Systems and security · Bern & Valais

We build it.
We secure it.
We keep it running.

Linux and Windows estates, private networks, websites, and the chain work under them. On-site in Bern and Valais. Mail me and I'll set a time.

A finding needs a repro. A system that is not monitored is not in production.

Mail me for a call Security review

BUILDRUNSECUREHOSTNETWORK

Services

Infrastructure, security, operations

One engineer. From a first look through to the weekly patch.

Build

New rooms, migrations, applications.

  • Infrastructure & datacenter

    Server rooms, racking and virtualisation on Proxmox, VMware or Hyper‑V. Linux and Windows Server, rolled out as code.

  • Web & applications

    Sites and web platforms, from design through hosting on infrastructure I run.

  • Web3 & smart contracts

    Solana programs and EVM contracts, SPL and Token‑2022 launches, NFT and Metaplex work, wallet‑connected front ends.

  • Automation & AI engineering

    Internal tools, agent pipelines and scheduled jobs that encode a workflow you already know.

Secure

A review with a proof you can run.

  • Protocol research & audit

    Smart‑contract and validator‑client review on Solana, EVM, Move, Substrate and Cosmos. Delivered as a runnable exploit.

  • Infrastructure security review

    Hardening, configuration, what is exposed, access and secrets on the estate you already run.

  • Application security review

    Web applications, APIs and the identity in front of them. Same proof standard as the protocol work.

  • IT and security consulting

    Threat modelling, disclosure, incident response, and turning a report into work for the following week.

Run

The weekly work.

  • Linux & Windows operations

    The hosts the rest sits on. Linux and Windows Server, directory and patch cadence, treated like my own machines.

  • Networks & connectivity

    Segmentation, firewalling and private mesh access that does not depend on a vendor portal.

  • Operations & resilience

    Monitoring, alerting, patching, log retention and backup, with restores that get rehearsed.

  • Validator & node operations

    Solana and EVM nodes, RPC endpoints and staking, run by someone who audits this software.

  1. 01

    Scope

    What is in, what is out, what proof looks like.

  2. 02

    Work

    I do it. You talk to me.

  3. 03

    Proof

    A running exploit, a restore test, or a system that stays up.

  4. 04

    Handover

    Notes, diagrams, access. You can run it without me.

Infrastructure

The stack I run

Small teams. Built so you can keep it.

SERVICESCONTAINERSVIRTUALISATIONHARDWARE
Hardware, virtualisation, containers, services.
Platform

Linux · Windows Server · Proxmox VE · VMware vSphere · Hyper‑V · Citrix · Docker

Network

Cisco · Fortinet · VLAN · SD‑WAN · MPLS · 802.1X · WireGuard · nginx

Security

Sophos · OPNsense · PKI · SIEM · Entra ID · SSO · Hardening

Cloud

Microsoft 365 · Azure IaaS / PaaS · Hybrid identity

Storage

SAN / NAS · NetApp · Veeam · Backup & DR

Code

PowerShell · Python · Terraform · Rust · Go · TypeScript · React

Web3

Solana / SVM · Anchor · EVM / Solidity · Foundry · Metaplex · Sui & Move · Substrate

Compute & virtualisation

Bare‑metal and virtualised Linux and Windows Server hosts on Proxmox, VMware or Hyper‑V. Capacity planning, hardening, patch discipline.

Networking

VLAN segmentation, firewalls, private mesh (WireGuard/Tailscale), reverse proxies and TLS termination.

Storage & backup

Redundant storage, snapshotting, offsite copies and restores that are actually rehearsed.

Identity & access

SSH key and certificate management, least‑privilege accounts, secrets handling, audited administrative access.

Containers & services

Docker and Compose, service isolation, health checks, zero‑downtime restarts, private registries.

Databases

PostgreSQL and Redis: tuning, replication, migrations, point‑in‑time recovery.

Monitoring

Metrics, structured logs, uptime and certificate monitoring, alert routing that respects working hours.

Automation & CI

Infrastructure as code, deployment pipelines, scheduled jobs with real failure reporting.

Security

Reported, fixed, shipped

Selected findings. Each went through the project's own security channel and was fixed before it sat here.

CoordinatedAll clustersFinding B-01ResolvedFOUNDREPORTEDFIXEDSHIPPED
ProgramFinding Status
MetaplexMissing signer check on the execution delegate allowed an attacker to forge a delegate for any agent asset and drain the asset signer.Resolved
Anza / AgaveTwo unbounded, root‑retained gossip‑vote maps drivable to kernel OOM by a single minimum‑stake vote account (remote memory exhaustion).Fix shipped, all clusters
SPL Token‑2022State corruption permanently locking deposited SOL.Resolved
Nervos CKBCritical deserialization flaw in the DAO withdrawal path.Resolved
LedgerStellar application finding.Resolved
ConfluxCross‑SDK differential: the Go SDK signed EIP‑1559 transactions with the priority fee set equal to the max fee.Resolved

Further disclosures are under coordinated embargo or in adjudication and are listed once resolved.

Security review

About

Tobias Brantschen

This is a one-person firm. Infrastructure, operations and security reviews. You talk to me.

On-site in Bern and Valais. Registered in St. Niklaus.

I have built and run production infrastructure since 2012, after my Informatiker EFZ. Linux and Windows, networks, virtualisation, storage, backup.

Security grew out of that work. I read protocol code the way I read a firewall ruleset: assume it is wrong until I can reproduce the failure. Every finding above went through the project’s own security channel and was fixed before it sat here.

ISC² Certified in Cybersecurity, plus vendor certifications for the platforms I run.

I audit protocols and I operate infrastructure. Both are the job.

Illustrated portrait of Tobias Brantschen

Contact

Mail me

A short mail is enough. I read it and come back with a time.

Enquiries

info [at] brlabs.ch
Projects, offers, questions.

Security

tobias.brantschen [at] brlabs.ch
Compromise, locked-out access, abuse. Straight to me.

Tobias Brantschen

LinkedIn

On site

Bern and Valais.
Remote in the rest of Switzerland.

Mail me for a call

46.1783° N07.8058° E

Common questions

What does a security review deliver?

A finding you can reproduce: a running exploit, a restore test, or a system that stays up. Not a scanner dump. Every finding goes through the project's own security channel before it is listed here.

What do you need from me to start a review?

The scope, access to the code or the estate, and one person who answers questions. The first call settles what is in, what is out, and what the proof looks like.

Who does the work?

I do. There is no team behind the address and no hand-off after the first meeting.

Do you work remotely?

Yes, across Switzerland. On-site in Bern and Valais, in German or English.

Do you take on IT operations for a small firm?

Yes. Linux and Windows estates, the network, backup, the weekly patch.

How do I start?

Mail info [at] brlabs.ch and I'll set a time. For a suspected compromise or locked-out access, write to tobias.brantschen [at] brlabs.ch directly.