What we know

The practices behind every package.

Eight practices, four in AI and four in IT, and every package further down draws on them. Open one to read what it covers.

Packages

What we sell.

Every package has a fixed scope and a fixed price, quoted in writing before work starts. We never hold write access to your systems: we work with read-only or test credentials you issue and can revoke, and every change arrives staged for you or your IT provider to apply.

1

Doors

Where you start: fixed price, read-only, paid in full before work starts.

Agent and MCP Security Review

  • One server or agent setup
  • Up to three, or one remote server with OAuth

You get a findings report in plain English, ranked by blast radius, a hardening pull request when the server is yours, and a 30-minute walkthrough, live or recorded.

AI Connection Blueprint

  • A questionnaire, one 60-minute call, then a written plan

You get a written plan for connecting AI to your own systems: what each connection may read and do, the approvals and logs it needs, the monthly cost, and one first build at a fixed price.

AI for IT Teams Workshop

  • Remote half day, up to 20 people

Your team learns how assistants reach real systems through MCP, which guardrails belong in code and how to vet a third-party server, and keeps the recording, the slides and a one-page rollout checklist.

Code Health Check

  • One repo up to 25,000 lines

One pull request adds CI, tests on the code paths that matter, secret scanning across full git history, a dependency audit and pinned actions, with a health report scored before and after.

2

Builds

Every build ships with tests, CI, documentation and a one-hour handoff.

Agent Team

  • Up to six Claude agents

Claude agents take on the work you repeat every week, each with its own job, behind guardrail hooks on anything risky and a validator that proves the setup works, on your own Claude plan.

Read-only MCP connector

  • One system, up to 10 tools

Your assistant reads one of your systems through an MCP server that logs every call and has no way to write.

Governed MCP connector

  • One or two systems, up to 25 tools

Your assistant can also make changes, but every write is previewed and approved before it runs, with rollback where the system’s API allows it and an append-only audit log.

Repo Fleet Hardening

  • Up to 20 repos in one GitHub organization

We bring the gates we run on our own repos to yours, as pull requests you merge: shared CI templates, actions pinned to commit SHAs, dependency updates gated on required checks, secret scanning and signed releases, with a fleet health report.

Private AI Gateway

  • With a blind model test on your prompts

Your team reaches every AI model through one front door on your own server, with a key per person, budgets per team, routing that includes local models, and usage logs.

AI for UniFi

  • One UniFi controller

Our open source mcp-unifi, configured read-only on your controller, lets an assistant answer questions about your network and stage changes as dry runs you apply, and you get a written network review.

3

Care plans

Billed monthly in advance. Three-month minimum, then month to month.

Connector care

  • Monthly, per connector

Dependency and security updates arrive as pull requests you merge, with fixes when the upstream API changes, a monthly health report and one small change a month.

Agent team or gateway care

  • Monthly, per agent team or gateway

You get model and tool updates, a monthly check that every agent still passes its validator, a usage and cost report and one small change a month.

Code health plan

  • Monthly, up to three repos

Dependency updates arrive triaged with plain-English summaries, plus CI upkeep, secret hygiene, review on up to 10 new pull requests a month and a monthly report.

Fleet care

  • Monthly, up to 20 repos

You get the code health plan across your whole fleet, with a monthly fleet report.

UniFi care

  • Monthly, per site

Each month we review configuration drift, firmware, firewall rules and new clients, and stage any fixes as dry runs you apply.

mcp-unifi support

  • Monthly, per organization

Teams that run the open source mcp-unifi themselves get email support with a two-business-day response and priority on their issues, through GitHub Sponsors or by invoice.

Who does the work

Claude agents we built do the bulk of it, and Pete Stergion reviews every deliverable before you see it.

How you pay

Doors are paid in full before work starts. Builds are half to book the start date, half on delivery. Care plans are billed monthly in advance.

What stays yours

Your AI seats, API keys and hosting stay in your name and on your card. We never resell them or mark them up.

Partners

For MSPs and IT firms.

