Your AWS foundation, built in 15 to 30 days.

We set up your AWS landing zone: a multi-account AWS Organization with single sign-on, guardrails, central audit logging, and encryption. We build it from our private library of 1,300+ templates and hand it over as Terraform your team owns. From $8,500, fixed in writing before we start.

Already running on AWS? We fix existing accounts too.

When teams call us

You are starting properly

You are moving to the cloud or launching a new product, and you want the structure right from day one.

You have outgrown one account

Everything runs in one account, people share administrator access, and one leaked key could reach all of it.

Customers are asking about security

An enterprise customer sent a security questionnaire, or a SOC 2, ISO 27001, or HIPAA audit is coming.

You have no platform engineer yet

Hiring one takes months. Your foundation does not have to wait for that hire.

What gets built

We build eight parts from the library and check each one before we hand it over.

One login for everyone, with MFA

Your team signs in through the identity provider you already use. When someone leaves, you remove them in one place and their AWS access goes with it.

Separate accounts for separate jobs

We put production, development, logs, and security in their own accounts. A mistake or a breach in one stays there.

Guardrails nobody can switch off

We set rules at the top of the organization. Even an administrator inside a workload account cannot override them.

An audit trail nobody can edit

We record every change in every account and store it in a separate account. The people making changes cannot touch it.

Threats and misconfigurations flagged early

When something looks wrong, like an exposed bucket or an unusual login, your team hears about it right away, before it turns into an incident.

A network built to your plan

Everything is private by default. You decide what the internet can reach.

Data encrypted, with keys you control

We encrypt your stored data and backups, and we write down which keys protect what so a reviewer can check it.

No surprise bills

You see spending by team and environment, and you get a warning before you hit a budget.

See exactly what we configure on AWS

How it works

  1. 1

    Free call

    We spend thirty minutes on what you run, what is coming, and what you need.

  2. 2

    Fixed quote

    You get a price and a short agreement in writing before any work starts.

  3. 3

    Design decisions

    We agree the account structure, IP plan, identity provider, and access groups with you. The clock starts here.

  4. 4

    Build and check

    We build from our private library, apply through the pipeline, and check every agreed control.

  5. 5

    Handover

    You get the code, the README, and the control list, and we walk your team through it.

For the standard foundation, we start the 15 to 30 days once we agree the accounts, network, and access with you. If your team is still settling the network or the login, the clock waits until you do.

Built from a library, not from scratch

We never start your foundation from a blank file. That is how we can fix the price and hold the dates.

What we build with

Our private engineering library

1,300+ templates

Every engagement draws on our private library for AWS, Azure, and Google Cloud. It is separate from the public one and is not published.

What you can see today

A public sample library

1,000+ free templates

Browse it to see how we write Terraform, and use any template you like. It is a sample of our work, not the full set we bring to your build.

Who does the work

A senior cloud engineer leads every engagement, and the person you talk to on the first call is the person who builds it. We take on a small number of engagements at a time so we can hold our dates. We share our background on the call.

Questions

What exactly do I get for $8,500?

The standard foundation: five AWS accounts in one region (management, log archive, security, production, and development) with single sign-on and MFA, guardrails, an audit trail nobody can edit, threat detection, a private network, encryption, and budget alerts. You get it as Terraform in your repository, with a pipeline, a README, a one-page list of every control we turned on, and a walkthrough with your team. Azure and Google Cloud follow the same pattern.

What makes the price go above $8,500?

Anything beyond the standard scope, such as more accounts or regions, a VPN or private link to an office, data center, or another cloud, or controls mapped to a framework like SOC 2 or ISO 27001. We call that an extended foundation. It starts at $12,500, and we quote the total and the timeline in writing before any work starts. Very large estates are scoped as their own project.

Whose account does this run in, and who pays the cloud bill?

Yours. We build everything in your own AWS, Azure, or Google Cloud environment, and you keep full control. Your cloud provider bills you directly for usage, including security services like threat detection and logging, and that is separate from our fee.

Do you certify us for SOC 2 or ISO 27001?

No. We build the cloud settings your auditor looks at and show them clearly. Your auditor issues the certificate, and your policies and training stay with you.

We already use a compliance tool like Vanta or Drata. Why do we need this?

Your compliance tool tells you what is failing. We fix the cloud so it passes, and we leave every fix as code so it stays fixed.

More questions about scope, access, and how we work

Tell us what you run and what is coming.

Thirty minutes, no charge. Afterwards we send you a fixed price in writing, or we tell you plainly why we are not the right fit.

Book a free call