Skip to content

Cloud & data engineering for startups that need to ship, not babysit infra.

Multi-region AWS / GCP / Azure platforms, Terraform-managed everything, zero-trust networking, and data pipelines that don’t page you at 3am. From a single-region MVP to a SOC2-ready production stack.

Rate $100 – $120 USD / hour · fixed-fee and retainer available

What you get

Reference architecture
a written document with diagrams (HLD + LLD) covering networking, identity, data, and observability.
Terraform / OpenTofu modules
versioned, linted, and PR-reviewed. No console clicking, ever.
CI/CD
trunk-based delivery, ephemeral environments per PR, signed images, and policy gates.
Observability
OpenTelemetry traces, structured logs, SLO dashboards wired in from day one.
Security baseline
short-lived cloud credentials, OIDC from CI, automated compliance scans (SOC2 / GDPR / HIPAA controls as required).
Runbooks & on-call handover
PagerDuty or Opsgenie integration, escalation tree, and a playbook per alert.

How we engage

  1. 01

    Discovery (2 weeks, fixed fee)

    Architecture review, infra audit, threat model, and a written remediation plan. No code written until you sign off on the plan.

  2. 02

    Scoped SOW

    Either a fixed-fee milestone plan or a monthly retainer with explicit deliverables and acceptance criteria.

  3. 03

    Weekly sprints

    One-week iterations, Friday demo, written changelog, no surprise scope.

  4. 04

    Handover

    Runbooks, recorded walkthroughs, an internal champions program, and the option to retain us on-call for 90 days.

Stack we work in

Compute

ECS, EKS, GKE, Cloud Run, Vercel, Fly.io, Render

Data

Postgres (RDS, Aurora, Cloud SQL), ClickHouse, BigQuery, Snowflake, Kafka, Kinesis, Pub/Sub

IaC

Terraform, OpenTofu, Pulumi, Helm, ArgoCD

Security

AWS IAM, GCP WIF, OIDC, Vault, Trivy, OPA / Conftest

Observability

OpenTelemetry, Grafana, Loki, Datadog, Honeycomb, Sentry

Compliance

SOC2 (Drata, Vanta), HIPAA, GDPR, ISO 27001

Reference architectures

Anonymized patterns from real engagements. Client names omitted; details available under NDA.

Series A logistics SaaS — greenfield on AWS

Multi-AZ ECS Fargate, Aurora Postgres, Terraform, GitHub Actions → ECR → ECS, Datadog. Day-one SLOs: 99.9% availability, p95 API latency < 300ms.

Healthtech pilot — SOC2 in 90 days

Full infra-as-code rewrite, IAM hardening, evidence pipeline in Drata, secrets via AWS Secrets Manager. SOC2 Type II issued without critical findings on first audit.

AI startup — multi-region inference

Active-active across us-east-1 and eu-west-1; OpenAI-compatible API behind a global accelerator; autoscaling on request queue depth; cost dashboards.

Questions we get asked

What does a typical cloud engagement look like?

Two-week fixed-fee discovery (architecture review, infra gaps, security audit) → scoped SOW → 1-week sprints with weekly demos → handover with runbooks and on-call rotation.

Do you work with pre-Series-A startups?

Yes — most of our clients are between seed and Series B. We help you design for SOC2 and HIPAA early so you can close enterprise pilots without a costly replatform.

Which clouds do you support?

AWS, GCP, Azure, and OCI. We also build hybrid patterns that span on-prem — especially for hardware startups with a private-datacenter requirement.

Do you take over an existing messy AWS account?

Both. Our discovery phase includes an honest audit of the existing footprint; we always present a written remediation plan before any migration work begins.

How do you handle data residency?

Active-active across regions where the workload allows it; pinned single-region where compliance (GDPR, ITAR, DPDP) requires it. Direct Connect / Interconnect bring-up is in our standard playbook.

Let’s scope it properly.

A 30-minute call. No deck, no pitch — we read your repo or your architecture diagram and tell you what’s realistic.