VMware Cloud Foundation 9 • Certified

Virtual Control

vSphere & VCF 9 Specialists | Infrastructure & Applications

We design, deploy, and operate VMware private cloud — and build the software that runs alongside it.

Scroll

What We Do

Three practices, one team, twenty-five years of production VMware behind all of them.

01

vSphere

Design, operations, upgrades, and the troubleshooting nobody else wants to take.

Twenty-five years of hands-on production vSphere — compute, storage, networking, high availability, cluster design, and certificate management across every release from 3.0 forward.

Our vSphere services →
02

VCF 9

Full-stack VMware Cloud Foundation 9.0.1 — bare metal to monitoring.

VCF 9 certified. SDDC Manager, vCenter Server 9.0.1, ESXi 9.0.1, NSX, vSAN, VCF Operations and Operations for Logs — deployed, integrated, patched, and documented.

Our VCF 9 services →
03

Applications

We ship software, not just slide decks.

Two products of our own: VCF Health Check, which audits an entire VMware Cloud Foundation environment in about five minutes and grades it A to F, and Virtual Forensics Suite, a code-signed offline recovery and drive-health tool. We build the same class of tooling for clients.

See both products →

Services

Scoped engagements with named deliverables. You know what you are buying before it starts.

Rates

$299/hr
Standard rate

Remediation, project work, and anything outside a fixed scope. Billed in quarter-hour increments against a written estimate you approve first.

$395/hr
Emergency & out of hours

Production down, or work that has to happen outside a maintenance window. Four-hour minimum.

Fixed
Where scope allows

Once an assessment has shown what is actually there, most projects can be quoted as a fixed fee instead. We would rather do that than run a meter.

Also available

These vary too much by environment to carry an honest list price — a three-host deployment and a four-domain one are not the same job. They are quoted from scope, or billed at the standard rate.

VCF 9 Deployment

Project
Quotedfrom scope

End-to-end build of a VMware Cloud Foundation 9 environment, including disconnected sites.

  • SDDC Manager → ESXi → vCenter → NSX → VCF Operations
  • Workload domain design and cluster layout
  • Offline depot and HTTPS repository for air-gapped environments
  • Certificate management, DNS/NTP integration, and as-built documentation

Operations & Monitoring Build-Out

Project
Quotedfrom scope

Monitoring that tells you something, configured by someone who has had to use it at 3am.

  • VCF Operations deployment, dashboard design, and KPI selection
  • Alert definitions and notification workflows that route to the right people
  • VCF Operations for Logs with syslog forwarding and content packs
  • Adapter integration across the VCF stack

Lifecycle & Patch Management

Retainer
Quotedmonthly, from estate size

Keeping the fleet current without a weekend outage every quarter.

  • SDDC Manager fleet lifecycle and bundle management
  • Offline depot maintenance for disconnected environments
  • Credential rotation and workload domain validation
  • Pre-flight checks and a documented rollback position before every change

Automation

Project
Quotedfrom scope

Repeatable infrastructure tasks, turned into tooling your team can run without us.

  • vCenter REST API and Guest Operations API integration
  • Python tooling for vSphere operations
  • OVA/OVF deployment automation with ovftool
  • Handover with source, documentation, and a runbook

Documentation & Runbooks

Add-on
Quotedor bundled with a project

The part everyone skips, written to the standard of the library published on this site.

  • Operational handbooks and health-check procedures
  • Incident runbooks with dependency-ordered recovery steps
  • As-built documentation after a deployment
  • Delivered as HTML and PDF, yours to keep and edit

Assessment

A fixed-scope look at what you have, ending in a written report and a plan.

Project

A defined build with a start, an end, a deliverable, and a handover.

Retainer

Ongoing lifecycle, monitoring, and escalation support for your VMware estate.

Platform Coverage

The stack we work in, end to end.

Core Platform

  • VMware Cloud Foundation (VCF) 9.0.1
  • SDDC Manager
  • vCenter Server 9.0.1
  • ESXi 9.0.1
  • NSX 4.x / NSX+

Operations & Monitoring

  • VCF Operations (formerly vRealize / Aria Operations)
  • VCF Operations for Logs
  • Dashboard design & KPI monitoring
  • Alert configuration & notification workflows

Deployment & Automation

  • OVA/OVF deployment (ovftool, vSphere Client)
  • vCenter REST API & Guest Operations API
  • Python automation for vSphere
  • Offline depot & HTTPS repository configuration
  • Lifecycle management via SDDC Manager Fleet

Infrastructure

  • Compute, storage, networking (vSAN, vDS, NSX overlay/VLAN)
  • High availability & cluster design
  • Certificate management
  • Syslog forwarding & log integration

Applications

Two products we build, ship, and support ourselves.

