agents & MCP servers
Give AI access to your systems without handing it the keys.
An MCP server is how an assistant like Claude reaches a real system: your network controller, your ticket queue, your file shares, your database. We build them the way we build our own. The server holds the credentials, enforces the rules in code where no prompt can reach them, and logs every call.
We will also tell you when you do not need one. A skill with a script is often enough, and when an app already ships an official connector, we configure and restrict that one instead of building another.
- One MCP server per build, for one or two internal systems or vendor APIs, read-only by default
- Credentials held on the server, never in the model’s context
- Read-only modes, dry-run previews and approval gates on anything destructive
- Audit logs with secrets scrubbed, ready for review
- Shipped as a signed Docker image with health checks, for your team to deploy on your own infrastructure
- Claude Code skills and agents for the work that does not need a server
mcp-unifi
Our open source UniFi server has 100+ tools, dry-run previews, composite rollback and a JSONL audit log. Read exactly how we build before you hire us.
See mcp-unifiSkill or server?
A server earns its place when it holds a credential, enforces a rule, stays running, serves another app, or has to work from anywhere. If none of those is true, a skill does the same job with less upkeep.
Read whyAgent Team
Up to six Claude agents, built the way we run our own company: each with its own job, routing so the right one answers, guardrail hooks on anything risky and a validator that proves the setup works.
- Up to six Claude agents
Model strategy
Pick models on evidence, not on leaderboards.
Public benchmarks test their models on their prompts and their hardware. We test candidates on your own prompts. Blind comparisons settle quality, per-call cost tracking settles price, and a gateway your team runs in front of every model lets you switch providers, cap spend and see who used what.
- Blind, side-by-side evaluations on your own prompts with Open Model Arena, run with an evaluation key you issue, cap and can revoke
- Local versus cloud: what a model on your own hardware can replace
- An AI gateway configuration your team runs under its own provider keys: routing, metering and per-team budgets
- Part of the Private AI Gateway: the cost per task for each candidate model, in plain English
Open Model Arena
Our blind, cost-aware arena runs against any OpenAI-compatible endpoint, local or cloud, in one container.
See the arenaWe run local models too
Models run on our own hardware every day, so we can tell you honestly where they hold up and where the paid API is still worth it.
Private AI Gateway
One front door on your own server for every model your team uses: a key per person, budgets per team and usage logs, with routing set by a blind side-by-side test on Open Model Arena that shows the cost per task.
- With a blind model test on your prompts
Workflow automation
Stop doing the same tasks every week.
Most businesses run on manual effort: copying data between tools, sending follow-ups by hand, pulling reports from three different places. We build workflows where Claude reads, drafts and routes the routine items, such as new leads, review requests and the weekly report, and every run leaves a log you can check.
- Claude agents for routine work: lead follow-ups, review requests, the weekly report
- Each agent with its own job, guardrail hooks on anything risky and a log of every run
- Runs on your own Claude plan, under your own keys
- Delivered as an Agent Team, with a validator that proves the setup works
Where to start
With the AI Connection Blueprint: a questionnaire, one 60-minute call, then a written plan for what AI may read and do in your systems, ending in one recommended first build at a fixed price.
- A questionnaire, one 60-minute call, then a written plan
Agents for the work you repeat
Our Agent Team build puts up to six Claude agents on the work you repeat every week, with guardrail hooks on anything risky, running on your own Claude plan.
- Up to six Claude agents
Guardrails & governance
Know what an agent did, and under whose authority.
Once agents act on real systems, the question changes from whether they can do something to whether they should, who said so, and whether you can prove what happened. We design those controls: scoped permissions, approval steps, append-only audit trails, and checks that run on their own instead of depending on someone remembering to look.
- Scoped, expiring grants for what an agent may do
- Human approval on irreversible actions
- Append-only, hash-linked audit logs
- Signed receipts for delegated work, built on the Writ protocol
- Verification with controls that prove each check can fail
- Plain-English policies your team can follow
Writ Protocol
Our draft protocol for passing bounded authority between agents and getting signed receipts back. Two implementations, 288 conformance vectors, Apache 2.0.
See WritAI enablement for IT teams
Our public playbook maps the AI application stack for IT teams: what to learn, what to skip and how to keep it safe. Self-paced and free to read, and the basis of our AI for IT Teams Workshop.
ai-upskill-playbookNetworks
Segmented and documented, with every change previewed first.
Most small business networks are one flat network where the guest Wi-Fi, the printer and the office laptops can all see each other. We design segmented UniFi networks: separate VLANs for staff, devices and guests, with firewall rules between them. Every change arrives as an mcp-unifi dry run that you or your installer review and apply on your own controller. We only ever hold a read-only key you can revoke.
- A written review of segmentation: VLANs, firewall zones, guest and IoT isolation
- Recommended changes staged as mcp-unifi dry runs you apply
- IPv6, VPN and secure remote access
- A configuration backup step built into every staged change
- Read-only reviews of firewall rules, open ports, firmware and Wi-Fi settings
- Ask for a change in plain English, get back a dry run you apply
We run what we sell
Our own network is a UniFi Cloud Gateway Fiber on 2 gig fiber, split into trusted, IoT, guest and management networks, managed through our own MCP server.
