The engineering is public before the invoice is.
RTFM maintains In a Box: eleven published self-hosted infrastructure and security blueprints. Configuration, dashboards, tests, trade-offs, and known gaps are all in the open. Read them, run them, and decide whether this is the standard you want in your environment.
make demoThree blueprints safe to build an engagement on.
Established maturity: broader test coverage, validated variants, verified recovery. These are the options behind the Hardened Deployment engagement.
Established
Know the blast radius before production teaches you.
Turns Terraform, Kubernetes, Ansible, Compose, CloudFormation, and Pulumi into a dependency graph with impact, drift, and security analysis. Runs in CI as a GitHub Action.
See what the system is doing without renting your telemetry back.
Prometheus, Loki, Tempo, Alloy, Grafana, and optional Pyroscope with ready-made dashboards, health tooling, and instrumented examples.
Detect what workloads do, not merely what their logs claim.
Falco runtime detection, routed alerts, searchable security events, MITRE ATT&CK dashboards, fleet collection, and optional private AI analysis.
Eight more, shipped and honest about their verification depth.
01 — Detection & Response
See hostile traffic before the incident report has to explain it.
Suricata deep packet inspection, CrowdSec behavioural detection, JA3/JA4 fingerprinting, and deliberate host or router blocking modes.
Bring runtime detection and explainable triage into the cluster.
An umbrella Helm chart wiring Falco, Falcosidekick, Loki, Grafana, and optional privacy-preserving AI analysis with three obfuscation levels.
02 — Posture & Prioritisation
Know which running images carry risk — and whether that risk is growing.
Discovers running container images, scans them with Trivy, retains vulnerability history, and feeds critical findings into AIB.
Fix the vulnerabilities attackers are actually using first.
Correlates VIB findings with CISA KEV and EPSS so active exploitation and probability — not CVSS alone — drive the queue.
Turn container policy from a spreadsheet promise into evidence.
Checks runtime configuration, SBOM licences, and base-image end-of-life status while retaining CycloneDX evidence for review.
03 — Trust & Access
Put one identity boundary in front of the services you operate.
Packages Authentik with its data services, generated secrets, identity health metrics, and an operational Grafana view. OIDC, SAML, LDAP, SCIM, MFA, SSO.
Issue internal certificates automatically and catch expiry before users do.
Runs step-ca with ACME support, trust-bootstrap helpers, endpoint probing, and certificate-expiry dashboards.
04 — Unified Suite
One operational view across vulnerabilities, exploitation, compliance, identity, and PKI.
Composes VIB, TIB, CIB, IIB, and PIB with pinned submodules and a unified Grafana dashboard, while every tool stays independently deployable. No fake “single pane” promise.
Stated plainly, including the gaps.
Established
Broader test coverage and validation. Safe to build an engagement on.
Active blueprint
Shipped and focused, with lighter verification. Useful, and honest about it.
Developing
Usable core with gaps stated plainly in the documentation rather than discovered in production.
Two further blueprints — Database in a Box and Cloud Audit in a Box — are in development and will be listed here when their source is published.