White-label infrastructure for agencies
You build the shiny part. I run what’s underneath.
DNS, servers, migrations, performance, security — under your brand, at a fixed price, with a handover document you can forward to your client.
You sold the project. Now somebody has to do the part nobody quoted for.
Move the DNS. Get email actually delivering. Harden the server. Run the cutover outside business hours. Take over infrastructure from a developer who left no documentation and won’t answer email.
Your designer can’t. Your developer doesn’t want to. Your junior will — and it becomes four billable hours and one outage.
That’s my job. Not yours.
You’ve heard these sentences before.
- “The site went down when we moved it.”
- “Their emails keep landing in spam.”
- “Nobody knows who actually owns the domain.”
- “The old developer vanished and took the passwords.”
- “It’s slow and nobody knows why.”
- “The certificate expired. Again.”
- “We inherited this server and we’re scared to touch it.”
- “WordPress got hacked, and it came back after the cleanup.”
- “We can’t update WordPress, it would break the site.”
If one of those is on your desk right now, that’s the whole reason this page exists. You don’t need to know the technical name for it — describe it in your own words and I’ll tell you what it costs.
What I do
Fix
DNS, SSL certificates, email delivery, Linux troubleshooting.
Move
Hosting, servers, domains, mailboxes, cloud. Cutovers with a rollback plan.
Optimize
MariaDB/MySQL, PHP, NGINX, Apache, Postfix, Linux. Bottleneck analysis.
Secure
Linux hardening, firewalls, VPN, access control.
Maintain
Updates, monitoring, small changes, expiry and backup watch.
Be the agency that never worries about infrastructure again.
Nobody needs a full-time infrastructure person. You need someone who already knows your estate, for a few hours a month. That isn’t a job you can hire for.
Once credentials are in the vault and there’s a channel open, sending me something costs you one line of typing. That’s the whole point.
| Feature | Monitor | Maintain | Manage |
|---|---|---|---|
| Domains covered (up to) | 10 | 25 | 50 |
| Servers covered (up to) | 2 | 5 | 10 |
| Monitoring — uptime, certs, domains, backups | ✓ | ✓ | ✓ |
| Expiry watch with an owner list | ✓ | ✓ | ✓ |
| Monthly patching & maintenance window — system, PHP, WordPress and plugins | — | ✓ | ✓ |
| Included small requests (under 30 min) | 2 | 6 | 15 |
| Reply within, counted inside your coverage window | next business day | same business day | 4 hours |
| Reserved slot in my week | — | — | ✓ |
| Named contact, shared channel, quarterly report | — | ✓ | ✓ |
| Discount on fixed-price jobs | — | 10% | 20% |
| Per month | $400 | $850 | $1,700 |
Scroll the table sideways →
What’s covered. One agency and its client estate. Larger estates are quoted. The plan is priced on the estate, not per client, so a request about any site in it is included.
Coverage window. Reply times are counted in your working hours, not mine — the window is named in your contract, and the clock only runs inside it. Default is Mon–Fri 08:00–19:00 Prague. On Manage I can name a window aligned to your morning instead: Mon–Fri 13:00–21:00 Prague, which is 07:00–15:00 New York. No annual lock-in. One month’s notice, either direction.
Prices are published and fixed, with no hourly billing
If the job runs long, that’s my problem. You will not pay more. Most agencies start with one job to see how I work.
