One method, four stages.
We move sequentially and document every step. At each stage, you know what's being produced and what you'll receive.
- 1.0
Scoping
We establish the scope, the operational constraints, and the security requirements that apply to your context. Most of this phase is spent talking with your technical teams, to understand their priorities and what constrains them.
What you receive
A scoping note: scope, constraints, requirements retained.
- 2.0
Design
We define the target architecture, the technical choices, the hardening reference framework selected, and the recovery plan.
What you receive
An architecture file with the technical choices justified.
- 3.0
Deployment
We implement, harden against the selected reference framework, and have the infrastructure formally accepted.
What you receive
The infrastructure in service, its documentation, and its acceptance report.
- 4.0
Operations
Once acceptance is confirmed under the terms of the contract, the infrastructure enters operations. We then provide operational and security maintenance, monitoring, and continuous remediation.
What you receive
Ongoing operations tracking and a regular vulnerability status report.
What we expect from you
Your technical teams, so we can understand their priorities and constraints, and someone authorized to approve quotes. That's what starting the work depends on, nothing more.
Indicative duration
- Scoping and design: about 15 days.
- Deployment: under 3 days, for several hundred virtual machines and LXC containers.
- Operations: ongoing.
The specification is the long phase. Deliberately.
Fifteen days of scoping for three days of deployment: the reverse of what's usually promised. Deployment is short because everything was decided beforehand, not because it was rushed.
Your context is specific.
Describe it to us: we'll tell you whether our approach applies, and if not, why.