Independent · not an AWS reseller · 3 pilot engagements open

You don't know
what's in your
AWS account.

AWS audit/Landing zones/Remediation & retainer

Neither does your team — not because they're careless, but because nobody has ever measured it. We read every account in your organization using a role that is mechanically incapable of changing anything, and hand back a report you can forward to your auditor, your insurer, or your largest customer's security review. Every finding in it has been checked by both of us.

2 Engineers on every engagement — each finding checked by the one who didn't write it
14+ Years running production cloud infrastructure between us — 8+ and 6+
3× AWS Certified — Solutions Architect, SysOps, Developer
0 Write operations the audit is capable of performing
01 — Inside the report

The report makes the next decision obvious.

Every screen below comes from a sample report that cloud-audit 0.20.0 generated against fictional accounts. None of it is a client result.

Executive summary

Money, exposure and safe fixes, on one screen.

The executive view puts money, exposure and safe fixes on the first screen. It also states exactly what was inspected — and what was not — so a low finding count can never masquerade as good coverage.

What was inspected — and what was not
Start here

The first page is a work queue, not a score.

If nothing else gets done, these do. Exposure first, then the safe changes that carry money — each item tagged with how risky the fix is and how long it should take.

Exposure first, then the safe changes that carry money.
Findings

Every finding names the resource and the next move.

Severity is only one dimension. Each item carries the affected resource, business consequence, remediation, change risk and estimated effort. Your team can turn the report into tickets without translating consultant language first.

Needs a decision · about 15 minutes per resource
Fix risk

Every fix is sorted by what it could break.

Safe now means no downtime and reversible. A window means a brief interruption. A decision means only your team knows the intent. The matrix shows how much of the work anyone can pick up on Monday.

Safe now — no downtime, reversible
Cost

Savings and located spend are never added together.

One row per issue, sorted by money, each tied to a named check. A saving is money that stops when you act; located spend is money the audit found and priced but cannot promise to remove — so the two totals sit side by side and are never summed.

Reducible share unknown — never added to savings
Well-Architected posture

A baseline the re-audit is measured against.

Controls in place out of the controls the audit could assess, one block per control, per pillar. The same evidence file regenerates the same scores, so the next audit shows exactly what moved.

Each block is one control
Collection gaps

It says what it could not see.

When a permission is missing or a region is disabled, the area is listed as not inspected instead of being counted as clean. Absence of findings there is not evidence of good configuration.

Not inspected is not the same as passed
Landing Zone · audit first, baseline second

Build the baseline from evidence, not assumptions.

The organization view exposes systemic gaps across accounts before the Terraform scope is finalized. Landing Zone itself is delivered as a repository you own; this audit is the input that shows which controls must be standardized and where exceptions exist.

One score per account — a single well-run account cannot mask the rest
02 — How it works

Five steps. About a week. Most of it is not your time.

Access

It is not permitted to change your account. That's enforced in code.

"Read-only" is not a promise in a contract — it is an interceptor sitting under every single AWS API call the tool makes.

Read more →
Coverage

Four pillars. Named resources. No "consider reviewing your posture."

Every finding names the resource, the region and the account.

Read more →
Method

Report and findings call

You get the document and an hour to walk through it. Then you decide whether to fix it yourself or scope the work with us.

Read more →
03 — Engagements

Three fixed-scope engagements. In this order.

Each one makes the next one quotable. You can stop after any of them, and the first one is built to be worth its fee even if you never speak to us again.

01 Available now

Cloud Audit

Read-only. One week. A document you own.

Every account, every enabled region, measured against the AWS Well-Architected pillars. You get a self-contained HTML report: what was inspected, what to do first, every finding tied to a named resource with a concrete remediation — and, unusually, an explicit list of what could not be checked.

  • Posture score per pillar, measured the same way twice
  • Every finding carries a fix class and an effort estimate
  • Cost findings in dollars, kept separate from located spend
  • Forwardable to an auditor or a customer security review
See the actual deliverable ↑

From $2,500 fixed

02 New accounts

Landing Zone

Empty account in. Defensible account out.

Plain Terraform — no Control Tower, no Terragrunt, no framework you have to learn. CloudTrail, SCPs, Block Public Access, EBS encryption by default, GuardDuty, Access Analyzer, budgets. Delivered as a repository you own, with no ongoing dependency on us.

  • Separate Terraform state per account, by design
  • Organization scope and per-account scope kept distinct
  • A repo that only ever creates — it cannot mutate what it didn't make
  • SCP review done with you, not decided for you
See how the scope is established ↑

Fixed Quoted at scoping

03 Ongoing

Remediation & Retainer

Fixing what the audit found.

The audit produces a scope line — "18 findings safe to apply, 3.7 hours" — which is already a proposal. Take it in-house and do it yourself, or hand it back to us as a fixed-scope sprint. Either outcome is fine; the report was built to work both ways.

  • Fixed-scope sprint: named findings, stated window, one number
  • Monthly retainer with a quarterly re-audit and a moving score
  • On-call, observability and incident review, if you want it
  • Never bundled into the audit price

Retainer $2,000–4,000/mo

Full pricing, tiers and rules →
04 — Who you're hiring

Two engineers. One surname. No account team.

JV

Joaquin Veliz

Senior DevOps / SRE · Córdoba, AR

Eight years running production cloud infrastructure.

GV

Gonzalo Veliz

DevOps / SRE Engineer · Argentina

Six years across AWS, Azure and GCP.

Who you're hiring →
05 — Next step

Let's find out what's in there.

Thirty minutes, no deck. You describe the estate, we tell you what we'd check and what it costs — one number, not a range. If it isn't worth doing, we'll say that too.