DevSecOps & Platform Engineering

Complex
infra.
Plain simple.

We build developer platforms, data engineering pipelines, and self-service infrastructure for organisations that operate where the hyperscalers don't follow — data centres, air-gapped networks, and regulated environments where your data stays yours.

OSS
Open source first
On-prem
Your rack, your rules
Zero
Vendor licensing fees
planesailing.io — platform bootstrap
# Bootstrap a full platform — Cloudyard + CloudGate
# on Proxmox, in a regulated data centre, airgapped
planesailing init \
  --provider proxmox \
  --airgap true \
  --components cloudyard,cloudgate
→ Bootstrapping Talos Kubernetes cluster...
✓ Control plane healthy (3 nodes)
✓ Cilium CNI configured
✓ OIDC provider connected
→ Deploying Cloudyard platform...
✓ Backstage dev portal live
✓ MinIO S3 cluster (12TB) ready
✓ Coder workspaces available
→ Deploying CloudGate sheepdip...
✓ Internal OCI registry running
✓ PyPI / npm mirrors active
✓ AI scan engine online
✓ Platform ready. Elapsed: 47m 12s
51.5074° N, 0.1278° W
London, England
planesailing.io
Our Position
The cloud is not the answer to every problem. For organisations in regulated industries, data centres, and air-gapped environments, the hyperscalers are a liability — not an asset. Your data should never leave your control. Your developers deserve the same self-service experience as AWS, running on your own iron. That is what we build.
What We Do

Enterprise DevSecOps.
End to end.

We've built the same platform six times across six organisations. We productised that experience into reusable, open-source infrastructure — then specialised in deploying it where traditional tooling breaks down.

01

Developer Platforms

Backstage-powered internal developer portals that give your engineers a single pane of glass — service catalogue, scaffolding, deployment, documentation. Self-service from day one.

BackstageGitLab CICoderOIDC
02

Data Engineering

Data platforms where data scientists and engineers are first-class citizens. Self-service data lake access, automated lineage, one-click workspaces with the IDEs and GPU access they actually need.

MinIOAirflowDataHubArgo
03

Kubernetes Infrastructure

Immutable, secure-by-design Kubernetes on bare metal, Proxmox, and OpenStack. We specialise in Talos Linux for production-grade clusters that don't require babysitting.

Talos LinuxCiliumProxmoxOpenStack
04

Supply Chain Security

AI-powered sheepdip pipelines that inspect every package, container, ISO, and artefact before it enters your environment. Purpose-built for air-gapped and data-diode architectures.

CloudGateTrivySBOMAir-gap
05

Observability & Security

Grafana Mimir, Loki, and Alloy wired across your entire stack from day one. Falco for runtime security. Alertmanager for intelligent incident routing. Nothing dark in your cluster.

GrafanaLokiFalcoPrometheus
06

Infrastructure as Code

OpenTofu and Terraform module libraries for multi-account AWS, Proxmox clusters, and hybrid cloud architectures. Repeatable, auditable, and owned by your team — not a black box.

OpenTofuTerraformAWSGitOps
Our Products

Productised from
real platform builds.

Every tool we sell exists because we built it first for a client. Cloudyard and CloudGate are the hardened, open-source versions of platforms we've deployed in production — packaged so you don't have to start from scratch.

Private Cloud Substrate
CloudBedrock

Bare metal to production Kubernetes in under two hours. Talos, Cilium, Rook-Ceph, and Keycloak — fully automated, 100% open source, no vendor lock-in.

  • Talos Kubernetes — immutable, API-driven OS with no SSH attack surface
  • Cilium eBPF networking — zero-trust network policy and observability built in
  • Rook-Ceph storage — software-defined block, object, and file on your hardware
  • Keycloak identity — SSO and OIDC from day one, no external IdP required
View CloudBedrock →
cloudbedrock — bootstrap
Talos nodes provisioned
Cilium CNI active
Ceph cluster healthy
Keycloak realm ready
Platform live in 1h 47m
Platform Accelerator
Cloudyard

Cloud-native self-service on your infrastructure. Developer portals, data lakes, and workspaces — running on your hardware, not someone else's cloud.

  • Backstage developer portal — one-click service scaffolding via GitLab CI
  • Self-service data lake — MinIO S3, OIDC-secured, zero ticket queue
  • Data science workspaces — Coder + PyCharm/VSCode, GPU-attached
  • Talos Kubernetes substrate — Proxmox, OpenStack, or bare metal
View Cloudyard →
portal.cloudyard.io — Service Catalogue
analytics-api Service
ml-pipeline-churn Data
ds-workspace-alex Workspace
Secure Package Inspection
CloudGate

AI-powered sheepdip for every artefact entering your environment. Nothing uninspected. Purpose-built for air-gapped and regulated infrastructure.

