Skip to content

Services

Every service has a clear scope and a written fixed quote. A senior architect leads the work.

Review, build, run

Every area follows the same path: a short review first, then the build, then ongoing care. You can start small and add the next step later.

Cloud foundations & networking

The base your systems run on in AWS, Azure or Google Cloud: account structure, secure networks, moves from your own data centre or between clouds, disaster recovery and lower monthly bills. All built as code.

Assess Popular

Cloud foundation check

In 1–2 weeks, we review your AWS, Azure or Google Cloud foundation against the CIS benchmark and tie every finding to evidence, the affected resources and a fix.

Duration:1–2 weeks
Assess

Zero Trust network review

A one-week review of how traffic enters, leaves and crosses your AWS, Azure or Google Cloud networks, with evidence for every finding, a target Zero Trust design and a prioritised roadmap.

Duration:1–2 weeks
Assess

Migration check

In 1–2 weeks, we assess what you run on-premises or in another cloud, with a migration approach per application, a wave plan and a cost estimate for AWS, Azure or Google Cloud.

Duration:1–2 weeks
Assess

Cloud cost quick wins

Lower your AWS, Azure or Google Cloud bill in one to two weeks by changing how the platform is built, from NAT and data transfer paths to commitments, with the quick wins delivered as code.

Duration:1–2 weeks
Build Popular

Landing zone sprint

A production-ready foundation on AWS, Azure or Google Cloud in 3 to 6 weeks, with single sign-on, guardrails, a hub network, central logging and a keyless pipeline, all built as code.

Duration:3–6 weeks
Build

Zero Trust network build

A Zero Trust network for the AWS, Azure or Google Cloud estate you already run, with a hub, private endpoints, central DNS and egress through a cloud firewall, built in 3 to 6 weeks without downtime.

Duration:3–6 weeks
Build

Migration and resilience

Move workloads from on-premises, another region or another cloud in planned steps, with a disaster recovery pattern that meets your RPO and RTO targets and restore tests that prove it.

Duration:2–8 weeks
Build

Guardrails as code and evidence pack

Up to about 30 preventive guardrails for AWS, Azure or Google Cloud, each with a test that proves it refuses a non-compliant change, and evidence mapped to CIS, ISO 27001 Annex A and NIST CSF.

Duration:2–4 weeks

Container platforms

Run your applications in containers without looking after servers: serverless options (ECS on Fargate, Azure Container Apps, Cloud Run) or Kubernetes (EKS, AKS, GKE, OpenShift).

Assess

Container platform check

A one-week, read-only review of your Kubernetes clusters or serverless container runtime, with evidence for every finding, a hardening plan ordered by risk and a readout with your team.

Duration:1 week
Build Popular

Serverless container platform

A platform for your containerised services on ECS on Fargate, Azure Container Apps or Google Cloud Run in 3–7 weeks, built as code with one reusable service module for every team.

Duration:3–7 weeks
Build Popular

Kubernetes platform

A Kubernetes platform on EKS, AKS, GKE or managed OpenShift in 5–6 weeks, run through GitOps, with access, policies, secrets and scaling in place and your first services onboarded.

Duration:5–6 weeks

DevSecOps & secure CI/CD

Build and release pipelines with security built in: no stored cloud passwords, automatic security scans, signed releases, infrastructure changes reviewed before they go live, and GitHub Enterprise with developer accounts your company manages.

Assess

DevSecOps gap check

In 1–2 weeks, a check of how your teams build and ship software, scored against OWASP SAMM and NIST SSDF, ending in a gap list and a 90-day plan.

Duration:1–2 weeks
Assess Popular

Pipeline security check

A one-week review of one CI/CD platform, from organisation settings to runners and secrets, with findings mapped to the OWASP Top 10 CI/CD Security Risks and SLSA.

Duration:1 week
Build

Keyless pipelines and secrets cleanup

Your pipelines move from long-lived cloud keys to short-lived federated tokens, with secret scanning and dependency gates that stop new leaks and risky dependencies before merge.

