Services · How to Engage

Scoped work, stated prices, no proposal theater.

Four ways to engage, from a fixed-price written assessment to embedded platform leadership. Every tier has a defined scope, an honest list of what it doesn't include, and a price you can see before the first call. Solutions describes what we do; this page is how to buy it.

Architecture & Compliance Teardown

A senior review of your cloud estate and compliance posture, in writing, in a week.

$2,500 fixed ~5 business days from receiving materials

You share your architecture, current controls, and where the pressure is coming from. We return a written 5-8 page assessment: what holds, what fails an audit or a security review, and the prioritized path to fix it — then walk it through with you on a 60-minute call.

What's included

  • Written architecture + posture assessment (5-8 pages)
  • Prioritized findings mapped to audit and deal risk
  • 60-minute walkthrough call with senior engineering leadership
  • A concrete 90-day recommendation you can execute with or without us

Not included

  • Hands-on implementation (that is the sprint or fractional work)
  • A formal audit or attestation

Typical fit

Teams that want a defensible outside read before committing to bigger work — or before an auditor or enterprise buyer takes their own look.

90-Day Readiness Sprint

From scattered controls to the start of your audit window in one focused quarter.

From $35,000 — milestone-billed at 30/60/90 90 days

The structured push to audit-ready: scope and gap assessment, the policy set, control implementation, and an evidence pipeline that generates artifacts continuously. Sequenced weekly, run alongside your team, with milestones at 30/60/90 days.

What's included

  • Scope + honest gap assessment against your target framework
  • Policy set drafted to what your team will actually do
  • Control implementation: identity, logging, change management, backup
  • Evidence pipeline live before the observation window starts
  • Readiness assessment + auditor handoff

Not included

  • The audit itself (we prepare you for your auditor, we are not the auditor)
  • Compliance-platform subscription fees, if you choose one

Typical fit

Teams with SOC 2 or HIPAA pressure on a deal timeline and no dedicated compliance owner to run the readiness lift internally.

Fractional Platform Engineering

Embedded senior platform leadership, without the principal-engineer hire.

$8,000-$12,000 / month 3-month minimum, month-to-month after

A defined weekly cadence of principal-level platform work: architecture direction, hands-on infrastructure, operational maturity, and the hiring guidance to eventually replace us. Landing zones, credential elimination, GitOps, on-call design — the work the Operating Library describes, done in your estate.

What's included

  • Defined weekly engagement (typically 10-20 hours/week)
  • Direct senior authorship on architecture and platform code
  • Platform roadmap, operating model, and vendor selection
  • Incident program + on-call maturity
  • Hiring, leveling, and handoff guidance

Not included

  • Full-time embedded staffing or body-shop augmentation
  • 24/7 on-call coverage of your production (see Managed Operations)

Typical fit

Teams of 10-80 engineers who need platform depth now and a bench they can grow into — not another full-time req.

Managed Compliance Operations

The evidence pipeline, attestations, and security reviews — run for you, continuously.

From $5,000 / month 12-month term

After readiness lands, someone has to keep it true: quarterly access reviews on time, evidence flowing, sub-processor list current, customer security questionnaires answered from a maintained response repository. We run that operating cadence so the posture the audit measured is the posture you actually keep.

What's included

  • Evidence pipeline operation + quarterly control cadence
  • Access reviews executed and recorded on schedule
  • Customer security-questionnaire responses from a maintained answer bank
  • Sub-processor and vendor review upkeep
  • Audit-cycle support when the assessor returns

Not included

  • Initial control implementation (that is the sprint)
  • Legal review of contracts, DPAs, or BAAs

Typical fit

Teams past their first audit who keep scrambling every renewal cycle — or losing deal velocity to security questionnaires.

Every engagement starts the same way.

An intro call, then a scoped discovery (one to two weeks), then a written recommendation — and only then an engagement decision. We don't generate proposals for work we don't think we should run, and the teardown exists precisely so the first commitment can be small.

Not sure which tier?

Start with the conversation, not the contract.

Tell us where the pressure is coming from — an audit, a deal, a bill, a platform that needs adult supervision — and we'll tell you honestly which tier fits, including "none yet."

Open a conversation