Skip to main content
TechHand Pro Solutions · Stack

TOOLS WE ACTUALLY RUN.

Not a logo wall of software we once evaluated. These are the vendors we partner with and the tools wired into TechHand Network Toolkit (TNT)—the same system that scans networks, files tickets, takes backups, and sends invoices.

  • Authorized partners named as partners
  • Everything else is a tool we run
  • No mystery stack
01

Partners

Authorized partners we resell and operate with under real agreements—not just logos on a slide.

Bitdefender GravityZone

Partner

Authorized MSP partner — endpoint protection we deploy and manage

Bitdefender GravityZone is our primary endpoint platform for managed-IT clients. TNT talks to the GravityZone MSP API to list companies, endpoints, and incidents, and the Windows TNT client can silently install the Bitdefender agent during onboarding. We watch detections, tune policy, and treat incidents as tickets—not as alerts that sit in a vendor console nobody opens.

Vendor site

IRONSCALES

Partner

Authorized partner — AI-assisted phishing defense for Microsoft 365

IRONSCALES is the email-security layer we recommend and resell for businesses whose inbox is the real perimeter. It sits on Microsoft 365, flags impersonation and payload phishing, and gives staff a one-click way to report a suspicious message. We include it in managed security bundles so mailbox protection is a named control—not an afterthought next to antivirus.

Vendor site

Hawk Host

Partner

Reseller partner — cPanel and WHM hosting we provision from TNT

Hawk Host is the hosting provider behind our managed web hosting. TNT’s WHM integration syncs accounts, provisions cPanel sites, opens support sessions, and handles DNS and email setup without a second control panel for day-to-day work. You get a hosting stack we already operate—not a random VPS we hope stays patched.

Vendor site
02

Backup and continuity

Image-based and file-level backup so a failed drive, ransomware event, or bad update is a restore—not a rebuild.

Acronis

Tool we use

Image-based backup and disaster recovery we deploy for managed clients

Acronis is the backup product we specify in managed-IT plans when a business needs full-machine images, not just file copies. We install agents, set retention, and verify restores so a ransomware event or dead disk is a recovery job. It is a tool we deploy and operate—not a live TNT API integration—and we treat restore tests as part of the work, not a checkbox on a quote.

Vendor site

FABS Auto Backup

Tool we use

Windows profile backup we run before repairs and migrations

FABS Auto Backup lives in the TNT technician toolkit. Before a drive clone, OS reinstall, or user migration we capture the Windows profile—documents, desktop, browser data, and mail—so the machine comes back looking like the customer left it. Fast, local, and boring on purpose: the goal is that nobody notices the backup except when they need it.

Vendor site
03

Endpoint and email security

Layered protection we install, monitor, and tune: endpoint agents plus phishing defense where the mailbox is the front door.

Malwarebytes

Tool we use

On-demand malware and PUP cleanup in the technician toolkit

Malwarebytes AdwCleaner is part of the TNT field toolkit for adware, toolbars, and stubborn PUPs that slip past a stock antivirus install. Technicians run a scan or a clean pass from the catalog, with results that feed the repair notes. It is a cleanup tool we bring to the machine—not a replacement for the managed endpoint agent.

Vendor site

Emsisoft

Tool we use

Command-line malware scanner for stubborn infections

Emsisoft’s command-line scanner is in the TNT technician catalog for deep malware sweeps when a GUI cleaner is not enough. We run it during disinfect-and-rebuild jobs, then verify the machine against the managed endpoint agent before it goes back into production. Catalog listing in TNT, not a cloud API—used where it earns its keep.

Vendor site
04

Network and security testing

Authorized discovery and vulnerability checks that run inside TechHand Network Toolkit (TNT)—with client approval before anything aggressive.

Nmap

Tool we use

Authorized network discovery and vulnerability scanning inside TNT

Nmap is the core of TNT’s network discovery. Onboarding scans map live hosts, open ports, and service versions; optional NSE vuln and vulners scripts surface CVEs with a CVSS floor so we are not drowning in noise. Every scan is scoped, logged, and run only on networks you authorize. Findings become tickets—not a 40-page PDF that dies in email.

Vendor site

Nuclei

Tool we use

Template-based vulnerability checks on approved targets

Nuclei (ProjectDiscovery) is one of TNT’s Tier-B scan recipes. After Nmap maps the surface, Nuclei runs curated templates against web and network services you have authorized—misconfigurations, known CVEs, exposed panels. Results parse back into TNT so we can prioritize fixes instead of dumping raw scanner output on a client.

Vendor site

testssl.sh

Tool we use

TLS audits before a site or mail host goes live

testssl.sh is the TLS recipe in TNT’s scan catalog. We use it on web and mail endpoints to catch expired chains, weak ciphers, protocol leftovers, and certificate mismatches before a customer’s bank or merchant scanner does. Output is translated into a short fix list—renew, disable, or replace—not a lecture on TLS versions.

