Services

Beyond products. Real engineering, every week.

Open-source integration. Managed WireGuard and WAN optimization. Cloudflare WAF and on-prem firewalls. Self-hosted email with proper spam filtering. The boring-but-critical infrastructure work that keeps South African businesses online.

Open source

We build on open source. And we give back.

Every product we ship is rooted in open-source foundations. We don't hide that — we celebrate it. Our engineers contribute fixes and features upstream, document our integrations, and publish the patterns we discover. If you want to extend or self-host any EchoPoint product, you can.

EchoSign

Forked from Documenso. Enterprise features unlocked, SA branding, runs on SA infrastructure.

Nexa ITSM

Forked from GLPI. Rebranded, customised workflows, local SSO.

EchoArchive

Built on Paperless-ngx. SHA-256 + HMAC audit chain on top of the open-source core.

EchoLink

Built on WireGuard. Go control plane + Vue dashboard. No proprietary VPN magic.

Want to self-host or extend an EchoPoint product?

Talk to us. We don't gatekeep the source — if you're a SA business that wants to run EchoSign on your own infrastructure, we'll help you get it stood up. Custom integrations welcome.

Networking & WAN

Managed WireGuard, WAN optimization, and SD-WAN patterns that work in SA.

From a single-site VPN to multi-branch SD-WAN with link failover and traffic shaping — we design, deploy and manage the kind of network you can sleep through load-shedding on.

Managed WireGuard (EchoLink)

Hosted WireGuard control plane. Deploy peers in minutes, manage from a browser, auto-installers for Linux and Windows.

  • Hub-and-spoke, full-mesh, and site-to-site topologies
  • Per-user enrollment tokens, QR configs for mobile
  • Real-time peer status + handshake monitoring
  • MikroTik config export for router-level integration

In-depth WireGuard configurations

Beyond the dashboard. We design and deploy custom WG topologies for multi-site businesses — split-tunnel, policy-routing, multi-WAN failover.

  • Multi-WAN failover (fibre + LTE + VSAT) with health-checked gateways
  • Split-horizon DNS over the tunnel
  • Policy-based routing (route specific subnets or apps over specific links)
  • Per-peer firewall rules and rate limits
  • BGP-aware setups where needed

WAN optimization

Faster, more resilient links. Especially important when your office is on a hybrid of fibre, LTE and satellite.

  • Link aggregation (LACP) across multiple ISPs
  • QoS and traffic shaping for VoIP, video and critical apps
  • MTU tuning and MSS clamping to fix weird satellite and captive-portal links
  • Bandwidth monitoring + capacity reports
  • SD-WAN-style failover between sites

Firewalls & on-prem security

pfSense, OPNsense and MikroTik done right. Including the boring-but-important stuff: rule reviews, segmentation, VPN termination.

  • Rule-base audits (we've seen some terrifying firewall configs)
  • Network segmentation (guest / corporate / OT / VoIP)
  • Site-to-site IPsec + WireGuard termination
  • IDS/IPS deployment (Suricata, Zeek)
  • Failover pairs for HA

Cloudflare WAF & edge security

Edge protection for every public EchoPoint property — and for client properties too. Set-and-forget: zero ongoing tuning time.

  • Universal baseline: HSTS, TLS 1.2+, Always-Use-HTTPS, HTTP/3
  • Cloudflare Free Managed Ruleset + Leaked Credentials Check
  • Bot Fight Mode + Browser Integrity Check
  • Per-app custom rules: rate limits, geo-blocking, WAF exceptions
  • Orange-cloud vs grey-cloud DNS strategy (mail grey-clouded, public apps orange)
  • Cutover with rollback plan
Managed email & spam filtering

Self-hosted Stalwart Mail + spam filtering. Your email, your server, your country.

For SA businesses that want POPIA-grade email sovereignty: a Stalwart Mail server on SA infrastructure, with Rspamd + ClamAV filtering, DMARC enforcement, and archiving into EchoArchive for compliance. We migrate you off M365 or Google Workspace with zero data loss.

Stalwart Mail — self-hosted email server

Modern Rust-based mail server: IMAP, JMAP, SMTP, CalDAV, CardDAV. Faster and more secure than Postfix/Dovecot stacks, and easier to operate.

  • Hosted on your VPS or on our managed infrastructure
  • CalDAV/CardDAV for contacts and calendars
  • Webmail included (Stalwart's built-in UI or Roundcube)
  • JMAP support for modern email clients
  • ActiveSync for iOS/Android (via Stalwart + tusk or native ActiveSync)

Managed spam & phishing filtering

Rspamd + ClamAV + DMARC/SPF/DKIM enforcement. ~99% catch rate, ~zero false positives on real mail.

  • Content analysis (word patterns, hidden text, spoofing tricks)
  • URL reputation (every link checked against 4+ threat databases)
  • Attachment scanning (viruses in PDFs, Word docs, ZIPs)
  • Sender verification (DMARC + DKIM + SPF — same tech the banks use)
  • Per-user quarantine portal with one-click release
  • Weekly threat report

Email archiving & compliance

Every inbound and outbound message is journaled to EchoArchive. Tamper-evident, fully searchable, ready for SARS or auditor hand-over.

  • Automatic journaling of all mail
  • SHA-256 hash + HMAC-signed audit chain
  • Full-text search across years of mail
  • Legal hold + eDiscovery export
  • 10+ year retention with cryptographic integrity

Migrate from M365 or Google Workspace.

We handle the full migration: MX cutover, mailbox sync, calendar/contact migration, autoreply rules, signature imports. Zero data loss. Zero downtime your team notices.

Talk to us