Assess, fix, keep it that way

EdgeReadyEdgeResolveEdgeAssure

For investors

EdgeSignalAll services
How it works Find your path Case studies Security About What we take on Book a 20-minute triage call
Legal

Terms

Last updated: January 2026

These terms explain the basis on which InfraEdge provides its website, assessments, infrastructure engineering services and related products.

About InfraEdge

InfraEdge provides cloud infrastructure assessment, remediation, assurance and technical diligence services across AWS, Azure and Google Cloud, with AWS as our deepest specialism.

Our services may include infrastructure discovery, configuration analysis, security and resilience reviews, infrastructure-as-code analysis, technical recommendations, implementation work and ongoing infrastructure assurance.

The exact scope, deliverables, timescales and fees for an engagement will be agreed with you before work begins and may be set out in a proposal, statement of work, order form or other written agreement.

Where an engagement-specific agreement conflicts with these general terms, the engagement-specific agreement takes precedence.

Our services

InfraEdge currently provides services including:

  • EdgeReady — infrastructure readiness assessment and prioritised recommendations.
  • EdgeResolve — implementation and remediation of agreed infrastructure improvements.
  • EdgeAssure — ongoing infrastructure assurance and identification of changes, regressions and emerging risks.
  • EdgeSignal — independent infrastructure and cloud diligence intended to help investors and technology companies better understand infrastructure maturity and risk.

The precise scope of each engagement is agreed before work begins.

Access to your systems

Some InfraEdge services require access to cloud accounts or subscriptions, infrastructure repositories, CI/CD systems or related engineering tools.

Where possible, we use read-only and least-privilege access for assessment activities.

Access capable of making infrastructure changes is treated separately and should only be requested where it is required for agreed remediation work.

You remain responsible for deciding who may access your systems and for removing InfraEdge access when it is no longer required.

We will not intentionally make material changes to your production infrastructure outside the scope and approval process agreed for the engagement.

Infrastructure changes

Where InfraEdge performs remediation or implementation work, our preferred approach is to make infrastructure changes through version-controlled infrastructure as code and your existing change-management process wherever reasonably possible.

Depending on the engagement, this may include:

Git → Pull Request → Plan → Review → Approval → Apply → Verification

Your infrastructure repositories and the resulting infrastructure code remain under your control.

Unless specifically agreed otherwise, InfraEdge does not independently approve production changes on your behalf.

Assessments and findings

Infrastructure assessments represent our professional technical assessment based on:

  • the systems and information available to us;
  • the scope of the engagement;
  • the permissions provided;
  • the state of those systems at the time of assessment; and
  • the evidence we are reasonably able to collect.

No infrastructure assessment can identify every possible vulnerability, failure mode or future operational issue.

A finding marked as passed or ready should therefore not be interpreted as a guarantee that a system is secure, compliant, continuously available or free from defects.

Where evidence is incomplete, inaccessible or inconclusive, InfraEdge may identify the relevant area as unknown or unverified rather than assuming that it passes.

Security and compliance

InfraEdge may assess infrastructure against recognised cloud engineering, security and operational practices.

Unless expressly stated in an engagement agreement, our services are not a penetration test, legal opinion, formal certification or regulatory audit.

References to standards, frameworks or a cloud provider’s recommended practices do not mean that InfraEdge certifies your organisation as compliant with those standards.

Where formal certification or specialist legal, regulatory or penetration-testing advice is required, an appropriately qualified provider should be engaged.

EdgeSignal and investment decisions

EdgeSignal provides technical infrastructure diligence and analysis.

Its findings are intended to help investors and organisations understand matters such as infrastructure maturity, scalability, resilience, security exposure, cloud economics and technical debt.

EdgeSignal does not provide investment, financial or legal advice and does not recommend whether an investment, acquisition or transaction should proceed.

Investment decisions remain the responsibility of the relevant investor and their professional advisers.

Customer responsibilities

To allow us to deliver an engagement effectively, you are responsible for providing reasonably accurate information, appropriate access and suitable contacts where required.

You remain responsible for your production systems and for approving material changes unless responsibility has expressly been agreed otherwise in writing.

Intellectual property

You retain ownership of your existing infrastructure, repositories, application code, data and other materials provided to InfraEdge.

Unless otherwise agreed, infrastructure code and documentation created specifically for your environment as part of a paid engagement will be provided to you for your continued use.

InfraEdge retains ownership of its pre-existing intellectual property, methodologies, assessment frameworks, tooling, automation, templates, generic infrastructure patterns and other reusable know-how.

We may improve our general tooling and methodologies based on experience gained while providing services, but we will not intentionally incorporate your confidential information, credentials or proprietary source code into reusable InfraEdge materials.

Confidentiality and data

We treat customer infrastructure information as confidential.

Information collected during an engagement is used for delivering the agreed service, producing findings and evidence, and supporting the associated engagement.

Further information about how we handle infrastructure evidence, access credentials, retention and deletion is on our security and privacy pages.

Availability

We aim to provide our services professionally and with reasonable care and skill.

Unless specifically included in an agreement, InfraEdge does not provide a 24/7 managed operations service, emergency response service or guaranteed infrastructure availability.

EdgeAssure identifies infrastructure conditions and changes within its agreed scope; it should not be treated as a substitute for your production monitoring, incident response or operational processes.

Fees and payment

Fees, payment schedules and any applicable taxes will be agreed as part of the relevant proposal, order or statement of work.

Additional work outside the agreed scope may require a revised scope or separate agreement before work begins.

Liability

Any specific limitations of liability applicable to a commercial engagement will be set out in the relevant agreement or statement of work.

Nothing in these terms is intended to exclude or limit liability where doing so would be unlawful.

Changes to these terms

We may update these terms as InfraEdge and its services evolve.

The latest version will be published on this page together with the date it was last updated.

Contact

Questions about these terms or an InfraEdge engagement can be sent to support@infraedge.org.

For security-related enquiries, please use the contact listed on our security page.