Services · 2026

Seven practices. One operator.

Every engagement is scoped, built, and handed over by the same person. No account managers, no subcontractors — just tight ownership from first call to final commit.

Engagement types

Fixed-scope · Retainer · Audit

Typical timeline

2–12 weeks

Availability

Accepting briefs Q2 2026

01

Custom software development.

Tailored web applications, internal tools, and backend services — designed around your exact workflow. React and TypeScript on the front, Python, C#, or Node on the back. Shipped with tests, docs, and a handover you can hire someone else off tomorrow.

  • Full-stack web applications
  • Internal tools & dashboards
  • REST / GraphQL APIs
  • Data pipelines & ETL
  • Auth, billing, admin panels
  • Performance & rewrites
02

Workflow automation.

If your team does it every week, it should run on a schedule. I build Python and C# automations that eat spreadsheets, glue SaaS tools together, and reclaim the hours your best people are spending on copy-paste work.

  • Scheduled ETL & reporting
  • SaaS & API integrations
  • Document processing pipelines
  • Scraping & data collection
  • Notion / Airtable / Sheets glue
  • Slack & email bots
03

Cybersecurity & pen testing.

Authorised, scoped engagements that map how a real attacker would break in — then give you a written roadmap to close every hole. Wireless audits use Software Defined Radio for the things Wi-Fi scanners miss.

  • External pen testing
  • Internal network assessments
  • Wireless & SDR audits
  • Web-app vulnerability testing
  • Remediation roadmap
  • Executive & technical reports
04

Network installation.

Enterprise-grade networking for homes, studios, and offices. Ubiquiti UniFi ecosystems designed and deployed end-to-end — site survey, cabling plan, device provisioning, VLAN segmentation, and ongoing monitoring.

  • Site survey & heat map
  • UniFi stack specification
  • Structured cabling consultation
  • Wi-Fi 6 / 7 deployment
  • VPN & remote access
  • Monitoring & alerting
05

Access control & zero-trust.

Identity you can audit, permissions that shrink on their own, and VLAN policies that assume the network is already hostile. Clean zero-trust architecture for small teams that want to punch above their weight.

  • SSO / identity federation
  • Role-based access control
  • VLAN & policy design
  • Guest / IoT isolation
  • Physical access integration
  • MFA & hardware keys
06

IT setup & onboarding.

Stand up a business from empty-desk to day-one-ready: workstations, cloud identity, email, backups, monitoring, and documentation so the next person to touch it doesn't need to start from scratch.

  • Workstation & device provisioning
  • Google / Microsoft 365 setup
  • Backup & disaster recovery
  • Asset & license inventory
  • Documentation & runbooks
  • Employee onboarding kits
07

Cloud migration & hardening.

Move off legacy without losing a day of business. I plan the migration, cut over in a maintenance window, and harden the new environment so nothing ships live with defaults still on.

  • Migration assessment
  • Cutover execution plan
  • AWS / GCP / DNS setup
  • DNS, email, DMARC
  • Post-migration hardening
  • Ongoing maintenance retainer

02 / Process

How every engagement runs.

01 / Discovery

Brief & scope

A 30-min call, a written brief, a fixed-price quote. No hourly surprises.

02 / Design

Architecture

Diagrams, interfaces, data model. Signed off before a single line is written.

03 / Build

Ship weekly

Demos every week. Changes in days, not quarters. You always know the status.

04 / Harden

Security pass

Tests, headers, access controls, secrets audit. Nothing ships with defaults on.

05 / Handover

Own it

Docs, runbooks, credentials, optional retainer. You're never locked in.

03 / FAQ

The questions I get most.

Solo. You work directly with me from first call to final handover. If a project genuinely needs another specialist, I'll tell you up front — and either bring someone trusted in, or refer you out.

Fixed scope, fixed price. You get a written quote after the discovery call and that number doesn't move unless the scope does. Retainers for ongoing work are billed monthly at an agreed rate.

Almost always. I'm comfortable inheriting codebases and networks. If something is genuinely too far gone or a bad fit, I'll tell you honestly and recommend the smallest useful step forward.

I work remotely by default and travel for network installs, audits, and any engagement where being on-site changes the outcome. Travel costs are priced into the quote, never tacked on afterwards.

You get documentation, credentials, and the keys. Optional retainers cover ongoing maintenance, monitoring, or new features. You're never locked into me — everything is documented well enough that anyone competent can take over.

Yes. Every engagement — especially security work — runs under a mutual NDA and a written scope-of-authorization. Credentials are handled through password managers and secrets vaults, never email or chat.

Ready to brief a project?

Send a short description of what you need. I reply within 24–48 hours with next steps or a straight "not a fit."