# Pronix Information Technologies > Congrats on setting up a new Doks project! - [Digital Sovereignty & Gaia-X — Pragmatically Implemented](https://pronix.info/digital-sovereignty/): Digital sovereignty and Gaia-X, implemented pragmatically: lean, open-source, production-tested systems you control — for the CEO (what to do) and the CIO (how). - [Cookies](https://pronix.info/cookies/): What cookies Pronix uses (if any) and how you can control them. - [Four disciplines, one outcome.](https://pronix.info/disciplines/): Four disciplines, one outcome — consulting, security, automation and digital sovereignty, each grounded in proven standards and delivered pragmatically. - [Pragmatic Automation — BPMN, DMN, CMMN & ISO 9001](https://pronix.info/automation/): Pragmatic process automation grounded in BPMN, DMN, CMMN and ISO 9001, with AI/LLM raising the degree of automation without media breaks. Modelled, decidable, auditable — for the CEO (what to do) and the CIO (how). - [Pragmatic Consulting — TOGAF, ArchiMate & Best-Practice Architecture](https://pronix.info/consulting/): Pragmatic consulting grounded in TOGAF, ArchiMate and Kotusev's Best Practice Architecture — enterprise architecture, organizational design and public-tender expertise that ships outcomes, not shelfware. For the CEO (what to do) and the CIO (how). - [Pragmatic Security — OSSTMM, ISO 27001 & BSI Grundschutz](https://pronix.info/security/): Pragmatic security grounded in OSSTMM, ISO 27001 and BSI IT-Grundschutz, with defense in depth lived — default-deny, auditable, measurable. Control you can prove, not just claim — for the CEO (what to do) and the CIO (how). - [Privacy](https://pronix.info/privacy/): Privacy policy for Pronix — what we collect, what we do not, and your rights regarding your data. - [Reference scenarios](https://pronix.info/scenarios/): Four reference scenarios showing how Pronix solutions combine end to end — from idea through public tender or own-team build to operational handover: sovereign workplace, confidential communications, process automation, and NIS2 security monitoring. - [Terms](https://pronix.info/terms/): Terms of use for the Pronix website and the consulting, engineering and operations services offered through it — scope, liability and acceptable use. - [Page not found](https://pronix.info/404/): The page you're looking for doesn’t exist or has moved. Check the URL, use the navigation to browse sections, or return to the homepage. - [About](https://pronix.info/about/): About Pronix — engineering for security, automation, and digital sovereignty. Production-grade open-source systems for organizations that need to stay in control. - [Services](https://pronix.info/services/): What Pronix delivers for clients — consulting, development, and ongoing operations for organizations building serious infrastructure. - [Portfolio](https://pronix.info/portfolio/): Two halves of the same craft — fractional senior roles you can engage on demand, and production systems we built and operate ourselves. - [Contact](https://pronix.info/contact/): Get in touch with Pronix — project inquiries, consulting and security requests, public-tender questions or support. We usually reply within one business day. - [Docs](https://pronix.info/docs/): Technical documentation for the Pronix product line — quickstarts, configuration, operations, and architecture notes for each product. ## Reference scenarios > Four reference scenarios showing how Pronix solutions combine end to end — from idea through public tender or own-team build to operational handover: sovereign workplace, confidential communications, process automation, and NIS2 security monitoring. - [Sovereign Digital Workplace — exit Big-Tech cloud via public tender](https://pronix.info/scenarios/sovereign-digital-workplace/): Reference scenario: from a Big-Tech cloud office to a sovereign, Gaia-X-aligned digital workplace via a public tender — idea, enterprise architecture, GATT/WTO procurement, build, hardening and operational handover. - [Confidential Communications — sovereign email, chat and calls, built with your own team](https://pronix.info/scenarios/confidential-communications/): Reference scenario: moving confidential communications off third-party SaaS to a self-hosted, sovereign stack — built with your own team, OSSTMM-assessed, operated under an ISO 27001 / BSI Grundschutz ISMS — from idea to handover. - [Media-break-free Process Automation — from a manual process to an automated, auditable flow](https://pronix.info/scenarios/process-automation/): Reference scenario: a manual, media-broken process becomes an automated, auditable flow — modelled in BPMN/DMN/CMMN, built as custom software with AI/LLM closing