VCF Health Check

Automated health monitoring & compliance for VMware Cloud Foundation.

Windows · Windows Server · macOS · Linux

One click and five minutes — or fully automated, with the report delivered to your inbox. VCF Health Check connects to your entire VCF environment, runs over 100 individual checks across every major component, and gives you a single grade — A through F — with a detailed report and specific remediation steps for every issue found. No manual SSH sessions. No hopping between six management consoles.

VCF Health Check report showing a B+ grade at 88 percent, with a component breakdown across Infrastructure, vCenter, SDDC Manager, NSX, VCF Operations, Fleet and Automation
The report it hands you One grade, the score behind it, and every component broken out with its own pass/warn/fail counts and trend. Self-contained HTML — open it in any browser, hand it to a client.
100+Health checks
5 minFull audit
10Report formats
A–FSingle grade
Run it yourself
One click. Five minutes.

Open the app, press Run Full Health Check, and watch live colour-coded results with an elapsed timer. When it finishes, open the HTML, JSON, text, CSV or Markdown report straight from the application.

Or never touch it again
Fully automated, straight to your inbox.

Schedule it in the GUI or at the OS level — Windows Task Scheduler, cron, or a systemd timer — and the report arrives by email with the grade and score in the subject line. Set a grade threshold so you are only notified when it actually drops.

What gets checked

  • vCenter Server — 36 checks. API and identity, VCF BOM compliance, system health, inventory, HA/DRS per cluster, datastore and vSAN capacity, orphaned VM objects, unclaimed vSAN-eligible disks, cluster CPU and memory thresholds, NTP, root password expiry, licensing, individual service status, alarms, snapshot aging, and VCSA disk partitions.
  • SDDC Manager — 16 checks. API reachability with retry, version and component health, certificate inventory with 60-day warning, backup age verification, system prechecks, stale task detection, resource locks, host drift, and depot connectivity.
  • Infrastructure and network — 14 checks. Forward and reverse DNS for every management component, SSL certificate expiry, TCP latency measurement, ESXi HTTPS reachability, SSH port verification, and coredump configuration.
  • NSX Manager — 11 checks. VIP-first API reachability with node fallback, control and management cluster stability, transport node state, alarm counts, edge cluster health, and distributed firewall rule sprawl.
  • VCF Operations and Aria Suite — 4 checks. Plus Fleet / vRSLCM — 2 checks.
  • Custom plugin checks. Drop a shell script in the plugin directory; it is auto-discovered, run, parsed, and folded into the grade. No code changes.

What you get back

  • An interactive HTML report — one self-contained file, no external dependencies. Donut chart, score trend sparkline, 90-day heatmap calendar, SVG dependency map, and SLA uptime tracker.
  • Executive and Technical views — a summary for leadership, full detail for engineers, toggled with one key.
  • A remediation playbook with checkboxes, estimated time-to-fix per item, grouped by component, exportable as a text file you can hand to an engineer.
  • Diff view comparing any two historical runs — exactly what changed, improved, and regressed.
  • Ten report formats — HTML, JSON (with a generated JSON Schema), plain text, PDF, CSV, Markdown, Prometheus/OpenMetrics, Ansible inventory, multi-environment dashboard, and config backup.
  • Seven notification channels — email, Slack, Microsoft Teams, PagerDuty, OpsGenie, syslog, and custom webhook, with threshold-based alerting so you are only paged when the grade drops.
  • Auto-remediation for safe fixes — cancels stale SDDC Manager tasks blocking the lifecycle queue and corrects known drift conditions.

Built for MSPs and service providers

Branded reports. Your logo, your company name, your contact email on every HTML, PDF and text report. Your clients see your brand, not ours.
Client tracking. Organise environments by client, track usage per client, and generate billing reports.
White label. At the Enterprise tier, rebrand the product entirely as your own.
API export. Feed JSON, Prometheus metrics and webhooks into ServiceNow, Grafana, Datadog, or whatever your operations team already runs.

