The part of hosting that becomes someone's second job. Done by us.
Eight capabilities, delivered with every server from the first day. Each one replaces a tool you would otherwise buy or a task someone on your team would otherwise carry.
Provisioning and hardening
A server that is ready for production, not a root password and good luck.
Every package is delivered within 48 hours of order with your operating system installed and hardened to the same baseline we run ourselves. You get SSH-key access, a firewall that allows only what you asked for, WireGuard for private access, and a written handover of what was configured.
- Ubuntu LTS, Debian, Rocky Linux or Proxmox VE
- CIS-aligned baseline, documented and versioned
- Firewall rules, fail2ban-style brute-force protection, unattended security updates
- Handover document with every setting and credential location
What it replaces: Two to three days of a senior engineer's time per server, repeated at every rebuild.
Patching and lifecycle
Kernels, packages and firmware stay current without you planning the evenings.
We agree a maintenance window with you, then run it. Security updates land continuously; kernel and firmware updates land in the window with a tested rollback. Critical vulnerabilities are patched within 72 hours and you get a note explaining what changed and why.
- Critical CVEs patched within 72 hours, high within 14 days
- Kernel and firmware updates with tested rollback
- Reboots coordinated with your release calendar
- Change log of every modification to the system
What it replaces: A patch rota, a change-management process and the person who forgets to run them.
Observability
Metrics, logs and uptime on one dashboard, with alerts that reach the right people.
Each server ships with a metrics agent, log shipping and external uptime checks. You get dashboards for host, disk, network and the services we manage, 13 months of retention, and alert routing to Slack, PagerDuty, Opsgenie or email. Application metrics can be scraped too.
- Host, disk, network, database and GPU dashboards
- Logs searchable for 13 months
- Alert routing to Slack, PagerDuty, Opsgenie or email
- Prometheus-compatible endpoint for your own application metrics
What it replaces: A Datadog or Grafana Cloud contract and the week it takes to make it useful.
Backups and recovery
Nightly encrypted snapshots to a second site, and the restore test to prove they work.
Backups run every night to a separate EU site, encrypted with keys you can hold, and are kept for 30 days by default. Once a quarter we restore a sample to a scratch system, verify it, and send you the report. Point-in-time recovery for Postgres is available on request.
- Nightly snapshots to a second EU location
- 30-day retention, 90 days as an add-on
- Quarterly restore test with a written report
- Point-in-time recovery for Postgres on request
What it replaces: A backup vendor, a storage account and the uneasy feeling that nobody has ever restored one.
Security
DDoS mitigation, a managed firewall, intrusion detection and weekly scans.
Volumetric DDoS mitigation is on from the first minute. We manage the host firewall, run intrusion detection, scan for vulnerabilities weekly and keep an audit trail of every change made to your systems. When you need to show an auditor, the evidence is already there.
- Always-on DDoS mitigation at the network edge
- Managed host firewall and intrusion detection
- Weekly vulnerability scans with a prioritised list
- Immutable audit log of every change, exportable
What it replaces: A security tooling subscription and the audit-evidence scramble every year.
Platform services
Kubernetes, Postgres, Redis, CI runners and object storage, run on your hardware.
When you want more than a hardened box, we run the platform: Kubernetes with GitOps, replicated Postgres with failover, Redis, GitHub or GitLab runners, an S3-compatible object store. Everything stays on hardware that is yours alone, inside the EU.
- Kubernetes (k3s or Talos) with ingress, certificates and GitOps
- Managed Postgres and Redis with failover and upgrades
- CI runners for GitHub Actions or GitLab
- S3-compatible object storage on Store packages
What it replaces: Several managed-service bills from a hyperscaler, each with its own egress charge.
Engineers, 24/7
A named engineer who knows your setup, and a team that answers within minutes.
You get a named engineer for the relationship and a round-the-clock team for incidents. Critical issues are answered by a human within 15 or 30 minutes depending on the package. Monthly, your engineer reviews capacity, cost and risks with you and proposes what to change.
- Critical response in 15 or 30 minutes, 24/7
- Named engineer and monthly review
- Migration and architecture help at a fixed hourly rate
- Status page and incident write-ups for every disruption
What it replaces: An on-call rotation your developers did not sign up for.
Exa, the AI operations engineer
Ask about your infrastructure in plain language. Exa proposes; an engineer approves.
Exa reads the metrics, logs, configuration and change history of your servers. It answers questions, spots anomalies before they become alerts, writes incident timelines, triages vulnerabilities and drafts fixes. Nothing Exa proposes runs until you or an Infraexa engineer approves it.
- Plain-language questions, answered from your real telemetry
- Anomaly detection ahead of threshold alerts
- Incident timelines and post-mortem drafts within minutes
- Patch and change proposals with one-click approval
What it replaces: Hours of dashboard archaeology every week, and the post-mortem nobody writes.
How a server is delivered.
A named engineer from day zero, production access within 48 hours, and a review every month.
- Day 0
Order and intake
You pick a package and tell us the OS, the services you need and who should receive alerts. A named engineer is assigned the same day.
- Day 1
Build and harden
The server is installed, hardened, enrolled in monitoring and backups, and tested against our checklist. You receive the handover document.
- Day 2
Handover
Access is live. Exa has read the configuration and answers questions from the first hour. Your engineer walks through the setup on a call if you want one.
- Week 1
Migration support
We help move data and traffic, at a fixed hourly rate for application work or included for the operations layer.
- Monthly
Review
Capacity, cost, incidents and upcoming changes, reviewed with your engineer. Exa prepares the briefing.
The operations layer is the same on every package. Compare the hardware on the pricing page, or read how the layer compares with doing it yourself in the production checklist guide.
Tell us what you run. We will tell you what it costs to run it properly.
A quote within one business day, from an engineer rather than a sales script. No setup fee, three-month minimum, delivery in 48 hours.