Questions we
actually get asked.
Not a curated marketing list. These are the real questions from scoping calls, RFPs, and late-night incident debriefs. Answered the same way they're answered in conversation — directly, by the engineer who does the work.
Straight answers,
no qualifying language
If an answer depends on context, that's stated. If proprietary sometimes makes more sense than open source, that's stated too. The point of an FAQ is to save a call — not to generate one.
Why open source vs. proprietary?
Four reasons, in order of weight: TCO, no lock-in, auditability, and community-driven security. The measured proof point is in the TCO guide — a significant reduction for the open-source stack against the proprietary equivalent, verified over 30 days of production operation. No vendor can match that because the cost structure is fundamentally different.
That said, open source is not a religion. When a proprietary tool is clearly the right call — rare, but it happens — that recommendation is made honestly. The bias is toward open source; the judgment is toward what works.
How does AI augmentation actually work day-to-day?
AI agents handle the toil: log triage, first-pass root-cause analysis, configuration drift detection, routine patch assessment. Humans make every decision that carries risk. The boundary is explicit and enforced.
Knowledge is captured continuously by the internal search engine — the cognitive system that records what was done, why, and what broke. Agent orchestration handles retrieval so prior context is available on the next incident. The agents platform and A2A (agent-to-agent protocol) coordinate agents without giving them authority over production changes.
Are you an outsourcing or managed services provider?
No. We are a partner, not a body shop. We do not take over your DevOps as an outsourced function and bill by the hour indefinitely. We embed, improve, and transfer: we design and implement workflows and methodologies, then hand them to your team with runbooks, decision logs, and training so you can own the routine.
We keep responsibility for the architecture and the hard calls, but the goal is to reduce routine overhead, minimize risk, and enable your team to maintain and improve the work. That frees us to move on to the next interesting challenge — and keeps your knowledge base richer than we found it.
What if we already have a DevOps team?
Most engagements are augmentative, not replacement. Existing teams are good at what they do — what they usually lack is specialized depth in open-source infrastructure, security hardening, or AI-augmented operations. That gap is where this practice fits.
Knowledge transfer is built into every engagement. We enrich your internal knowledge base as we work, and by the end your in-house team owns the workflow, the runbooks, and the reasoning. That's the point.
Do you work with our existing stack?
Yes. The practice is stack-agnostic but open-source-biased. If the current stack is sound, it stays. If parts of it are creating cost, risk, or toil, that's flagged honestly — with a recommended path and a TCO comparison, not a vague suggestion.
What's your engagement model?
Scoping call → proposal → build and transfer → ongoing support. No lock-in contracts. The scoping call is free and scoped, and produces a written proposal whether or not the engagement proceeds.
Each engagement is designed to leave your team with a workflow, documented in your knowledge base, and the training to maintain it. We do not staff the account permanently; we make ourselves less necessary for the routine while staying accountable for the architecture.
How do you handle security and compliance?
DevSecOps from day one, not bolted on at the end. Wazuh runs as the SIEM. Dependency-Track and govulncheck handle vulnerability scanning. SonarQube gates code quality. Hardening is applied to every layer — Proxmox VE, LXC, WireGuard, the application tier.
Work is done with ISO 27001 and NIS2 awareness. For regulated environments (fintech, defense), compliance mapping is part of the deliverable, not a separate engagement.
Are you a one-person shop or a team?
A senior boutique practice. One principal, AI-augmented. Direct accountability — the person who scopes the work is the person who does the work. No handoffs, no junior staffing, no account managers between you and the engineering.
This is a deliberate choice. It limits volume, which is why only a few engagements are taken at a time. The trade-off is depth and accountability over scale.
What's your typical engagement size?
Selected, high-value engagements. This is not a volume model. A few partners are taken on at a time, each with a meaningful scope — architecture design, full-stack migration, or a workflow build-and-transfer for a critical lifecycle stage.
The ideal engagement ends with your team owning more of the routine than at the start, and with your knowledge base containing the runbooks, decision logs, and methodology to keep improving without us.
Do you offer ongoing support?
Yes, but the goal is to make it less necessary over time. The full lifecycle includes operate, support, and improve stages. SLA-backed maintenance is available — patching, upgrades, performance optimization, incident response, and proactive risk tuning.
While we support, we keep transferring knowledge: every incident, every RCA, and every tuning decision is captured in your knowledge base. We want your team to handle the routine and the prevention; we keep the architecture and the hard calls.
Can you help with migration from proprietary to open source?
Yes — this is a core specialty. Proxmox VE replacing VMware. Zabbix replacing Datadog. Wazuh replacing proprietary SIEM. Gitea replacing GitHub Enterprise. Migrations are planned, staged, and reversible. No big-bang cutover unless the system is small enough to make it safe.
What industries do you work in?
Fintech, defense, high-tech manufacturing, and SMB IT. Sensitive and regulated environments where infrastructure failure has real cost — financial, operational, or legal. References available under NDA.
How do you price your services?
Custom-scoped per engagement. Not per-seat, not per-hour. A fixed proposal with defined deliverables and a defined price is produced after the scoping call. Contact for a scoping call — the conversation is faster than reading a pricing page.
Do you sign NDAs?
Yes, routinely. References from prior engagements in fintech and defense are available under NDA. The work is sensitive by nature — confidentiality is the default, not the exception.
What's your response time for production incidents?
Depends on the engagement level. SLA-backed response times are defined for ongoing support customers. For project-only engagements, best-effort with a clear escalation path. The specifics are set in the proposal — no ambiguity after signing.
Do you work remotely or on-site?
Primarily remote. On-site engagement is available for specific needs — kickoff, sensitive compliance work, or hands-on migration — in Israel and the EU. Most of the work is done remotely because most of the work is infrastructure, and infrastructure doesn't care where you sit.
Go deeper
The TCO question is the one we get most. The full line-item breakdown — licensing, per-node pricing, support contracts, and the six cost categories — is in the TCO guide. Read the TCO guide →
For the production engagements behind these answers, the case studies have the metrics, the stack, and the outcomes. See case studies →
Still have a question?
If it's not covered here, it's probably worth a call. Scoping calls are free, scoped, and produce a written proposal — whether or not the engagement goes ahead.