Service Catalog

A technical breakdown of all cybersecurity offerings, organized by category with detailed descriptions.

Endpoint & Server Security

4 services
EDR / XDR

Real-time endpoint detection and response with behavioral analytics, automated containment, and rollback capabilities. Agents deploy on Linux, Windows, and macOS.

Ubuntu Pro Compliance

Canonical Ubuntu Pro subscription with Livepatch, FIPS-certified modules, and CIS hardening profiles enforced via configuration management.

Patch Management

Centralized vulnerability patching across the full fleet with staging rings, change windows, and rollback support.

Privileged Access Management

SSH key rotation, session recording, and just-in-time elevation for administrative accounts on managed hosts.

Network & Perimeter Security

4 services
NGFW / Firewall Management

Next-generation firewall deployment and tuning with application-aware rules, IPS/IDS, and SSL inspection. Supports physical and virtual firewall appliances.

Network Segmentation

VLAN and micro-segmentation design to isolate critical assets, limit lateral movement, and enforce zero-trust network access policies.

Switch Management

Managed switch configuration, port security, 802.1X authentication, and continuous monitoring of network infrastructure.

VPN & Zero-Trust Access

WireGuard and IPSec VPN tunnels, plus zero-trust network access (ZTNA) for remote workers without traditional VPN exposure.

Threat Detection & Response

4 services
SIEM (Wazuh)

Centralized security information and event management using Wazuh. Aggregates logs from endpoints, servers, and network devices with correlation rules and MITRE ATT&CK mapping.

Threat Hunting

Proactive hypothesis-driven threat hunting using endpoint telemetry, network flow analysis, and threat intelligence feeds to uncover stealthy adversaries.

Incident Response

24/7 incident response with documented playbooks, forensic triage, containment, eradication, and full post-incident reporting.

Security Monitoring (SOC)

Continuous monitoring with dedicated security analysts, alert triage, and escalation workflows backed by runbooks for every severity level.

Data Protection & Resilience

3 services
Backup & Disaster Recovery

Immutable, encrypted backups with 3-2-1 strategy, bare-metal restore, and documented recovery time objectives (RTO) and recovery point objectives (RPO).

Data Encryption

AES-256 encryption at rest, TLS 1.2+ in transit, and centralized key management with rotation policies and hardware security module (HSM) support.

Ransomware Recovery

Air-gapped backup repositories, rapid recovery orchestration, and post-recovery hardening to prevent reinfection.

Compliance & Governance

3 services
Compliance Auditing

Continuous compliance monitoring for HIPAA, PCI-DSS, NIST 800-171, and CIS benchmarks with automated evidence collection and audit-ready reporting.

PKI & Certificate Management

Public key infrastructure with automated certificate lifecycle management, TLS certificate issuance, and user-based PKI tier for smart card and client cert authentication.

Policy Development

Custom security policy authoring aligned to your industry standards, including acceptable use, access control, and incident response policies.

Cloud & Hybrid Security

3 services
Cloud Posture Management

Continuous configuration assessment of cloud workloads, identity permissions, and storage exposure across hybrid environments.

Container Security

Image vulnerability scanning, runtime protection, and Kubernetes cluster hardening for containerized workloads.

Identity & Access (IAM)

SSO integration, MFA enforcement, and least-privilege role design across cloud and on-premise identity providers.

base44
Edit with Base44