Google Cloud

Your Google Cloud foundation, built in 15 to 30 days.

We set up your Google Cloud landing zone: an organization with single sign-on, organization policies, central audit logging, and encryption. We build it from our private template library and hand it over as Terraform. This page is for teams that have already chosen Google Cloud.

Price
From $8,500
Fixed in writing before we start.
Time
15 to 30 days
For the standard foundation, counted from the day we agree the design and get access.

Already decided on Google Cloud? Then start here. We do not spend your first week choosing a cloud. Already running workloads? We fix existing accounts too.

What the price covers

Standard foundation

$8,500, fixed

The projects shown below, in one region, with the full baseline, in 15 to 30 days. This is the scope we can price before we even talk.

Extended foundation

From $12,500

When you need more than the standard scope, we price it after the call. Common reasons are more projects or regions, a VPN or private link to an office, data center, or another cloud, and controls mapped to a framework like SOC 2 or ISO 27001. Each one adds to the scope, so we quote the total and the timeline in writing before any work starts.

Running dozens of projects, several regions, or a complex hybrid network? We scope that as its own project. We build everything in your own Google Cloud environment. Google Cloud bills you directly for usage, including security services like threat detection and logging, and that is separate from our fee.

The structure you get

We set up 4 projects under one Organization and folders, and each one has a single job. When you need more, you add them from the same code.

Organization and folders

  • Logging

    Collects audit logs from every project and keeps them locked.

  • Network host

    Holds the Shared VPC that every workload project uses.

  • Production

    Runs your live workloads.

  • Development

    Gives your team a place to build and test.

What gets built

Each part starts in plain words and then lists exactly what we configure. Whoever approves the budget and whoever checks the work can read the same page.

One login for everyone, with MFA

Your team signs in through Google Workspace or the identity provider you already use. Remove someone there and their cloud access goes with it.

  • Single sign-on. We use Cloud Identity or Google Workspace, federated with Okta or Microsoft Entra ID if you run them.
  • MFA everywhere. We enforce 2-step verification.
  • Clear roles. We map your groups to IAM roles and give no one the basic Owner or Editor role.
  • Keyless pipelines. We disable service account key creation, and your CI/CD uses Workload Identity Federation.

Separate projects for separate jobs

We put production, development, logging, and networking in their own projects, under folders that carry the rules.

  • Folder layout. Common services, production, and non-production each get a folder.
  • Dedicated projects. Logging and the Shared VPC host get projects of their own.
  • Projects from code. New projects arrive with the full baseline already applied.

Guardrails nobody can switch off

We set organization policies above where day-to-day administrators work, so every project follows them.

  • No outside sharing. Domain-restricted sharing stops anyone granting access to accounts outside your company.
  • Region limits. Resources can only run in the regions you use.
  • Safe defaults. Buckets use uniform bucket-level access, and projects start without default networks.
  • Controlled VM access. Virtual machines require OS Login.

An audit trail nobody can edit

We collect every administrative action across your organization in one place that workload teams cannot alter.

  • One log sink. An aggregated organization sink sends logs to a dedicated logging project.
  • Your retention rules. A retention policy and bucket lock keep logs as long as your audit requires.
  • Sensitive data access. We turn on Data Access audit logs for the services that hold sensitive data.

Threats and misconfigurations flagged early

Exposed resources and risky settings reach your team while they are still easy to fix.

  • Organization-wide scanning. Security Command Center runs at the organization level.
  • Alerts that reach people. Findings go to email or chat for the people who act on them.

A network built to your plan

Everything is private by default. We manage the network centrally and share it with the projects that need it.

  • Your IP plan. We build a Shared VPC with subnets to the ranges you agree.
  • Controlled traffic. Hierarchical firewall policies and Cloud NAT handle outbound traffic.
  • Private access. Private Google Access and VPC flow logs are on.
  • Wider connections. We scope and quote Cloud VPN and Interconnect separately, as part of an extended foundation.

Data encrypted, with keys you control

Google encrypts everything by default. Where your review asks for it, you hold the keys.

  • Your keys. Cloud KMS customer-managed keys rotate on schedule where you need them.
  • Controlled key use. We log key access and limit it to named groups.

No surprise bills

You see spending by team and environment, and you get a warning before you hit a budget.

  • Budget alerts. Billing budgets warn you per project.
  • Cost by team. Labels show who spends what.

What you get

  • Your code. Terraform lives in your repository, and a pipeline runs a plan on every pull request.
  • Your state. Remote state sits encrypted and locked in your own account.
  • A clear README. Your next engineer can pick it up without calling us.
  • An auditor-ready list. One page lists every control we turned on.
  • A walkthrough. We take your team through it on a call.

What you bring

  • Your environments. Tell us which accounts you need.
  • Your network. Share your IP ranges and anything the network has to reach.
  • Your people. Name your identity provider and who gets which access.
  • An administrator. Someone who can grant us access on day one.

We start once these are settled, so your 15 to 30 days go into building.

What we leave out

  • Deploying or changing your application
  • Migrating an existing estate
  • Overnight or on-call support
  • Policies, training, and vendor reviews
  • The audit itself, or a certificate

How it runs

  1. 1

    Free call

    We spend thirty minutes on what you run, what is coming, and what you need.

  2. 2

    Fixed quote

    You get a price and a short agreement in writing before any work starts.

  3. 3

    Design decisions

    We agree the account structure, IP plan, identity provider, and access groups with you. The clock starts here.

  4. 4

    Build and check

    We build from our private library, apply through the pipeline, and check every agreed control.

  5. 5

    Handover

    You get the code, the README, and the control list, and we walk your team through it.

For the standard foundation, we count the 15 to 30 days from the day we agree the accounts, network, and access. For an extended scope, we confirm the timeline with your quote. If you have those ready on day one, expect something closer to 15. If your team is still settling the network or the login, the clock waits until you do.

Security that pays off every day

A secure foundation means fewer ways in, a smaller blast radius when something goes wrong, and problems caught while they are still small. When an auditor or a customer's security team asks, the Google Cloud settings are easy to show. If you need a certificate, your auditor issues it. We do not certify you.

Customer security reviews
SOC 2, ISO 27001
Healthcare
HIPAA
Payments
PCI DSS
Security standards
NIST CSF, CIS Benchmarks

We work with US-based companies. If your company is outside the US, we can still help through an engagement agreement written for you, and we follow the laws and frameworks that apply to you, such as GDPR.

Book a free call

Tell us what you run and what is coming. We reply within one business day to set up a call, then send you a fixed price and a short agreement.

Once the foundation is live, our managed cloud operations can keep running changes as code from $4,500 a month, with your team approving each one.

Other clouds: AWS, Azure.

Request

Cloud foundation