Service
Security & Compliance
Reduce the number of ways in, then prove what happened on the ones that remain.
- Segmented
- No more flat network behind one VPN
- Evidence
- Control artefacts auditors accept
- Rotation
- Secrets with owners and expiry dates
Infrastructure security is mostly subtraction. Fewer paths in, fewer standing credentials, fewer machines that can reach the database, fewer humans with production access. Then enough logging to answer “what happened” without guessing.
We do the engineering, not the paperwork theatre — though we produce the artefacts the paperwork needs.
Where the exposure usually is
Across the estates we audit, the recurring findings are consistent:
- A flat internal network where any compromised laptop can reach every production service.
- Long-lived cloud access keys in CI, in a developer’s shell history, and in a Slack thread from 2023.
- Management interfaces — hypervisors, switches, IPMI, Grafana — reachable from more places than anyone believes.
- No central log retention, so an incident investigation starts with “do we still have those logs?”
- Backups that exist but have never been restored, and are reachable with the same credentials as production.
What we build
Segmentation and access. Identity-aware access per service instead of a VPN that grants the whole network. Short-lived certificates rather than static keys. Device posture — managed, encrypted, patched — as a condition of reaching production. This is where the device management practice and the security practice meet.
Hardening. CIS-aligned baselines applied through Ansible, enforced continuously rather than at build time. Minimal base images, non-root containers, read-only root filesystems, and a documented exception register for the things you genuinely cannot turn on.
Secrets. Vault or cloud KMS, dynamic database credentials where the application supports it, automated rotation, and mTLS between internal services so a network foothold is not an application foothold.
Detection. A log pipeline that actually retains — host, network flow, cloud audit, and edge logs into Loki or your SIEM. Wazuh or Falco for host and container behaviour, CrowdSec at the edge. Alerts routed to a human with a runbook attached, because an alert with no runbook is a notification.
# Alert on what matters, with the response written down.
- alert: ProductionSSHFromUnmanagedDevice
expr: sum by (user, src) (ssh_login_total{posture!="managed"}) > 0
for: 0m
labels: { severity: critical, page: platform-oncall }
annotations:
summary: "SSH to production from an unmanaged device ({{ $labels.user }})"
runbook: "https://runbooks.internal/ssh-unmanaged"
Compliance without the pantomime
ISO 27001 and SOC 2 sample evidence. They want to see that a change was reviewed, that access was granted and revoked, that a backup was restored, that a vulnerability was triaged within the window you claimed.
We wire the systems so that evidence is a by-product of doing the work properly — merge requests as change records, identity provider logs as access records, scheduled restore tests with retained output — rather than a quarterly scramble to reconstruct it.
GeekyAnts is itself ISO-certified, so this is a process we run internally and not only for clients.
Who this is for
Teams selling into enterprise for the first time and discovering that their security questionnaire has 300 rows. Teams who have had an incident and do not want a second one. Regulated workloads — financial services, health, anything with residency obligations.
Questions
Asked often enough to answer here.
Is this a penetration test?
No. We do authorised configuration review and architecture work, and we will run vulnerability scanning against systems you own. For adversarial testing we scope a separate engagement or work alongside your existing testing firm and fix what they find.
We need SOC 2. Can you get us there?
We cover the infrastructure half — access control, change management, encryption, logging, backup and recovery evidence. You still need an auditor and policy work; we make the technical controls real and produce the artefacts that get sampled.
Our access control is one VPN and a shared password manager.
That is extremely common and it is where we usually start. Identity-aware access per service, short-lived credentials, device posture as a condition of access, and an audit trail that shows who reached what and when.
Will hardening break our applications?
Some of it will, which is why baselines land in staging first with a documented exception process. A control nobody can live with gets reverted and worked around rather than silently disabled.
Also
The rest of the estate.
- InfrastructureWe take the estate you already have and make it legible, automated and boring.
- NetworkRouting, peering and address space — designed on paper, built as code, proven by withdrawal tests.
- CDN & EdgeYour own content network on your own address space — or a sane configuration of someone else's.
- On-PremA private cloud that behaves like a public one — self-service, API-driven, and yours.
- AI InferenceRun your models on hardware you control — for cost, for latency, or because the data cannot leave.
- Device & MDMEvery laptop and phone enrolled, encrypted, patched and accounted for — from unboxing to offboarding.
- ObservabilityKnow it broke before the customer does — and know which layer, in one click.
- All servicesOverview, delivery method and the things we will tell you not to buy.
Next step
Tell us what breaks at 3am.
A 30-minute call with the engineers who would do the work — not a sales desk. We will tell you whether this is a bolt.sh problem or something you can fix in-house.