On AWS, Google Cloud or Azure — whichever your team and your software already assume. The length depends on what you have today; the scope says which.
Week by week
- Week 1 — what exists, and the plan. An inventory of the accounts, workloads and access you have now, and a written design for where it’s going. You approve the plan before anything changes.
- Weeks 2–3 — the foundation. Organisation and accounts for separation, identity on least privilege, and the network — all written as code (infrastructure as code), reviewed like any other change.
- Weeks 3–5 — the pipeline and the signals. Automated testing and deploys (CI/CD), logging, monitoring and backups, so a change ships the same way every time and a failure reaches a person.
- Final weeks — the move and the handover. Workloads cut over with a way back, a restore tested end to end, and the runbook walked through with your team.
SOC 2, the technical half
SOC 2 is a common security audit for software companies. The foundation puts the technical controls it asks for in place: access, logging, change management, backup and monitoring. Policies, risk registers and audit management come from our sister company, Signal & Soil. Need both? One scope, two invoices.
What happens after
Retain us to run it, month to month, or walk away with everything. It’s your account, your code and your runbook either way.