When a client asks you for AI, we do the review or the build behind you, under your name. You keep the relationship, the credentials and the managed IT.

Under your name.

A partner rate on every door and build, delivered behind you.

  1. You keep the client relationship and first-line support
  2. Your team reviews and applies every staged change
  3. Read-only or test credentials that you or your client issue and can revoke
  4. Care plans at the standard rate
  5. We never resell AI seats, API keys or hosting
  6. No help desk, monitoring or on-site work: we never compete for your managed IT

How it starts

Write to us about your firm and the client work you have in mind. Each partnership starts with a one-page agreement that sets your partner rate. The usual first step is the AI for IT Teams Workshop for your own staff.

Ask about partnering
AI solutions · 01

Agents & MCP servers

Give AI access to your systems without handing it the keys.

An MCP server is how an assistant like Claude reaches a real system: your network controller, your ticket queue, your file shares, your database. We build them the way we build our own. The server holds the credentials, enforces the rules in code where no prompt can reach them, and logs every call.

We will also tell you when you do not need one. A skill with a script is often enough, and when an app already ships an official connector, we configure and restrict that one instead of building another.

  • One MCP server per build, for one or two internal systems or vendor APIs, read-only by default
  • Credentials held on the server, never in the model’s context
  • Read-only modes, dry-run previews and approval gates on anything destructive
  • Audit logs with secrets scrubbed, ready for review
  • Shipped as a signed Docker image with health checks, for your team to deploy on your own infrastructure
  • Claude Code skills and agents for the work that does not need a server
Proof

mcp-unifi

Our open source UniFi server has 100+ tools, dry-run previews, composite rollback and a JSONL audit log. Read exactly how we build before you hire us.

See mcp-unifi

Skill or server?

A server earns its place when it holds a credential, enforces a rule, stays running, serves another app, or has to work from anywhere. If none of those is true, a skill does the same job with less upkeep.

Read why

Agent Team

Up to six Claude agents, built the way we run our own company: each with its own job, routing so the right one answers, guardrail hooks on anything risky and a validator that proves the setup works.

  • Up to six Claude agents
See the package
AI solutions · 02

Model strategy

Pick models on evidence, not on leaderboards.

Public benchmarks test their models on their prompts and their hardware. We test candidates on your own prompts. Blind comparisons settle quality, per-call cost tracking settles price, and a gateway your team runs in front of every model lets you switch providers, cap spend and see who used what.

  • Blind, side-by-side evaluations on your own prompts with Open Model Arena, run with an evaluation key you issue, cap and can revoke
  • Local versus cloud: what a model on your own hardware can replace
  • An AI gateway configuration your team runs under its own provider keys: routing, metering and per-team budgets
  • Part of the Private AI Gateway: the cost per task for each candidate model, in plain English
Proof

Open Model Arena

Our blind, cost-aware arena runs against any OpenAI-compatible endpoint, local or cloud, in one container.

See the arena

We run local models too

Models run on our own hardware every day, so we can tell you honestly where they hold up and where the paid API is still worth it.

Private AI Gateway

One front door on your own server for every model your team uses: a key per person, budgets per team and usage logs, with routing set by a blind side-by-side test on Open Model Arena that shows the cost per task.

  • With a blind model test on your prompts
See the package
AI solutions · 03

Workflow automation

Stop doing the same tasks every week.

Most businesses run on manual effort: copying data between tools, sending follow-ups by hand, pulling reports from three different places. We build workflows where Claude reads, drafts and routes the routine items, such as new leads, review requests and the weekly report, and every run leaves a log you can check.

  • Claude agents for routine work: lead follow-ups, review requests, the weekly report
  • Each agent with its own job, guardrail hooks on anything risky and a log of every run
  • Runs on your own Claude plan, under your own keys
  • Delivered as an Agent Team, with a validator that proves the setup works

Where to start

With the AI Connection Blueprint: a questionnaire, one 60-minute call, then a written plan for what AI may read and do in your systems, ending in one recommended first build at a fixed price.