Enterprise security from day one

Credentials encrypted at rest with Fernet symmetric encryption and a machine-local key.
PBKDF2-HMAC-SHA256 password hashing at 310,000 iterations with a per-password salt.
Role-based access control — admin and operator, brute-force lockout, session timeout, and password expiry.
Full audit trail with ISO timestamps, CSV-exportable for compliance. Optional LDAP / Active Directory authentication.
Windows 10 & 11, Windows Server, macOS, Linux Python 3.8+ & Bash 4.0+ No cloud, no agents, no SaaS Runs entirely on your infrastructure Desktop GUI + CLI

Pricing

Essentials
$399/mo
or $3,999/year

One VCF environment, one client. All 100+ checks, all 10 report formats, all 7 notification channels. For a team that wants to run it against production before committing to a fleet.

Starter
$1,999/mo
or $19,999/year

Up to 5 VCF environments for up to 3 clients. All 100+ checks, all 10 report formats, all 7 notification channels, encrypted credential storage, role-based access, and audit trail.

Enterprise
$5,499/mo
or $54,999/year

Up to 100 environments, unlimited clients. Everything in Professional, plus API export, full white-label rebranding, usage analytics and billing, and priority support.

Custom
from $6,500/mo
Tailored agreement

More than 100 environments or special requirements. Custom plugin development, dedicated support, and a plan built for your exact needs.

Request a licence key

White-label rebranding — running the engine under your own name and branding — is available on Enterprise and quoted to your use. Every installation includes a setup wizard that walks you through activation in under two minutes. No lengthy onboarding, no professional services engagement, no training required.

Virtual Forensics Suite

Recover what's lost. Catch what Windows hides.

v1.10.3

One Windows program that does two jobs. It recovers data from drives that have failed, been wiped, encrypted, or lost their files — and the rest of the time it watches drives so you can sell a customer a replacement before the old one takes their photos with it. Fully offline. No account, no sign-in, no activation server.

Windows Health Check system health tab listing security, storage, hardware and resilience checks
The checks Windows does not show you Security, storage, hardware, resilience and performance — each with the finding spelled out, not just a status light.
Virtual Forensics Suite home screen with the Disk Recovery and Windows Health Check tools
Two tools, one program Pick the job: recover files, or find out whether the drive is dying.
Windows Health Check drive table showing SMART verdicts, drive age and predicted failure
A verdict, not a data dump SMART verdict, drive age against design life, and a predicted-failure outlook per drive — with the reasoning underneath.
Disk Recovery browsing a live NTFS volume found on a scanned disk
Browse before you commit Scan a disk, open the volume it finds, and pick exactly what to recover — the source stays read-only throughout.

Disk Recovery & Forensics

  • Undelete and carving. Restores files with their real names and folder structure. Where even the record is gone, it reads the drive end to end for the telltale opening bytes of 14 file types — photos and images, the format modern iPhones and Android phones save, Word, Excel and PowerPoint in both modern and legacy formats, video, audio, SQLite databases, icons and programs. Six of them state their own length internally, so they come out exactly the right size instead of a guess with junk on the end.
  • “Windows says the drive needs formatting.” Works on Windows drives (NTFS) and on memory cards, phones, cameras and portable drives (exFAT, FAT32). Finds the data even when the partition table is wiped, and can rebuild that table and write it back — which often just makes the drive work again.
  • Linux drives, NAS boxes and Raspberry Pi. Reads ext2, ext3 and ext4 — the filesystems Windows cannot open at all, and offers to format if you plug one in. Covers NAS boxes, Raspberry Pis, Steam Decks and Android internal storage, and falls back to a backup copy of the filesystem header if the main one is destroyed.
  • A NAS or server with several drives — RAID. Reassembles RAID 0, 1 and 5 from the member drives and presents the result as one ordinary volume you can browse and recover from. With RAID 5, one drive can be missing entirely and its contents are rebuilt from the others. It works out the likely settings and shows you the evidence for each guess rather than silently picking one and hoping.
  • BitLocker. Enter the customer’s 48-digit recovery key and the drive opens; every other feature then works on it exactly as on a normal drive. A wrong key is refused rather than quietly used — get decryption subtly wrong and you do not get an error, you get a drive full of convincing nonsense that looks exactly like recovered data.
  • Dying drives. Rescue imaging copies the drive to a file, skipping bad patches quickly and returning to them later, so the job can be stopped and resumed and the failing drive is only ever read once. A genuine hardware fault is reported as one, with advice to stop before a clean-room recovery gets harder.
  • The drive will not show up, or the PC will not start. Triage tells you why — a genuinely dead drive, one Windows sees but cannot read, a bad cable or enclosure, or a perfectly good drive with no readable partition table — and can capture a copy the moment an intermittent drive reappears. Builds bootable rescue media on a USB stick for a machine that will not boot.
  • Network recovery. Run a small agent on a machine you cannot take apart and recover across the network. The connection is encrypted and locked to one specific certificate and access token, so it can only ever talk to the machine you meant it to.
  • Damage report. Imaging a dying drive almost never gets every sector. It records which ones it could not read and tells you which files those sectors belonged to — an answer a customer can act on, where “1,412 bad sectors” is not. Free in every edition.
  • Works from a copy. Reads raw images, E01 evidence files, and VHD and VMDK virtual disks from Hyper-V, VMware and VirtualBox, identified by content rather than filename, so a mislabelled file still opens.
  • Read-only by construction. The recovery engine contains no code capable of writing to a drive — not “it tries not to”, the ability is not there. Everything that writes lives in a separate component used only by the clone, partition and secure-erase tools.
  • Proving what you did. Every recovered file gets a hash recorded in a manifest, backed by a tamper-evident log where each entry is chained to the one before, so a deleted or edited entry shows up as a break. Evidence images open correctly in FTK Imager and the libewf tools — other people’s software, not ours.

