CX-01 / CORE — Infrastructure, Identity & Managed IT
Infrastructure built correctly once.
Networks, identity and managed IT for organizations that can’t afford downtime — engineered end to end by one accountable person, so you never rebuild it at the next expansion.
21%
Under the competing bid
$40K+
Saved vs. larger firms
1–3 days
On-site build time
0
Shared logins after rollout
✓FortiGate & UniFi networks✓Active Directory → Entra ID✓Microsoft 365 + MFA✓HIPAA-aligned design✓Site-to-site VPN✓Same-day remote support
System blueprint
One identity. Every site. No rework.
Most small-business IT is a pile of one-off fixes. CORE is a designed system: the network, the identity layer and the devices are built to the same plan — so adding a site, a hire or a policy is configuration, not another project.
SITES
Your locations
Offices, clinics, warehouses, remote staff
→
NETWORK
FortiGate + UniFi
VLANs, QoS for voice, site-to-site IPsec VPN
→
IDENTITY
Microsoft Entra ID
One login per person, MFA everywhere
→
WORKSPACE
Microsoft 365
Mail, devices, policies, retention
→
PEOPLE
Role groups
Admin / Management / Staff — instant offboarding
Cloud-first identity means the directory never has to be rebuilt for a new location — ever.
What CORE deploys
Everything between the wall jack and the login screen
Designed, installed and managed by the same person. No hand-offs between a sales engineer, a project team and a helpdesk.
01
Network rebuilds
FortiGate firewalls, UniFi switching and Wi-Fi, structured Cat6, racks and patch panels. VLAN segmentation for staff, voice and guests. QoS tuned for VoIP.
02
Identity & Active Directory
On-prem AD migrated to Microsoft Entra ID with Microsoft 365 Business Premium. MFA for every user, admin and VPN session. No kiosks, no shared logins.
03
Managed IT & helpdesk
24/7 monitoring, same-day remote support, patching, UniFi and firewall updates, monthly health reports and priority on-site when it matters.
04
Security & compliance design
HIPAA-aligned segmentation and retention, audit-ready logging built for security — not surveillance — and E911 compliance for phone systems (Kari’s Law, RAY BAUM’s Act).
05
Multi-site connectivity
Site-to-site VPN between locations, ISP and demarc coordination, remote-access VPN for staff who work from anywhere.
06
Hosting & cloud
Managed VPS hosting on CloudPanel, Docker workloads, Cloudflare, backups and migrations off agency hosting.
From the field
What a CORE rollout looks like
Representative build log from a three-site healthcare deployment — network, VPN and identity brought online in days, not quarters.
[2026-06-09 14:02:11] site=toledo ipsec_tunnel=UP peer=tiffin-b1 latency=9ms
[2026-06-09 14:02:13] vlan10=staff vlan20=voice vlan30=residents qos=voice-priority sip_alg=disabled
[2026-06-09 14:05:40] entra_id users=15 admins=2 mfa=enforced shared_logins=0 kiosks=0
[2026-06-09 14:06:02] m365 business_premium=active device_policy=applied retention=hipaa-aligned
[2026-06-09 14:11:27] handoff incumbent MSP controller migrated → crossover tickets_open=0
[2026-06-09 14:11:28] status=OPERATIONAL on_site=1–3 days completion=< 1 week
Log is illustrative; values reflect the Preferred Pathways Toledo/Maumee build, June 2026.
Impact
Preferred Pathways: three sites, one identity, 21% under the competing bid
A multi-site healthcare provider chose this design over a $95,000 on-premise proposal from a larger firm. Crossover delivered the network and identity build 21% under that bid, took over management from the incumbent MSP, and brought the Toledo site online in 1–3 days on-site. The full story — challenge, architecture, timeline, results — is in the case study.
Sites3 locations + remote VPN
IdentityOn-prem AD → Entra ID
Staff~15 users, 2 admins
Timeline1–3 days on-site, < 1 week
ComplianceHIPAA-aligned, E911
Outcome21% under bid · $40K+ saved
Why it’s different
A partner on your side of the table
The difference between a vendor with a ticket queue and one accountable engineer who designed the system.
| Crossover CORE | Typical MSP | |
|---|---|---|
| Who you talk to | The founder who designed and built your system — every time | An account manager, then a ticket queue |
| Response | Same-day remote, priority on-site, 24/7 monitoring | SLA windows and escalation tiers |
| Architecture | Built correctly once; cloud-first identity that never needs a rebuild | Rebuilt or re-quoted at every expansion |
| Overhead | Zero employees — low overhead, immediate response | Layers of staff you pay for |
| Logging | For security and audit readiness, not surveillance | Often an add-on |
| Billing | Flat, adaptable milestones; no mileage or commute billed; problems from my build aren’t billed | Hourly surprises |
How it works
From first look to fully managed
A clear, phased path. You see every milestone and you’re never handed off.
01
Assess
A free checkup of your current setup: network, identity, backups, phones. You get a short written list of what I’d tighten — yours to keep either way.
02
Architect
A written plan with the target design, hardware list, milestones and what each phase unlocks. Hardware is purchased at cost, in your name.
03
Build
On-site in 1–3 days per location, completion within a week. Cut-overs scheduled around your operations, with a rollback path for every step.
04
Manage
Monitoring, patching, updates, monthly health reports and a real person to call. Expansions become configuration, not projects.
Free · no strings · no upsell
Free IT checkup for Ohio businesses
A quick look over your office setup, identity and backups, with a short list of anything I’d tighten up — yours to keep whether or not we ever work together. In person within about 90 minutes of Tiffin, or remote anywhere in the U.S.
Questions
Frequently asked
Q.Do you replace our current MSP, or work alongside them?
Either. I’ve taken over full network management from an incumbent MSP mid-project — including the controller handoff — and I’ve also worked alongside phone and AV vendors on the same build. The goal is one accountable owner for the outcome.
Q.Can you work with the hardware we already own?
Yes, where it’s sound. I standardize on FortiGate and UniFi because they’re reliable and affordable, but the assessment tells us what stays and what goes. Hardware is bought at cost in your name, never marked up.
Q.Is this HIPAA compliant?
Compliance is a program, not a product, so I design to HIPAA-aligned standards: segmented networks, MFA, role-based access, retention and audit-ready logging. You get documentation your compliance officer or auditor can actually use.
Q.What does managed IT include?
24/7 monitoring, same-day remote support, patching and firmware updates, UniFi and firewall maintenance, monthly health reports and priority on-site visits — for all your locations under one flat monthly plan.
Q.How fast can you start?
The free checkup can usually happen within days. Builds are scheduled around your operations; a single-site network rebuild is typically 1–3 days on-site with completion inside a week.
Ready to stop rebuilding your IT every time you grow?
Tell me about your sites, your staff and what breaks. You’ll be talking directly with me — not a queue.