  • A questionnaire, one 60-minute call, then a written plan

Agents for the work you repeat

Our Agent Team build puts up to six Claude agents on the work you repeat every week, with guardrail hooks on anything risky, running on your own Claude plan.

  • Up to six Claude agents
See the package
AI solutions · 04

Guardrails & governance

Know what an agent did, and under whose authority.

Once agents act on real systems, the question changes from whether they can do something to whether they should, who said so, and whether you can prove what happened. We design those controls: scoped permissions, approval steps, append-only audit trails, and checks that run on their own instead of depending on someone remembering to look.

  • Scoped, expiring grants for what an agent may do
  • Human approval on irreversible actions
  • Append-only, hash-linked audit logs
  • Signed receipts for delegated work, built on the Writ protocol
  • Verification with controls that prove each check can fail
  • Plain-English policies your team can follow
Proof

Writ Protocol

Our draft protocol for passing bounded authority between agents and getting signed receipts back. Two implementations, 288 conformance vectors, Apache 2.0.

See Writ

AI enablement for IT teams

Our public playbook maps the AI application stack for IT teams: what to learn, what to skip and how to keep it safe. Self-paced and free to read, and the basis of our AI for IT Teams Workshop.

ai-upskill-playbook
IT solutions · 05

Networks

Segmented and documented, with every change previewed first.

Most small business networks are one flat network where the guest Wi-Fi, the printer and the office laptops can all see each other. We design segmented UniFi networks: separate VLANs for staff, devices and guests, with firewall rules between them. Every change arrives as an mcp-unifi dry run that you or your installer review and apply on your own controller. We only ever hold a read-only key you can revoke.

  • A written review of segmentation: VLANs, firewall zones, guest and IoT isolation
  • Recommended changes staged as mcp-unifi dry runs you apply
  • IPv6, VPN and secure remote access
  • A configuration backup step built into every staged change
  • Read-only reviews of firewall rules, open ports, firmware and Wi-Fi settings
  • Ask for a change in plain English, get back a dry run you apply

We run what we sell

Our own network is a UniFi Cloud Gateway Fiber on 2 gig fiber, split into trusted, IoT, guest and management networks, managed through our own MCP server.

Read the build

AI for UniFi

Our open source mcp-unifi, configured read-only on your controller, lets an assistant answer questions about your network and stage changes as dry runs you apply. It includes a written review of segmentation, firewall rules, open ports, firmware and Wi-Fi.

  • One UniFi controller
See the package
IT solutions · 06

Servers & hosting

Locked down to a checklist we published.

We run our own servers to one standard: hardened security, automated backups, monitoring and patching, with containers, reverse proxies and secure tunnels for the services we self-host. If we host your website, it runs on our own server, patched and backed up daily.

Every item below is on the checklist we published, free to follow on a server you own.

  • Full firewall configuration with explicit allow and deny rules
  • SSH hardening: custom port, key-only auth, fail2ban
  • Admin panels restricted by IP, with FTP and plaintext mail ports closed
  • Security headers on every domain (HSTS, X-Frame-Options, Referrer-Policy)
  • SSL certificates installed and auto-renewing
  • Automated OS security patches and daily kernel update checks
  • Daily encrypted off-site backups with a retention policy
  • Uptime and resource monitoring with alerts

You own the server

We never ask for SSH access. Follow the checklist yourself or hand it to your IT provider, and start with the free server security check, which reads only what your server shows the internet.

Get the free check

We own the server

For every site we host: it runs on our own server, patched and backed up daily off-site, with HTTPS included. You keep your domain and DNS, and we send you the exact records to set.

Works with any provider

Hetzner, DigitalOcean, Linode, Vultr, AWS Lightsail, OVH. If it runs Linux, the checklist applies, and it is the same one we run on our own servers.

The checklist
IT solutions · 07

Security & code health

Your codebase, production ready.

