optim · services

One vendor for the stack,
and the boxes underneath it.

Four ways to work with us. Most engagements start as one and grow into another — the teams that write the firmware are the teams that operate the cloud your fleet's control plane runs on, so there is no handoff between them to go wrong.

4.21M
MANAGED DEVICES
via global ACS
99.998%
CONTROL-PLANE UPTIME
trailing 90d
6
POPS
3 continents
AS207819
OUR OWN ASN
transit to edge
├ ──── [01] how we engage ──── ──── ┤
01 / 04
// Managed operations

We run it. You get an API.

Sovereign IaaS, NVR, LLM inference, eCommerce and ACS delivered as managed platforms on the same Talos-on-bare-metal foundation we operate for our own telco customers. You integrate against an API; our SREs carry the pager.

  • Talos Linux 1.14
  • · Cilium L7 / mTLS
  • · 24/7 on-call
  • · 99.99% SLA
02 / 04
// Contract engineering

Firmware, from bring-up to OTA.

Wireless and camera firmware shipped at carrier scale — OpenWrt, OpenWiFi, prplOS and RDK-B across MediaTek Filogic, Qualcomm IPQ and Broadcom BCM. BSP, radio tuning, mesh, security hardening and the update path that keeps it maintainable.

  • 802.11ax / 802.11be
  • · TR-369 / USP
  • · BSP + bring-up
  • · Signed OTA
03 / 04
// Integration & migration

Moving a fleet without a flag day.

Bringing an existing device estate or workload onto infrastructure you control: ACS migration with the fleet online, workload moves off hyperscalers into a jurisdiction you name, and the identity and network plumbing that has to work before any of it matters.

  • Fleet cutover
  • · Multi-tenant ACS
  • · OIDC / step-ca
  • · BGP / anycast
04 / 04
// Sustaining engineering

The years after the launch.

Long-lived device software needs someone who still understands it in year five. We take over shipped firmware and platforms — CVE response, kernel and toolchain moves, silicon EOL migrations, and conformance work as the standards shift underneath.

  • CVE response
  • · Kernel / toolchain uplift
  • · Silicon EOL moves
  • · Conformance
├ ──── [02] how a programme runs ──── ──── ┤

Five steps, no handoff.

The same engineers run every step. That is the whole reason the sequence works.

  1. 01

    Platform and requirements review

    Hardware, chipset SDK, existing firmware or fleet, compliance constraints and the launch date. Under NDA if you prefer. Output: a scoped statement of work with named engineers.

  2. 02

    Architecture and bring-up

    Board bring-up or cluster design, BSP selection, data-model and protocol decisions, and the CI that every later change goes through. Nothing ships from a laptop.

  3. 03

    Build, with your team in the loop

    Weekly demos on target hardware or the live cluster. Reproducible, signed builds from the first sprint. A shared channel with the engineers doing the work, not an account manager.

  4. 04

    Validation on target

    Conformance (TR-069 / USP, ONVIF, EasyMesh), radio and performance on the actual SKU, health-gated rollouts to a canary cohort before the fleet.

  5. 05

    Operate and sustain

    We carry the pager for managed platforms and stay on firmware for CVE response, kernel and toolchain uplift and silicon end-of-life. The team that built it is the team on call.

├ ──── [03] questions we get before the first call ──── ──── ┤
Do you sign NDAs before a technical discovery call? +

Yes. We will sign yours or send ours before any architecture or fleet detail is shared. Most of our references are also under NDA, which is why the work pages describe the engineering rather than name the customer.

Who owns the code and IP after delivery? +

You do. Source, build system, documentation and associated IP transfer at delivery. Where we use our own open-source components, they stay under their published licence and we say so up front.

How quickly can you contribute to an existing codebase? +

For OpenWrt, OpenWiFi, prplOS and RDK-B trees our engineers are landing reviewed changes within one to two weeks of repository access and an architecture walkthrough. We have shipped on all four.

Where is our data, and who can reach it? +

Managed platforms run in the PoP you name: AMS, FRA, LON, SIN, SYD or IAD. LLM inference can be pinned EU-only with zero prompt retention. Access is mTLS and OIDC through our own PKI, not a SaaS dependency, and a DPA is available.

What time zones do you work in? +

Engineering is European with on-call coverage 24/7 for managed customers. We structure overlap with US and APAC teams and keep async handoffs written down.

What happens when requirements change mid-programme? +

Managed operations and dedicated-team engagements are built for moving scope: we re-baseline the sprint plan rather than hold you to a spec that no longer fits. Fixed-scope work is re-quoted in writing.

Tell us what you're building.

Drop your name, what you're building, and a contact channel. A human who ships code will reply within one business day.

PGP key available on request · we reply within one business day