the gaps, under ISO 9001 — from idea to handover. - [Security Monitoring & NIS2 — from assessment to a working SOC and certification readiness](https://pronix.info/scenarios/security-monitoring-nis2/): Reference scenario: meeting NIS2 by building provable security monitoring — OSSTMM assessment, self-hosted SIEM/XDR, hardened perimeter, ISO 27001 / BSI ISMS — from idea to a working SOC and handover. ## About > About Pronix — engineering for security, automation, and digital sovereignty. Production-grade open-source systems for organizations that need to stay in control. ## Services > What Pronix delivers for clients — consulting, development, and ongoing operations for organizations building serious infrastructure. - [Consulting](https://pronix.info/services/consulting/): Consulting that reaches beyond engineering — public-tender response, enterprise architecture (TOGAF, Kotusev), organizational rebuild, security & architecture team building. - [Development](https://pronix.info/services/development/): Embedded delivery — we build the internal services, integrations, and infrastructure you need, using the same AI-augmented methodology behind our own products. - [Support](https://pronix.info/services/support/): Ongoing operations for the systems you run — monitoring, incident response, hardening, updates and dependency care, under a predictable monthly retainer. ### Consulting > Consulting that reaches beyond engineering — public-tender response, enterprise architecture (TOGAF, Kotusev), organizational rebuild, security & architecture team building. ### Development > Embedded delivery — we build the internal services, integrations, and infrastructure you need, using the same AI-augmented methodology behind our own products. ### Support > Ongoing operations for the systems you run — monitoring, incident response, hardening, updates and dependency care, under a predictable monthly retainer. ## Portfolio > Two halves of the same craft — fractional senior roles you can engage on demand, and production systems we built and operate ourselves. - [Rent-a-Security-Officer](https://pronix.info/portfolio/rent-a-security-officer/): Rent-a-Security-Officer — fractional / interim CISO. Strategic security leadership without a full-time hire. Risk, audit, architecture, incident response oversight. - [Rent-a-Data-Protection-Officer](https://pronix.info/portfolio/rent-a-data-protection-officer/): Rent-a-Data-Protection-Officer — external DPO under GDPR Art. 37. Independent, qualified, available. Compliance, DPIA, RoPA, supervisory-authority contact. - [Rent-an-Enterprise-Architect](https://pronix.info/portfolio/rent-an-enterprise-architect/): Rent-an-Enterprise-Architect — fractional / interim chief architect. Current-state and target-state EA, governance, transformation roadmaps. TOGAF + Kotusev grounded. - [Rent-a-Process-Manager](https://pronix.info/portfolio/rent-a-process-manager/): Rent-a-Process-Manager — fractional process owner. BPMN-grade process design, optimization, and automation-readiness. From ambiguous workflows to documented systems. - [Rent-a-Marketing-Manager](https://pronix.info/portfolio/rent-a-marketing-manager/): Rent-a-Marketing-Manager — fractional / interim head of marketing. Strategy, market research, customer journey, brand positioning, mystery shopping. - [Rent-a-Public-Tender-Lead](https://pronix.info/portfolio/rent-a-public-tender-lead/): Rent-a-Public-Tender-Lead — interim bid lead for international public procurement. RFP/RFI analysis, response architecture, consortium coordination, compliant submission. - [Custom Software Development](https://pronix.info/portfolio/custom-software-development/): Custom software development — from small helpers to complex production systems. Extreme Programming methodology: results-focused engineering practices, not ceremonial process overhead. - [Notification Guard](https://pronix.info/portfolio/notification-guard/): Notification Guard — granular Android notification filtering with weekday + time profiles, a visual rule editor, and a hardcoded privacy filter for sensitive app categories. Fully local, no network. - [Realtime Decision Platform](https://pronix.info/portfolio/realtime-decision-platform/): AI-driven real-time decision platform — an event-driven, multi-tenant architecture for high-frequency data streams with predictive intelligence. - [Abusive HTTP Watch](https://pronix.info/portfolio/abusive-http-watch/): Abusive HTTP Watch — a production OpenBSD daemon that scans access logs in real time for attack tokens and feeds source IPs straight into the firewall blocklist. - [Sovereign Security & Observability Platform](https://pronix.info/portfolio/sovereign-security-observability-platform/): Sovereign