Windows Health Check

  • SMART verdicts for hard disks, SSDs and NVMe drives — a plain answer rather than a wall of raw numbers — plus the drive’s age in years, how worn an SSD is, and a predictive outlook.
  • Early warnings that catch data loss before it happens. Reads the Windows event log and flags a drive logging read-retries, bad blocks or “file system corrupt” errors — often before SMART notices — names the affected drive, warns when there is no recent backup, and warns when a drive is nearly full.
  • 25 or more whole-PC checks across security, hardware, storage, system, recovery readiness, performance and battery. Some are per-drive, so the exact number depends on the machine.
  • History and trend, so you can show a customer their drive getting worse over months.
  • Continuous drive monitoring in the background. A system-tray monitor re-runs the drive health check on an interval you set and raises an alert the moment any drive reaches Replace Soon or Replace Now, so a drive that starts failing is not missed between manual checks. Every run is written to the health history, and it keeps working while the suite is open even if the Health window is closed.
  • Export the whole audit — drives, every check, and the disk event log — as CSV, JSON or a printable HTML report.
  • Fleet collection for customers whose PCs you look after.
  • Honest about blind spots. Many USB enclosures do not pass drive health through at all, and it reports Unknown rather than inventing a reassuring Healthy.
  • Usage summary — how many drives a machine has worked on, month by month, taken from its own logs. Counts only: no customer names, file names, drive serials or case details, by construction.

What it honestly will not do

It cannot recover overwritten data. If something was written over the old data, the old data is physically gone. Nobody recovers that, at any price.
It cannot fix a physically broken drive. Snapped heads, a dead motor, a burnt board — that needs a clean room. The program tells you when you are in that situation instead of grinding away.
It cannot undelete on Linux drives. Linux wipes a deleted file’s location map, so there is genuinely nothing left to follow. It recovers the files that are still there.
It is not certified for legal admissibility. It is read-only and chain-of-custody aware, but has not been through independent forensic validation such as NIST CFTT. The known limitations are written down and available on request.
NTFS · exFAT · FAT32 · Linux ext2, 3 and 4 RAID 0, 1 and 5 BitLocker with the recovery key Raw · E01 · VHD · VMDK Windows 10 & 11 (64-bit), Administrator rights Licence checked offline — no activation server 1,038 automated tests on every build GUI + CLI (vfcli, vwhc)

Editions

Personal
Your own and family machines

Recovering files — undelete, carving, NTFS, exFAT, FAT32, Linux (ext) and RAID.

Professional
Repair shops, IT pros, consultants

Everything in Personal, plus E01 evidence imaging with chain of custody, WinPE rescue media, and the tools that write to a drive — cloning, partition management, partition-table repair and secure erase.

Always free
In every edition

All drive and PC health checks, scanning a drive, browsing and previewing what is on it, and the damage report that says what a failing drive lost. You can quote a job without a licence; you need one to hand the files back. A 30-day trial unlocks everything.

Request a pilot

Health checks, scanning, drive analysis and file preview are always free. Recovery, evidence imaging, rescue media and fleet monitoring unlock with a licence.

Downloads & Updates

Current releases, and the channel both applications check for new ones.

Virtual Forensics Suite

1.10.3
Platform
Windows 10 & 11 (64-bit)
Released
30 August 2026
Installer
VirtualForensicsSuite-1.10.3.msi
SHA-256
A4ADBDBCD3CC1FC979C4EC97119B9D0A57D4813000B24A8821F1080E6891F902

Verify the download against this hash before installing. Health checks, scanning, drive analysis and file preview are always free; recovery and imaging require a licence.

