Services

Nine engagements, each scoped to a decision and an outcome

Every engagement starts with the same question — what decision are you trying to make, and how will you know it went well. What follows is the shape of the work, what triggers it, and what you hold at the end of it.

012–6 weeks · assessment

Architecture review & guidance

We need to know what to do before we commit a year to it.

We read the system as it actually is — code, infrastructure, delivery pipeline, and the decisions already baked in — then put a target architecture and a sequenced path next to it. The output is written down and defensible: C4 views, architecture decision records, a risk register with owners, and a roadmap ordered so the first increment ships and pays for itself. Advisory can continue through the build if you want a second set of eyes on it.

What you get
  • Current-state assessment
  • Target architecture (C4) + ADRs
  • Risk register, scored and owned
  • Sequenced roadmap, first increment scoped
02project or retainer

AWS cloud architecture & cost

The AWS footprint grew by accident and nobody owns it.

More than a decade specialising in AWS, most of it building the account itself rather than the app on top. Multi-account Organizations laid down as infrastructure code, the public/private boundary drawn with VPC endpoints, PrivateLink and internal load balancers, identity federated through Identity Center, SAML and OIDC instead of long-lived keys, and least-privilege IAM held honest by a resource registry that fails the build when a policy is missing an action. Cost is treated as an architecture problem, not a report: one streaming engagement came down 72% in eleven months, another ed-tech footprint was rebuilt from scratch across twelve accounts.

What you get
  • Multi-account Organization, fully IaC
  • Network, identity and access boundary
  • Least-privilege IAM, drift-checked in CI
  • Cost baseline and reduction plan
033–12 months · project

Platform decomposition

The monolith is the ceiling and everyone knows it.

Contractor-built proofs of concept and long-lived monoliths come apart in phases, never in a rewrite. We draw the service boundaries, replace repo coupling with versioned build-time contracts, move compute onto an event fabric, and sequence the extraction so every phase is releasable on its own. Done at scale more than once: an agent-native data platform out of a PoC monolith, and an ed-tech marketplace into 50+ services and 100+ serverless functions.

What you get
  • Boundary and phasing plan
  • Build-time contract / spec registry
  • Event fabric and compute plane
  • Extraction delivered phase by phase
04retainer or project

Developer experience & platform engineering

Our engineers spend their week on plumbing.

Cognitive load belongs to the platform, not to the people using it. We build the scaffolding CLI, the golden templates, the versioned shared-infrastructure library and the CI/CD your teams consume as a pinned release — so an engineer gets security scanning, release cutting, telemetry and cloud setup by including a target, not by learning how any of it works. New services go from init to deployed instead of days of hand-wired infrastructure.

What you get
  • Scaffolding CLI + golden templates
  • Versioned shared IaC, reusable CI/CD
  • Drift enforcement so templates cannot rot
  • Adoption path, onboarding per repo
056–12 weeks · project

Release reliability & production hardening

We’re launching and nobody can tell me if it will hold.

We replace assumptions with numbers: a controlled load and cold-start campaign in a real environment, a capacity model derived from measured job durations rather than estimates, then the fixes. Autoscaling that reacts in seconds instead of minutes, graceful drain so a deploy cannot kill in-flight work, scale-in protection, dashboards, paging alerts and runbooks shipped with the service. On the most recent engagement that moved cold-start scale-out from a measured 360 seconds to under five, and failure rate from 2% to 0.3%.

What you get
  • Load, cold-start and capacity campaign
  • Scaling model from measured data
  • Autoscaling, drain and reliability fixes
  • Dashboards, alerts, runbooks, break-glass
06project or advisory

Agentic & MCP platform engineering

The AI demo works. Production is a different story.

Agentic products fail in the platform layer, not in the prompt. We build the parts that let them survive real traffic: sandboxed execution of model-generated code with credential scrubbing and process-group kills, compute tiered so an agentic burst cannot starve the interactive lane, capability APIs that tell the model the truth about the machine it is running on, and MCP servers and CLIs so a coding agent or a terminal user can drive the same product surface.

What you get
  • Sandboxed execution runtime
  • Tiered compute with queue isolation
  • Capability contracts and evaluations
  • MCP server / CLI distribution
07monthly retainer · days per month

Fractional principal / interim architect

We need principal judgment, not another headcount.

A fixed number of days a month as your design authority: design reviews, ADRs written down, the hard calls made with you rather than for you, roadmap negotiated against real capacity, and whichever engineer is stuck this week unstuck. Useful when the team is strong but junior, when an architect is on leave, or when the org is between principal hires and cannot stall for two quarters.

What you get
  • Design review cadence
  • ADRs and standards authored
  • Roadmap and risk negotiated
  • An escalation path for whatever is stuck
081–3 weeks

Technical due diligence

We’re about to write a check and need a real read on the codebase.

For acquirers, investors and boards: an independent read on architecture, delivery capability, security posture, cloud-cost trajectory and key-person risk, with a remediation estimate in weeks and dollars rather than adjectives. Written findings first, then a call to walk the partners through what matters and what does not — in language a non-technical committee can act on.

What you get
  • Architecture and code assessment
  • Delivery capability, key-person risk
  • Security and cloud-cost read
  • Remediation estimate + findings call
09alongside any engagement

Team mentorship & pattern transfer

We want the team to be able to run this after you leave.

Engagements end with the client operating the system, not with a support contract. That means pairing while it is built, a design-review habit that outlives the engagement, standards and runbooks living in your repositories, and the patterns underneath explained until your engineers can extend them without us. Where a team is growing, we help with the interview loop and hold the principal-level bar.

What you get
  • Pairing and review cadence
  • C4, ADRs and runbooks in your repos
  • Operational handover, on-call ready
  • Hiring-bar and interview-loop support

Not sure which of these you need? That is what an assessment is for — and it is a legitimate place to stop.

Start a project