Security & Observability Platform — self-hosted SIEM, XDR, log analytics and observability. Open-source alternative to per-gigabyte cloud security-monitoring suites. - [Sovereign Edge Firewall](https://pronix.info/portfolio/sovereign-edge-firewall/): Sovereign Edge Firewall — sovereign custom firewall with dual-provider high availability, segmented security zones, and full auditability. No vendor lock-in. In production. - [Sovereign Certificate Authority](https://pronix.info/portfolio/sovereign-certificate-authority/): Sovereign Certificate Authority — internal Let's Encrypt-style CA with the ACME protocol and fully automated cert enrollment for every internal service. In production. - [Sovereign Collaboration Platform](https://pronix.info/portfolio/sovereign-collaboration-platform/): Sovereign Collaboration Platform — self-hosted file sharing, document collaboration, calendar, contacts, and tasks. Privacy-respecting alternative to Big-Tech cloud office suites. - [Sovereign Messaging Platform](https://pronix.info/portfolio/sovereign-messaging-platform/): Sovereign Messaging Platform — self-hosted real-time chat with end-to-end encryption and cross-organization federation. Slack and Teams alternative without vendor lock-in. - [Sovereign Voice & Video Platform](https://pronix.info/portfolio/sovereign-voice-video-platform/): Sovereign Voice & Video Platform — self-hosted real-time voice and video calls with NAT traversal. Zoom and Webex alternative without per-minute fees or participant caps. - [Sovereign Email Platform](https://pronix.info/portfolio/sovereign-email-platform/): Sovereign Email Platform — self-hosted email on an active/active high-availability cluster. ML-based spam filtering, anti-phishing, and anti-virus. Microsoft-365 and Google-Workspace alternative without vendor lock-in. - [Sovereign AI Platform](https://pronix.info/portfolio/sovereign-ai-platform/): Sovereign AI Platform — self-hosted LLM inference cluster with a multi-user chat interface. ChatGPT-class capability without sending a single prompt to a vendor's cloud. ### Rent-a-Security-Officer > Rent-a-Security-Officer — fractional / interim CISO. Strategic security leadership without a full-time hire. Risk, audit, architecture, incident response oversight. ### Rent-a-Data-Protection-Officer > Rent-a-Data-Protection-Officer — external DPO under GDPR Art. 37. Independent, qualified, available. Compliance, DPIA, RoPA, supervisory-authority contact. ### Rent-an-Enterprise-Architect > Rent-an-Enterprise-Architect — fractional / interim chief architect. Current-state and target-state EA, governance, transformation roadmaps. TOGAF + Kotusev grounded. ### Rent-a-Process-Manager > Rent-a-Process-Manager — fractional process owner. BPMN-grade process design, optimization, and automation-readiness. From ambiguous workflows to documented systems. ### Rent-a-Marketing-Manager > Rent-a-Marketing-Manager — fractional / interim head of marketing. Strategy, market research, customer journey, brand positioning, mystery shopping. ### Rent-a-Public-Tender-Lead > Rent-a-Public-Tender-Lead — interim bid lead for international public procurement. RFP/RFI analysis, response architecture, consortium coordination, compliant submission. ### Custom Software Development > Custom software development — from small helpers to complex production systems. Extreme Programming methodology: results-focused engineering practices, not ceremonial process overhead. ### Notification Guard > Notification Guard — granular Android notification filtering with weekday + time profiles, a visual rule editor, and a hardcoded privacy filter for sensitive app categories. Fully local, no network. ### Realtime Decision Platform > AI-driven real-time decision platform — an event-driven, multi-tenant architecture for high-frequency data streams with predictive intelligence. ### Abusive HTTP Watch > Abusive HTTP Watch — a production OpenBSD daemon that scans access logs in real time for attack tokens and feeds source IPs straight into the firewall blocklist. ### Sovereign Security & Observability Platform > Sovereign Security & Observability Platform — self-hosted SIEM, XDR, log analytics and observability. Open-source alternative to per-gigabyte cloud security-monitoring suites. ### Sovereign Edge Firewall > Sovereign Edge Firewall — sovereign custom firewall with dual-provider high availability, segmented security zones, and full auditability. No vendor lock-in. In production. ### Sovereign Certificate Authority > Sovereign Certificate Authority — internal Let's Encrypt-style CA with the ACME protocol and fully automated cert enrollment for every internal service. In production. ### Sovereign Collaboration