Hosting falls short
The site or app is stuttering and shared hosting can't keep up. It needs its own server, with real control and without fighting strangers for resources.
Plan no. 001 — Server setup, development and maintenance
§01 — From zero to production
System, services and access hardened — ready to work, not a “hello world”.
§02 — Custom development
Made for your case; no templates with the logo swapped.
§03 — How it detects
Add-onBulwark
The grade here is a sample; yours comes from your real server.
§04 — Defence · what it blocks
Rules that work on their own; the counter is just to give you an idea.
§05 — Access by schedule
Add-onTimeGate
You set the hours: “8 to 8” is only an example.
§06 — Watched, up to date
It warns you in time, with room to react.
From lean servers to bespoke builds. Tell us about your project.
→ Request a proposalPlan no. 001 — Server setup, development and maintenance
We set up, build, maintain and secure servers to spec, from zero to production. Tell us about the project and get a concrete proposal, no strings attached.
From zero to production: system, services and access hardened, ready to work.
Plugins, automations and integrations made for your case, not a template.
We audit the configuration and grade it, with the issues and how to fix them.
Brute force, bots and scans stop on their own, without you watching the logs.
Opens and closes access on the schedule you set; “8 to 8” is only an example.
Backups, usage and alerts, so you hear about it in time.
Spec — Services
All made to measure, no fixed catalogue. Each job is weighed on its own and only what's needed gets built.
From zero to production: base system, the services the project calls for, encrypted traffic and access with the door already shut. It's tested under real load before it's called done, and left documented so it can be run without depending on whoever set it up. Already have a server? It gets reviewed and tuned without starting over.
When what you need doesn't exist, or exists half-built, it gets written: automations, integrations between systems, the pieces that join what you already have. Written for the actual case, with no spare modules, and tested before delivery. Handed over documented and maintainable, so someone else can pick it up tomorrow without guessing.
Bulwark, an in-house add-on, goes over a server's configuration and grades it A to F, like a checkup. Each weak point comes explained (what it is, why it matters, how to fix it), not a bare number. It touches nothing on its own: it looks first, then you decide what to apply.
Almost everything that hits a server is automated noise: password dictionaries, bots trying doors, bulk scans. It's cut off with rules that work on their own and block whoever keeps knocking, without living in the logs. The noise stays out, and it never reaches you.
TimeGate, another in-house add-on, opens and closes access (to the whole server or one area) on a schedule you set. Eight to eight, weekends only, or whatever window you need; it flips on schedule, with no one having to remember to open or close it.
Once it's running, the server isn't left to fend for itself: automatic backups (one of them off the machine), an eye on usage, and alerts when something starts to slip. The point is to hear about it in time, with room to react. It stays looked after month to month, or documented for you to run yourself.
Cases C1–C4 — Who it's for
You don't need to know servers to spot your own case; seeing the problem is enough. The solution is built to measure.
The site or app is stuttering and shared hosting can't keep up. It needs its own server, with real control and without fighting strangers for resources.
A project with many users at once, in real time, that can't afford to go down at the worst moment.
Migrate what you already have to another provider or server without losing data or going offline along the way.
A server that runs, but that lacks security, backups, or someone to watch over it and keep it up to date.
Phases 01–04 — How a job is handled
There are no automatic quotes or off-the-shelf plans here. Every project goes through four steps before anything is touched, and the scope and price are put in writing before starting.
You say what you need, where it stands and where it has to get to. Through the form or by email, with as much detail as you like.
The case is studied in depth (requirements, risks, what already exists) to know what the project needs before giving a figure.
You get a proposal with the concrete scope and budget for that project, worked out for it rather than pulled off a catalogue.
What was agreed is built, tested and delivered working, with the documentation to run it afterwards.
What the case needs gets built, not a forced template.
No lock-in; what gets delivered is clear before starting.
What's delivered is tested and documented: it's shown to work.
In production it can stay watched and looked after, if you want.
Verification — No smoke and mirrors
It was set up from zero, built to measure, and it's kept running and defended like any other job. It's not a showcase: it's the same work, in production and in plain sight.
Traffic is encrypted and each service runs separate from the rest, with access cut down to the essential.
Backups happen on their own and each service's usage is watched live, without hovering over it.
Intrusion attempts and bot scanning are detected and blocked on their own.
It's all published, and you can audit it right here, a little further down.
Demo — Live audit
The auditor scores each setting by what it risks and sums it up as a grade from A to F. Flip a switch and watch it recompute on the spot. It's a demo model; the real one reads your actual server, not these three.
Try weakening the configuration:
Annex — Workshop sample
From Bulwark, an in-house add-on: a tamper-evident security log. Every line chains the previous line's hash (SHA-256), so if someone edits or deletes a past event the chain breaks and it shows. No libraries, just the JDK.
synchronized void append(String type, String message) { long seq = lastSeq + 1; String stamp = new SimpleDateFormat("yyyy-MM-dd HH:mm:ss").format(new Date()); String msg = clean(message); String t = clean(type); // each event chains the previous one's hash String hash = sha256(lastHash + "|" + seq + "|" + stamp + "|" + t + "|" + msg); // …the line (seq, time, event, hash) is appended to the file lastSeq = seq; lastHash = hash; // the link for the next one}
Queries — FAQ
There's no fixed rate. Every project is analysed and quoted to measure after talking it through, based on what it really needs. Asking costs nothing, and neither does the proposal.
Even better. The case is studied and we propose just what's needed, without overselling or charging for things that don't add value.
It depends on the scope. Before starting, a realistic timeline is agreed in writing, counting the testing and delivery, not just the development.
Yes. What already exists can be reviewed, secured, maintained or migrated. There's no need to start from scratch.
No. No lock-in or strings: the scope is agreed up front and it's clear what's delivered. If one day you want to run it yourself, it's documented for exactly that.
It's handed over working, with access transferred and the documentation to run it yourself. The first few days, whatever needs adjusting gets adjusted; and if you'd rather not keep an eye on it, it stays watched over for a monthly fee.
Stamp — Contact
Describe what you need and where you stand. Each case is studied and answered with a realistic proposal. No commitment and no cost to ask.
What happens when you write:
Form
With what you tell us, the case is analysed and answered with a realistic proposal. Add as many details as you like.
By submitting you accept the processing of your data to handle your request and prepare a proposal. See the Privacy Policy.
Direct alternative: ariel@cobayka.es