Vendor site

Wireshark

Tool we use

Packet capture when “the network is slow” needs evidence

TNT uses tcpdump and tshark (Wireshark’s CLI) for packet capture and filtering during network analysis. When a VoIP call drops, a printer storms the LAN, or a workstation talks to somewhere it should not, we capture—not guess. Captures stay scoped to the incident and are handled as operational data, not a fishing expedition.

Vendor site

Metasploit

Tool we use

Gated exploit-framework recipes for authorized tests only

Metasploit appears in TNT as a Tier-C recipe—dry-run gated, never a default scan. When a client has authorized a deeper test, we can run auxiliary and exploit modules from an allowlisted path instead of improvising on a laptop. Production scans stay on Nmap and Nuclei; Metasploit is the exception that requires a written yes.

Vendor site

Kali Linux

Tool we use

Isolated worker for allowlisted nmap jobs

TNT’s Kali worker is a small, authenticated job server that runs allowlisted Nmap scans away from the main application. Heavy discovery does not sit on the same process as invoices and tickets. The worker is scoped, logged, and reached over an internal HTTP job API—not an open pentest box on the public internet.

Vendor site
05

AI and automation

Cloud models when the job needs them, local GPU inference when data should stay on our hardware.

OpenAI

Tool we use

Cloud models for TNT chat, writing assists, and vision when a job needs them

TNT’s LLM client talks to OpenAI for staff chat, premium writing passes on blog and email drafts, and vision or image jobs that the local GPU should not own. Client data is scoped to the task; we do not dump a whole customer database into a prompt. When the work can stay on-box, we prefer Ollama—OpenAI is the cloud lane, not the only lane.

Vendor site

Ollama

Tool we use

Local LLM runtime so routine AI work never has to leave the server

Ollama runs local models for TNT chat and automation when we want inference on our own hardware. A Caddy bridge exposes an OpenAI-compatible endpoint so the same TNT client can fail over between cloud and local without a rewrite. Model pulls and health checks are first-class operations—not a hobby install on someone’s laptop.

Vendor site

NVIDIA

Tool we use

CUDA GPUs for local speech, diarization, and image generation

TNT’s voice sidecar (Whisper speech-to-text, Kokoro TTS, pyannote diarization) and optional image-gen worker run on NVIDIA CUDA. GPU health is part of the monitor—nvidia-smi and nvcc checks—not a hope that the card is still there. Local inference is how ticket voice notes and meeting transcripts stay on our metal.

Vendor site

Cursor

Tool we use

Cloud agent handoffs and an MCP server for staff automation

TNT exposes a Model Context Protocol server and a Cursor cloud-agent handoff so staff can turn a chat into a scoped engineering task without copying secrets into a prompt. Repositories are linked on purpose; the agent sees the tools we allow, not the whole disk. It is how we keep AI-assisted development inside the same access model as the rest of the shop.

Vendor site
06

Hosting and web platform

The stack behind managed hosting: control panels, reverse proxies, certificates, and edge protection.

cPanel & WHM

Tool we use

Hosting control plane TNT automates for managed sites

cPanel and WHM are the control plane for accounts we host. TNT provisions sites, syncs packages, opens cPanel sessions, and wires DNS and email without sending a customer into a 200-icon dashboard on day one. SpamAssassin can be flagged at provision time. You get a managed site; we keep the panel.

Vendor site

Nginx

Tool we use

Reverse proxy in front of TNT, portals, and MCP

Nginx terminates TLS and routes the main TNT app, the inbox portal, and the MCP endpoint. It is the boring, well-understood front door: rate limits, routing, and logs in one place instead of exposing Gunicorn or sidecars directly. Hosting customers sit behind the same discipline we use on our own stack.

Vendor site

Caddy

Tool we use

Local LLM bridge between TNT and Ollama

Caddy runs TNT’s LLM bridge: a /healthz plus OpenAI-compatible /v1 that proxies to Ollama. That keeps the application talking one API shape whether the model is local or in the cloud, and it keeps Ollama off the public network. Small, explicit, and replaceable—the way a bridge should be.

Vendor site

Let's Encrypt

Tool we use

Automated HTTPS for the sites we host

Let’s Encrypt is how managed hosting sites get trusted HTTPS without a yearly certificate circus. Certificates are issued and renewed as part of provisioning, not as a fire drill when a browser starts warning visitors. Encryption in transit is the default, not an upgrade.

Vendor site

Cloudflare

Tool we use

Edge CDN and protection in front of customer-facing pages

Cloudflare sits in front of selected customer-facing surfaces for CDN, TLS, and abuse absorption. TNT’s own portals also pull Font Awesome via Cloudflare’s CDN where a self-host is not warranted. The point is a quieter origin and a faster first paint—not a marketing badge.