Platform > Sovereign Collaboration Platform — self-hosted file sharing, document collaboration, calendar, contacts, and tasks. Privacy-respecting alternative to Big-Tech cloud office suites. ### Sovereign Messaging Platform > Sovereign Messaging Platform — self-hosted real-time chat with end-to-end encryption and cross-organization federation. Slack and Teams alternative without vendor lock-in. ### Sovereign Voice & Video Platform > Sovereign Voice & Video Platform — self-hosted real-time voice and video calls with NAT traversal. Zoom and Webex alternative without per-minute fees or participant caps. ### Sovereign Email Platform > Sovereign Email Platform — self-hosted email on an active/active high-availability cluster. ML-based spam filtering, anti-phishing, and anti-virus. Microsoft-365 and Google-Workspace alternative without vendor lock-in. ### Sovereign AI Platform > Sovereign AI Platform — self-hosted LLM inference cluster with a multi-user chat interface. ChatGPT-class capability without sending a single prompt to a vendor's cloud. ## Docs > Technical documentation for the Pronix product line — quickstarts, configuration, operations, and architecture notes for each product. - [Abusive HTTP Watch](https://pronix.info/docs/abusive-http-watch/): Documentation for Abusive HTTP Watch — quickstart, configuration reference, and operational notes for the real-time HTTP attack-token detection daemon. - [Sovereign Edge Firewall](https://pronix.info/docs/sovereign-edge-firewall/): Documentation for Sovereign Edge Firewall — architecture concepts, dual-provider HA, zone segmentation, and operational notes. - [Notification Guard](https://pronix.info/docs/notification-guard/): Documentation for Notification Guard — overview of the Android notification filtering app and pointer to its privacy model. - [Realtime Decision Platform](https://pronix.info/docs/realtime-decision-platform/): Documentation for the Realtime Decision Platform — architectural overview of the event-driven, multi-tenant decision platform. - [Sovereign Certificate Authority](https://pronix.info/docs/sovereign-certificate-authority/): Documentation for the Sovereign Certificate Authority — internal Let's Encrypt-style CA. ACME client integration and operations. ### Abusive HTTP Watch > Documentation for Abusive HTTP Watch — quickstart, configuration reference, and operational notes for the real-time HTTP attack-token detection daemon. - [Quickstart](https://pronix.info/docs/abusive-http-watch/quickstart/): Get Abusive HTTP Watch tailing an access log and writing the blocklist in under ten minutes. - [Configuration](https://pronix.info/docs/abusive-http-watch/configuration/): Full environment-variable reference for Abusive HTTP Watch, plus the whitelist file format and how the blocklist is consumed. - [Operations](https://pronix.info/docs/abusive-http-watch/operations/): Operational notes for Abusive HTTP Watch — log-rotation handling, syslog events, rc.d lifecycle, and troubleshooting recipes from production. ### Sovereign Edge Firewall > Documentation for Sovereign Edge Firewall — architecture concepts, dual-provider HA, zone segmentation, and operational notes. - [Architecture](https://pronix.info/docs/sovereign-edge-firewall/architecture/): Architecture of the Sovereign Edge Firewall — dual-provider HA, zone segmentation, transparent security layers, and SSL offloading as antivirus. - [Operations](https://pronix.info/docs/sovereign-edge-firewall/operations/): Operations for the Sovereign Edge Firewall — failover drills, log review, zone-boundary verification, and routine housekeeping. ### Notification Guard > Documentation for Notification Guard — overview of the Android notification filtering app and pointer to its privacy model. - [Privacy model](https://pronix.info/docs/notification-guard/privacy-model/): The privacy model of Notification Guard — what is stored, what is filtered before storage, and the compliance rules built into the architecture. ### Realtime Decision Platform > Documentation for the Realtime Decision Platform — architectural overview of the event-driven, multi-tenant decision platform. - [Architecture](https://pronix.info/docs/realtime-decision-platform/architecture/): Architecture of the Realtime Decision Platform — event-driven core, ML pipeline, multi-tenant model, and observability layer. ### Sovereign Certificate Authority > Documentation for the Sovereign Certificate Authority — internal Let's Encrypt-style CA. ACME client integration and operations. - [ACME clients](https://pronix.info/docs/sovereign-certificate-authority/acme-clients/): How to point standard ACME clients at the Sovereign Certificate Authority — certbot, acme.sh, lego, Caddy, Traefik.