Incident line — call any time info@xoopie.com +91 74199-74199

§Infrastructure · security · monitoring

Build. Secure. Monitor. Recover.

Enterprise-grade technology engineering without enterprise-level complexity. XOOPIE designs and supports infrastructure across networking, cybersecurity, cloud, monitoring, backup and disaster recovery.

No obligationFindings are yours either wayReply within one business day

Build and secure — engineering the infrastructure that has to hold Build-side infrastructure work and secure-side monitoring meet at a central exchange point, and resolve into a monthly evidence report listing backup jobs, verified restores, measured recovery time and log coverage. Sample values shown for layout purposes only. BUILD · SECURE Infrastructure & cloudNetwork & securityStrategy MONITOR · RECOVER Monitoring & SIEMBackup & DRIncident response ILLUSTRATIVE EVIDENCE REPORT — SAMPLE DATA Backup jobs completedRestores verified Recovery test — measuredLog sources reporting 1,41238 / 3800:41:1261 / 63 PASS PASS PASS ACTION
Reliable
Recovery is a design decisionNot a product bought afterwards.
Secure
Assumed broken until evidencedWe test it, then hand you the result.
Smart
The cheapest fix is usually unfoundOften a smaller scope than you arrived with.

What we commit to, in writing

  • ISO 27001-alignedControls mapped to the 2022 standard, with evidence collected continuously rather than before an audit
  • DPDPA 2023 readyRetention schedules, data principal workflows and localisation evidence built in from the start
  • Immutable by defaultObject Lock in compliance mode on every tier — undeletable even with domain admin
  • Data resident in IndiaPrimary and secondary copies in country; cross-border only on your written request
  • Recovery proven, not claimedScheduled restore tests with the measured time reported to you in writing
  • Service credits on breachApplied automatically to the next invoice — you never have to raise a claim

Full detail on service standards · Our own posture on security & governance

§00The problem

IT becomes difficult when infrastructure cannot be seen, understood or recovered.

Most outages and breaches trace back to one of those three failures — not to a missing product. Visibility, understanding and tested recovery are engineering properties, not purchases.

§01How we work

Understand. Assess. Design. Implement. Monitor. Improve.

  1. 01

    Understand

    What you actually run today, and what constraints — budget, staffing, regulatory — shape any solution.

  2. 02

    Assess

    Gaps against the specific requirement, not a generic checklist.

  3. 03

    Design

    A solution sized to your environment, with the trade-offs stated plainly.

  4. 04

    Implement

    Staged, reversible changes, outside business hours where it matters.

  5. 05

    Monitor

    Ongoing visibility, not a one-time deployment left to drift.

  6. 06

    Improve

    Measured against what actually happened, and adjusted from there.

§01What we work on

Seven disciplines, one accountable team.

No fabricated scale here — just the areas we are actually staffed to design, run and evidence.

Infrastructure

Servers, virtualization and hybrid architecture, documented and recoverable.

Cybersecurity

Firewall, SIEM, NAC and endpoint, assessed and defended.

Network

Routing, switching, Wi-Fi and connectivity that is designed, not improvised.

Cloud

AWS and Azure architecture, migration and identity, built to fail safely.

Backup & DR

Immutable backup, replication and recovery that is tested, not assumed.

Monitoring

Logs, alerting and network health, watched by people who read the output.

Technology Strategy

Roadmap, build-versus-buy and vendor review you can defend to a board.

§01BWhy XOOPIE

Senior expertise. Direct involvement. Practical engineering.

Engineering First

We focus on how systems actually work, not just which product is being sold.

Security by Design

Security is considered across infrastructure, identity, network, endpoint and data — not bolted on at the end.

Practical Solutions

Recommendations fit the organization's actual environment, budget and operational requirements.

Direct Expertise

You work directly with experienced technical decision-makers, not a relayed brief.

§02What we do

Five categories. Deliberately not fifty.

Each is something we can staff properly, evidence monthly and defend in an audit — rather than a catalogue of everything a client might conceivably ask for.

01

Infrastructure & Cloud

Designing and running the estate itself — servers, virtualization and cloud on AWS or Azure — with resilience built in rather than bolted on. Storage, migration and ongoing infrastructure management live here, because recoverability is an architectural property, not a product you buy later.

Includes
  • Server infrastructure
  • Virtualization & VMware
  • Cloud on AWS & Azure
  • Storage
  • Migration
  • Infrastructure management
02

Network & Connectivity

Enterprise networking designed and documented, not improvised at the switch. Routing, switching, wireless and edge connectivity — including the ISP-facing infrastructure organizations rely on but rarely staff for properly.