  • AI behavioural scanning — catches novel supply chain attacks, not just CVEs
  • Internal package mirrors — PyPI, npm, OCI, Terraform, RPM, ISOs
  • Air-gap & data diode — one-way transfer for classified and regulated networks
  • SBOM & compliance audit trail — full chain of custody for every admission
View CloudGate →
cloudgate.io — Live Scan Feed
14:32:01numpy==2.1.0 (PyPI)PASS
14:31:44requests==2.99.0 — exfiltration detectedBLOCK
14:31:20python:3.12-slim (OCI)PASS
14:30:55torch==2.4.1+cu121 (PyPI)PASS
Secure Secret Sharing
PigeonHole

GPG/OpenPGP end-to-end encrypted secret sharing from the terminal. Share credentials, API keys, and sensitive files with cryptographic confidence — self-hosted, open source.

  • End-to-end GPG encryption — ProtonMail/gopenpgp, only the recipient's private key decrypts
  • Chain of trust via OIDC — cryptographic key linked to your identity provider automatically
  • S3-compatible storage — any size, self-hosted on MinIO or any S3 backend. Works with Cloudyard out of the box.
  • Terminal native & cross-platform — macOS, Linux, Windows, Docker. Running in under a minute.
View PigeonHole →
pigeonhole send — terminal
$ pigeonhole send \
  --to [email protected] \
  --secret "DB_PASS=s3cr3t"
→ Fetching Alice's public key...
✓ Encrypted · GPG RSA-4096
✓ Uploaded to S3 · TTL: 24h
✓ Secure link ready to share
How We Engage

We embed.
We don't just advise.

Platform engineering is not a report. It's months of hard-won configuration, integration debugging, and edge-case archaeology. We've done that work already. We bring it with us.

Phase 01

Architecture Review

We map your current state — infrastructure, toolchain, team topology, pain points. We identify the highest-leverage improvements and design a platform architecture that fits your constraints.

WorkshopsDiscoveryADRs
Phase 02

Platform Bootstrap

We deploy the foundation — Talos Kubernetes, networking, identity, observability. Your team gets a running cluster with all the hard parts already solved: CNI, PKI, OIDC, storage.

TalosCiliumVaultGrafana
Phase 03

Platform Acceleration

We layer Cloudyard and CloudGate onto the foundation. Developer portal, data platform, secure package registry — pre-integrated, opinionated, and tuned to your team's workflow.

CloudyardCloudGateBackstage
Phase 04

Knowledge Transfer

We don't leave you dependent on us. Every deployment comes with team training, comprehensive runbooks, and the acceleration knowledge to operate, extend, and evolve the platform yourselves.

TrainingRunbooksDocs
Who We Serve

We go where the
hyperscalers don't.

Our specialisation is environments where standard cloud-native tooling breaks down: offline networks, data centre tenants, and regulated industries with strict data residency requirements.

🏢

Data Centre Tenants

SaaS and software companies hosting in third-party data centres who need cloud-native self-service without migrating to AWS. We give you the developer experience without the hyperscaler dependency.

🏦

Financial Services

Banks, trading platforms, and fintech companies with data residency mandates and air-gap requirements. Full DevSecOps stack that satisfies your compliance team without slowing your engineers.

🛡

Defence & Government

Classified and official-sensitive environments. Air-gapped platform deployments, one-way package transfer via data diode, and IL-compliant infrastructure built on zero-trust principles.

🏥

Healthcare & Life Sciences

NHS trusts, clinical systems, and pharmaceutical R&D with HIPAA/DSP Toolkit requirements. Data engineering platforms where patient data never leaves your controlled environment.

Critical Infrastructure

Energy, utilities, and CNI operators under NIS2. Operational technology environments that need software supply chain security and platform engineering done to a standard that regulators accept.

🏗

VMware Exits

Companies leaving VMware vSphere after Broadcom's pricing changes. We provide a clean migration path to Proxmox or OpenStack with a full modern platform replacing what VMware provided.

Kubernetes
Talos, Cilium, ArgoCD, Flux
📊
Data Platform
MinIO, Airflow, DataHub, Spark
🔐
Security
Falco, OPA, Vault, OIDC
👁
Observability
Grafana, Loki, Mimir, Alloy
🧱
IaC
OpenTofu, Terraform, Pulumi
Open Source Philosophy

No licensing
tax.

Every component we deploy has a thriving open source community, extensive documentation, and a path to enterprise support that doesn't go through us. We believe the open source ecosystem is the support contract.

"We've watched organisations pay millions in VMware and proprietary tooling licences for capabilities that open source communities have matched or exceeded. The only thing holding most teams back is integration — and that's exactly what we provide."

Talos Linux Kubernetes Cilium Backstage ArgoCD Argo Workflows MinIO Airflow DataHub Coder OpenWebUI Grafana Loki Mimir Alloy Falco OpenTofu Vault GitLab Trivy Keycloak Proxmox OpenStack cert-manager
Get In Touch

Let's chart
your course.

Whether you're planning a VMware migration, building out a data platform, securing an air-gapped environment, or just trying to give your developers the self-service experience they deserve — let's talk.

// Speak to the Team