Mid-sized companies usually defend themselves with a scattering of separate measures: antivirus on the workstations, a VPN for remote work, backups “when we remember,” and mail on a public service. Each piece works on its own, but there is no coherent picture: data sits on employee laptops, correspondence runs through somebody else’s servers, and the whole IT perimeter rests on a single system administrator.
Monolith Plus is the platform I built as an answer to that problem: a hardware and software complex that gives a company enterprise-grade protection without its own data centre or an in-house security team. At its core sits a private secure cloud that the client fully controls. Below I break down the architecture, the key engineering decisions, and my role in the project.
- Architecture: three servers and a single entrance
- Workplaces in the cloud
- Protected devices: two perimeters on one machine
- Communications nobody can listen in on
- Monitoring and the panic button
- What Monolith Plus gives the business
- Infrastructure and stack
- My role in the project
- Frequently Asked Questions
- Need a Consultation?
Architecture: three servers and a single entrance
In Monolith Plus the client’s infrastructure is deployed as an isolated private cloud built from three nodes, each with its own role.
- The security server is the only way in. All traffic passes through it: deep packet inspection, intrusion detection, VPN termination, and authentication of users and services. The internal network is not visible from outside at all.
- The main server hosts the workloads: virtual desktops, mail, telephony, chat, and files. Computation happens in the data centre rather than on office machines.
- The backup server continuously mirrors the main one and allows a switchover on failure without stopping work.
The core idea is isolation with a single controlled entrance. An attack that would go straight for a workstation or a mail server on an ordinary network runs into the security server here and never reaches the perimeter. A hypervisor handles virtualization and resource allocation, so the segments are isolated from each other too: compromising one node does not open the rest.
Workplaces in the cloud
Monolith Plus moves employee workstations into the cloud as virtual desktops. The office computer becomes a thin client: it displays a picture and forwards keystrokes, but stores and computes nothing locally.
The practical consequence is simple. A lost or stolen laptop stops being a security incident, because there is no data on it. The employee connects to the same workspace from another device and carries on where they left off. Connections work from anywhere over an encrypted channel, and the channel can be modest: a remote desktop runs fine even on mobile internet, while heavy applications execute on server hardware rather than on an ageing office PC.
Protected devices: two perimeters on one machine
The cloud protects the data, but the device in the employee’s hand remains. Monolith Plus gives it a separate line of solutions.
The smartphone carries two isolated profiles, work and guest, with separate file systems and app sets. Whichever password you enter decides which environment boots, and the guest side has no path to work data. Storage is encrypted with AES-256 in XTS mode, and the SIM card is protected against reissue and cloning, which closes the attack on hijacking your number and the accounts tied to it. The phone still behaves like a phone: the usual messengers work, their traffic simply travels inside the protected tunnel.
The computer follows the same principle: two operating systems in encrypted partitions, where the main one holds a hidden volume whose existence is not detectable from outside. Access to the protected environment goes through a hardware USB token as the second factor. Without the token and the password, there is no way in, even with the machine physically in hand.
Communications nobody can listen in on
Telephony, video, mail, and chat all run inside the Monolith Plus perimeter. A call is encrypted twice at the transport level: the device first raises a TLS tunnel to the security server, and the server then opens its own tunnel to the internal VoIP server. On top of that, the conversation itself is protected by ZRTP and SRTP: the first negotiates the keys, the second secures the voice stream.
The value is not only cryptographic strength. The provider sees neither who you are calling nor where your VoIP server sits. Corporate mail and a chat platform are deployed the same way, on the client’s own infrastructure rather than on a public service where a company’s correspondence becomes somebody else’s asset.
Monitoring and the panic button
Monolith Plus watches for atypical activity: bulk copying of data, an attempt to install unauthorised software, an account behaving oddly. Each of those raises a flag for the administrator. This is protection against an insider rather than only an outside attacker, and in practice that is the part clients need most often.
There is also a panic button: pressing it locks every virtual desktop in the company within seconds. It can be a physical button in the office or a control on the owner’s phone. The scenario it was built for is a sudden visit or an active attack, when the decision has to be made immediately and without explanation.
What Monolith Plus gives the business
- Continuity. Redundancy and automatic failover mean hardware failures or attacks do not stop the work. The business also stops depending on one system administrator, so a resignation or a sick leave no longer paralyses IT.
- Predictable costs. Capital expenditure turns into operating expenditure: there are no servers to buy and no fleet refresh to fund, because old machines make perfectly good thin clients. Licensing and updates are centralised.
- Mobility. People work from the office, from home, and on the road inside the same protected environment, with no separate VPN links between branches.
- Control and compliance. This is your isolated cloud, not an account in someone else’s service: you decide which jurisdiction holds the data and who can reach it. That noticeably simplifies meeting requirements such as GDPR or industry standards, and data-centre staff cannot read your data because it is stored encrypted.
Who needs this first: companies with a distributed team, businesses handling sensitive information (legal and medical practices, finance, R&D), and organisations under regulatory requirements. I apply the same compartmentalization principle at the level of a single device too, in MStar 2225 and in the approach to a private phone.
Infrastructure and stack
- A private cloud (IaaS) on virtualization, in Tier III or better data centres, with redundant power, links, and cooling.
- Encryption: AES-256 XTS for storage, TLS 1.2/1.3 for channels, ZRTP/SRTP for voice, covering metadata as well as content.
- Two-factor authentication on hardware tokens for system and remote-desktop access.
- A firewall with deep packet inspection and intrusion detection on the security server.
- Virtual desktops, corporate mail, VoIP telephony, and chat delivered as services inside the perimeter.
- Open components at the base (KVM/QEMU virtualization, WireGuard and OpenVPN tunnels), plus integration of enterprise products on request.
My role in the project
I was the CEO and architect of Monolith Plus and built the project from zero, from raising investment to a working business with a team of more than 20 in-house staff and around 40 contracted experts worldwide.
- Product architecture. I designed the hardware and software complex: the three-server layout, the compartmentalization model, and the protection of devices and communications.
- Product management. Growth strategy, market and competitive analysis, product vision and backlog prioritisation, and ownership of the product economics (P&L).
- Client deployments. I led projects from planning and technical assessment through testing, acceptance trials, and contractor coordination.
- Commercial side. Business plans and financial models, new business lines, and representing the company externally.
Frequently Asked Questions
How is this different from an ordinary cloud like Google Workspace? With a public service you get an account inside somebody else’s infrastructure and live by the provider’s rules. Monolith Plus gives you an isolated private cloud where you decide which jurisdiction holds the data and who can reach it.
What happens if an employee’s laptop is stolen? Nothing critical: the data lives in the cloud, the computer acts as a thin client, and access is locked behind a hardware token. The employee continues from another device.
Do we need to replace our computers? No. Computation happens on the server, so even older machines work well as thin clients.
What is the panic button? An instant lock of every virtual desktop in the company, triggered by a physical button in the office or from the owner’s phone.
Does the system protect against your own employees? Yes. It tracks atypical activity such as bulk copying or unauthorised software, and access policies limit who can open what.
Need a Consultation?
If you are building protected IT infrastructure for a company and want to work out how much isolation your case actually needs, book a free 15-minute call. We will go through your situation and identify what will make the fastest difference.

