Menu
What we build with

The tools we trust — and why.

There is no go-to product at upSigma. For every job there are several good open-source tools; we know them, we've compared them, and we pick the one that fits the need in front of us. Below is the field we choose from, job by job, in plain words. Where you already pay for Microsoft 365 or Google Workspace, we set those up properly instead of replacing them.

How to read this page

Each line is one job your company might need done. First the tool we usually reach for and why; then the others we know and would pick if your situation asked for it.

Online Presence

Serving your website
Usual picknginx — the web server behind a large share of the internet; fast, boring, reliable.
Also in the toolboxCaddy (automatic HTTPS out of the box), HAProxy, Traefik, Nginx Proxy Manager
The padlock
Usual pickLet's Encrypt — free, automatically renewed security certificates.
Also in the toolboxstep-ca for certificates inside your own network
The address book of the internet (DNS)
Usual pickPowerDNS — your domain's records, signed with DNSSEC, run by us.
Also in the toolboxBIND 9, Unbound
Knowing who visits
Usual pickMatomo — full visitor statistics that stay on our servers and need no cookie banner.
Also in the toolboxUmami, Plausible (lighter, same privacy stance)

Communication

The mail engine
Usual pickPostfix & Dovecot — sending and storing; the same software behind a great deal of the world's email.
Also in the toolboxStalwart (a modern all-in-one), Mailcow and Mailu (complete suites), Cyrus
Keeping junk out
Usual pickRspamd with ClamAV — spam, virus and impersonation checks.
Also in the toolboxProxmox Mail Gateway as a filter in front of mail hosted anywhere
Proving your mail is yours
Usual pickNot tools but protocols: SPF, DKIM, DMARC — three public records that tell every receiving server which mail really came from you.
Also in the toolbox—
Mail in the browser, calendars and contacts
Usual pickRoundcube
Also in the toolboxSOGo (calendar and contacts with Outlook and phone sync), Grommunio (the closest open replacement for an Exchange server), Kolab, Horde

Digital Workplace

The company's files
Usual pickOpenCloud — files, sharing and permissions, apps for every device.
Also in the toolboxNextcloud (the incumbent, with calendars, office and chat built in), Seafile (fast, lean sync), ProjectSend (sending files to clients)
Working from anywhere
Usual pickWireGuard (with wg-easy) — modern, simple, fast VPN.
Also in the toolboxHeadscale (a mesh VPN that follows the laptop), OpenVPN
A desktop in the browser
Usual pickApache Guacamole — your company desktop from any device, nothing stored on the device itself.
Also in the toolboxWebtop, RustDesk (remote help on your own screen)
Writing things down
Usual pickWiki.js — procedures and know-how, searchable.
Also in the toolboxBookStack (books-and-chapters structure), DokuWiki (plain and durable; our own wiki runs on it)
Customers, quotes, people
Usual pickSuiteCRM (customers and quotes) and OrangeHRM (employees and leave). The platform is ours to host; how the flow should work is a Process Expertise project.
Also in the toolboxFrappe HR, MintHCM

Managed & Hosted Services

The firewall at the edge of your office
Usual pickOPNsense — modern interface, frequent updates; staff and guest Wi-Fi kept apart.
Also in the toolboxpfSense, VyOS (for routing-heavy sites), IPFire, OpenWrt (on the access points themselves)
Who gets on the network
Usual pickFreeRADIUS (one login per employee for Wi-Fi and VPN), OpenNDS (the guest Wi-Fi welcome page)
Also in the toolbox—
Addresses and inventory of the network
Usual pickKea (hands out addresses), NetBox or phpIPAM (which address belongs to what), Oxidized (a backup of every network device's configuration)
Also in the toolbox—
Filtering dangerous sites
Usual pickPi-hole or AdGuard Home — blocks known bad and tracking domains for the whole office.
Also in the toolbox—
One identity per employee
Usual pickAuthentik — one sign-in for the company's apps, two-step where it matters.
Also in the toolboxKeycloak (heavier, enterprise-grade), Authelia (lightweight), FreeIPA and Zentyal (a full directory for offices that need a domain controller), LLDAP
Passwords and certificates
Usual pickVaultwarden — company password vault, encrypted end to end (we can't read it); step-ca — a private certificate authority for the inside of your network; acme-dns — certificates that renew themselves even for systems the internet can't reach.
Also in the toolboxPassbolt, EJBCA (for large PKI needs)
Hearing about problems first
Usual pickZabbix or Icinga — monitoring of servers, network and services with alerts to your people.
Also in the toolboxCheckmk, Prometheus + Grafana (metrics and dashboards), LibreNMS (network devices), Uptime Kuma (a simple status page), SmokePing, ntopng (traffic analysis)
Keeping the logs
Usual pickGraylog or Grafana Loki — central logs you can search when something happened.
Also in the toolboxElastic Stack (heavier)
Keeping intruders out
Usual pickCrowdSec or Fail2ban (blocks brute-force attempts), Suricata (watches network traffic for attacks), Wazuh (one place for security events), AIDE (detects changed system files)
Also in the toolboxZeek
Servers and storage
Usual pickProxmox VE (runs the servers as virtual machines), Samba and TrueNAS (file server and network storage).
Also in the toolboxXCP-ng, Docker (for business applications), Coolify, Arcane / Dockhand (managing containers with a web interface), Cockpit
Backups that restore
Usual pickProxmox Backup Server (servers) and Restic (computers and files) — encrypted, deduplicated, tested.
Also in the toolboxBorg, UrBackup, Bareos, ReaR and Clonezilla (bare-metal recovery and disk imaging)
Servicedesk and inventory for IT teams
Usual pickGLPI with OCS Inventory — tickets, assets, licences, knowledge base.
Also in the toolboxZammad, Znuny — or your existing tool (Jira Service Management, ServiceNow, Freshservice), which we configure rather than replace

Check-ups

What an attacker sees
Usual pickNmap (what's reachable), Nikto and ZAP (weaknesses in websites), testssl.sh (the quality of your encryption), Trivy (known vulnerabilities in software we host)
Also in the toolbox—
How many colleagues click
Usual pickGoPhish — the harmless fake email, with results per department.
Also in the toolbox—

Don't recognise any of these? That's fine — you don't need to. What matters is that for every job there is more than one good tool, we know them, and none of them belongs to a vendor who can change the price or the rules on you.