You shipped fast and it works. But there are no tests, no CI pipeline, no security audit, and error handling is an afterthought. We add the checks that hold the line: CI with lint, type checks and tests, secret and dependency scans, and tests on the paths that matter most. One pull request, fixed scope, yours to review and merge.

Code written with AI needs this more, not less. It produces more code than anyone can review, so the checks that run without a reviewer are the ones that count.

  • Test suites aimed at the code paths that matter, with coverage reporting
  • CI pipelines with linting, type checks, tests and build verification
  • Secret scanning across full git history, dependency audits, pinned actions
  • Bugs found during the review, ranked in the report and fixed in the pull request where they are in scope
  • A health report with before and after scoring

Code Health Check

Point us at a repository. We review the codebase, write the tests, configure the tooling and deliver a pull request you can review and merge. A larger repo gets a quote.

  • One repo up to 25,000 lines

Repo Fleet Hardening

The same gates we run on our own repos, across up to 20 of yours in one GitHub organization: shared CI templates, pinned actions, dependency updates that merge only after required checks pass, secret scanning, lockfile drift checks, and SBOMs with signed releases.

  • Up to 20 repos
See the package

Monthly code health plan

As you ship, we keep it there: dependency updates triaged with plain-English summaries, CI upkeep, secret hygiene and review on up to 10 new pull requests a month, with a monthly report. Every update arrives as a pull request you merge.

  • Monthly, up to three repos
IT solutions · 08

Web platforms

Where we started, and still a website that earns its keep.

We have built websites since 2009, for music festivals with 10,000+ attendees and local shops with five employees. We still build them, on their own or as part of a bigger project: fast, search-ready and hosted on our own server, so a fix is ours to make, with no other vendor’s ticket queue in the way.

  • A fixed-scope site with a set page count, built on the same fast stack as this one
  • Search visibility built in from day one: local SEO, structured data, page speed
  • Hosting and upkeep for stores already in our care
  • Migrations off GoDaddy, Wix, Squarespace, WordPress.com and Weebly

The advantage

When your site runs on our server, search fixes ship with the site, with no third party in between.

Tiers and prices

Three fixed website tiers and three hosting tiers, with the prices on the page.

See websites

Free checkup

Send us your URL and we will send back a graded audit of search visibility, speed, security and structured data. No cost, no strings.

Get the checkup
  • Preview before write
  • You apply the change
  • Log every call
  • Credentials stay out of the prompt
  • Sign the receipt
  • Test the test
  • Verify before done
Ways to work with us

Door, build, care plan.

Start wherever you are: a door to find out where you stand, a build to add what is missing, or a care plan to keep it that way. Every offer is listed in the packages above, and your price is fixed in writing before work begins.

A

Door

A fixed-price first step: a security review of your agents and MCP servers, a plan for connecting AI to your systems, a workshop for your IT team or a code health check. Every fix arrives staged, as a pull request or a dry run, for you to apply.

B

Build

A defined project: an agent team, an MCP connector, repo fleet hardening, a private AI gateway or AI for your UniFi network. Fixed scope, delivered as staged changes you apply.

C

Care plan

A monthly plan for a connector, an agent team or gateway, your code repos or your UniFi sites. Updates and fixes arrive staged, as pull requests or dry runs you apply. Questions go in writing and get a written answer within two business days.

Free checkups

Find out where you stand.

Two reports we will run on any public site, in plain English, at no cost, and they are yours whether or not you work with us. If you want to go further, the paid next step is an AI Connection Blueprint.

Server security check

Is your server exposed?

We scan your server's public-facing security: headers, SSL, version leaks, exposed login pages and more. You get a plain-English report with what to fix first.

SEO checkup

How does your site rank?

A full SEO audit: search visibility, page speed, structured data and more. Graded with a prioritized action plan. No cost, no strings.

See services

Tell us what you want checked or automated. We will tell you what it takes.

No sales pitch and no discovery call that is really a sales call. A straight answer about what we can build, how we would keep it safe, and what it costs, quoted in writing.