Duration:1–3 weeks
Build Popular

Secure CI/CD pipeline

A pipeline that scans every change, builds each image once, promotes it by digest and asks for approval before production, for one app in 2–3 weeks or up to 10 repositories in 4–5 weeks.

Duration:2–5 weeks
Build

Terraform and OpenTofu delivery pipeline

A keyless pipeline for your Terraform or OpenTofu code that plans on every pull request, applies only after approval, checks every plan against policy and reports drift on a schedule.

Duration:2–3 weeks
Build

Software supply chain security

Signed images, SBOMs and build provenance to SLSA Build Level 2 for up to 10 repositories, checked at deploy time so that only images your pipeline built can run.

Duration:2–3 weeks
Build

DevSecOps operating model

Security champions, threat modelling, fix deadlines, an exception register and a shared definition of done for up to 10 teams, tracked on a dashboard built from the tools you already have.

Duration:3–4 weeks
Build

GitHub Enterprise Managed Users setup

A GitHub enterprise on GitHub.com or GHE.com (EU) where every developer account comes from your identity provider, built as code in 2–3 weeks, or 4–6 weeks with your repositories moved in.

Duration:2–6 weeks

Identity, PKI & domains

Who and what can sign in, and what they may do: Microsoft 365 and Entra ID security, admin access, internal certificates (PKI), and your domains and DNS kept safe and managed as code.

Assess

PKI review

A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.

Duration:1 week
Assess Popular

Domain and external attack surface check

A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.

Duration:1 week
Build Popular

Microsoft 365 security baseline

Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.

Duration:1–3 weeks
Build

Identity modernisation

Business applications moved from passwords and legacy federation to Entra ID single sign-on, with hybrid sync, tenant and domain moves, and one corporate sign-in for AWS and Google Cloud where you need it.

Duration:2–6 weeks
Build

Privileged access hardening

Admin access split into tiers, done from separate admin accounts on dedicated workstations and granted just in time, built with PIM, Conditional Access and Intune in 2–3 weeks.

Duration:2–3 weeks
Build

Private PKI and certificate automation

A private CA hierarchy on one platform, with automated enrolment and renewal, working revocation and expiry alerts, built as code in 3–4 weeks.

Duration:3–4 weeks
Build

DNS as code

Every DNS zone and record managed in code with pull request review and drift detection, imported in place with zero record changes or moved to a new provider, in 2–3 weeks.

Duration:2–3 weeks
Build

Email domain protection

SPF, DKIM and DMARC at reject for up to 5 sending domains, MTA-STS with TLS reporting, and parked domains locked down, staged over 8–12 weeks with a check before every step.

Duration:8–12 weeks

Security hardening & assurance

Make your systems harder to attack, and show it: hardened servers, finding and fixing vulnerabilities, alerts on risky cloud changes, threat modelling and Zero Trust reviews.

Assess Popular

Zero Trust assessment

In 1–2 weeks, a review of identity for people, devices and workloads, cloud guardrails and CI/CD, with every control checked as declared, refused and in effect, ending in a maturity rating per area and a roadmap.

Duration:1–2 weeks
Assess

Threat modelling workshop

A STRIDE threat model of one system or major feature, built with your team in two half-day sessions over one to two weeks, with a data-flow diagram, trust boundaries and prioritised mitigations in your backlog.

Duration:1–2 weeks
Build Popular

OS hardening baseline

Linux and Windows Server hardened to CIS Benchmarks Level 1 in two to six weeks, built as code with golden images, enforced settings, drift checks and compliance evidence for every host.

Duration:2–6 weeks
Build

Vulnerability management setup

Scanning for hosts, containers, Kubernetes, serverless functions and code dependencies, with triage rules, fix deadlines by severity, ticket integration and a weekly report, set up in two to five weeks.

Duration:2–5 weeks
Build

Cloud alerting baseline

Central audit logs and about 15 or 25 tested alert rules for high-risk changes in AWS, Azure or Google Cloud, each with a runbook and routed to your on-call tool, tickets or chat, in two to four weeks.

Duration:2–4 weeks
Build

NIS2 incident readiness

An incident response plan, cloud runbooks and forensic readiness that help you prepare for the NIS2 reporting deadlines, tested in a tabletop exercise with your team over two to three weeks.

