Skip to main content

CLOUD ARCHITECTURE — FIXED-PRICE AUDIT

A diagnosis, at a fixed price,
before you commit a budget

Before you migrate, rebuild or renegotiate, you need a diagnosis: what actually costs money, where US legal process could reach your data, and how much of the environment could be rebuilt from code today. We audit read-only, in 2–3 weeks, at a fixed price — and hand over a prioritised roadmap instead of a proposal for a twelve-month project.

2–3 wk

Duration, results included

Fixed

Price — no day-rate creep

Read-only

Zero changes to production

3

Dimensions assessed

01 — THE PROBLEM

What usually goes wrong.

Most mid-market cloud environments have never been audited — they have accumulated. Costs rise quarter over quarter without a nameable driver, the “Frankfurt region” counts as sovereign internally, and the only complete map of the infrastructure lives in one person's head. Migration and modernisation decisions then get made on gut feeling — or on the slides of a vendor who profits from the rebuild. Most mid-market cloud estates were never designed. They accumulated.

EU policy on cloud sovereignty consistently separates where data sits from who can legally compel access to it — infrastructure operated by a US-headquartered provider stays within reach of US legal process even when the servers are in the EU. Since NIS2, DORA and the Data Act's switching provisions came into force, the same question also has to be answered with evidence rather than assurance.

Sound familiar?

  1. The cloud bill grows faster than the workloads — and nobody can say why.
  2. The “Frankfurt region” is treated as EU-sovereign — under the CLOUD Act it is not.
  3. No current architecture map; the environment was clicked together in a console.
  4. An upcoming project — migration, AI platform, certification — needs a baseline first.
  5. The last “cloud consultation” ended in a proposal for a twelve-month project.

02 — WHAT WE BUILD

What we build.

COST

What drives the bill, and who owns it

Cost broken down by driver and workload rather than by service line, with the unattributed remainder named as such. Savings potential is quantified with the effort it would take to realise it, so you can decide what is worth doing.

SOVEREIGNTY

Where your data sits, and who could reach it

Residency, key ownership, encryption design, subprocessors and the realistic exit path — assessed per workload, because the answer is rarely the same for all of them.

REPRODUCIBILITY

How much of this could you rebuild tomorrow

Infrastructure-as-code coverage, drift between code and reality, audit trail and bus factor. The number is usually lower than the team expects, and it is the one that determines how expensive every other change will be.

ROADMAP

What to do first — and what to leave alone

Findings turned into a sequence with effort estimates and dependencies, including the parts that are already fine. We have no stake in the rebuild, which is the point of asking us.

Three audit dimensions converging into findings and a prioritised roadmapThree inputs on the left converge into two outputs on the right. The inputs are cost — drivers, attribution and waste; sovereignty — residency, keys and CLOUD Act reach; and reproducibility — infrastructure-as-code coverage and bus factor. They converge into findings, described as evidence rather than opinion, which feeds a prioritised roadmap that is yours to keep. A band underneath reads: read-only access, two to three weeks, fixed price, no follow-on project required.COSTdrivers · attribution · wasteSOVEREIGNTYresidency · keys · CLOUD ActREPRODUCIBILITYIaC coverage · bus factorFINDINGSevidence, not opinionPRIORITISED ROADMAPyours to keepRead-only access · 2–3 weeks · fixed price · no follow-on project required
fig. 01 — what the audit measuresWe have no stake in the rebuild. The roadmap names what to do first, what can wait, and what is already fine — including the parts where the honest answer is "leave it alone".

03 — DELIVERY

Four steps, no ceremony.

STEP 01

Kickoff & read-only access

Scoping call, goal definition, read-only access to billing, IAM overview and resource inventory. Nothing in your environment changes — at any point in the audit.

STEP 02

Analysis

Cost drivers and attribution, CLOUD Act and residency exposure, IaC coverage and rebuildability. Tool-assisted, with an architect reading the output — not a generated report.

