Your cloud. Your keys.
No lock-in.
Microsoft 365 hardening, Azure landing zones, and AI automation for EU operators under DORA and NIS2.
Every deliverable is licensed to you perpetually, and transferable to a successor supplier without asking us. Terms, section 04.
Licensing and tooling we deploy, sourced at wholesale through Pax8
Three lanes, sharp edges.
Each engagement stays in one of three lanes. FinOps is a scoped service, not a fourth lane. When a brief falls outside them, we say so and refer out.
Modern Workspace
Licensed wisely. Hardened tightly. Documented fully.
Microsoft 365, Google Workspace, hardware and migrations, routed through Pax8 marketplace at wholesale. Microsoft 365 is assessed against the ITSailor Microsoft 365 Security Baseline; other platforms use their stated benchmark. Everything is documented so the next person can pick it up without you. Microsoft raised Microsoft 365 Business list prices in July 2026; existing customers keep old pricing until renewal, so a pre-renewal licence audit usually nets flat-to-lower spend.
Security & Infrastructure
Audit-pass posture, not audit-survive posture.
Azure landing zones, threat detection and response (Microsoft Defender, Sentinel), and Backup/DR - built as NIS2-aligned, DORA-ready evidence your auditor can open, deployable as Terraform on day one.
AI & Automation
Automate the tickets your team handles manually.
HELMGATE puts a second named approver and a hash-chained record on the admin actions you dread: a compromised account, a risky policy change, a departure. The Copilot Readiness Audit checks what Copilot will be able to reach in your tenant before you switch it on. Custom workflows where they pay for themselves.
Cloud Cost Evidence (SEAWALL)
Find what your cloud is charging you for nothing.
Budgets, anomaly alerts and Service Control Policies as Terraform you own, with a Grafana dashboard on top. Self-serve for AWS, or as a named-hours retainer once the estate needs a standing owner.
Three live. Two shipping.
Built in-house from real tenant work. Offboarding Evidence, Tenant Monitor, and SEAWALL are live and sellable today. HELMGATE is open to three design partners, and the Copilot Readiness Audit is a fixed-price engagement you book, not a subscription you start.
We make it easy
to fire us.
Every engagement closes with an Exit Kit: a handover pack your next vendor can load in 24 hours. That's the point. You are never locked in, so we stay accountable the whole time.
- Runbooks for every deployed control
- Terraform and automation source, ready to merge
- Credential inventory, owned by your tenant
- Architecture doc with every decision on record
Read-only by default. Delegated OAuth permissions or scoped service principals - tagged, time-boxed, revocable in one click.
Audit data and form submissions are stored in EU regions. Every sub-processor and its location is disclosed. We don't sell, profile, or train on your data.
ITSAILOR / EXIT KIT
Exit Kit: Table of Contents
- Runbooks (incident, access, backup and restore)
- Terraform and automation source
- Credential and licence inventory
- Architecture record and open decisions
Handover complete within 24 hours of close-out.
The handover sequence
- Day 1Credential inventory, tenant-owned.
- BuildTerraform source, ready to merge.
- DocumentRunbooks for every control.
- HandoverArchitecture doc, decisions on record.
The licensing catalogue, priced.
2,200+ software SKUs from 104 vendors, provisioned through Pax8 wholesale and billed by ITSailor in Malta. 1,783 carry a listed price; the other 496 are metered or bespoke, so we quote those. No sales call required for what is already priced.

If the brief fits ITSailor, you get a scoped path.If it does not, you get a direct answer and a useful referral.
Michal Jatczak · Founder
Where clients usually start.
Each playbook is scoped to your stack and delivered in weeks, not quarters.
Rapid AI Prototyping
De-risk your AI investment with 4-week pilot engagements that prove ROI.
Scoped to you
Cloud Infrastructure Modernization
Standardize your Azure landing zones for scale, security and performance.
Scoped to you
Secure Remote Workforce
Empower your team to work from anywhere without security compromises.
Scoped to you
What we're learning, in public.
Technical writing across AI, security, and modern workspace. No vendor fluff - every article links to a real tenant decision or a live product.
The Google Workspace scope for reading a leaver's app grants is not read-only
Listing a Google Workspace user's third-party app tokens needs admin.directory.user.security, the same scope that deletes them, and Google lists no read-only variant. Microsoft Graph lists the equivalent grants with Directory.Read.All. Treat the Google credential as a revocation key.
A daily offboarding check can prove closure only as a bound
A leaver check that runs once a day can report closure only as a bound between two runs. A Graph 429, including one inside a batch that returns 200, and a membership read that returns nulls can each make a degraded run look clean, so an absence counts only from a run that read cleanly.
Under a Microsoft Customer Agreement, Azure credits sit on the billing profile and a budget does not stop spend past them
Under a Microsoft Customer Agreement, Azure credits are applied to a billing profile invoice and a Cost Management budget only notifies. Read the billing profile spendingLimit property before trusting anything to stop spend, and use an Azure Policy deny rule where new spend must be refused.
Ready when you are.
Thirty minutes with Michal, directly. No sales team in the way. Bring the problem; leave with the next move.
