>_
unspentlabs.space
operational · accepting consultations

Security, sovereignty, & signal.

A three-person collective building lightweight, defensible security for small businesses and individuals who refuse to outsource their trust. SIEM endpoints that don't drown you. Bitcoin custody that survives you.

team3 operators
focusdefense · custody · counsel
est.remote · worldwide
01 / about

Three operators. One mandate.

We're a small team on purpose. Small means the people who scope your work are the people who do your work. No account managers, no handoffs, no theater.

01
OP

Operator

Detection & Response

Builds the SIEM spine — Wazuh deployments tuned for shops that can't afford a SOC but can't afford to ignore one either.

  • Wazuh
  • EDR
  • correlation rules
02
CK

Custodian

Key Architecture & Inheritance

Designs multisig setups, key-shard distribution, and recovery plans that outlive the holder. Self-custody that's actually recoverable.

  • multisig
  • inheritance
  • key material
03
CO

Counsel

Strategy & Advisory

Translates risk into decisions. Threat models, vendor review, and the unglamorous policy work that makes the technical work stick.

  • threat modeling
  • policy
  • review
02 / services

What we actually do.

Three core practices. Everything else is a conversation.

01

Lightweight SIEM & Wazuh endpoints

+

Full-stack Wazuh deployments sized for small businesses — agents that don't hog the box, rules that fire on what matters, and dashboards a non-analyst can read at 7am.

  • Right-sized agent rollout & tuning
  • Custom decoders & correlation rules
  • Log hygiene, retention, and alert triage playbooks
  • EDR integration & active response
02

Bitcoin self-custody, multisig & inheritance

+

Custody architectures where you keep the keys — and your heirs can actually recover them. Multisig quorums, geographic key distribution, and inheritance documents that don't leak the seed.

  • Multisig setup (2-of-3, 3-of-5) & coordinator config
  • Cold storage & hardware wallet workflows
  • Inheritance letters & recovery runbooks
  • Key-shard geography & compromise drills
03

Consultation & everything else

+

The bucket for everything that doesn't fit a label: threat modeling, hardening reviews, vendor due diligence, incident response prep, and the awkward questions you'd rather ask someone who's done it before.

  • Threat modeling workshops
  • Infrastructure & cloud hardening reviews
  • Incident response tabletops
  • Ad-hoc advisory retainers
03 / principles

How we work.

01

Small by design

Three people, no layers. The person you brief is the person who ships.

02

You keep your keys

We design custody so it's yours. We never hold key material. Ever.

03

Signal over noise

Alerts that mean something. Rules tuned to your environment, not a default pack.

04

Documented, not magic

You leave with runbooks, diagrams, and the ability to run it without us.

04 / contact

Let's talk about what's actually keeping you up.

Brief intro, the problem, and a rough timeline. We reply within two business days. PGP available on request.

We take on a small number of engagements at a time. If we're not the right fit, we'll tell you who is.