Request a pilot

VCF Health Check

9.2
Platform
Windows 10/11, Windows Server, macOS, Linux
Released
30 August 2026
Installer
VCF-Health-Check-9.2-Setup.exe
Requires
Python 3.8+ and Bash 4.0+ (Git Bash on Windows)
SHA-256
0957204952747745032969D69B03F60476D412BE19D643ECB1F59D22C460DDA4

Installs per user, so no administrator rights are needed. Licensed per environment; the setup wizard activates in under two minutes.

Request a licence key

Release channel

Both applications check for new versions themselves. The manifests are published at http://virtualcontrolllc.com/updates/ and can be read directly if you need to mirror releases into an air-gapped environment.

  • /updates/virtual-forensics-suite/latest.json
  • /updates/vcf-health-check/latest.json

Sites that mirror internally can point either application at their own channel with an environment variable — VFS_UPDATE_URL for the Suite, VCFHC_UPDATE_URL for VCF Health Check — with no rebuild.

Proof

A production-grade VCF 9 environment we built from the ground up — where every procedure we sell gets tested first.

Management Plane
SDDC Manager 9.0.1
Lifecycle & Fleet Management
vCenter Server 9.0.1
Infrastructure Management
NSX Manager
Network Virtualization
Compute Hosts
ESXi 9.0.1 Host 1
Nested Hypervisor
ESXi 9.0.1 Host 2
Nested Hypervisor
ESXi 9.0.1 Host 3
Nested Hypervisor
Operations & Services
VCF Operations 9.0.1
Analytics Cluster
VCF Operations for Logs 9.0.1
Centralized Logging
Offline VCF Depot
HTTPS Repository
Windows AD / DNS / NTP
Directory & Infrastructure Services

Field Reports

Root cause analysis and health-check procedures from real incidents. Published, not summarised.

NSX Manager 9.0.1 Cold Start Service Failure

Complete RCA documenting NSX Manager service chain failure after cold start, manual service recovery in dependency order, and VCF Operations adapter re-integration.

View Report →

VCF Environment Health Check Report

Comprehensive environment health assessment covering cluster status, resource utilization, compliance validation, and remediation recommendations.

View Report →

NSX Health Check Handbook

Complete NSX Manager health check procedures covering cluster status, transport nodes, logical switching, routing, firewall rules, and certificate validation.

View Report →

vCenter Health Check Handbook

Comprehensive vCenter Server health validation including services, database, SSO, certificates, inventory, and performance assessment.

View Report →

ESXi Health Check Handbook

ESXi host health validation covering hardware status, storage, networking, services, patches, and configuration compliance.

View Report →

vSAN Health Check Handbook

vSAN cluster health assessment including disk groups, resync status, capacity, performance, network configuration, and data integrity checks.

View Report →

VCF Operations for Logs Health Check Handbook

VCF Operations for Logs health validation covering cluster status, ingestion rates, storage capacity, forwarders, content packs, and alerting configuration.

View Report →

Fleet / SDDC Manager Health Check Handbook

SDDC Manager and Fleet Management health checks covering lifecycle operations, bundle management, credential rotation, and workload domain validation.

View Report →

About

Virtual Control LLC is a managed service provider for vSphere and VMware Cloud Foundation 9 — and a software company.

We do two things. We build, operate and troubleshoot production private cloud on vSphere and VMware Cloud Foundation 9 — from bare metal through to monitoring. And we write the software that sits alongside it, shipped as real, code-signed Windows products rather than prototypes.

Everything we sell gets built and broken first in our own VCF 9 lab. The health-check procedures, the recovery runbooks, the root cause analyses on this site are the actual working documents, published as they were written. That is the standard you get on an engagement.

Michael Hayes, founder of Virtual Control LLC
Michael Hayes
Founder & Principal Engineer

Twenty-five years of hands-on production vSphere, VCF 9 certified, VCP 3.0–6.5. Based in St. Cloud, Florida.

VCF 9
Certified
25+
Years Production vSphere
End-to-End
Deploy • Operate • Troubleshoot

Certifications

VCF 9 Certified

Broadcom

VMware Cloud Foundation 9 deployment, operations, and lifecycle management

VCP 3.0 – 6.5

VMware

VMware Certified Professional across vSphere versions 3.0 through 6.5

Talk to Us

Tell us what is broken, what you are building, or what you need assessed.