Cloud (AWS / Azure)
Cloud-native architecture, containers and serverless deployments.
The cloud rewards good architecture and punishes guesswork. Our AWS and Azure consulting work designs environments that are secure by default, cost-aware by design, and simple enough that your own team can operate them — as a one-off engagement or as a dedicated team on retainer.
How we deliver Cloud (AWS / Azure).
Landing zones
Accounts, networking and IAM structured properly from the first resource.
Containers & serverless
ECS, Kubernetes or Lambda — matched to the workload, not the hype.
Infrastructure as code
Terraform-managed environments you can rebuild from a repo.
Security & compliance
Encryption, secrets management and least-privilege access throughout.
Data residency by design
Region selection driven by where your users' data legally has to sit, not by whichever region the console defaults to.
Migration without a big bang
Moving workloads in stages, with a rollback that actually works, rather than one weekend and crossed fingers.
What this actually involves.
Your region is a compliance decision, not a default
The console picks a region for you and it's rarely the right one. Under HIPAA you need a signed business associate agreement with the provider and every service in scope to be an eligible one. Under Egypt's PDPL, storing personal data abroad is a cross-border transfer that catches AWS, Azure, Microsoft 365 and Google Workspace automatically, licensed per destination country, with full enforcement in October 2026. We settle this before the first resource exists.
Residency rules are routinely overstated
Saudi PDPL Article 29 permits transfers where the destination offers adequate protection, using SDAIA's standard contractual clauses or binding corporate rules — what it actually requires is a documented risk assessment, not in-Kingdom hosting. You'll hear the same overstatement about US and EU data. We read the rule and tell you what it says, including the times it's cheaper than you were told.
Least privilege is what auditors actually test
Not whether you have encryption — everyone has encryption. Whether long-lived access keys exist, whether humans log in through SSO with MFA, whether the break-glass account is monitored, and whether anyone has reviewed who can reach production this quarter. We set those up as defaults, so the review is a report rather than a project.
A backup you haven't restored isn't a backup
Recovery time and recovery point go into the design as numbers, then get tested — an actual restore into a clean environment, on a schedule, with the result written down. Most teams discover their backup gaps during the incident.
Cost control is an architecture problem
Most runaway cloud bills come from three things: over-provisioned always-on compute, egress nobody modelled, and log retention set once and forgotten. We size against real usage and put alerts on the spend before it becomes a quarterly surprise.
You should be able to rebuild it without us
Every environment is defined in Terraform in your repository. If we disappeared tomorrow, your team could recreate the whole stack from code. That's the test we design to.
Outcomes, not deliverables.
- Environments reproducible from code — no snowflake servers
- Security posture you can show an auditor
- Cloud spend that tracks usage, not waste
- Region and transfer decisions that survive the regime you're actually under
- Root account and billing in your name from day one
What you'll want to ask.
Who holds the cloud root account?
You do. Billing in your name, root credentials with you, our access granted as a role you can revoke in one click. If an agency holds your root account, you don't really own your infrastructure.
Will we be stuck on your tooling?
No. Terraform, standard CI/CD, mainstream managed services. Nothing proprietary, nothing that only we know how to operate.
Do we have to host in a specific country?
Usually less than you've been told, but it depends on your data and your sector — and for Egypt it changes in October 2026. We'll tell you what the rule actually says rather than defaulting to the most expensive interpretation, in either direction.
Do you handle HIPAA or SOC 2 requirements on the infrastructure side?
On the infrastructure side, yes — eligible services only, a BAA in place with the provider, encryption, logging, access review and change control configured to the controls those frameworks test. What we won't do is tell you we're certified. SOC 2 is an attestation an auditor issues about a specific organisation for a specific period; if you need one covering your own environment, we build to it and work with the auditor you choose.
What if something breaks at 3am?
We agree the on-call reality before you sign, in writing — what's covered, response times, escalation, and what isn't. Cairo is UTC+2, which overlaps the Gulf and European working day almost entirely and covers the US East Coast morning; for US clients we cover Fridays and name the rota rather than leaving it to hope. Ask any offshore vendor to put the response time in the contract — the answer tells you a lot.
What happens to the bill when we grow?
It should grow with usage and nothing else. We model the cost curve before building — compute, egress, storage and log retention are the four that surprise people — and put alerts on the spend at thresholds you set. If the architecture only makes sense at your current size, we'll say so now rather than at ten times the traffic.
Let's talk about cloud (aws / azure).
Tell us about your product, timeline and goals — we'll get back within one business day.

