Services / Cloud cost & security review

01

Find what is wasting money and what is exposed, in two weeks.

A fixed-scope review of your AWS or Azure environment. We read your bills, your accounts and your configuration, then hand you a written report that ranks every finding by savings, risk and effort.

Who it is for

  • Startups whose cloud bill is growing faster than revenue
  • Teams preparing for SOC 2, a bank partnership or an enterprise security questionnaire
  • Companies that inherited an account from an engineer who has left
  • Founders who want an outside opinion before a large migration or funding round

Signs you need it

  • The bill went up and nobody can explain why
  • You are not sure who has admin access
  • Resources exist that nobody recognizes
  • Nobody outside the team has ever reviewed the setup

What is included

Spend analysis

Costs broken down by service, account, environment and tag. Idle and oversized resources, commitment coverage (Savings Plans, reservations), data transfer and storage lifecycle.

Identity and access

Root and admin usage, MFA, long-lived access keys, over-broad roles and cross-account trust.

Network exposure

Public endpoints, security groups and open ports, public buckets and snapshots, missing edge protection.

Data protection

Encryption at rest and in transit, backups and whether restores are ever tested, secrets stored in code or environment variables.

Logging and detection

Audit log coverage and retention, and alerts on the events that actually matter.

What you get

  • Written report with every finding ranked by impact and effort
  • Estimated monthly savings for each cost finding
  • A 30/60/90-day remediation plan
  • Walkthrough call with your team
  • Terraform snippets for quick wins, where they apply

Timeline

  1. Day 1

    Kickoff call and read-only access set up

  2. Days 2–8

    Analysis of billing, identity, network, data and logging

  3. Days 9–10

    Report delivered and walked through with your team

Common questions

What access do you need?

A read-only role in each account. We send you the exact IAM policy or Azure role definition to create, and you can remove it the day the review ends.

Do you fix the problems as well?

If you want us to. Many teams fix the quick wins themselves from the report; others hire us for the remediation as a separate, scoped project.

Which clouds do you cover?

AWS and Azure. Google Cloud on request.

OTHER SERVICES

Not sure where to start?

Most engagements begin with a free 30-minute call and a cloud review.

Get in touch