| Service | What you get | Delivery | Price |
|---|---|---|---|
| Legacy infrastructure takeover audit | Full inventory, risk register ranked by severity, remediation plan — every figure read off the machine, not assumed | 7–10 days | $1,280 |
| Migration with a no-downtime cutover target | Staged copy, verification checklist, TTL-managed cutover, rollback plan | 5–7 days | $900 |
| Email deliverability rescue | Diagnosis, delisting, auth fixed, before/after inbox test | 5 days | $770 |
| Emergency access recovery | Registrar, host or former developer chased; ownership recovered | up to 10 days | $770 |
| Workload-tuned server build | Everything in the standard build, plus: your workload measured, kernel and stack tuned to it, services stripped to what you actually run, before/after numbers | 7 days | $1,500 |
| Server build & hardening | Firewall, SSH keys, TLS auto-renew, backups, monitoring, runbook | 5 days | $900 |
| Spam filter rescue | Bayes retrained on a verified corpus, scanner sets split so spam scores instead of rejecting, before/after false-positive count | 5 days | $770 |
| Production upgrade (OS / PHP / Node / WordPress) | Staging test, maintenance window, rollback plan, verification | 5 days | $640 |
| Performance audit | Bottleneck analysis measured at the origin, prioritised findings with expected gain. Implementation quoted from the findings — the audit fee comes off it. | 5 days | $640 |
| Backup + verified test restore | Automated backups, offsite copy, documented successful restore — an unverified backup is only a hypothesis | 3 days | $515 |
| Email deliverability setup | SPF, DKIM, DMARC, MTA-STS, TLS-RPT, MX verified, aggregate reporting enabled | 3 days | $385 |
| Domain + DNS + Cloudflare setup | Zone built, proxy and rules configured, authenticated origin pulls with your own private CA, CAA set, handover document | 3 days | $320 |
| Expiry protection setup | Domains and certs inventoried, auto-renew, alerting, owner list | 2 days | $260 |
Scroll the table sideways →
Delivery is the date by which it’s done, counted from when I have access — not how long the work takes. Most jobs finish sooner; the date is what I commit to.
On migrations I plan for zero downtime and say so in writing: HTTP traffic moves behind a managed TTL, and where mailboxes or a live database are involved I tell you in advance exactly what the unavoidable window is, before you agree to the date. The performance audit above is the fixed-price half; implementation is quoted from its findings — anyone offering “we’ll make it fast” for one price is guessing. If you commission the implementation within 60 days, the audit fee comes off it — the audit is the discovery, and you shouldn’t pay for that twice. Access recovery includes 6 hours of chasing, third-party fees at cost; if I can’t recover it, half comes back. Prices are indicative; the binding price, scope and date are confirmed in writing before work starts. Business clients only.
Sometimes you need the thinking, not the hands.
Twenty-five years of architecture, infrastructure and performance work — in blocks when you need a second opinion, or as a written review you can hand to your client.
| Package | What you get | Validity | Price |
|---|---|---|---|
| Consulting block — 1 hour | Call or screen share, decisions made, written summary afterwards | this week | $190 |
| Consulting block — 5 hours | Drawn down as you need it, any of the five areas, 30-min increments | 3 months | $810 |
| Consulting block — 10 hours | As above, plus priority scheduling in my week | 6 months | $1,420 |
| Requirements → written specification | Workshops with you or your client, then a document your developers can build from: user stories, acceptance criteria, data model, integrations, effort estimate | 10 days | from $1,400 |
| Architecture review | Written assessment: current state, risks, scaling and cost limits, prioritized roadmap. Forwardable to your client or their board. | 10 days | $1,900 |
| Cloud or multi-server migration | Plan, staged execution, cutover, rollback, full handover. Scoped per project. | scoped | from $2,400 |
Scroll the table sideways →
Business analysis — turning what the client actually wants into something a developer can build — is covered by the blocks, or delivered as the fixed-price specification above. Implementation is quoted separately: your team builds it, or I do. Anything outside the five areas: tell me what it is and you’ll get a scoped fixed price, not an hourly estimate.
When I am available
- Reachable
- Mon–Fri, 08:00–19:00 Prague — that’s 02:00–13:00 New York
- Hands-on work & cutovers
- 08:00–12:00 Prague = 02:00–06:00 New York = 07:00–11:00 London
- Which means
- your risky overnight cutover happens in my normal working morning — awake, unhurried, coffee in hand
- Something on fire
- same-day start where the calendar allows · rush surcharge +50%
Prague is CET in winter, CEST in summer. New York and London shift with me, so these pairings hold year-round except for the two or three weeks each spring and autumn when Europe and the US change clocks on different dates — then New York is one hour later than shown. Every cutover date is confirmed in writing with both local times spelled out, so this is never left to arithmetic.
