DeltaZulu OÜ · Tallinn, Estonia

Practical security engineering for infrastructure that has to hold.

DeltaZulu is a small technology company focused on cybersecurity, infrastructure, and defensive engineering. We build tools and operational practice for teams that need their systems to keep working under pressure — not theatre, not buzzwords, not generic dashboards.

Based in
Tallinn, Estonia
Practice
Cybersecurity & infrastructure
Posture
Defensive, calibrated
Status
FOSS active · Commercial follows
Practice

Three areas, treated as one discipline.

Cybersecurity, infrastructure, and defensive engineering are not separate motions for us. They are the same problem at different layers: keeping systems trustworthy when something unexpected hits them.

01

Cybersecurity

Practical, evidence-led security work — not posture theatre. We focus on the controls and telemetry that actually shape outcomes during an incident, and the audit artefacts buyers can defend in a review.

Threat exposure DNS-layer defence Evidence outputs
02

Infrastructure

Networks, resolvers, edge services, identity boundaries — the load-bearing parts of an organisation's stack. We design, instrument, and harden infrastructure with operational realities in mind, not just topology diagrams.

Network design Hybrid deploys Resolver hygiene
03

Defensive engineering

Detection, response, drills, and the tooling that makes them survivable at small-team scale. We build for the operator who is on-call at 02:00, not for the slide-deck audience three quarters later.

Detection Incident drills Runbooks
What we build

Tools for security ops, network visibility, infrastructure assurance, and defensive testing.

Some of this work is released openly. Some becomes the basis for commercial products. The throughline is the same: instrumentation and controls a small operations team can actually run, audit, and explain.

01

Security operations

Day-to-day tooling for detection, triage, and response — built so a small team can keep pace without drowning in vendor consoles or low-signal alerts.

02

Network visibility

Resolver telemetry, DNS-layer signals, and traffic instrumentation that make the boring parts of a network legible — well before an investigation needs them.

03

Infrastructure assurance

Controls, checks, and evidence outputs aligned to compliance regimes (NIS2, DORA-adjacent). The kind of artefacts a procurement reviewer actually reads.

04

Defensive testing

Realistic exercises, attack-path validation, and tabletop scaffolding — the unglamorous discipline that turns a written runbook into something a team trusts at 02:00.

Open source

Some of our work is published openly.

FOSS releases are how we share the parts of our practice that are most useful to peers and downstream users. They are not the company's commercial surface — they are the operational scaffolding under it.

Three current releases under the DeltaZulu-OU organisation. More tooling, including resolver-side telemetry and defensive-testing scaffolds, follows the same publish-when-useful cadence.

Browse the GitHub org
Commercial work

Hosted services and commercial products follow separately.

Our open-source work is the practice. Commercial offerings are deliberately announced apart from it — when they are mature enough to defend on their own terms, with their own positioning and support obligations.

The first commercial direction is protective DNS for regulated supply chains.

It builds on the same resolver-telemetry and evidence-output work that runs through our open practice. When it is ready to stand on its own page, it will have one.

01
DZNS · Protective DNS
Filtering plus governed telemetry for compliance-pressured buyers.
Forthcoming
02
Hosted operational services
Managed defensive engagements for partner-led delivery.
Roadmap