Essential
$199
per month
Somebody is watching, and you get told what changed.
Right whenOne account running one thing, where nobody currently looks at it between incidents.
Most AWS work stops at handover. I do the build — migrations, pipelines, security, cost — and then I stay and operate it, so the account has somebody looking at it between incidents rather than only during one.
A read-only role, an inventory of what exists, and a conversation about what actually matters if it breaks. Nothing changes in your account.
A dated record of how the account is configured today. Every month after this is measured against it, which is the only reason a monthly report has anything to say.
Alerts reviewed, patches applied in an agreed window, backups verified by restoring one, cost and security drift checked against the baseline.
What changed, what it cost, what I did about it, and what I recommend next — in writing, monthly, whether or not anything went wrong.
Three plans. None of them includes project work — builds, migrations and architectural changes are quoted separately, from the catalogue below.
$199
per month
Somebody is watching, and you get told what changed.
Right whenOne account running one thing, where nobody currently looks at it between incidents.
$449
per month
Watched, reviewed, and small changes made without a new quote every time.
Right whenA production workload with customers on it, where small changes come up most months.
$899
per month
The recovery is planned, tested once a year, and the reporting stands up to an auditor.
Right whenRevenue depends on it being up, or somebody outside the company asks you how it is run.
| Essential | Business | Advanced | |
|---|---|---|---|
| Monthly | $199 | $449 | $899 |
| AWS accounts | 1 | Up to 2 | Agreed at onboarding |
| Monitored resources | Up to 5 | Up to 15 | Agreed at onboarding |
| Monitoring & alert review | ✓ | ✓ | ✓ |
| Backup verification | ✓ | ✓ | ✓ |
| Monthly patch window | ✓ | ✓ | ✓ |
| Cost drift review | ✓ | ✓ | ✓ |
| Security drift review | ✓ | ✓ | ✓ |
| Monthly report | ✓ | ✓ | ✓ |
| Included change time | — | 2 hours a month | 6 hours a month |
| Additional engineering time | $65/hr | $65/hr | $65/hr |
| Discount on catalogue work | — | 10% on catalogue work | 15% on catalogue work |
| Incident assistance | Charged at the emergency rate | Sunday to Thursday, 09:00–18:00 EET | Priority, within Sunday to Thursday, 09:00–18:00 EET |
| Monthly optimisation pass | — | ✓ | ✓ |
| Restore testing | — | Quarterly | Quarterly, or as agreed |
| DR plan | — | — | ✓ |
| Tested failover exercise | — | — | Annual |
| Change management | — | — | ✓ |
| Compliance-oriented reporting | — | — | ✓ |
| Typical response target | 1 business day | 4 business hours | Agreed coverage window |
| 24×7 NOC/SRE coverage | No | No | No |
| Your AWS bill | Paid by you, directly to AWS | Paid by you, directly to AWS | Paid by you, directly to AWS |
Every plan above measures this month against last month. On day one there is no last month — no baseline, nothing to diff, nothing for the first report to say. A retainer on an account nobody has reviewed is a standing charge for nothing, and you would work that out by about week six.
So it starts with a review: fixed price, read-only, and yours to keep whether or not you go any further. If you do go further, it becomes the baseline everything afterwards is measured against.
Short engagements that tell you what you have and what it is costing you. Nothing changes in your account.
What your account actually looks like, what breaks first, and what it is costing you to keep it that way.
From $299 2–4 days
Where the money is going, what can be cut without touching reliability, and what it is worth.
From $249 2–3 days
One question answered fast: why did the bill jump, and will it happen again next month.
From $149 1 day
What is exposed, who can reach it, and what an attacker would find first. Nothing is changed.
From $299 2–4 days
What should move, what it will cost to run, and in what order — before anybody commits.
From $399 3–5 days
What you actually have, written down, so it survives whoever built it leaving.
From $299 2–5 days
Two hours on a call about a decision you are stuck on. No engagement, no proposal afterwards.
$140 Same day–2 days
Getting something onto AWS, or rebuilding what is already there so it survives contact with production.
