Cyber Immunity in Cluj-Napoca
Enterprise IT services in Cluj-Napoca: on-site visits from Alba Iulia, 24/7 remote monitoring, < 15 min response for SOC emergencies. We work for companies with critical infrastructure that demand strict SLA.
Enterprise services in Cluj-Napoca
🐧 Linux Servers
Linux Debian (preferred), Ubuntu Server, RHEL, Rocky, Alma. CIS hardening, Lynis audit, 24/7 monitoring, automated daily backup.
- Advanced iptables/nftables ruleset
- OpenVPN, IPsec, WireGuard server + client
- GeoIP filtering, IP reputation, CrowdSec
- HA cluster (Pacemaker, Corosync, DRBD)
- Kernel tuning, ZFS, LVM, performance optimization
- systemd, journald, centralized log shipping
- Ansible playbooks, Bash automation
- Backup with Bacula, BorgBackup, Restic
- Prometheus node_exporter monitoring
- Full CIS Benchmark + Lynis audit hardening
🛡️ Firewall & Security
We secure the network perimeter with Fortinet enterprise, pfSense, OPNsense, Mikrotik or hardened Linux iptables/nftables. 20+ firewalls in production, zero breach.
- FortiGate all series + FortiAnalyzer + FortiManager
- OpenVPN, IPsec, WireGuard, SSL VPN site-to-site
- GeoIP + IP reputation (CrowdSec, Spamhaus)
- IDS/IPS Suricata + Snort inline
- SD-WAN, multi-WAN failover, traffic shaping QoS
- Legacy firewall migration → FortiGate
- Replace expensive UTM with OPNsense + Suricata
- SD-WAN multi-branch with zero-touch deploy
- VPN site-to-site IPsec with HA
- Linux firewall hardening + CrowdSec auto-block
💠 VMware vCenter
VMware vCenter clusters with real HA, hyperconverged vSAN, NSX-T microsegmentation. Post-Broadcom migrations to Proxmox with 60-90% savings.
- vSphere 7/8, vCenter design + multi-site deploy
- HA + DRS + vMotion + Storage vMotion
- vSAN, NFS, iSCSI, Fibre Channel
- Site Recovery Manager (SRM) DR orchestration
- Native Veeam B&R integration
- NSX-T microsegmentation, distributed firewall
- Horizon VDI basic
- vRealize Operations + Log Insight
- Major version upgrade with zero downtime
- Capacity planning, right-sizing, cost optimization
🪟 Hyper-V
Hyper-V Failover Cluster with hyperconverged Storage Spaces Direct. Clean P2V migrations, cross-site replication, Veeam integration.
- Hyper-V Server (standalone & Core)
- Failover Cluster Manager for HA
- Storage Spaces Direct (S2D) hyperconverged
- Live Migration zero-downtime patching
- Hyper-V Replica cross-site DR
- SCVMM (System Center Virtual Machine Manager)
- PowerShell DSC automation
- Nested virtualization, GPU passthrough
- iSCSI, SMB 3.0, ReFS deduplication
- Clean P2V migrations without data loss
🟠 Proxmox VE
Proxmox VE 8.x with Ceph: same functionality as VMware, without expensive licensing. Staged migration from VMware without extended downtime.
- Multi-node cluster with HA Manager
- Distributed hyperconverged Ceph storage
- ZFS local with async replication
- LXC containers + KVM VMs in same cluster
- Proxmox Backup Server with deduplication
- 0€ Community Edition license
- 110-1000€/CPU/year Enterprise Subscription (optional)
- Typical 60-90% savings vs VMware
- Typical ROI in 6-12 months
- Staged migration from VMware with OVF Tool
🌐 Networking
Multi-vendor enterprise switching (Cisco, Dell, Ubiquiti UniFi, HPE Aruba, Juniper, Mikrotik) + enterprise WiFi 6/6E. Predictive site survey, RADIUS 802.1X.
- Cisco Catalyst, Nexus switches (CLI)
- Dell PowerSwitch / OS10 + Force10 legacy
- Ubiquiti UniFi PoE + self-hosted controller
- VLAN 802.1Q, trunking, LAG/LACP, MSTP/RSTP
- Wireless WiFi 5/6/6E indoor/outdoor + site survey
- HPE Aruba, Juniper EX switches (basic)
- Layer 3 routing, OSPF, static, policy-based routing
- RADIUS 802.1X authentication
- NetFlow / sFlow collection + analysis
- SNMP network monitoring with LibreNMS / Zabbix
📊 Monitoring & 24/7 SOC
See everything, miss nothing. Stack Nagios + Check_MK + Zabbix + Grafana + Prometheus + Loki. Calibrated alerting (zero spam), 24/7 human SOC with response < 15 min.
- Nagios Core/XI + Check_MK Raw + Tribe29
- Zabbix 7.x custom templates per platform
- Grafana dashboards + Prometheus exporters
- Loki / Graylog / ELK for log aggregation
- Suricata IDS/IPS + Wazuh SIEM + CrowdSec
- Response time P1: < 15 minutes (24/7)
- Response time P2: < 1 hour
- Response time P3: < 4 business hours
- Uptime monitoring: 99.99%
- On-call rotation with escalation matrix
☸️ Kubernetes & microservices
Production-grade K8s cluster: self-hosted (kubeadm, RKE2, k3s edge) or managed (EKS/AKS/GKE). GitOps with ArgoCD, secrets in Vault, full observability, strict RBAC.
- Self-hosted K8s cluster (kubeadm, RKE2, k3s)
- Managed: EKS, AKS, GKE setup and migration
- Service mesh: Istio, Linkerd with mTLS
- GitOps with ArgoCD / Flux for automatic CD
- Velero backup + restore cross-cluster
- Monolith → microservices migration
- CI/CD pipeline with zero-downtime deploy
- Multi-cluster with disaster recovery
- Auto-scaling HPA + Cluster Autoscaler
- Edge computing with k3s on IoT/branch sites
💻 Custom Software
Custom applications integrated with your infrastructure: database connections, API integrations, BI dashboards, AI chatbots (Claude/OpenAI), ETL pipelines, automations.
- Database connections (PostgreSQL, MySQL, MSSQL, Oracle)
- REST / SOAP / GraphQL API integrations + webhooks
- BI Dashboards (Streamlit, Grafana, Metabase)
- AI Chatbot with LLM (Claude, OpenAI) + business context
- ETL pipelines (Python, Airflow, parallel workers)
- Stack: Python, Node.js, PHP, .NET, Java
- Frontend: React, Vue, Streamlit, Flask
- Database: PostgreSQL, MySQL, MongoDB, Redis
- Queues: RabbitMQ, Kafka, Redis Streams
- Deploy: Docker, K8s, GitLab CI/CD
What we offer clients in Cluj-Napoca
📋 Free infrastructure audit
We analyze what you have in production and report risks, opportunities, optimizable costs.
📐 Implementation plan
Roadmap with priorities, timelines, budget. Informed decisions, not surprises.
🔧 Implementation + hardening
CIS Benchmarks, GDPR-ready, NIS2 compliant. Best practices, not copy-paste.
📚 Complete documentation
Network diagrams, runbooks, self-hosted wiki. You own everything.
📡 24/7 Monitoring
Human SOC with response < 15 min P1/P2. Zero black-box, calibrated alerting.
📞 Strict SLA support
Clear contract with documented RTO/RPO. Direct communication on Telegram/Signal.
🚗 On-site visits
From Alba Iulia we reach Cluj-Napoca for physical interventions, audit, training.
🎓 Internal team training
We pass technical knowledge to your team. We do not make you dependent on us.