Duration:2–3 weeks
Advise

Fractional security architect

A senior security architect on agreed days each month, typically 2, 4 or 6, for your security roadmap, design reviews, customer questionnaires, policies, supplier reviews and incident advice.

Duration:Monthly

AI you can govern

Use AI in development and in your products without losing control: rules for AI coding assistants, safe access to AI models with checks before new AI features go live, and cloud platforms built for AI.

Assess

AI risk quick scan

In 1–2 weeks, a read-only review of the AI tools, model keys, agents and data flows in your organisation, with the risks ranked and a 30/60/90-day plan to fix them.

Duration:1–2 weeks
Build Popular

Governed AI coding agents

Let your engineers use AI coding agents on real repositories, with written working agreements, grounded answers, read-only cloud access and human consent before every production change.

Duration:1–2 weeks
Build

AI model access and release gates

Give your applications one controlled route to AI models with a keyless fallback, keep model calls in EU regions and hold generative features back until evaluation and data-protection sign-off.

Duration:2–3 weeks
Build Popular

AI platform landing zone

A governed place in your cloud for AI agents and AI-enabled apps, built as code in four to six weeks: inherited guardrails, approved models and regions only, and a keyless identity for every agent.

Duration:4–6 weeks

Build & modernise

New web apps, APIs and integrations, and older applications moved to modern containers, on a secure base from day one.

Assess

Product and architecture discovery

A discovery of 1–2 weeks that turns a product idea into a first-release scope, an architecture, a build estimate and a delivery plan, before you commit budget to the build.

Duration:1–2 weeks
Build Popular

Cloud-native web app or MVP

A web app or MVP with its API, built in your own AWS, Azure or Google Cloud environment in 4 to 12 weeks, with infrastructure as code, CI/CD and security gates from the first commit.

Duration:4–12 weeks
Build

API and integration platform

Tested integrations with your suppliers, partners and payment providers that handle timeouts, retries and duplicate messages, so one slow partner cannot stall your product. Built in 2 to 8 weeks.

Duration:2–8 weeks
Build Popular

Legacy app modernisation

Older applications, including .NET and IIS apps, moved into containers on Amazon ECS on AWS Fargate, Azure Container Apps or Cloud Run, with CI/CD and a tested rollback for every release.

Duration:3–10 weeks

Advisory

Senior advice when you need it: a working session with an architect, written comparisons of technology options, a 12-month roadmap or a part-time architect.

Advise

Architecture call

A 90-minute working session with a senior architect on one hard architecture question, followed by a written memo with the recommendation and next steps within three working days.

Duration:90 minutes
Advise

Technology decision papers

A written recommendation on a platform choice that is expensive to reverse, such as Microsoft 365 or Google Workspace, an identity platform, an AI platform or a cloud, with licensing and costs worked out.

Duration:1–3 weeks
Advise

Cloud and digital roadmap

A review of your cloud, your workplace platform and your applications over three weeks, ending in a 12-month roadmap with effort and cost ranges, and one presentation to your board.

Duration:3 weeks
Advise

Fractional architect

A senior cloud and platform architect on your team for a set number of days each month, without a full-time hire. Decisions get reviewed and your platform backlog moves every month.

Duration:Monthly

Care plans

We keep things running after go-live: monitoring, updates and fixes for your cloud platform and applications, with optional 24/7 cover for critical incidents.

Run Popular

Platform Care

Business-hours care for your cloud platform: monitoring and alerting, monthly patching, backup and restore checks, a monthly block of change hours and a monthly report, with 24/7 cover as an add-on.

Duration:Monthly
Run

App Care

Business-hours care for your live web and mobile apps: security and dependency updates, uptime and error monitoring, backup checks and a monthly allowance of hours for fixes and small changes.

Duration:Monthly
Run Popular

24/7 critical cover

An add-on to Platform Care or App Care: an engineer acknowledges a P1 incident within 30 minutes, 24/7/365, with cover starting after 4–6 weeks of onboarding.

Duration:Monthly

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.