What I don’t offer, so you’re never disappointed:
- A 24/7 on-call rotation — I’m one person, and pretending otherwise would be a lie
- Open-ended time-and-materials billing
- Commitments I can’t put in a calendar
“And if you disappear?”
Fair question. I’m one person, and you’d be handing me the infrastructure your client depends on. So the arrangement is built so that you are never dependent on me being reachable:
- The credentials are yours, in your vault. I work with access you grant and can revoke at any time. Nothing is registered in my name — if I vanish tomorrow, you are not locked out of anything.
- Every job ends with a handover document written for whoever comes next, not for me. What changed, what it depends on, what to watch, what to do when it breaks. Another competent person can pick it up without ever speaking to me.
- No lock-in. One month’s notice, either direction. Nothing to unpick.
- Twenty-four years running the same kind of business — a hosting, domain and network company. I did not start this last year.
You’re not buying someone you can’t replace. You’re buying someone who documents the work as though you could.
“Can’t AI do all of this now?”
Mostly, yes. I use it on everything — that’s part of why these prices are fixed, and lower than they would have been five years ago. But:
- It gives you the steps. It doesn’t know which of three plausible answers applies to this server.
- It won’t tell you the nameservers are locked at a registrar whose support answers in four days.
- It doesn’t feel the difference between running that command on Tuesday morning and Friday at 17:00.
- It can’t verify the result on infrastructure it can’t see, and it doesn’t know what “normal” looked like before you started.
- And when the client’s email stops at 2am, it can’t be the person who is responsible for it.
You’re not paying me to know the commands. You’re paying me to decide, to verify before applying, and to be accountable afterwards.
What I commit to
- 25+ years — Linux, networking, infrastructure, architecture, performance.
- No juniors on your infrastructure. Ever.
- Your client stays your client. I work under your brand and never contact them without your say-so. Mutual no-poach, in writing.
- The handover document goes out under your name, not mine. Forward it to your client as your own work.
- Czech, English, Spanish. I can join the client call — or stay completely invisible.
- Your procurement questions already have answers. Signable MSA and NDA, and a completed security questionnaire — ask and you’ll have them the same day.
- Spanish-speaking clients are not a problem. Twenty years working across LatAm and the Caribbean — Dominican Republic, Panama, Guatemala, El Salvador, Honduras. I can run the technical call in Spanish.
- Voice, if you ever need it. Multi-tenant PBX, call centres, IVR, SIP and WhatsApp Business — FreeSWITCH and Asterisk, built across four countries. Quoted separately; just ask.
Who is behind this
I have worked in IT infrastructure for over 25 years. For almost a quarter of a century I ran my own company doing colocation, web hosting and domains. I have also worked as technical director at companies in finance and telecoms.
I lived and worked in Latin America and the Caribbean for twenty years, so alongside Czech and English I am comfortable working in Spanish.
Much of my work is covered by NDAs, so you will not find client names or detailed case studies here. I am glad to provide references on request.
More about my background in my professional CV at pavlikj.com.
How it works, without meetings
You describe the problem
Email, WhatsApp or your Slack. Two sentences is usually enough.
Fixed price and a date, next morning at the latest
Off the price list where it fits, quoted where it doesn’t.
I do it
Under your brand. You hear when it starts and when it’s done — nothing in between unless it needs your decision.
You get a handover document
What changed, what it depends on, what to watch, what to do if it breaks.
Send me the thing you’ve been avoiding.
- jan@pavlik.do
- Phone
- +420 735 842 934
- +420 735 842 934
- Hours
- Mon–Fri 08:00–19:00 Prague · cutovers 08:00–12:00 Prague
- Based in
- Czech Republic · working with agencies in the EU, UK, US and LatAm
Not an agency? Write anyway.
