Who it’s for
Your cloud platform runs production workloads, and an FCA, PRA, or PCI audit or an enterprise due-diligence review is on the horizon. You are weighing three options: hire a senior cloud security architect, engage a big-four team, or bring in a specialist. A new hire takes months to land and onboard. A big-four team leaves you a report. Wait too long and the architecture hardens around decisions an auditor will question.
This engagement leaves a working secure-by-default platform, controls committed to your repository, and a runbook your team maintains after we leave. That is the decision on the table.
Outcome
- An architecture document that maps controls to risks to regulators
- A baseline secure-by-default platform pattern the engineering team reuses for every new service
- A landing-zone build or review covering identity, network, logging, KMS (Key Management Service), secrets, and observability
- Remediated controls committed to your repository and evidenced for audit, not a list of recommendations
- A runbook for the operating team to keep the controls effective
The architecture document and control evidence pack are scoped to what an external auditor needs to see, not what is convenient to produce.
Operating model
We embed part-time with your platform engineering team, shaping the engagement around their sprint cadence rather than pulling them off delivery. We own the architecture review, the threat model, and the control design; your team owns implementation, with our guidance in code review. At close, your team inherits the architecture record, the runbook, and the control evidence pack, not a dependency on us. The board and audit-committee summary is a named deliverable, not an afterthought.
Engagement length and shape
- Initial scope: 6 to 10 weeks depending on platform size.
- Retainer: monthly thereafter, scoped per new platform component.
Most consultants leave a slide deck. Salvador Cloud left an operating model the team is still using two years later.
What's NOT in scope
- Building the platform itself (we partner with platform engineering teams)
- Day-to-day SecOps (see DevSecOps and SOC service)
- Vendor-specific certifications (we focus on the architecture)
Anonymised case study
See how this service plays out in practice.
Read the case study →
Frequently asked
-
What does a cloud security architecture review cover?
Account / tenant boundary, identity model, data-plane segmentation, logging and detection coverage, key management, third-party access, and the deployment pipeline that produces it all. The deliverable is a current-state diagram, a gap list mapped to your regulator(s), and a prioritised remediation plan with owners. -
How is this different from a CSPM tool?
CSPM tools surface misconfigurations against a generic baseline. Architecture review surfaces the design decisions upstream of those misconfigurations — the ones a tool can't catch (e.g. trust boundary violations, control gaps between accounts, IAM inheritance traps). Both are useful; one is not a substitute for the other. -
We're multi-cloud. Does that matter?
Multi-cloud sharpens the architecture conversation rather than complicating it. The control patterns are similar across AWS / GCP / Azure; the gaps tend to be at the joins (federated identity, shared data planes, cross-cloud observability). We treat each cloud on its own terms but keep the threat model unified. -
Do you implement the changes, or just recommend them?
We design the controls, write the IaC patterns, and pair with your platform team on the first implementation. After that, the patterns live in your repo and your team extends them. We don't build out every account — that's not where the value is. -
How long does this take?
A single-account or single-cloud review is typically 4 weeks. A multi-account multi-cloud architecture engagement is typically 8 weeks initial / monthly retainer thereafter. Both end with concrete artefacts you keep regardless of whether you continue.
Next step
Ready to scope this engagement?
No proposals, no pitching. We'll diagnose, scope, and price up front.