About Expertise Work Managed Apps
Business Website Online Store Sales CRM Team Drive Online Academy Newsletter System Booking System Shared Inbox Knowledge Base Short Links Business Manager Photo Gallery Survey Platform Community Forum Project Boards Estate Agency Car Workshop Restaurant Clinic Photography Studio
AWS
Assess & advise Build & migrate Automate & operate Secure & comply Urgent & go-live
Projects
Hosted Monitoring & Dashboards Self-Hosted Observability Stack Bulk Document Data Extraction Email Deliverability Diagnosis & Repair SEO Migration Recovery AWS Security Review VPS Hardening & ModSecurity Cloud Architecture & Resilience Review SSL & Server Configuration Container Security Review DNS & Email Troubleshooting DevOps Deployment & Rollback Review WordPress Hardening Retainer Data Pipeline Rerun Review Metric Reconciliation
Free Tools
Website Health Check Email Domain Health Check DNS Health Check SSL Certificate Checker Redirect Chain Checker Robots.txt Checker XML Sitemap Validator Docker Compose Checker WordPress Security Check AWS IAM / S3 Policy Checker Domain Registration Lookup Uptime Monitoring Trial Downtime Cost Calculator AWS Cost Estimator Cloud Architecture Self-Assessment DevOps Engagement Builder Self-Managed VPS vs Managed AWS
Blog Certifications Hire Me

AWS Architecture Review

What your account actually looks like, what breaks first, and what it is costing you to keep it that way.

Price and scope

From $299

Typically $299–$699, fixed in writing before anything starts.

2–4 days
Working days, counted from the moment I have access — not from the day you agree.

What moves it up

  • More than one AWS account, or an Organization with no landing zone
  • No existing diagram, so the topology has to be derived from the API rather than read
  • Infrastructure created by hand over years, where nothing explains why a resource exists

Some of this you can check yourself, right now, for free: Cloud Architecture Self-Assessment →

A typical single-availability-zone AWS accountA VPC with one public and one private subnet in a single availability zone. Three faults are marked: one NAT gateway carrying all outbound traffic, an RDS instance with no standby, and an application instance whose security group is open to the whole internet. The second availability zone is empty.InternetAWS ACCOUNTVPCPUBLIC SUBNET · AZ-APRIVATE SUBNET · AZ-AAZ-Bnothing here,so nothing fails overALBNAT gatewayall egressapp EC2sg 0.0.0.0/0RDSno standbyegress
AWS Architecture Review

What actually goes wrong

The account works, so nobody looks at it. What a review finds is almost never a fault that is breaking something today — it is the fault that only shows up on the day something else fails. One NAT gateway that every private subnet routes through. An RDS instance with no standby, in an account whose owner believes AWS handles that. A security group opened to 0.0.0.0/0 for an afternoon of debugging eighteen months ago, still open, still forgotten, and no longer attached to anything anyone remembers creating.

How I find it

  • aws ec2 describe-nat-gateways --query 'NatGateways[].[NatGatewayId,SubnetId,State]'
  • aws rds describe-db-instances --query 'DBInstances[].[DBInstanceIdentifier,MultiAZ,BackupRetentionPeriod]'
  • aws ec2 describe-security-groups --filters Name=ip-permission.cidr,Values=0.0.0.0/0
  • Cost Explorer, grouped by service and then by usage type, over the last three months

What you get

  • A written findings document, ordered by what fails first rather than by AWS service
  • A current-state architecture diagram, derived from the account rather than from what you were told
  • Every finding with the command or console path that produced it, so you can re-run it yourself
  • A cost note naming which line items are structural and which are waste
  • A remediation order, with the two or three items worth doing before anything else

Questions

Do you need write access to my AWS account?

No. A review is read-only and I ask for a role with ReadOnlyAccess and nothing more. Write access is a separate conversation attached to a separate engagement, and it is never the default on this one.

How is this different from running the Well-Architected Tool myself?

The tool asks you questions and records your answers. It is genuinely useful and it is free, so run it. What it cannot do is look at your account and tell you that the answer you gave about backups is not what the account is actually configured to do. That gap is the whole engagement.

What if the review finds nothing serious?

Then you get a document saying so, with the evidence, and you have something to hand an auditor or an investor. That is a real outcome and it is not a refund case. A review that has to find something to justify itself is a review you cannot trust.

Will you fix what you find?

Not inside this engagement. The review is deliberately read-only so that nothing changes underneath you while you are still deciding. The fixes are quoted separately, and the review fee comes off the first one if you take it within 30 days.

AWS IAM & Access Cleanup

Who can do what in your account, who has not used it in a year, and what to take away first.

From $299 2–4 days

Want this done?

Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.

Prefer to talk? Book a free call ↗  ·  Or hire me on Upwork ↗  ·  Typical reply within one business day.

When I answer

Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.

No 24/7 desk, and I will not pretend otherwise

One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.

Your AWS bill stays yours

You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.

A price that starts with "from" is a starting price

Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.