IT companies and distributed teams
Work tools stopped opening and everyone has a different workaround. You need shared access on your own server.
Case: Corporate gateway on Xray and nginx for an IT team →Self-hosted, private VPN networks, DevOps and monitoring
We move Notion, Zapier and Google Workspace onto the client's own servers — the company never loses access to its tools overnight, and data never leaves the perimeter. We build private VPN networks for teams and services. We set up auto-deploy, monitoring and backups — if something breaks, you find out from an alert within minutes, not from a customer complaint.
A separate line of work is censorship circumvention for business: an entry node in Russia, an exit node abroad, SNI-based routing and a custom client for Windows and Android that picks a live entry point by itself.
Typical situations and what we do about them.
Because of regional restrictions Canva, Notion, Jira and AI tools stopped opening, and public workarounds break the security policy. We deploy a corporate gateway on the company's own servers: traffic is encrypted and access is split by role.
Editing one site can take down a neighboring service, and certificates are renewed by hand. We separate them into containers and docker networks behind a single entry nginx.
A direct connection to an exit server abroad is filtered at the moment it is established. We build an entry node in Russia, a permanent tunnel between nodes and an exit node abroad, as in our own VPN service.
Types of clients we have already built this for.
Work tools stopped opening and everyone has a different workaround. You need shared access on your own server.
Case: Corporate gateway on Xray and nginx for an IT team →Sites share a server with other services and get in each other's way. You need a dedicated server with isolation, certificates and backups.
Case: A private server for several websites on Docker and nginx →Games, launchers and Discord must open on every machine without lag. You need a VPN for the venue with split tunneling: games go direct, everything else through a secure channel.
Case: OshaVPN: VPN client for Android, Windows 10/11 and Windows 7 →You need voice, chat and streaming on your own server, with roles and closed access, and no third-party cloud.
Case: Peregovorka (ToshaStream): streaming server and team voice chat →Types of work in this area. Each links to a case where it is already done.
The gateway runs on the company's Linux servers: Xray handles routing and encryption, nginx sits at the entrance. Access is split by employee role, and connecting takes one click. Corporate data stays inside the perimeter.
A single entry nginx accepts HTTP and HTTPS and routes requests to the sites. Each site lives in its own container and its own docker network, and Let's Encrypt certificates renew themselves. The configuration is kept in a git repository.
A docker-mailserver container with Postfix, Dovecot, Rspamd and fail2ban receives and sends mail, and you read it in Roundcube or a mail client. We set up the DNS records: MX, SPF, DKIM, DMARC and PTR. Spam is not discarded but placed in the Junk folder.
nginx on the entry node splits websites, the panel and the VPN by SNI on one port, and a permanent frp tunnel carries all traffic to the exit server. A separate Marzban node with VLESS Reality runs autonomously. A domain change is one command with no dropped sessions.
A closed browser-based platform: SRT streaming, viewing over HLS and WebRTC, voice directly between participants (up to 10 people per channel), chats and access roles. Everything runs in Docker Compose, and a 90-day chat history sits in SQLite on your server.
Five static pages: Android, iPhone and iPad, Windows, macOS and Linux. They open in a Telegram Mini App from the bot, so a person with no experience doesn't have to write to support. No build step or server is needed for them.
What stays with the client after handover.
From the first request to handover: at every step it is clear what happens next.
We look at what runs now and where, which services are unavailable or get in each other's way, and which data must stay inside the perimeter. Before any estimate, you get a description of the task.
We decide which services go on which servers, how to split them into containers and networks, and who gets access with which role.
We install the entry nginx, the service containers and HTTPS certificates with automatic renewal on the client's server or ours.
We set up access roles and traffic encryption, and for mail and SSH login we turn on brute-force protection (fail2ban).
We enable nightly data snapshots, container health checks and alerts to the administrator about failures.
We hand over the configuration in a repository, a README written as a technical specification, a CHANGELOG and connection guides. Support is free for a month after handover.
Ballpark figures to understand the order of magnitude. Exact estimates come after the audit.
A corporate gateway for staff, your own mail on the domain with DKIM and SPF.
Docker, nginx, certificates, backups and monitoring: several sites on one server.
A communication server instead of Discord: voice rooms, chats, screen streaming.
The audit and the proposal are free. No hourly billing: the price is fixed for the result, the exact figure comes in the proposal after the audit. Support after delivery starts at $100 a month, the first month is free. Timelines are individual and set once the specification is approved.
5 projects — with the task, the solution and the numbers
our own product in production, version 1.50.0: voice, chats and a private stream
our own product: a relay in Russia, a persistent tunnel and a node in the Netherlands
for an IT company: work tools available again, on its own servers
our own product: site isolation, HTTPS, self-hosted mail and backups
open pages for a Telegram Mini App: five platforms, no build step, no dependencies
A short review is free: we'll look at the task and tell you what's worth doing and roughly for how much.