Vendor site
07

Business systems

Billing, messaging, and Google Workspace integrations that keep invoices, alerts, and calendars in one operational picture.

Stripe

Tool we use

Checkout, invoices, and the customer payment portal

TNT bills through Stripe: Checkout sessions, webhook-driven invoice status, a finance ledger, and the customer portal so clients can pay without mailing a check. Card data never touches our database. Failed payments surface as operational facts, not as a surprise at the end of the month.

Vendor site

Twilio

Tool we use

SMS two-factor and inbound ticket texts

Twilio carries TNT’s SMS two-factor codes, inbound ticket texts, and “send as Jeremiah” replies so a client can text a problem and it lands in the same ticket queue as email. Signatures are validated; we do not accept spoofed webhooks. Phone is a first-class channel, not a sticky note on the desk.

Vendor site

Google Workspace

Tool we use

OAuth, Calendar, Gmail ingest, and login bot protection

TNT signs in with Google OAuth, syncs calendars, ingests Gmail into the inbox portal, and uses reCAPTCHA on public forms. Staff are not copying meeting notes out of a personal inbox. Tokens live in server config, not in a browser extension, and scopes are the ones the job actually needs.

Vendor site
08

Platform engineering

What TNT itself is built on—mature, boring infrastructure on purpose.

Flask

Platform

The web framework TNT and our custom apps are built on

TNT is a Flask application: routes, sessions, Socket.IO, and the portal surfaces that clients actually use. The same stack is what we reach for when a Magic Valley business needs a custom app that a page builder cannot honestly do. Small framework, explicit code, no mystery runtime.

Vendor site

Python

Platform

The language the toolkit, workers, and scanners speak

Python is the implementation language for TNT, the AI worker, voice sidecar, Kali job server, and backup jobs. One language across the shop means a scan recipe, a webhook, and a restore script can share libraries and logging instead of becoming three unrelated snowflakes.

Vendor site

SQLAlchemy

Platform

ORM and Alembic migrations for a schema we can actually evolve

SQLAlchemy and Alembic (Flask-Migrate) own TNT’s data model. Tickets, devices, invoices, and vault entries are tables with migrations—not a JSON blob we hope we remember. When the schema changes, it is a reviewed migration, not a hand-edit on a live SQLite file.

Vendor site

PostgreSQL

Platform

Production-ready database engine TNT is built to run on

TNT speaks PostgreSQL through psycopg when TNT_DB_URI is set. The application is developed to move off SQLite without a rewrite so multi-user load, backups, and row-level discipline match the rest of a serious MSP stack. We pick the engine that matches the load—not the one that was easiest on day one.

Vendor site

Redis

Platform

Job queue for background AI work

Redis is TNT’s AI worker queue. Long jobs—research, writing passes, image work—leave the request thread and run in tnt-ai-worker so a slow model cannot stall the UI. Optional rate-limit storage lives here too. If the worker is down, the app still serves tickets; it just stops taking on extra AI load.

Vendor site

Ubuntu Linux

Platform

The OS every TNT service is deployed on

TNT runs on Ubuntu with systemd units for the app, workers, voice, MCP, Kali jobs, and backups. Scanners get sudoers entries; secrets live outside the repo. We deploy the way we tell clients to deploy: one OS, named services, logs you can actually read.

Vendor site

Playwright

Platform

Headless Chromium for marketing screenshots and site checks

TNT uses Playwright (Chromium) to capture showcase screenshots of sites we build and host. Browsers live in a dedicated directory, not on a staff laptop. That is how a case study image stays current without a manual pass through 12 viewports.

Vendor site
09

Field diagnostics

Technician toolkit we carry on every repair and onboarding visit.

Sysinternals

Tool we use

Autoruns and process tools for Windows forensics on the bench

Microsoft Sysinternals—especially autorunsc—is in the TNT technician catalog for persistence hunts. We export CSV or XML of everything that starts with Windows, then decide what belongs. When a “slow PC” is actually a leftover updater, this is how we prove it.

Vendor site
10

Built in-house

Software we wrote, host, and stand behind.

TNT — TechHand Network Toolkit

Built in-house

The operations platform we built for managed IT, hosting, and repair

TNT is our own platform: tickets, documentation, network scans, backups, billing, voice notes, and the client portal on one set of records. Hourly SQLite snapshots and scheduled full backups run as systemd jobs. When you call, the person who answers is looking at the same system that scanned your network last week—not a spreadsheet and a hope.

Learn more

Trademark notice

Logos and names are trademarks of their respective owners and appear here under nominative fair use to identify the products we partner with or operate. “Partner” is reserved for Bitdefender, IRONSCALES, and Hawk Host. Everything else is a tool we deploy or run. Use of a mark does not imply sponsorship beyond the relationship described on this page.

Want this stack on your network?

LET'S GET IT
HANDLED.