Includes
  • Enterprise networking
  • Routing & switching
  • SD-WAN & VPN
  • Wi-Fi
  • ISP infrastructure & BGP
  • RADIUS, DHCP & DNS
03

Cybersecurity

Prevention, detection and a rehearsed response, considered across infrastructure, identity, network, endpoint and data rather than sold as a single box. Assessment first, so spend follows the actual gap.

Includes
  • Firewall
  • SIEM & SOC
  • NAC
  • EDR / XDR
  • Vulnerability & security assessment
  • DDoS protection & incident response
04

Monitoring, Logs & Observability

Coverage you can evidence, not a dashboard nobody logs into. Network and infrastructure monitoring with alerting tuned to your environment, so an alert means something when it fires.

Includes
  • Log management
  • Network monitoring
  • Infrastructure monitoring
  • Alerting
  • Wazuh & Elastic/OpenSearch
  • Coverage reporting
05

Backup & Disaster Recovery

Don't just check whether backup completed — test whether you can recover. Immutable storage, replication and scheduled restore testing, with the measured result reported to you in writing.

Includes
  • Backup architecture
  • Veeam
  • Immutable backup
  • Replication
  • Restore testing
  • Business continuity
06

Technology Strategy

Senior technical judgement, available when you need it rather than on a permanent salary. A roadmap you can defend to a board, honest build-versus-buy calls, and governance that turns technical exposure into commercial language.

Includes
  • Technology roadmap
  • Build vs buy analysis
  • Vendor & contract review
  • Security governance
  • Compliance readiness
  • Board reporting

Full detail on every category — including all eleven service pages — plus recovery objectives, log retention and storage tiers on — recovery objectives, log retention, storage tiers — are published in full on the service standards page.

§02BHow we engineer

Build. Break. Measure. Improve.

The engineering philosophy behind every category above — architecture is only as good as the failure you tested it against.

01

Build

Design the environment around your actual requirements — not a generic template.

02

Break

Test failure scenarios and weaknesses deliberately, before they find themselves.

03

Measure

Monitor performance, security and recovery — and report what the evidence actually shows.

04

Improve

Continuously strengthen the environment based on what measurement revealed.

See this applied to specific failure modes on the failure engineering page, and to full environments in the architecture library.

§04Typical situations

You are probably here for one of these six reasons.

Capability lists are hard to buy from. These are the situations clients actually arrive with, and what we do first.

Situation 01

“We just failed an audit.”

A finding you cannot evidence your way out of — usually retention, access review, or recovery testing that exists on paper only. We start with a gap assessment against the specific findings, not a generic sweep.

Situation 02

“Something has happened.”

Suspicious access, a ransom note, or money that went to the wrong account. We start by containing it, then preserving evidence — in that order, because evidence from a system still being encrypted is worth little.

Situation 03

“Nobody documented this network.”

Switches, firewall rules and routing built up over years with no current diagram and nobody left who designed it. We start by mapping the estate as it actually runs, then propose the safe path to something maintainable.

Situation 04

“Our backups may not work.”

A suspicion, usually correct, that the nightly job is green because it last succeeded some time ago. We start by attempting a real restore this week. The result is the only honest starting point.

Situation 05

“A client is asking hard questions.”

An enterprise customer or insurer has sent a security questionnaire, and answering honestly would lose the contract. We start by answering it truthfully in private, then closing what matters to that buyer.

Situation 06

“We're about to spend a lot.”

A platform decision or vendor proposal nobody internally can challenge technically. We start by separating the requirement from the proposed solution — often it is three times larger than it needs to be.

§05Technologies we work with

Vendor-neutral in practice, not just in the brochure.

Where your existing tooling is well chosen we manage it rather than replace it. These are technologies XOOPIE genuinely works with today — not a partner-tier logo wall.

Cloud & Identity

AWS, Microsoft Azure, Microsoft 365, Entra ID

Security & Endpoint

Fortinet, SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint, Wazuh, osquery

Monitoring & Logs

Wazuh, Elastic, OpenSearch, Vector, Fluent Bit, MITRE ATT&CK, Sigma rules

Backup & Storage

Veeam, Restic, Rclone, AWS Backup, Azure Backup, S3 Object Lock

Virtualization & Infra

VMware, Terraform

Network & Edge

Cloudflare

This list grows only as fast as our real, hands-on experience with a platform does. Full breakdown on the technologies page.

§06Engineering scenarios

How we would approach it — shown, not just claimed.

