The perimeter around the estate, and the encryption inside it. Firewall deployment and network segmentation on one side; certificate enrolment, configuration and lifecycle management on the other. Both are areas where the failure is sudden, visible and entirely preventable — and both are areas where we apply the same sovereignty argument as everywhere else, using an open-source firewall platform rather than a subscription appliance.
Services in this capability
SSL/TLS certificate services
Enrolment, configuration across every platform that needs it, optional internal CA, and renewal that does not depend on memory.
Read more →
OPNsense firewall and network security
Sizing, deployment, policy design, segmentation, VPN and intrusion prevention — with the device itself monitored.
Read more →
Why these sit together
An expired certificate and an unsegmented network fail in the same way: quietly, until the moment they do not. Both are also areas where the work is well understood and the tooling is mature — the gap is almost always that nobody owns the lifecycle.
So we build ownership into the deployment. Certificates become tracked assets with expiry alerting. Firewall configuration is documented with the intent behind each rule, and device health is monitored alongside everything else. The point is that neither becomes a black box only one person understands.
The platforms in this capability
