Security, AI, and infrastructure — built in-house, run in production, refined every day.
AI agents wired into the ERP, CRM and Outlook you already use. Managed EDR and email security on a platform built here, not resold from someone else. And the networks, servers and backups underneath all of it, kept running. You deal directly with the person who builds and operates it.
Three things, done by the same pair of hands.
Many providers deliver one of these and subcontract the rest. I handle all three in-house — which is why they integrate cleanly, rather than being stitched together after the fact.
drwxr-xr-x ai-integration/ Agents inside the tools your team already uses ▸
Agents and connectors integrated directly into your ERP, CRM and Outlook — rather than a standalone chatbot sitting alongside them.
- Salesforce, HubSpot, Monday.com, Dynamics, NetSuite, Sage — or your custom in-house app
- Vendor-agnostic: Claude, OpenAI, or self-hosted private models
- Scoped, least-privilege database credentials — read-only first
- Approval gate on every write and outbound email
- Live ERP Agent Console demo — open it
drwxr-x--- security/ Managed EDR and email security, hosted in Canada ▸
Endpoint detection and response with a secure email gateway, on a single Canadian-hosted platform I built and operate in-house — not a rebranded third-party product.
- 1,200+ detection rules in production
- 23,000+ threat indicators, refreshed every 6 hours
- 5/5 threat-intel feeds live
- Monitored 24/7, tamper-evident audit log
- Email gateway that filters threats before they reach the inbox
drwxr-xr-x infrastructure/ The layer everything else depends on — plus the web front end ▸
The foundational layer most people only notice when it fails — plus fast, standards-based websites with no vendor lock-in when you need a public presence.
- AD/Entra, VLANs, Wi-Fi and point-to-point links
- WireGuard VPN, Azure/AWS, cloud backup
- Sites, portals and dashboards — hand-built, yours to keep
- No proprietary CMS you can't leave
Traditional antivirus recognises threats by signature: if a file has been seen and catalogued before, it is blocked; anything new goes unnoticed. EDR works on behaviour instead — it monitors what software actually does on the machine. A process that begins encrypting files, reaching for stored credentials, or moving where it has no business being is flagged and contained on that behaviour alone, with no prior signature required.
That is the difference between blocking malware already on record and catching an intrusion no one has named yet — which is where most real breaches begin.
Most of this started as a lab, not a product line.
I built this stack because I wanted to understand it properly, and I've been tuning it ever since. The security platform watching your endpoints is the same one watching mine — not as a sales point, but because I'd be running it either way.
# high-level overview — architecture only, no addresses or secrets. $ systemctl list-units --type=service --state=running edr-platform › self-built EDR + email gateway [hosted in Canada] private-cloud › files, VPN, backups on my own hardware llm-runtime › self-hosted models, 7B–14B, air-gapped option erp-agent-console › the ERP demo, guardrails + audit log on web-frontends › client sites + portals, hand-coded $ uptime --since first box racked years ago. rebuilt more times than I'd admit. still running.
Everything here has been rebuilt at least once, usually after breaking it myself at an unreasonable hour. That's the part I enjoy — and it's why I know these systems well enough to explain them to you.
Already a client? Sign in here.
Services marked VPN aren't exposed to the public internet at all — you reach them over an encrypted tunnel, which is the point.
No account yet? Access is provisioned per client and scoped to your own organisation only — email me and I'll set it up.
The platform, in numbers.
A snapshot of what is running in production today.
Connecting an AI agent directly to your ERP raises a fair question: what prevents a costly mistake? The answer is scope and sign-off. The agent starts read-only — it can query and draft, but change nothing. Any action that writes a record or sends an email is held for a person to approve before it runs, and every request, approved or declined, is written to an audit log that cannot be altered afterward.
The result is the speed of an assistant that works continuously, with the controls and accountability of a properly governed business process.
Who you're working with.
What started as a single secondhand server on a shelf has grown into a real practice — a private cloud, a security platform I built from the ground up, and consulting work for businesses across BC. The same curiosity that had me racking servers at 1 a.m. is what I bring to client work now.
My core is sysadmin, networking, hardware, DevOps, Linux and Windows Server — the layer everything else depends on. I take messy, real-world problems and turn them into production systems that hold up, then keep them running.
Something I put real effort into: explaining the work in plain language. No jargon wall, no "trust me, it's technical." If I can't put what I'm doing in terms that make sense to you, I probably don't understand it well enough yet — and that's on me to fix, not you.
Book your free audit
A no-cost 60-minute review plus a short written report: where AI integration would actually pay off, and where your security gaps are — yours to keep, no obligation.
- The one workflow AI could take off your team's plate first
- Where your endpoints and mail flow are actually exposed
- One quick win you can act on right away
Prefer email? sahibdhaliwal14@gmail.com · Reply within one business day.