A server built the way you would build it on day 400, not day one.
From $199 1–2 days
Moved onto AWS with the cutover rehearsed, the DNS planned, and the old host still standing.
From $459 2–5 days
WordPress on AWS built so it can survive an instance dying, not just a traffic spike.
From $399 2–4 days
PostgreSQL or MySQL onto RDS, with the cutover rehearsed and a way back.
From $549 3–7 days
Subnets, routing and security groups laid out so the next person can read them.
From $349 2–4 days
Static hosting where the bucket is private, the certificate is right, and deploys invalidate the cache.
From $249 1–3 days
A zone moved with every record accounted for, and the TTLs lowered before the change rather than after.
From $199 1–2 days
Your containers running on AWS with secrets out of the environment and logs off the disk.
From $459 2–5 days
Containers that deploy without downtime, and that stop deploying when the new version is broken.
From $649 3–7 days
A cluster built to be operated, not just created — upgrades, ingress, identity and cost included.
From $1,099 5–12 days
Lambda behind API Gateway, with the database connections and the failure paths thought through.
From $549 3–7 days
More than one of everything that matters, and a failover somebody has actually performed.
From $849 5–10 days
Off another cloud or out of a rack, in stages, with each stage independently reversible.
From $849 5–12 days
Application mail that arrives, with bounces handled before they cost you the account.
From $299 2–4 days
Model access wired up properly — private networking, quotas, logging and a spend ceiling.
From $749 4–10 days
The work that stops the same incident happening twice — pipelines, monitoring, backups you have actually restored.
A pipeline that deploys on green — and that can put yesterday back without rebuilding it.
From $459 2–5 days
Your existing infrastructure in code, with state somewhere two people can safely use it.
From $649 4–10 days
Alerts that fire when customers are affected, and stay quiet the rest of the time.
From $299 2–4 days
Backups covering everything that matters, and one of them restored and timed in front of you.
From $449 2–5 days
Capacity that follows demand, and instances sized for the load you have rather than the one you feared.
From $399 2–4 days
Access, logging and edge protection, and the technical groundwork an auditor will ask you for.
Who can do what in your account, who has not used it in a year, and what to take away first.
From $299 2–4 days
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
Rules tuned against your real traffic, in count mode first, so nothing legitimate gets blocked.
From $349 2–4 days
The technical controls a HIPAA workload needs on AWS, built and documented. Not a certification.
From $1,149 7–15 days
The AWS half of a SOC 2 readiness effort, built so the evidence generates itself.
From $1,399 10–20 days
Something is broken now, or something is going live this weekend. Sunday to Thursday, 09:00–18:00 EET.
Something is down, burning money or possibly compromised. A flat triage fee, then hourly.
$249 Same day–2 days
A booked window with someone watching, a rollback prepared, and a decision point agreed in advance.
From $349 1–2 days
You keep working, because nothing I run depends on me being awake — the monitoring, the alerting and the backups are yours, in your account, and they carry on without me. What you do not get is someone answering at 3am. That is why every plan says no 24/7 cover rather than burying it, and if round-the-clock response is genuinely what you need, you need a team and I will tell you so.
No, and that is deliberate. A retainer on an account nobody has looked at is a standing charge for nothing — there is no baseline to compare next month against, so the first report has nothing to say. Every plan starts with a review, and the review is a fixed price you can take on its own and walk away from.
You tell me, and it stops at the end of the month you have paid for. Everything I built is in your account and stays there. You get the infrastructure code, the runbooks and the documentation, and I will hand over to whoever comes next. Nothing here is set up so that leaving is expensive.
A sales team, an account manager, a 24/7 desk, and a name your board has heard of. Those are real things and for some companies they are worth the difference. What you are getting instead is the person doing the work talking to you directly, and no margin paying for anybody sitting between the two.
Send me what your AWS account looks like — roughly is fine — and I will tell you which of these is worth doing first, and which you can safely ignore.
Prefer to talk? Book a free call ↗ · Or hire me on Upwork ↗ · Typical reply within one business day.
Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.
One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.
You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.
Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.