The engineering is public before the invoice is.
RTFM maintains In a Box: thirteen self-hosted infrastructure and security blueprints. Configuration, dashboards, tests, trade-offs, and known gaps are all in the open. Read them, run them, and decide whether this is the standard you want in your environment.
make demo01 — Context & Operations
Know the blast radius before production teaches you.
Turns Terraform, Kubernetes, Ansible, Compose, CloudFormation, and Pulumi into a dependency graph with impact, drift, and security analysis. Runs in CI as a GitHub Action.
See what the system is doing without renting your telemetry back.
Prometheus, Loki, Tempo, Alloy, Grafana, and optional Pyroscope with ready-made dashboards, health tooling, and instrumented examples.
Give developers real databases, real tooling, and a safe place to learn.
Five database engines, six web UIs, monitoring, backups, migrations, sample data, and connection helpers in one development platform.
CI-backed lab platform
Source not yet public
02 — Detection & Response
Detect what workloads do, not merely what their logs claim.
Falco runtime detection, routed alerts, searchable security events, MITRE ATT&CK dashboards, fleet collection, and optional private AI analysis.
See hostile traffic before the incident report has to explain it.
Suricata deep packet inspection, CrowdSec behavioural detection, JA3/JA4 fingerprinting, and deliberate host or router blocking modes.
Bring runtime detection and explainable triage into the cluster.
An umbrella Helm chart wiring Falco, Falcosidekick, Loki, Grafana, and optional privacy-preserving AI analysis with three obfuscation levels.
Keep the cloud audit trail. Keep the detections. Keep the evidence.
Collect, normalise, search, and detect across AWS, GCP, Azure, and Cloudflare on Vector, PostgreSQL with TimescaleDB, and Grafana.
70 tests
1M-event benchmark · HA and restore drills
Source not yet public
03 — Posture & Prioritisation
Know which running images carry risk — and whether that risk is growing.
Discovers running container images, scans them with Trivy, retains vulnerability history, and feeds critical findings into AIB.
Fix the vulnerabilities attackers are actually using first.
Correlates VIB findings with CISA KEV and EPSS so active exploitation and probability — not CVSS alone — drive the queue.
Turn container policy from a spreadsheet promise into evidence.
Checks runtime configuration, SBOM licences, and base-image end-of-life status while retaining CycloneDX evidence for review.
04 — Trust & Access
Put one identity boundary in front of the services you operate.
Packages Authentik with its data services, generated secrets, identity health metrics, and an operational Grafana view. OIDC, SAML, LDAP, SCIM, MFA, SSO.
Issue internal certificates automatically and catch expiry before users do.
Runs step-ca with ACME support, trust-bootstrap helpers, endpoint probing, and certificate-expiry dashboards.
05 — Unified Suite
One operational view across vulnerabilities, exploitation, compliance, identity, and PKI.
Composes VIB, TIB, CIB, IIB, and PIB with pinned submodules and a unified Grafana dashboard, while every tool stays independently deployable. No fake “single pane” promise.
Stated plainly, including the gaps.
Established
Broader test coverage and validation. Safe to build an engagement on.
Active blueprint
Shipped and focused, with lighter verification. Useful, and honest about it.
Developing
Usable core with gaps stated plainly in the documentation rather than discovered in production.