(Network & infrastructure)
Network services, from the floor plan to the cloud routing table
A network is noticed only when it fails. Our network services cover the design, the segmentation, the remote access and the monitoring that keep it quietly doing its job.
(The flat network problem)
Most small networks grew rather than being designed. One address range, everything able to reach everything, a firewall with rules nobody dares delete, and a VPN so slow that staff have found other ways to work. Every one of those is a decision that made sense on the day and nobody revisited.
Redesign rarely means replacing hardware. More often it means addressing, segmentation and access rules written down properly, then applied to equipment you already own. The switch in the cupboard is usually fine; the plan for it never existed.
(What we deliver)
Network services we deliver
Office, data centre and cloud are treated as one network, because your traffic does not respect the boundary between them.
-
Addressing plan, VLANs, routing, DNS and DHCP set out in a document before anything is configured — with the growth you expect built in. Design work also produces the diagram your next engineer will need, which is usually the missing artefact.
-
Replacing the flat VPN tunnel with identity-based access: WireGuard, Tailscale or Cloudflare Access, tied to your directory and multi-factor authentication, granting a person access to named applications rather than to the whole network. Contractors get scoped access that expires without anyone remembering.
-
Separating what should never have shared a broadcast domain: guest Wi-Fi, staff devices, servers, payment systems, printers, cameras and building controls. Rules written with a purpose and a review date, plus a documented cleanup of the ones inherited from three network administrators ago.
-
VPCs and VNets laid out deliberately — subnets, route tables, security groups, private endpoints — with site-to-site or transit connectivity back to your offices. Traffic between environments made explicit, and nothing reaching the internet because a default allowed it to.
-
Zabbix or LibreNMS polling the links, switches, firewalls and circuits, with Grafana dashboards and alerts that fire before users notice. Capacity trends matter as much as outages: most upgrades should be planned in advance, not bought in a panic.
-
New sites fitted out — cabling, racks, switching, Wi-Fi surveyed for real coverage rather than guessed, internet circuits ordered with enough lead time. Moves and upgrades are rehearsed, run out of hours, and carry a rollback plan written before the first cable is pulled.
(Equipment and tooling)
- 01Cisco, MikroTik, Ubiquiti
- 02Fortinet and pfSense
- 03WireGuard and OpenVPN
- 04Tailscale and Cloudflare Zero Trust
- 05AWS VPC and Transit Gateway
- 06Azure VNet and ExpressRoute
- 07Zabbix, LibreNMS, Grafana
- 08Ansible for device configuration
- 09Ekahau and Wi-Fi surveys
(How we work)
How a network change is delivered
Five stages. The cutover is the shortest of them, which is the whole idea — everything before it exists so the switch takes minutes.
-
01
Survey
What is physically there: circuits, cabling, equipment and firmware, current addressing, live firewall rules and who actually depends on what. Undocumented dependencies are found now, when they are cheap, rather than during the cutover.
-
02
Design
Addressing, segmentation, routing, access rules and resilience, written up with a diagram and reviewed with you. Where budget constrains the design, the compromise is recorded so nobody wonders about it in two years.
-
03
Build and pilot
New configuration staged alongside the old, with one team or one floor moved first. A pilot exposes the printer, the badge reader and the legacy application that nobody mentioned in the survey.
-
04
Cutover
Scheduled out of hours with a runbook, a rollback point and a check sheet for the morning after. Someone from our side is on site or reachable through the first working day.
-
05
Hand over
Diagrams, configuration backups, credentials in your password vault, monitoring live and a walkthrough with whoever supports it next — your team or your managed service provider.
(Why Team of Keys)
Why our network work tends to hold
Network projects go wrong in a small number of well-known ways: a survey that was really a guess, a cutover with no way back, and documentation written afterwards, if at all.
-
01
Designed on paper first
Addressing and segmentation are agreed in a document before equipment is touched. Changing a diagram costs an hour; changing a live network at midnight costs considerably more.
-
02
Vendor-neutral by habit
The bench works across Cisco, MikroTik, Ubiquiti, Fortinet and pfSense, so the recommendation follows the requirement and the budget. Reusing hardware you already own is a legitimate outcome.
-
03
Cutovers with a way back
Configuration is backed up, the rollback is written before the change and the window is chosen with your operations, not ours. Nothing important gets migrated on a Friday.
-
04
Segmentation that survives contact
Segments are drawn around how people actually work, then tested with the applications that cross them. A design that blocks the finance team on Monday morning gets reverted, and it should.
-
05
Documented to hand over
Diagrams, rule sets with reasons, firmware versions and credentials in your vault. Whoever supports the network next should not need to reverse-engineer it, including us.
(Related)
More in quality & security
(FAQ)
Questions, answered
A survey and design for a single site is a fixed price and takes one to two weeks. Implementation is quoted from that design, since the cost depends heavily on what hardware can be reused. Office fit-outs are priced per point and per rack, with cabling and circuits passed through at supplier cost.
Usually, and it is the first thing checked. Plenty of switches and firewalls are perfectly capable and simply configured badly or running old firmware. The survey lists what to keep, what to re-purpose and what is genuinely end of life because the vendor has stopped issuing security patches.
Design, staging and pilot work happen alongside the live network with no disruption. The cutover itself is scheduled out of hours or at a weekend, typically a two to four hour window, with a rollback point and someone reachable the following morning. You get the plan and the window in advance.
Often not in the traditional sense. If your applications are all software as a service or cloud-hosted, identity-based access per application is safer and faster than tunnelling everyone onto a corporate network. A VPN or private link still earns its place for legacy systems, management interfaces and site-to-site connectivity.
Yes, as monitoring plus an agreed monthly capacity for changes, firmware updates and firewall rule reviews. Where you already have a managed service provider, we hand over the documentation and monitoring and step back. Some clients keep us only for design and cutovers, which works fine.
(Global presence)
Nine countries, one studio behind them.
Every project is designed, built and shipped from one studio.
Turn the globe, or pick a country to see what we deliver there.
NoidaDrag to turn
Studio · Noida, India · --:--
(Next step)
Send us the floor plan or the network diagram
Whatever exists — a drawing, a rack photo, a list of sites. You get a survey scope, a design price and an honest view of what you can keep.
START
