Assess, fix, keep it that way

EdgeReadyEdgeResolveEdgeAssure

For investors

EdgeSignalAll services
How it works Find your path Case studies Security About What we take on Book a 20-minute triage call
Scope

What we take on, and the three things we genuinely cannot.

Most of the time the answer is yes. If it sits underneath your application — on AWS, Azure or GCP — it is probably ours, including stepping in as your platform team for a few months while you hire, which is the most common version of this. The three real limits are at the bottom of the page rather than buried in a contract.

In scope
01 / 03

Ask. The answer is usually yes.

The services page names three stages and an investor lens because most requests arrive in those shapes. It is not a menu you have to order from.

01

Be your platform team for a while

Fractional or bridge platform engineering capacity, and the most common shape this takes. No hire yet, or one starting in three months, and infrastructure work stacking up in the meantime. We pick it up on a named number of days a month, work in your repositories through your review process, and hand over as your engineer ramps. It is a temporary platform team, and there is no pretence that it is anything else.

02

The cloud platform your application runs on

Accounts, identity, networking, deployment, logging, backups, cost, guardrails, the pipeline, the Terraform — on AWS, Azure or GCP. If it sits between your code and the cloud provider's API and it is causing you trouble, it is in scope, whether or not it matches something on the services page. Database administration, endpoint and office IT, and the inside of your application are not ours, and we will say so rather than have a go.

03

Work that does not fit any of the named offers

The named offers exist because most requests fall into those shapes, not because we refuse anything else. A migration, a rebuild, a one-off piece of automation, a fortnight of pairing with your engineers — say what you need on the call and we will tell you whether we can do it well.

04

A second opinion, or design review before you build

Frequently the cheapest thing we sell. An hour on a design that has not been built yet is worth more than a week on one that has, and we are happy to be the people who tell you the plan is fine and you do not need us.

05

Cleaning up after an incident, once it is over

The post-mortem, the fix, and the check that would have caught it. We do not pitch during a live incident and we do not run the incident — but the week afterwards, when everyone is tired and the actions are about to be forgotten, is a genuinely useful place for an outside pair of hands.

06

Getting an estate ready for someone else to inherit

Before a platform hire starts, before diligence, before an acquirer's technical team arrives. Documented, reproducible, and legible to someone who has never seen it — which is a different objective from making it correct, and needs to be worked at deliberately.

Capacity is the constraint, not appetite. We are small and senior by design, so some weeks the answer is "yes, from the eleventh" — and we would rather give you the date than squeeze you in and do it badly.

Out of scope
02 / 03

Three limits, and they are real.

These are not negotiating positions and there is no version of the conversation where they move. Each one has an alternative attached, because "no" on its own is not much use to you.

We do not run a 24/7 on-call rota

There is no pager and we will not pretend otherwise. Buying out-of-hours cover from a firm without a rota is worse than having none, because you will believe you are covered at three in the morning. Ask and we will give you names of people who genuinely do this.

We cannot certify you as compliant

Nobody who is not an independent auditor can. We close the engineering gaps behind specific SOC 2 or ISO 27001 controls and hand over the evidence an auditor asks for, which is most of the work — but a SOC 2 report is issued by an auditor and ISO 27001 certification by an accredited body, never by us.

We do not hold production authority

Every change is approved by a named person on your side, bound to a specific plan hash. If the requirement is that we apply changes to production without you in the loop, we are structurally the wrong supplier. That gate is not a setting.

Penetration testing and application security auditing are specialist disciplines that we are not qualified to sell, so we do not. We will tell you when a questionnaire genuinely requires one and introduce you to people who do it properly.

What we will not say to win the work
03 / 03

Seven promises we are not allowed to make.

An internal rule written down before there was a website to put it on. Nobody here can make any of these commitments in a proposal. It is published because a supplier’s constraints tell you more than their claims do.

  • 24-hour response without a signed service level agreement and an actual rota behind it
  • Compliance certification of any kind
  • A fixed migration price before discovery has happened
  • Guaranteed cloud savings
  • Zero downtime
  • A delivery date before access is confirmed
  • Unlimited Slack access or unmetered engineering time

The related one, on the other side: we will not accept remediation work from a company we have run investor diligence on for 90 days after the report, and we disclose it in writing to the investor if we are approached. That rule costs us revenue and is worth more than the revenue.

Not sure whether it is our kind of problem?

Describe it in twenty minutes and we will tell you straight — whether we can help, whether it needs someone else, or whether it is not worth doing yet. There is no charge and nothing is quoted on the call; if there is work worth doing, a written scope reaches you within 24 hours.