We don't publish case studies built on clients who haven't agreed to be named. Instead, reference architectures for common situations — clearly labeled as illustrative, not a deployed customer story.

Illustrative architecture

University Network Security Architecture

Firewall, core network, NAC, RADIUS, Active Directory, DHCP, DNS, monitoring, SIEM and backup — how the pieces fit together for a campus environment.

§07How we prove it

Every month, one document that grades our own work.

Not a dashboard you have to log into and interpret — a short report listing every commitment we made and what actually happened against it.

Crucially it includes what we missed. A report that only ever shows green is one nobody is reading properly. When we fall short it appears here with an owner and a date — because a provider who hides small failures will certainly hide large ones.

  • Backup outcomes and verified restores, not job status
  • Recovery objectives measured against the agreed target
  • Every incident, with response and containment times
  • Log coverage — including sources that went silent

Illustrative Monthly Evidence Report

Demo data — not live client data, not actual XOOPIE operational performance
Demo data
Backup jobs completedServers, endpoints and SaaS1,412 / 1,412Pass
Restores verifiedSampled and integrity-checked38 / 38Pass
Recovery test — measured RTOTarget 01:00:0000:41:12Pass
Immutable copies heldObject Lock, compliance mode100%Pass
Log sources reporting2 sources silent — see note61 / 63Action
Incidents raised · containedMedian containment 00:06:404 · 4Pass
Illustrative narrative only: two log sources stopped reporting on day 14 after a firewall change. Detected day 14, restored day 15. Owner and date recorded inside.

DEMO DATA. This is a sample format, not a real report and not a real client's numbers. Your actual monthly report reflects your estate and the standards in your agreement.

§08Onboarding

Four weeks. No downtime. Reversible at every step.

You may stop at the end of any week and keep everything we have documented to that point.

  1. Week 01

    Discovery

    An inventory of assets, identities, network paths, existing tooling and — most revealingly — what your current backups actually contain.

  2. Week 02

    Deployment

    Agents, collectors and backup jobs rolled out in waves outside your business hours, with rollback tested before each wave.

  3. Week 03

    Tuning & first restore

    Detection tuned to your environment so alerts carry meaning. We run a full restore and give you the measured result in writing.

  4. Week 04

    Cutover

    We run alongside your existing arrangement, compare coverage, close the gaps, then take ownership with your sign-off.

§09When it goes wrong

A plan someone can follow at three in the morning.

The worst moment to design an incident process is during an incident. Yours is written, agreed and rehearsed beforehand — naming who acts, in what order, and who authorises each decision.

Typical approach — the specific response times and notification commitments for your environment are set out in your signed agreement, not promised here as a blanket guarantee.

  1. Immediate

    Automated containment

    Pre-authorised actions fire without waiting for a human — host isolated, session terminated, indicator blocked.

  2. Early

    A named person owns it

    Not a queue and not a rota — one engineer, reachable by phone, who stays with it through to closure.

  3. Shortly after

    You are told

    A call and written notice covering what we know, what we have done, and what we need from you.

  4. As required

    Clean-room recovery

    Restores land in an isolated network and are scanned before reconnection, so the payload never returns with the data.

  5. Following days

    Written post-incident review

    Root cause, timeline, remediation owners — including an honest account of anything we could have done better.

§10Built around your environment

Every infrastructure environment is different.

We start with the existing architecture, understand the constraints and design an appropriate solution — rather than a standard package regardless of what you actually run.

§06BIndustries

Sized to how your sector actually runs.

Reference architectures by sector — illustrative, not fabricated case studies.

§12Who we are

New company. Not new to the work.

Xoopie is young, and we will not pretend otherwise by borrowing a history we do not have. Here is the honest case for a smaller, newer firm — and where it stops.

  • Senior engineers, not a script. No first-line call centre between you and the person who understands your environment.
  • Nothing legacy to defend. No decade-old vendor commitment to justify, so we deploy what suits your estate rather than our margin.
  • Small enough to care about one account. You will not quietly stop receiving attention because a larger logo arrived.
  • We decline work we would do badly. If a requirement needs a capability we lack, we will say so and name someone who has it.
Where the case stops: if you need a global follow-the-sun operations centre with hundreds of analysts and a twenty-year audit history, we are not that — and you will hear it on the first call rather than the third.

Senior Technical Involvement

Technology decisions should be made by people who understand the infrastructure behind them. XOOPIE maintains a direct, engineering-led approach where architecture and technical decisions receive senior attention — rather than being routed through account management layers to whoever is free.

