An edge server fronting a hypervisor over an encrypted tunnel, with seven separated service containers behind a reverse proxy doing automated TLS. Mail authenticated properly end to end — SPF, DKIM, reverse DNS, MTA-STS, and DMARC set to reject rather than merely observe. Split-horizon DNS, an intrusion-prevention layer filtering forwarded traffic rather than just local traffic, capped logging, and nightly configuration backups.