Read the buildAI for UniFi
Our open source mcp-unifi, configured read-only on your controller, lets an assistant answer questions about your network and stage changes as dry runs you apply. It includes a written review of segmentation, firewall rules, open ports, firmware and Wi-Fi.
- One UniFi controller
Servers & hosting
Locked down to a checklist we published.
We run our own servers to one standard: hardened security, automated backups, monitoring and patching, with containers, reverse proxies and secure tunnels for the services we self-host. If we host your website, it runs on our own server, patched and backed up daily.
Every item below is on the checklist we published, free to follow on a server you own.
- Full firewall configuration with explicit allow and deny rules
- SSH hardening: custom port, key-only auth, fail2ban
- Admin panels restricted by IP, with FTP and plaintext mail ports closed
- Security headers on every domain (HSTS, X-Frame-Options, Referrer-Policy)
- SSL certificates installed and auto-renewing
- Automated OS security patches and daily kernel update checks
- Daily encrypted off-site backups with a retention policy
- Uptime and resource monitoring with alerts
You own the server
We never ask for SSH access. Follow the checklist yourself or hand it to your IT provider, and start with the free server security check, which reads only what your server shows the internet.
Get the free checkWe own the server
For every site we host: it runs on our own server, patched and backed up daily off-site, with HTTPS included. You keep your domain and DNS, and we send you the exact records to set.
Works with any provider
Hetzner, DigitalOcean, Linode, Vultr, AWS Lightsail, OVH. If it runs Linux, the checklist applies, and it is the same one we run on our own servers.
The checklistSecurity & code health
Your codebase, production ready.
You shipped fast and it works. But there are no tests, no CI pipeline, no security audit, and error handling is an afterthought. We add the checks that hold the line: CI with lint, type checks and tests, secret and dependency scans, and tests on the paths that matter most. One pull request, fixed scope, yours to review and merge.
Code written with AI needs this more, not less. It produces more code than anyone can review, so the checks that run without a reviewer are the ones that count.
- Test suites aimed at the code paths that matter, with coverage reporting
- CI pipelines with linting, type checks, tests and build verification
- Secret scanning across full git history, dependency audits, pinned actions
- Bugs found during the review, ranked in the report and fixed in the pull request where they are in scope
- A health report with before and after scoring
Code Health Check
Point us at a repository. We review the codebase, write the tests, configure the tooling and deliver a pull request you can review and merge. A larger repo gets a quote.
- One repo up to 25,000 lines
Repo Fleet Hardening
The same gates we run on our own repos, across up to 20 of yours in one GitHub organization: shared CI templates, pinned actions, dependency updates that merge only after required checks pass, secret scanning, lockfile drift checks, and SBOMs with signed releases.
- Up to 20 repos
Monthly code health plan
As you ship, we keep it there: dependency updates triaged with plain-English summaries, CI upkeep, secret hygiene and review on up to 10 new pull requests a month, with a monthly report. Every update arrives as a pull request you merge.
- Monthly, up to three repos
Web platforms
Where we started, and still a website that earns its keep.
We have built websites since 2009, for music festivals with 10,000+ attendees and local shops with five employees. We still build them, on their own or as part of a bigger project: fast, search-ready and hosted on our own server, so a fix is ours to make, with no other vendor’s ticket queue in the way.
- A fixed-scope site with a set page count, built on the same fast stack as this one
- Search visibility built in from day one: local SEO, structured data, page speed
- Hosting and upkeep for stores already in our care
- Migrations off GoDaddy, Wix, Squarespace, WordPress.com and Weebly
The advantage
When your site runs on our server, search fixes ship with the site, with no third party in between.
Tiers and prices
Three fixed website tiers and three hosting tiers, with the prices on the page.
See websitesFree checkup
Send us your URL and we will send back a graded audit of search visibility, speed, security and structured data. No cost, no strings.
Get the checkup- Preview before write
- You apply the change
- Log every call
- Credentials stay out of the prompt
- Sign the receipt
- Test the test
- Verify before done
Door, build, care plan.
Start wherever you are: a door to find out where you stand, a build to add what is missing, or a care plan to keep it that way. Every offer is listed in the packages above, and your price is fixed in writing before work begins.
Door
A fixed-price first step: a security review of your agents and MCP servers, a plan for connecting AI to your systems, a workshop for your IT team or a code health check. Every fix arrives staged, as a pull request or a dry run, for you to apply.
Build
A defined project: an agent team, an MCP connector, repo fleet hardening, a private AI gateway or AI for your UniFi network. Fixed scope, delivered as staged changes you apply.
Care plan
A monthly plan for a connector, an agent team or gateway, your code repos or your UniFi sites. Updates and fixes arrive staged, as pull requests or dry runs you apply. Questions go in writing and get a written answer within two business days.
Find out where you stand.
Two reports we will run on any public site, in plain English, at no cost, and they are yours whether or not you work with us. If you want to go further, the paid next step is an AI Connection Blueprint.
Is your server exposed?
We scan your server's public-facing security: headers, SSL, version leaks, exposed login pages and more. You get a plain-English report with what to fix first.
How does your site rank?
A full SEO audit: search visibility, page speed, structured data and more. Graded with a prioritized action plan. No cost, no strings.
Tell us what you want checked or automated. We will tell you what it takes.
No sales pitch and no discovery call that is really a sales call. A straight answer about what we can build, how we would keep it safe, and what it costs, quoted in writing.