Legal
Terms of the price list
Prices published on this page are indicative and are not a binding offer. The binding price, scope and delivery date are confirmed in writing for each individual job before work begins. A fixed price covers the scope described in that written confirmation; anything outside it is quoted separately. These terms apply only where that written confirmation refers to them.
Services are provided to businesses only (B2B). Payment terms are 14 days from the invoice date.
Liability for damages is limited to the fee paid for the job concerned, except where Czech law does not permit such limitation — in particular for damage caused intentionally or by gross negligence. A higher cap can be agreed in writing for an individual engagement. The relationship is governed by the law of the Czech Republic and the courts of the Czech Republic have jurisdiction.
Privacy notice
Controller: Jan Pavlík, Company ID 72625635, Školská 660/3, 110 00 Praha 1, Czech Republic. Contact: jan@pavlik.do.
What I process: technical data needed to deliver and secure this website, including IP address, request time, requested URL, browser or user-agent information and diagnostic or security logs. If you contact me by e-mail, telephone, WhatsApp or another offered channel, I process your contact details, message content and any information you voluntarily provide. If I provide you with a hosting or managed service, I also process your identification, billing and contract details, the service configuration, invoices and payment history, support requests, and records of incidents or of abuse and DSA notices.
Data you store in a service I run. If I host a website, mailbox, database or server for you, you may store personal data about your own customers, users or staff in it. For that data you are the controller and I am the processor: I process it only to operate, secure, back up, restore and support the service, on your documented instructions, under the data processing agreement. Administrator access is restricted and logged, traffic is encrypted, systems are hardened and monitored, and the infrastructure is backed up daily with the last seven daily images available. I do not use the content of your data for my own purposes.
Why, and on what basis: technical data are processed to operate, protect, troubleshoot and prevent abuse of the website on the basis of legitimate interests (Article 6(1)(f) GDPR). Enquiry and project data are processed to answer you and take steps before entering into a contract, to perform a contract, to protect legitimate legal and business interests and, where required, to comply with legal obligations (Article 6(1)(b), (c) and (f)).
Who receives it: hosting and infrastructure providers, including Hetzner and other technical providers; Cloudflare for delivery and security; e-mail and telecommunications providers; the contact service you choose, such as WhatsApp; professional advisers; and public authorities where disclosure is legally required. Personal data are not sold.
International transfers: some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another safeguard permitted by the GDPR. Cloudflare’s current safeguards are described in its Data Processing Addendum. The privacy terms of an independently selected contact service also apply when you use that service.
How long: server and security logs are retained for no longer than three months unless a security incident requires longer investigation. E-mail is deleted from the inbox once it is no longer needed, and deleted items are permanently removed within three months. Ordinary replies that are not part of client, project, contractual, accounting, tax or legal-claim records are deleted once no longer needed. Client and project correspondence is archived by year and retained for the contractual relationship and applicable limitation periods. Accounting, tax and other legally required records are retained for their statutory periods, up to ten years where applicable, and relevant records may be kept longer while a dispute or legal claim is active.
Your rights: subject to the GDPR conditions, you may request access, rectification, erasure, restriction or portability and may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting prior lawful processing. Exercise these rights at jan@pavlik.do.
Your choice: providing contact or project information is voluntary, but without the information needed to identify and answer your request I may be unable to respond or provide services. No automated decision-making or profiling is used.
Cookies and complaints: this website uses no analytics or marketing cookies and does not write to local storage. Infrastructure or security providers may use strictly necessary technical mechanisms. You may lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Praha 7, at the Office’s contact page.
Hosting service terms
Hosting is not offered as a standalone product, nor actively marketed to consumers — it is arranged individually. For those cases the general terms, consumer information, abuse policy, DSA contact points, hosting privacy information and data processing agreement are published in full. The Czech text governs.