CX-01 / CORE — Infrastructure, Identity & Managed IT

Infrastructure built correctly once.

Networks, identity and managed IT for organizations that can’t afford downtime — engineered end to end by one accountable person, so you never rebuild it at the next expansion.

21%
Under the competing bid
$40K+
Saved vs. larger firms
1–3 days
On-site build time
0
Shared logins after rollout
FortiGate & UniFi networksActive Directory → Entra IDMicrosoft 365 + MFAHIPAA-aligned designSite-to-site VPNSame-day remote support
System blueprint

One identity. Every site. No rework.

Most small-business IT is a pile of one-off fixes. CORE is a designed system: the network, the identity layer and the devices are built to the same plan — so adding a site, a hire or a policy is configuration, not another project.
SITES
Your locations
Offices, clinics, warehouses, remote staff
NETWORK
FortiGate + UniFi
VLANs, QoS for voice, site-to-site IPsec VPN
IDENTITY
Microsoft Entra ID
One login per person, MFA everywhere
WORKSPACE
Microsoft 365
Mail, devices, policies, retention
PEOPLE
Role groups
Admin / Management / Staff — instant offboarding
Cloud-first identity means the directory never has to be rebuilt for a new location — ever.
What CORE deploys

Everything between the wall jack and the login screen

Designed, installed and managed by the same person. No hand-offs between a sales engineer, a project team and a helpdesk.
01
Network rebuilds
FortiGate firewalls, UniFi switching and Wi-Fi, structured Cat6, racks and patch panels. VLAN segmentation for staff, voice and guests. QoS tuned for VoIP.
02
Identity & Active Directory
On-prem AD migrated to Microsoft Entra ID with Microsoft 365 Business Premium. MFA for every user, admin and VPN session. No kiosks, no shared logins.
03
Managed IT & helpdesk
24/7 monitoring, same-day remote support, patching, UniFi and firewall updates, monthly health reports and priority on-site when it matters.
04
Security & compliance design
HIPAA-aligned segmentation and retention, audit-ready logging built for security — not surveillance — and E911 compliance for phone systems (Kari’s Law, RAY BAUM’s Act).
05
Multi-site connectivity
Site-to-site VPN between locations, ISP and demarc coordination, remote-access VPN for staff who work from anywhere.
06
Hosting & cloud
Managed VPS hosting on CloudPanel, Docker workloads, Cloudflare, backups and migrations off agency hosting.
From the field

What a CORE rollout looks like

Representative build log from a three-site healthcare deployment — network, VPN and identity brought online in days, not quarters.
[2026-06-09 14:02:11] site=toledo ipsec_tunnel=UP peer=tiffin-b1 latency=9ms [2026-06-09 14:02:13] vlan10=staff vlan20=voice vlan30=residents qos=voice-priority sip_alg=disabled [2026-06-09 14:05:40] entra_id users=15 admins=2 mfa=enforced shared_logins=0 kiosks=0 [2026-06-09 14:06:02] m365 business_premium=active device_policy=applied retention=hipaa-aligned [2026-06-09 14:11:27] handoff incumbent MSP controller migrated → crossover tickets_open=0 [2026-06-09 14:11:28] status=OPERATIONAL on_site=1–3 days completion=< 1 week
Log is illustrative; values reflect the Preferred Pathways Toledo/Maumee build, June 2026.
Impact

Preferred Pathways: three sites, one identity, 21% under the competing bid

A multi-site healthcare and disability-services provider in Tiffin, Fostoria and Toledo needed a network rebuild and a real identity foundation. The competing proposal was a $95,000 on-prem build from a larger firm. Crossover delivered the identity and network phase 21% under that bid with lower long-term overhead — and took over network management from the incumbent MSP.
  • On-prem Active Directory migrated to Microsoft Entra ID; Microsoft 365 Business Premium org-wide
  • FortiGate + UniFi rebuild with VLANs for staff, voice and residents; site-to-site VPN Toledo ↔ Tiffin
  • MFA for every staff, admin and VPN login — zero shared logins, instant offboarding
  • Toledo/Maumee site built in 1–3 days on-site, hardware included, paid in full
  • Formal E911 compliance notice delivered with the phone rollout
Sites3 locations + remote VPN
IdentityOn-prem AD → Entra ID
Staff~15 users, 2 admins
Timeline1–3 days on-site, < 1 week
ComplianceHIPAA-aligned, E911
Outcome$40K+ saved vs. larger firms
“Thank you for your assistance on the Preferred Pathways phones in Maumee. We will keep you in mind for future projects.”
Sound Solutions of Ohio — phone systems partner on the build
Why it’s different

A partner on your side of the table

The difference between a vendor with a ticket queue and one accountable engineer who designed the system.
Crossover CORETypical MSP
Who you talk toThe founder who designed and built your system — every timeAn account manager, then a ticket queue
ResponseSame-day remote, priority on-site, 24/7 monitoringSLA windows and escalation tiers
ArchitectureBuilt correctly once; cloud-first identity that never needs a rebuildRebuilt or re-quoted at every expansion
OverheadZero employees — low overhead, immediate responseLayers of staff you pay for
LoggingFor security and audit readiness, not surveillanceOften an add-on
BillingFlat, adaptable milestones; no mileage or commute billed; problems from my build aren’t billedHourly surprises
How it works

From first look to fully managed

A clear, phased path. You see every milestone and you’re never handed off.
01
Assess
A free checkup of your current setup: network, identity, backups, phones. You get a short written list of what I’d tighten — yours to keep either way.
02
Architect
A written plan with the target design, hardware list, milestones and what each phase unlocks. Hardware is purchased at cost, in your name.
03
Build
On-site in 1–3 days per location, completion within a week. Cut-overs scheduled around your operations, with a rollback path for every step.
04
Manage
Monitoring, patching, updates, monthly health reports and a real person to call. Expansions become configuration, not projects.
Free · no strings · no upsell
Free IT checkup for Ohio businesses
A quick look over your office setup, identity and backups, with a short list of anything I’d tighten up — yours to keep whether or not we ever work together. In person within about 90 minutes of Tiffin, or remote anywhere in the U.S.
Questions

Frequently asked

Q.Do you replace our current MSP, or work alongside them?
Either. I’ve taken over full network management from an incumbent MSP mid-project — including the controller handoff — and I’ve also worked alongside phone and AV vendors on the same build. The goal is one accountable owner for the outcome.
Q.Can you work with the hardware we already own?
Yes, where it’s sound. I standardize on FortiGate and UniFi because they’re reliable and affordable, but the assessment tells us what stays and what goes. Hardware is bought at cost in your name, never marked up.
Q.Is this HIPAA compliant?
Compliance is a program, not a product, so I design to HIPAA-aligned standards: segmented networks, MFA, role-based access, retention and audit-ready logging. You get documentation your compliance officer or auditor can actually use.
Q.What does managed IT include?
24/7 monitoring, same-day remote support, patching and firmware updates, UniFi and firewall maintenance, monthly health reports and priority on-site visits — for all your locations under one flat monthly plan.
Q.How fast can you start?
The free checkup can usually happen within days. Builds are scheduled around your operations; a single-site network rebuild is typically 1–3 days on-site with completion inside a week.

Ready to stop rebuilding your IT every time you grow?

Tell me about your sites, your staff and what breaks. You’ll be talking directly with me — not a queue.