STEP 03

Findings review

An interim session with your team: validate the findings, sharpen priorities, separate quick wins from structural work. What your team already knows does not get dressed up as an insight.

STEP 04

Roadmap & hand-over

Findings report with quantified cost potential, a sovereignty assessment and a prioritised roadmap with effort estimates. The document is yours — execute it with us or without us.

TYPICAL 2–3-WEEK AUDIT

kickoff & read-only access
wk 1

analysis
wk 1–2

findings review
wk 2

roadmap & hand-over
wk 2–3

Results in 2–3 weeks: findings report, quantified cost drivers, sovereignty assessment and a prioritised roadmap — yours to keep, with or without a follow-on project.

Typical anchors: architecture audit from €5,900 net (fixed) · fixed-scope builds from €12,000 net · fractional lead from €1,200 net/day.

04 — WHAT YOU GET

What you have at hand-off.

All of it in your repos, your cloud

  1. A findings report

    Evidence per finding, quantified where quantification is honest, and flagged where it is an estimate.

  2. A sovereignty assessment

    Residency, key ownership, subprocessors and exit path per workload — in the form your DPO can cite.

  3. A prioritised roadmap

    Sequenced work with effort estimates, written so your team or another partner can execute it.

Where we fit — and where we don't.

Best fit for

  • You want to know what your cloud really costs — and why — before signing off the next budget
  • A migration, sovereignty or consolidation project is coming and the decision needs a basis
  • The environment grew organically and nobody can explain it end to end
  • You want a second opinion from architects with no stake in the follow-on project

Not ideal for

  • Environments with current IaC, clean cost attribution and documented architecture — there is little to find
  • Pure price negotiations with your provider, with no architecture question attached
  • Single applications without a meaningful cloud estate behind them

THE STACK

Production-tested tools, not a wish list.

  • AWS
  • GCP
  • Azure
  • Hetzner
  • OVHcloud
  • Terraform
  • Pulumi
  • OpenTofu
  • Kubernetes
  • Snowflake
  • BigQuery
  • dbt

What is cloud architecture audit consulting?

A cloud architecture audit is an independent, time-boxed review of an existing cloud environment along three dimensions: cost (drivers, attribution, savings potential), sovereignty (CLOUD Act exposure, data residency, encryption and key ownership) and reproducibility (infrastructure-as-code coverage, audit trail, bus factor). We run it read-only and deliver findings, an assessment and a prioritised roadmap at a fixed price.

Common questions —
straight answers.

What does a cloud architecture audit cost?

It runs at a fixed price that depends on the size of the environment — accounts, providers, workloads. We name the exact figure after a short scoping call, before you commit rather than after. There is no day-rate extension: the scope is set before we start.

Do you need access to our production environment?

Read-only. The audit works from read-only roles on billing data, IAM overviews and resource inventories. We change nothing, deploy nothing and need no write permissions — afterwards the environment is exactly as we found it.

What do we get at the end, concretely?

A findings report in three parts: quantified cost drivers and savings potential, a sovereignty assessment covering CLOUD Act exposure, data residency and key ownership, and a prioritised roadmap with effort estimates. The document is yours — as a decision basis, a negotiation tool, or the starting point of a project.

Does the audit lead to a follow-on project with you?

Not by design. The roadmap is written so your own team or another partner can execute it. If you do want to build with us afterwards we already know the environment — but the audit sells a diagnosis, not a project.

How long do the findings stay valid?

The cost picture moves fastest — expect it to drift within a couple of quarters as workloads change. The sovereignty assessment and the reproducibility baseline hold considerably longer, because they describe design decisions rather than usage. Most clients treat the roadmap as valid for a budget cycle.

Related work

HEALTHCAREAn EU-sovereign data platform for a healthcare provider100%EU-resident data16 wkend to end

Ready to put cloud architecture audit into production?

A 30-min call. We'll bring an architecture sketch and a rough number.

Book a call

or write: hello@saloid.com · gräfelfing · de