AWS

Your AWS foundation, built in 15 to 30 days.

We set up your AWS landing zone: a multi-account AWS Organization with single sign-on, guardrails, central audit logging, and encryption. We build it from our private template library and hand it over as Terraform that your team owns and can change.

Price
From $8,500
Fixed in writing before we start.
Time
15 to 30 days
For the standard foundation, counted from the day we agree the design and get access.

On Azure or Google Cloud? We build the same foundation there too. Already running workloads? We fix existing accounts too.

What the price covers

Standard foundation

$8,500, fixed

The accounts shown below, in one region, with the full baseline, in 15 to 30 days. This is the scope we can price before we even talk.

Extended foundation

From $12,500

When you need more than the standard scope, we price it after the call. Common reasons are more accounts or regions, a VPN or private link to an office, data center, or another cloud, and controls mapped to a framework like SOC 2 or ISO 27001. Each one adds to the scope, so we quote the total and the timeline in writing before any work starts.

Running dozens of accounts, several regions, or a complex hybrid network? We scope that as its own project. We build everything in your own AWS environment. AWS bills you directly for usage, including security services like threat detection and logging, and that is separate from our fee.

The structure you get

We set up 5 accounts under one AWS Organization, and each one has a single job. When you need more, you add them from the same code.

AWS Organization

  • Management

    Runs billing and the organization itself. Nothing else lives here.

  • Log archive

    Collects audit logs from every account and keeps them locked.

  • Security

    Runs threat detection and collects findings for the whole organization.

  • Production

    Runs your live workloads.

  • Development

    Gives your team a place to build and test.

What gets built

Each part starts in plain words and then lists exactly what we configure. Whoever approves the budget and whoever checks the work can read the same page.

One login for everyone, with MFA

Your team signs in through the identity provider you already use. When someone leaves, you remove them in one place and their AWS access goes with it.

  • Single sign-on. We connect IAM Identity Center to Okta, Microsoft Entra ID, or Google Workspace.
  • No stray credentials. We enforce MFA and create no IAM users or long-lived access keys.
  • Clear roles. We map your groups to permission sets for admin, developer, read-only, and billing.
  • Root protection. We lock down the root user and document a break-glass procedure for emergencies.
  • Keyless pipelines. Your CI/CD signs in through OIDC roles, so no keys sit in your build system.

Separate accounts for separate jobs

We put production, development, logs, and security in their own accounts. A mistake or a breach in one stays there.

  • Organization layout. We set up AWS Organizations with organizational units for security, infrastructure, and workloads.
  • Dedicated accounts. Logs and security tooling get accounts of their own.
  • Room to grow. You start with production and development and can add more later.
  • Accounts from code. New accounts arrive with the full baseline already applied.

Guardrails nobody can switch off

We set rules at the top of the organization. Even an administrator inside a workload account cannot override them.

  • Protected logging. Service control policies stop anyone from disabling CloudTrail, GuardDuty, or Config.
  • Locked membership. Accounts cannot leave the organization, and the root user cannot act.
  • Region limits. Resources can only run in the regions you actually use.
  • Safe defaults. S3 Block Public Access and default EBS encryption are on in every account.

An audit trail nobody can edit

We record every change in every account and store it in a separate account. The people making changes cannot touch it.

  • Organization trail. CloudTrail covers every account and validates its log files.
  • Encrypted storage. Logs land in the log archive account, encrypted with KMS.
  • Your retention rules. We keep logs as long as your auditor asks, with S3 Object Lock where you need it.
  • Resource history. AWS Config records how your resources change across accounts.

Threats and misconfigurations flagged early

When something looks wrong, like an exposed bucket or an unusual login, your team hears about it right away, before it turns into an incident.

  • Threat detection. GuardDuty watches every account, managed from the security account.
  • Posture checks. Security Hub runs the AWS Foundational Security Best Practices and CIS benchmarks.
  • Outside sharing. IAM Access Analyzer flags anything shared outside your organization.
  • Alerts that reach people. High-severity findings go to email or Slack.

A network built to your plan

Everything is private by default. You decide what the internet can reach.

  • Your IP plan. We lay out a VPC per environment to the ranges you agree.
  • Layered subnets. Public and private subnets span availability zones, with NAT for outbound traffic.
  • Clean accounts. We remove default VPCs and turn on VPC flow logs.
  • Wider connections. We scope and quote links to an office, a data center, or another cloud separately, as part of an extended foundation.

Data encrypted, with keys you control

We encrypt your stored data and backups, and we write down which keys protect what so a reviewer can check it.

  • Your keys. KMS customer-managed keys come with scoped key policies and rotation.
  • Encryption by default. S3, EBS, and log storage are encrypted from the start.
  • Encrypted connections only. Bucket policies refuse any request that is not encrypted.

No surprise bills

You see spending by team and environment, and you get a warning before you hit a budget.

  • Budget alerts. AWS Budgets warns you per account.
  • Cost by team. A tag policy and cost allocation tags show who spends what.
  • One bill. Consolidated billing runs from the management account.

What you get

  • Your code. Terraform lives in your repository, and a pipeline runs a plan on every pull request.
  • Your state. Remote state sits encrypted and locked in your own account.
  • A clear README. Your next engineer can pick it up without calling us.
  • An auditor-ready list. One page lists every control we turned on.
  • A walkthrough. We take your team through it on a call.

What you bring

  • Your environments. Tell us which accounts you need.
  • Your network. Share your IP ranges and anything the network has to reach.
  • Your people. Name your identity provider and who gets which access.
  • An administrator. Someone who can grant us access on day one.

We start once these are settled, so your 15 to 30 days go into building.

What we leave out

  • Deploying or changing your application
  • Migrating an existing estate
  • Overnight or on-call support
  • Policies, training, and vendor reviews
  • The audit itself, or a certificate

How it runs

  1. 1

    Free call

    We spend thirty minutes on what you run, what is coming, and what you need.

  2. 2

    Fixed quote

    You get a price and a short agreement in writing before any work starts.

  3. 3

    Design decisions

    We agree the account structure, IP plan, identity provider, and access groups with you. The clock starts here.

  4. 4

    Build and check

    We build from our private library, apply through the pipeline, and check every agreed control.

  5. 5

    Handover

    You get the code, the README, and the control list, and we walk your team through it.

For the standard foundation, we count the 15 to 30 days from the day we agree the accounts, network, and access. For an extended scope, we confirm the timeline with your quote. If you have those ready on day one, expect something closer to 15. If your team is still settling the network or the login, the clock waits until you do.

Security that pays off every day

A secure foundation means fewer ways in, a smaller blast radius when something goes wrong, and problems caught while they are still small. When an auditor or a customer's security team asks, the AWS settings are easy to show. If you need a certificate, your auditor issues it. We do not certify you.

Customer security reviews
SOC 2, ISO 27001
Healthcare
HIPAA
Payments
PCI DSS
Security standards
NIST CSF, CIS Benchmarks

We work with US-based companies. If your company is outside the US, we can still help through an engagement agreement written for you, and we follow the laws and frameworks that apply to you, such as GDPR.

Book a free call

Tell us what you run and what is coming. We reply within one business day to set up a call, then send you a fixed price and a short agreement.

Once the foundation is live, our managed cloud operations can keep running changes as code from $4,500 a month, with your team approving each one.

Other clouds: Azure, Google Cloud.

Request

Cloud foundation