Standard foundation
$8,500, fixed
The subscriptions shown below, in one region, with the full baseline, in 15 to 30 days. This is the scope we can price before we even talk.
Azure
We set up your Azure landing zone with Entra ID sign-in, policy guardrails, central logging, and encryption. We build it from our private template library and hand it over as Terraform. This page is for teams that have already chosen Azure.
Already decided on Azure? Then start here. We do not spend your first week choosing a cloud. Already running workloads? We fix existing accounts too.
Standard foundation
$8,500, fixed
The subscriptions shown below, in one region, with the full baseline, in 15 to 30 days. This is the scope we can price before we even talk.
Extended foundation
From $12,500
When you need more than the standard scope, we price it after the call. Common reasons are more subscriptions or regions, a VPN or private link to an office, data center, or another cloud, and controls mapped to a framework like SOC 2 or ISO 27001. Each one adds to the scope, so we quote the total and the timeline in writing before any work starts.
Running dozens of subscriptions, several regions, or a complex hybrid network? We scope that as its own project. We build everything in your own Azure environment. Azure bills you directly for usage, including security services like threat detection and logging, and that is separate from our fee.
We set up 4 subscriptions under one Management group hierarchy, and each one has a single job. When you need more, you add them from the same code.
Management group hierarchy
Management
Runs central logging and monitoring.
Connectivity
Holds the hub network that every workload connects through.
Production
Runs your live workloads.
Development
Gives your team a place to build and test.
Each part starts in plain words and then lists exactly what we configure. Whoever approves the budget and whoever checks the work can read the same page.
Your team signs in with their Microsoft Entra ID account. When someone leaves, you disable them once and their Azure access goes with it.
We put production, development, and the shared platform in their own subscriptions. A mistake in one stays there.
We assign rules at the management group, so every subscription underneath follows them.
We send every change and every sign-in to a central workspace that the people making changes do not control.
Risky settings and suspicious activity reach your team while they are still easy to fix.
Everything is private by default. Your workloads connect through one hub that you control.
We encrypt your stored data and keep secrets and keys in one audited place.
You see spending by team and environment, and you get a warning before you hit a budget.
We start once these are settled, so your 15 to 30 days go into building.
We spend thirty minutes on what you run, what is coming, and what you need.
You get a price and a short agreement in writing before any work starts.
We agree the account structure, IP plan, identity provider, and access groups with you. The clock starts here.
We build from our private library, apply through the pipeline, and check every agreed control.
You get the code, the README, and the control list, and we walk your team through it.
A secure foundation means fewer ways in, a smaller blast radius when something goes wrong, and problems caught while they are still small. When an auditor or a customer's security team asks, the Azure settings are easy to show. If you need a certificate, your auditor issues it. We do not certify you.
We work with US-based companies. If your company is outside the US, we can still help through an engagement agreement written for you, and we follow the laws and frameworks that apply to you, such as GDPR.
Tell us what you run and what is coming. We reply within one business day to set up a call, then send you a fixed price and a short agreement.
Once the foundation is live, our managed cloud operations can keep running changes as code from $4,500 a month, with your team approving each one.
Other clouds: AWS, Google Cloud.