Golem Trust Computing Ltd.¶
Golem Trust Computing operates from a converted fish warehouse near the Shades in Ankh-Morpork. Ponder Stibbons (former HEX operator at Unseen University) and Adora Belle Dearheart (postal systems expert) provide cloud hosting for the city’s merchant guilds.
They host critical systems for the Patrician’s Office, the Civic Defence Establishment, the Royal Bank of Ankh-Morpork, and merchant guilds across the Circle Sea. All infrastructure runs on Hetzner Cloud in Finland. As much as possible is European and/or open source.
That last line is doing more work than it lets on. A converted fish warehouse near the Shades now carries the routine compute of the Patrician’s Office, the Establishment, the Royal Bank, and guilds across the Circle Sea, which turns a small firm into a strategic position whether or not its founders ever meant it to be one. From here it reads as ordinary business: capacity, uptime, the occasional maintenance window. Seen from the capitals that depend on it, the same firm is the single largest shared dependency of the Circle Sea Arrangement, and the quietest lever in it. A golem works on the word in its head, and the words are written here, on a sovereign-sounding service that is itself run on someone else’s yard in Finland.
This chronicles their technical journey building security.
- Startup
- Scale-up
- Enterprise
- The Kubernetes migration
- Service mesh and mutual TLS
- The Assassins’ Guild encryption requirement
- The quantum threat
- Post-quantum cryptography
- Trends in cryptanalysis: defensive perspective
- Policy as code with OPA
- Vulnerability management at scale
- The Bug Bounty programme
- Threat intelligence with MISP
- Supply chain security
- Behavioural analytics and ML detection
- Red Team operations
- Deception technology
- Runtime security with Falco
- Chaos engineering
- Alternative tools
- Runbooks
Each phase focuses on what is actually built: the machinery humming in the back room, the tools that occasionally spark, the automation that behaves itself most days, and the security woven into daily graft. Once the real work is done, the evidence more or less accumulates by itself, like paperwork in the Patrician’s antechamber. Cross references to the purple crossroads point out which bits happen to keep auditors happy, but the real motive is stopping threats.