Pricing
You aren't buying our time — you're buying an answer you can't get internally, delivered in a week, backed by tooling that took months to build.
One number, stated up front, for a defined scope.
Priced on the outcome, not on hours. You aren't buying our time — you're buying an answer you can't get internally, delivered in a week, backed by tooling that took months to build.
Pilot
First three clients, any size. In exchange for a named testimonial and permission to publish an anonymised case study.
Single account
One AWS account, up to three regions.
Small estate
Up to ten accounts, all enabled regions.
Organization
Eleven to fifty accounts, collected org-wide via StackSet.
Large organization
Fifty accounts and above. Quoted after scoping.
Annual re-audit
Same scope, measured again. Quoted in the first proposal, not sold to you later.
No hourly rate
Quoting hours turns the conversation into "why does it take twelve hours" instead of "is this finding worth knowing about."
No contingency pricing
"A percentage of savings found" creates a direct incentive to inflate the numbers. The numbers being trustworthy is the entire product.
No savings promised in advance
We don't know what's in your account yet. We'll tell you what we look for. The report speaks for itself.
Scope moves, price doesn't
If the number is too high, we cut accounts or regions. Discounting would just teach you the number was invented.
Your AWS partner will do this for free. Here's the honest difference.
If you have an AWS account manager, you have probably been offered a Well-Architected Review. It's a good framework — so good that every finding in our report carries the same pillar and best-practice ids, so you can lay the two side by side. The difference isn't the framework. It's who's holding the pen, and what they're reading.
The two are not mutually exclusive, and we'll say so on the call. If a free partner review gives you what you need, take it — we'd rather lose the engagement than sell you a duplicate.
The questions you were going to ask on the call.
What access do you actually need?
An IAM role with the AWS-managed ReadOnlyAccess and SecurityAudit policies, assumed with an ExternalId you generate. You deploy it from a CloudFormation template we give you — as a StackSet if it's an organization. We never receive a credential, and deleting the stack ends the access completely.
How do I know the tool can't change anything?
Two independent layers. Your IAM role doesn't grant write permissions in the first place. And under that, the tool intercepts every AWS SDK call and refuses anything outside a read-only allowlist — including secret-reading calls that AWS itself classifies as reads. An unrecognised verb is a refusal, not an exception. There are dedicated tests asserting this, and they are the reason the tool exists in the shape it does.
We already have Security Hub / GuardDuty / a free scanner. Why pay?
Those tell you what fired. They don't tell you what it means for your business, which six things to do first, what the fix costs, what it risks, or — critically — what they couldn't see. A scanner produces alerts. This produces a decision, in a document, with a name on it.
Who actually does the work?
Both of us, on every engagement — there is nobody else. One of us runs collection and drafts the findings; the other reviews every one of them against the evidence before the report is written. You will know which of us did which half, because we will tell you on the findings call. What you will never get is a senior name on the proposal and a junior doing the work, because there is no junior.
You're in Argentina. Is that a problem?
It surfaces on the first call anyway, so: no, and we won't price from it either. You're paying for the value of the finding, and a public S3 bucket is worth exactly the same to find whether we live in Córdoba or Boston. Both of us work UTC-3, overlap comfortably with US and European business hours, and have spent our careers on distributed English-speaking teams.
What if the audit finds nothing serious?
Then you have a document saying so, measured rather than assumed, that you can hand to an enterprise prospect or an insurer. That's a real outcome, and it's why the report opens with what was inspected rather than with a finding count. We don't pad reports — a finding that doesn't survive your own console check discounts every other page.
Is the landing zone a Control Tower replacement?
No, and we'd rather say it here than be caught saying it later. It doesn't do account vending. It's plain Terraform that takes a new or empty account to defensible defaults, delivered as a repo you own with no dependency on us. It also deliberately cannot import or mutate resources it didn't create — that's a different product with a different risk profile.
Does this give me compliance certification?
No. The findings map to Well-Architected pillars and the landing-zone defaults are CIS-aligned, but neither is an attestation and neither carries standing with an auditor on its own. What the report is good for is answering the questions an auditor or a customer's security review will ask, with evidence.
How long until I have the report?
About a week from the moment the role is deployed, and the majority of that is triage rather than waiting. Your team's total involvement is roughly a thirty-minute scoping call, an hour or two deploying a stack, and an hour on the findings call.