● UK · EU — Regulated fintech & energy Certifications delivered: ISO 27001 · PCI DSS v4 · DORA

Service

Cloud Security Architecture & Engineering

Architecture reviews, control design, and secure-by-default platforms for AWS, Azure, and GCP at regulated scale.

Who it’s for

Your cloud platform runs production workloads, and an FCA, PRA, or PCI audit or an enterprise due-diligence review is on the horizon. You are weighing three options: hire a senior cloud security architect, engage a big-four team, or bring in a specialist. A new hire takes months to land and onboard. A big-four team leaves you a report. Wait too long and the architecture hardens around decisions an auditor will question.

This engagement leaves a working secure-by-default platform, controls committed to your repository, and a runbook your team maintains after we leave. That is the decision on the table.

Outcome

The architecture document and control evidence pack are scoped to what an external auditor needs to see, not what is convenient to produce.

Operating model

We embed part-time with your platform engineering team, shaping the engagement around their sprint cadence rather than pulling them off delivery. We own the architecture review, the threat model, and the control design; your team owns implementation, with our guidance in code review. At close, your team inherits the architecture record, the runbook, and the control evidence pack, not a dependency on us. The board and audit-committee summary is a named deliverable, not an afterthought.

Engagement length and shape

Most consultants leave a slide deck. Salvador Cloud left an operating model the team is still using two years later.

M.K.CIO, UK energy market operator

What's NOT in scope

Anonymised case study

See how this service plays out in practice.

Read the case study →

Frequently asked

  • What does a cloud security architecture review cover?
    Account / tenant boundary, identity model, data-plane segmentation, logging and detection coverage, key management, third-party access, and the deployment pipeline that produces it all. The deliverable is a current-state diagram, a gap list mapped to your regulator(s), and a prioritised remediation plan with owners.
  • How is this different from a CSPM tool?
    CSPM tools surface misconfigurations against a generic baseline. Architecture review surfaces the design decisions upstream of those misconfigurations — the ones a tool can't catch (e.g. trust boundary violations, control gaps between accounts, IAM inheritance traps). Both are useful; one is not a substitute for the other.
  • We're multi-cloud. Does that matter?
    Multi-cloud sharpens the architecture conversation rather than complicating it. The control patterns are similar across AWS / GCP / Azure; the gaps tend to be at the joins (federated identity, shared data planes, cross-cloud observability). We treat each cloud on its own terms but keep the threat model unified.
  • Do you implement the changes, or just recommend them?
    We design the controls, write the IaC patterns, and pair with your platform team on the first implementation. After that, the patterns live in your repo and your team extends them. We don't build out every account — that's not where the value is.
  • How long does this take?
    A single-account or single-cloud review is typically 4 weeks. A multi-account multi-cloud architecture engagement is typically 8 weeks initial / monthly retainer thereafter. Both end with concrete artefacts you keep regardless of whether you continue.

Next step

Ready to scope this engagement?

No proposals, no pitching. We'll diagnose, scope, and price up front.