Cloud & Virtualization
AWS
Workload placement, network boundaries and access control on AWS, sized to measured demand.

Capabilities
What we implement
- VPC and subnet design
- Instance sizing and placement
- Managed service selection
- Cost-aware architecture
Security
How it is hardened
- IAM least privilege
- Security group discipline
- Logging and audit trails
Editions & pricing
AWS editions and vendor pricing
Vendor list prices for the editions we deploy. Deployment, migration, hardening and support are quoted separately by Techno Trader PK — they are never bundled into these figures.
| Edition | Licensed by | Vendor list price |
|---|---|---|
| EC2 t3.medium (on-demand)Sized per workload; use the AWS calculator for a firm figure. | per instance / month | Quote only |
| EC2 m6i.large (on-demand) | per instance / month | Quote only |
Prices are checked against the vendor's published price list. Last verified 9 Sept 2026. Vendor list prices exclude tax and can change without notice. Vendor pricing page
Architecture
AWS landing zone reference
Accounts, network boundaries and identity are laid out before workloads land, so growth does not turn into an unreviewable sprawl of resources.
01 · Account & identity
Organizations / OUsIAM roles & SSOGuardrail policiesSeparate accounts for production and non-production; humans use roles, not long-lived keys.
02 · Edge
Route 53CloudFront / WAFApplication Load BalancerTLS terminated at the edge, rate limiting and managed rule groups applied before traffic reaches compute.
03 · Network
VPCPublic subnetsPrivate subnetsNAT / VPC endpointsOnly load balancers and bastions are public; everything else egresses through NAT or private endpoints.
04 · Compute & data
EC2 / Auto ScalingECS or EKSRDSS3Instances sized from measured load, storage encrypted with KMS, multi-AZ where the RTO requires it.
05 · Operations
CloudWatchCloudTrailAWS BackupBudgets & alarmsAudit trail retained centrally; backups and cost alerts configured at build time, not after the first surprise.
FAQ
AWS questions we are asked
- How do you keep AWS costs predictable?
- Right-sizing from measured utilisation, scheduled shutdown of non-production, S3 lifecycle rules, and budget alarms wired to email before spend becomes a monthly discovery.
- Do we need multi-AZ or multi-region?
- Multi-AZ is the default for anything with a real RTO. Multi-region is only worth its complexity and cost when the business genuinely cannot tolerate a regional outage.
- How is access controlled?
- Federated sign-in with MFA, permissions granted through roles scoped per environment, and no shared root or static access keys in application code.
- Can you migrate our existing servers to AWS?
- Yes. Discovery maps dependencies and licensing, replication runs ahead of the window, and cutover follows a rehearsed runbook with documented rollback.
Related
Other cloud & virtualization platforms
AWS is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.
Ready to scope the work?
Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.