Account
Cloud infrastructure operations

We run the cloud science runs on.

The scientific platforms on top, and the security, network, backup and cost backbone underneath. We work with research, biotech and energy sector enterprises whose operations depend on cloud infrastructure. Most of our record comes from biotechnology, and it remains our flag vertical: teams need platforms that work, and the layer underneath needs an owner.

11 platform capabilities · 13 backbone layers · AWS & GCP.

Two layers

What we operate

Two layers, one hand. The platforms your teams work in, and the backbone that keeps them secure, connected, backed up and affordable.

Layer 01

Scientific platform operations

Installation, version upgrades, migration, maintenance and daily operations for the platforms your teams use every day. Our deepest catalogue is research computing; the same discipline carries to any workload on the same cloud services.

Cloud Service Tech
AWS + GCP HPC clusters and Slurm scheduler-managed clusters provisioned as code, sized for the workload and rebuilt rather than repaired.
  • Slurm
  • AWS ParallelCluster
  • CloudFormation
  • EC2 GPU
AWS + GCP Schrödinger Maestro and license server operations: installation, version upgrades, cross-account license access.
  • Schrödinger
  • Maestro
  • License Server
AWS + GCP Dotmatics and D360 application servers on DEV and PROD, load balancing, TLS and single sign-on integration.
  • Dotmatics
  • Certara D360
  • ALB
  • ACM
  • Okta OIDC
AWS + GCP RStudio / Posit and Shiny server builds, packages compiled from source, LTS upgrades without breaking user configuration.
  • RStudio Server
  • Shiny
  • R
  • Ubuntu Pro/ESM
  • nginx
AWS + GCP Jupyter and managed notebooks migration from user-managed instances to managed Workbench, service-account scoping.
  • Jupyter
  • Vertex AI Workbench
  • Service Accounts
AWS + GCP ELN and lab data platforms Signals, Spotfire and Egnyte: integration, access paths, serverless bridges to messaging.
  • Signals
  • Spotfire
  • Egnyte
AWS + GCP Scientific database operations Oracle on DEV and PROD: version upgrades, restores from backup, capacity and performance.
  • Oracle
  • EC2
  • EBS Snapshot
  • AMI
AWS + GCP Proteomics, structural biology and AI/NLP workloads cryo-EM reconstruction, ParallelCluster, GPU nodes and notebook pipelines.
  • AWS ParallelCluster
  • CryoSPARC
  • Open OnDemand
AWS + GCP Scientific and lab application servers Pipeline Pilot, Knime, FragPipe and Bartender: builds, domain join, licence handling.
  • Pipeline Pilot
  • KNIME
  • FragPipe
  • BarTender
  • Managed AD
AWS + GCP Instrument data platforms capacity planning, archival strategy and licence management for instrument databases.
  • Oracle
  • EBS Snapshot
  • S3 Glacier
AWS + GCP End-of-life modernisation in-place LTS upgrades and clean rebuilds, with user configuration carried through intact.
  • Ubuntu Pro/ESM
  • Ubuntu LTS
  • Machine Images
Layer 02

The backbone

The services we run for everything those platforms stand on — identity, security, network, backups and cost discipline.

Cloud Service Tech
AWS + GCP IAM and service-account hygiene least-privilege accounts scoped per resource, dormant key cleanup, actAs audit.
  • AWS IAM
  • GCP IAM
  • Permissions Boundary
  • MFA
AWS + GCP Security operations wiz.io and CIS Benchmarks: continuous findings, alarm tuning, remediation you can audit.
  • wiz.io
  • Security Hub
  • GuardDuty
  • AWS Config
  • CIS
AWS + GCP Third-party tooling you already run Cloud-native services are the default. Where a third-party security platform is already in place, we operate it alongside them or feed its findings into the infrastructure controls — you are not asked to drop what works.
  • wiz.io
  • Security Hub
  • AWS Config
  • EventBridge
AWS + GCP Identity Okta SSO, Managed AD and MFA on one directory, with federation kept in sync.
  • Okta
  • Managed Microsoft AD
  • AWS SSO
  • MFA
AWS + GCP Network VPN, VPC peering, load balancers and DNS, including cross-cloud HA tunnels verified over BGP.
  • Site-to-Site VPN
  • GCP HA VPN
  • Cloud Router
  • BGP
  • DNS
AWS + GCP Certificate lifecycle issuance, a renewal calendar and expiry alerting, so a chain never runs out unnoticed.
  • ACM
  • Certificate Manager
  • PKI
  • CloudWatch
AWS + GCP Patch and backup cadence a monthly OS patch round across both clouds, and backup plans that are actually restored from.
  • AWS Backup
  • EBS Snapshot
  • GCP Snapshot
AWS + GCP Cost discipline rightsizing, anomaly investigation, idle-resource cleanup and lifecycle tiering.
  • Cost Explorer
  • Compute Optimizer
  • Rightsizing
AWS + GCP CRO and external partner data exchange scoped identities, cross-account policies, presigned flows for regulated data.
  • S3
  • GCS
  • IAM
  • Presigned URL
AWS AWS WorkSpaces secure desktops for overseas teams without issuing them VPN or directory accounts.
  • AWS WorkSpaces
  • Transit Gateway
  • AD Connector
AWS + GCP Serverless integrations Cloud Run and functions behind private egress, reaching databases inside the VPN.
  • Cloud Run
  • Cloud Functions
  • AWS Lambda
  • Serverless VPC Access
AWS + GCP Vendor deprecation management database, container and desktop end-of-life notices tracked and closed before the deadline.
  • Oracle
  • Ubuntu LTS
  • Container Runtimes
AWS + GCP Observability and live dashboards centralised audit logs and purpose-built dashboards behind VPN.
  • BigQuery
  • Cloud Logging
  • CloudWatch
  • Cloud Run

If something you run is not on this list, write anyway; if it runs in your cloud and your business depends on it, it is in scope.

The model

How the work runs

When the work grows, a defined project becomes permanent operational ownership, and the operation stays visible through live dashboards. You don't create an account to start: we talk, write the scope down, and define the project. Accounts come later, by invitation, when the work becomes ongoing.

Project

Every engagement starts as a defined project. We write the scope down and price it for the job.

Ownership

When the work grows, it becomes permanent operational ownership: we take the account, we operate it, and we answer for the outcome. We keep the client list short and the relationships deep — we have run one biotechnology company's infrastructure this way for years.

Dashboards

The operation stays visible through custom live dashboards. You see what we see.

Visibility

Live dashboards

To keep the operation visible, we build custom live dashboards for what you need — your infrastructure, in real time. We don't hand over raw numbers. Every dashboard carries an engineer's reading: what changed, what it means, and what we did about it.

Start the conversation for your cloud infrastructure.

If your workloads run in the cloud and the layer underneath has no owner, share your requirements and let us discuss the right approach for your environment.