The People Behind XOOPIE

Lalit Bhardwaj

Founder & Technology Strategist

Every engagement is scoped by the founder rather than handed to a salesperson, and you keep a direct line for the life of the account. If that stops being true as we grow, it will be because we told you who replaced him — not because you noticed.

XOOPIE is a small team by design. As it grows, this section will only ever list people who are genuinely part of it — no invented headcount.

§13Questions

Including the awkward one.

You are a new company. Why should we trust you with this?

Not on the strength of a website. Do three things instead. Ask for a scoped pilot on one part of your estate. Ask to speak to the engineer who would actually run your account, rather than a salesperson. Ask us to restore your own data while you watch.

A new company that answers those three well is a better bet than an established one that deflects them — and your current provider deserves exactly the same three questions.

Are your backups genuinely immutable?

Yes. We use S3 Object Lock in compliance mode, so an object cannot be modified or deleted before its retention expires — including by your administrators, by our engineers, or by ransomware operating with domain admin credentials. We follow the three-two-one-one-zero rule and verify restores rather than assuming them.

Where is our data stored?

In India. Primary and secondary copies sit in Indian data centre regions by default, with a cross-border copy only where you explicitly ask for one. That keeps DPDPA 2023 and RBI data-localisation discussions short.

Can we start with a single service?

Yes, and we prefer it. Most engagements begin with one service — backup, log collection or endpoint monitoring — so you can judge us on delivered work rather than promises. There is no minimum bundle and no penalty for starting small.

How is the service priced?

Per user, per device or as a fixed monthly retainer, depending on which reflects your estate most fairly. Storage is billed on volume stored, with retrieval and egress included. Every proposal is fixed against a written scope and issued after one discovery conversation.

What happens if we decide to leave?

You receive your data, your documentation and a clean export, and we assist with the handover. That is written into the agreement rather than negotiated at the end of a term. A provider who makes leaving difficult is telling you something about their confidence in the work.

What does the monthly evidence report actually contain?

Every commitment we made, measured against what happened: backup outcomes and verified restore results, recovery objectives met or missed, incidents with response and containment times, patch position, and log ingestion coverage including sources that went silent. Where we fell short it appears with an owner and a date rather than being omitted.

How quickly can you onboard us, and will it disrupt operations?

About four weeks. Discovery and asset inventory, then staged agent and collector deployment outside business hours, then detection tuning and a first verified restore, then a parallel run against your existing arrangement and a scheduled cutover with your sign-off. Deployment is agent-based and staged, so there is no downtime.

Can you take over monitoring and network management without a full replacement project?

Yes. We deploy monitoring alongside your existing network and infrastructure first, so you get visibility immediately. Replacement or redesign work, where it is genuinely needed, is scoped separately and only with your agreement.

Can you help us respond to a security questionnaire from a client?

Yes. We answer it truthfully with you in private first, so both sides know the real position, then close the gaps that matter to that specific buyer rather than every gap at once.

What happens during a live security incident?

Pre-authorised containment steps run immediately, a named engineer takes ownership, and you receive a call and written notice as soon as we have a confirmed picture. Recovery runs into an isolated clean-room environment, and a written post-incident review follows. Exact response and notification times are set out in your signed agreement, not as a blanket promise here.

More detail on service standards, our own security and the glossary.

§14Start here

Let us look at what you actually have.

A short assessment: your external attack surface, gaps in identity and endpoint coverage, what your logs would show after an incident, and whether your backups genuinely restore. The findings are yours whichever way you decide.

No obligation · No setup fee · Findings delivered either way

A conversation, not a funnel.

Tell us roughly what you have and what concerns you. We will tell you honestly whether we are the right fit — and if we are not, we will say who might be.

  • Emailinfo@xoopie.com
  • Telephone — answered 24×7+91 74199-74199
  • Available wherever you need usRemote first, on site when the work genuinely requires it
  • Dealing with an incident right now?Call and say “security incident”. Please do not wait for an email reply.

What happens next

  • We reply within one business day — a person, not an autoresponder
  • A 30-minute call: technical, no slide deck, no script
  • A scoped assessment where it looks like a fit
  • A fixed proposal against a written scope

Request an assessment

Tell us what you have.

No obligation, no sales sequence, no mailing list.

Please enter your name.
Please enter your organisation.
Please enter a valid email address.
Please enter a contact number.

Send it however suits you

WhatsApp opens with your details already written out — review it, then press send. Nothing is transmitted until you do. We reply within one business day; for an active incident please telephone rather than wait.

Talk to XOOPIE