KeMeT Tech
← All practice areas
02 / Cloud

Multi-cloud architecture

Landing zones and reference architectures that hold up under audit and stay cheap.

What we ship

A landing zone that an enterprise security team will accept on first review. Network topology, identity model, policy-as-code, logging pipeline, budget guardrails, and a written rationale for every decision.

On Azure: management group hierarchy, hub-and-spoke with Azure Firewall or NVA, Entra ID with conditional access, Defender for Cloud baseline, Azure Policy assignments, custom diagnostic settings to a central Log Analytics workspace.

On AWS: Control Tower or hand-rolled multi-account, Transit Gateway hub, IAM Identity Center, Security Hub baseline, SCPs, CloudTrail Organization Trail. On GCP: organization hierarchy, Shared VPC, Cloud Identity, SCC, custom org policies.

Why the scope is predictable

Cloud landing zones are well-understood. The scope is finite. We have shipped enough of them that estimation is precise. You get the deployed infrastructure plus the architecture decisions document, not a stack of slides and a change-order request.

Cost outcome

Every engagement includes a cost-recovery pass: spot reservations, idle resource cleanup, right-sizing, savings plans, commitment discounts. Typical month-one cut on a single workload is twenty to thirty percent. We document where every dollar went so finance can sign off.

What you receive

Deliverables, by line item.

  • Deployed landing zone in your account
  • Architecture decision record covering every choice
  • Policy-as-code library (Azure Policy, SCP, OPA, or Sentinel)
  • Network diagram with every flow labelled
  • Cost baseline and savings recommendations
  • Production runbook for routine ops
How the engagement runs

Four steps, no mystery.

  1. 01
    Discovery call

    Thirty minutes with the senior engineer who does the work. Your environment, your constraint, your deadline.

  2. 02
    Written scope in 48h

    Deliverables, timeline, and one fixed price, in writing. Sign it through your normal procurement flow.

  3. 03
    Build in your tenant

    Work lands in your repos and your cloud accounts from week one. A demo of working output every week.

  4. 04
    Handoff, documented

    Runbook, architecture decisions, and a working session with your team. You own everything we built.