Anthilla

Fog/edge infrastructure first

Why fog/edge before the cloud

The promise of the cloud was to simplify. Twenty years later, it has produced: vendor lock-in, opaque costs, unpredictable latencies, regulatory drift (Schrems II, NIS2, AI Act), dependence on foreign hyperscalers for sensitive Italian data.

Fog/edge is the architectural answer: the infrastructure lives close to the customer, not in someone else’s datacenter behind another nation’s firewall. Latency under 5ms. Total sovereignty. Post-incident recovery without depending on a service provider.

Anthilla infrastructure stack — real numbers

Component Current status Notes
Uptime 122+ days Since January 9, 2026, active snapshots
Go daemons (anth-*) 11 active Reactor, realtime, threatd, guardian, hashdb, whitelist, diskwatch, logkeeper, logarchive, watcher, blacksync
systemd timers 16 active backup, sync, hardening, monitoring, log rotation, integrity check
Threat IP block ~29,500 permanent kernel-level DROP, multi-layer anti-attack
fail2ban jail 13 active SSH, web scanning, login hardening, etc
Storage pool 2 (dual) production pool + replica pool, 0 errors, compression active, frequent/hourly/daily/weekly snapshots
Whitelist 211 entries CIDR+prefix, auto-sync FLUX user mobile

5-layer threat management

  1. Detection: real-time log monitoring, filesystem watchdog, pattern matching
  2. Blocking: kernel DROP, silent close or 403, global blacklist
  3. Synchronization: firewall rule export (1min), 3-way sync verification (1min), blacklist sync (inotify zero-polling)
  4. Intelligence: anth-historical-analyzer (5min log .gz retro), threat-update (hourly), threat-intelligence (daily)
  5. Behavioral: batch behavioral analysis, real-time scoring

Dual-pool storage — snapshot policy

Production pool and replica pool managed by an internal tool (replaces standard open source tool)::

  • frequent_* – every 15 minutes
  • hourly_* – every hour
  • daily_* – every 02:30
  • weekly_* – every Sunday 03:00
  • repl_* – rsync prod → replica every 30 minutes

Automatic cleanup: an internal cleanup tool removes expired snapshots according to retention policy. Result: 148 active snapshots, 17G used out of 127G production pool.

Heritage 2001→2026

The company was not born yesterday. The first domain dates back to 2002 and Ivan Dorna’s experience starts from 2001. In over 20 years we have seen:

  • The dot-com bust (2001-2003)
  • The arrival of the cloud (2006-2010)
  • The commodity SaaS era (2010-2018)
  • Generative AI pretraining (2020-2023)
  • Multi-level prompting + agentic AI (2024-2026)

Patient construction. No bandwagon. No startup pivot. No exit playbook. Just infrastructure that works, year after year.

Working with Anthilla means accessing a living stack. Not slides, not PoC: 24/7 production. For partnerships or consulting: contacts@anthilla.com