╔══════════════════════════════════════════════════════════════════════╗
║ SERVICES — STRATEGIC ENGAGEMENT CATALOGUE ║
║ Ciprian Stefan Plesca // Xolo Go OÜ ║
╚══════════════════════════════════════════════════════════════════════╝
Read this first.
This is not a service menu. It is a capability declaration. Engagements are selected, not sold. If you are evaluating whether this is the right fit, you are already in the right place.
CLASSIFICATION: STRATEGIC // INFRASTRUCTURE
ENGAGEMENT TYPE: Architecture + Implementation + Governance
What this covers:
Private, self-hosted AI infrastructure designed for organisations that cannot place sensitive workloads on shared cloud infrastructure. This engagement produces operational AI systems that you own, control, and can audit — without vendor dependency or data residency risk.
Deliverables:
- Threat-modelled AI infrastructure architecture
- Self-hosted LLM deployment (on-premise or private cloud)
- Inference stack configuration (Ollama / vLLM / llama.cpp)
- Data residency enforcement controls
- Prompt governance & audit logging framework
- Operational runbook with incident response procedures
- Compliance mapping (GDPR / NIS2 / sector-specific)
Indicators this engagement is right:
- You handle data you cannot place in OpenAI, Google, or Microsoft infrastructure
- You operate in a regulated sector (finance, legal, healthcare, defence-adjacent)
- You need AI capability without surrendering control of the weights or the outputs
- Your legal or compliance team has raised concerns about cloud AI
CLASSIFICATION: SECURITY // ARCHITECTURE
ENGAGEMENT TYPE: Assessment + Design + Remediation Roadmap
What this covers:
End-to-end zero-trust architecture for organisations migrating away from perimeter-based security models. Designed for hybrid environments, remote-first operations, and systems where the boundary between internal and external has already dissolved.
Deliverables:
- Current-state security posture assessment
- Zero-trust maturity scoring (CISA ZTM aligned)
- Identity-first access architecture design
- Microsegmentation blueprint
- Device trust framework
- Privileged access management (PAM) design
- Implementation roadmap with prioritised controls
- Security controls mapped to ISO 27001 / NIST CSF 2.0
Indicators this engagement is right:
- Your organisation assumed internal networks are trusted
- Remote access is via VPN without continuous verification
- You have had or are concerned about lateral movement in a breach scenario
- You are preparing for SOC 2, ISO 27001, or NIS2 compliance
CLASSIFICATION: COMMERCIAL // POSITIONING
ENGAGEMENT TYPE: Strategy + Build + Authority Architecture
What this covers:
GitHub presence designed for institutional trust — the kind that converts enterprise conversations, attracts acquisition interest, and survives technical due diligence. This is not documentation work. It is technical authority infrastructure.
Deliverables:
- GitHub profile and repository architecture strategy
- Profile README engineered for operator-level trust signals
- Repository structure standardisation across all public assets
- Documentation hierarchy (README → PROFILE → DOCS)
- Commercial signals: licensing, sponsorship readiness, contribution guidelines
- Due-diligence audit of existing public repositories
- Monetisation pathway design (sponsorship, licensing, productisation)
Indicators this engagement is right:
- Your GitHub is your first impression with serious technical evaluators
- Investor or acquirer due diligence begins with your repositories
- You want your open-source work to generate commercial leverage
- Your existing GitHub presence does not reflect the quality of your actual work
CLASSIFICATION: OPERATIONS // GOVERNANCE
ENGAGEMENT TYPE: Design + Implementation + Compliance Mapping
What this covers:
Governance-first automation for organisations that need to scale operations without scaling risk. Built for regulated environments where every automated action must be attributable, auditable, and reversible.
Deliverables:
- Current process audit & automation opportunity mapping
- Governance framework design (role-based execution, approval chains)
- Workflow orchestration implementation (n8n / Make / custom)
- AI-augmented workflow integration with human-in-the-loop controls
- Audit logging architecture
- Policy-as-code implementation
- Runbooks for every automated process
Indicators this engagement is right:
- Your team is executing repetitive processes that carry compliance risk
- Automation exists in your organisation but is ungoverned
- You are scaling operations and cannot scale headcount proportionally
- You operate in a sector where every action requires an audit trail
CLASSIFICATION: COMMERCIAL // PRODUCT
ENGAGEMENT TYPE: Strategy + Positioning + Revenue Architecture
What this covers:
Technical products positioned for acquisition, sponsorship, and recurring revenue. This engagement bridges the gap between technical execution and commercial readiness — the gap that causes most excellent technical work to generate zero economic return.
Deliverables:
- Asset inventory and commercial potential assessment
- Acquisition readiness evaluation and gap analysis
- Licensing strategy design
- GitHub Sponsors configuration and tier architecture
- Documentation that converts technical reviewers to paying customers
- Positioning narrative for fundraising, partnership, or acquisition contexts
Indicators this engagement is right:
- You have built something of genuine technical value that generates no revenue
- You are preparing a product for acquisition or institutional investment
- Your open-source projects attract stars but no sponsorship
- You want to productise existing infrastructure without rebuilding it
CLASSIFICATION: STRATEGIC // ADVISORY
ENGAGEMENT TYPE: Ongoing Retained Advisory
What this covers:
A standing advisory relationship for founders, technical leaders, and operators who make architecture decisions with long-term consequences. Not a consulting retainer. A trusted second opinion from someone who has built the systems you are designing.
Structure:
- Fixed monthly engagement with defined access windows
- Architecture review of all significant system decisions
- Security posture check-ins against evolving threat landscape
- On-call escalation for critical architectural decisions
- Quarterly posture review and roadmap refinement
Indicators this engagement is right:
- You make architecture decisions whose consequences will last 5+ years
- You have no senior security or infrastructure advisor on your team
- You are entering a new technical domain (AI, ZT, regulated infrastructure)
- You want a named, accountable architecture advisor — not a consulting firm
STEP 1: INITIAL CONTACT
Submit a brief via: stefanowien777@gmail.com
Include: Context, scope signal, and timeline.
Do not include: RFPs, NDAs before context, or open-ended exploration.
STEP 2: QUALIFICATION
A brief written exchange to establish fit.
Most engagements are declined here — not as a judgment,
but because fit determines outcome.
STEP 3: PRIVATE TECHNICAL BRIEFING
30-minute private briefing via: cal.com/ciprian-stefan-plesca
Structured, specific, and scoped to your operational context.
STEP 4: PROPOSAL
Scoped proposal with deliverables, timeline, and commercial terms.
Invoiced through Xolo Go OÜ (EU VAT: EE102156920).
STEP 5: ENGAGEMENT
Structured, milestone-driven, with defined handoff criteria.
entity: "Xolo Go OÜ — Ciprian-Stefan Plesca"
registry: "Estonia · 14717109"
vat: "EE102156920"
invoicing: "EUR — EU and international"
payment_terms: "50% advance, 50% on delivery (project)"
retainer: "Monthly, invoiced in advance"
contracts: "Governed under Estonian / EU commercial law"
nda: "Available on request post-qualification"╔═════════════════════════════════════════════════════════╗
║ Ready to begin? Start here: ║
║ 📅 cal.com/ciprian-stefan-plesca ║
║ 📧 contact@localpulse.pro ║
╚═════════════════════════════════════════════════════════╝