Some of our past work.
11 anonymised engagements, described by their technical shape rather than by client name. No logos, no testimonials we have not collected, and no statistics we did not measure.

An AWS landing zone for a gaming company, built for launch spikes and a non-production estate far bigger than production.
A gaming company’s AWS estate given a proper landing zone — Control Tower and Account Factory for vending, an OU and SCP structure, a network built for centralised egress and future regions, and guardrails sized for a launch spike.

A founder-managed AWS account, turned into a platform the team could inherit.
A growing SaaS company’s hand-built AWS account, mapped, split into a multi-account structure, and moved into Terraform behind a reviewed pipeline.

A brownfield AWS estate, imported into Terraform without a rebuild.
A scale-up’s hand-built AWS estate, discovered and imported into Terraform state resource by resource, with future changes moved behind pull requests.

The engineering gaps behind a SOC 2 readiness programme, closed.
A B2B SaaS company’s AWS estate hardened ahead of a SOC 2 readiness programme — IAM, logging, encryption, backups and access reviews, with technical evidence produced for the audit.

One Azure subscription holding everything, redesigned into a proper management group hierarchy.
A single overloaded Azure subscription split into a management group hierarchy — platform, landing zone and workload subscriptions — with centralised identity and policy-based guardrails.

A safe path from a Git commit to a production Azure change.
A secret-and-laptop Azure deploy process replaced with Azure DevOps workload identity federation, reviewed Terraform plans on every pull request, and a human approval gate on production.

Backups that had never been restored, proven to work — and timed.
AWS Backup coverage mapped against stated RTO and RPO per workload, then proven with controlled restore tests and recovery runbooks with measured timings.

AWS spend reviewed and reduced, without adding operational risk.
An AWS estate right-sized against real utilisation, with idle resources removed and commitment discounts applied — every change made through the same reviewed pipeline as any other.

Continuous assurance for a Kubernetes platform, so a clean cluster stays clean between deploys.
A Kubernetes platform on GKE connected for continuous assurance — Argo CD sync drift, admission policy, workload identity and backup coverage tracked on a schedule, with new problems surfaced to a named owner.

An AWS platform, made ready for its largest customer yet.
A platform readied for its largest enterprise customer yet — scaling, database resilience, deployment controls and monitoring reviewed, with the highest-risk changes made before launch.

Independent AWS due diligence, before the money moved.
Independent AWS due diligence for an investor ahead of a technology investment — architecture, security, IaC maturity and cloud economics, translated into investment impact.
Book a 20-minute triage call
Twenty minutes, no charge. We work out what would actually help — which is sometimes us and sometimes not. Nothing is priced on the call; if there is work worth doing, a written scope and a price reach you within 24 hours.