Packages

Three ways to run production Kubernetes.

Launch, Scale and Comply are the same platform at three depths. Each tier contains everything in the one before it, so you start where your team actually is today and move up when the business makes you.

Tier 01

Launch

Production, without the sprawl.

For a first real production cluster, or a team whose deploys are still manual.

Where every engagement starts
  • Managed Kubernetes cluster in your own cloud account
  • Worker nodes in a single availability zone
  • Private network, load balancer and ingress
  • CI/CD pipeline: validate → build → deploy
  • Secret scanning that fails the build on any finding
  • Image scanning that fails the build on critical vulnerabilities
  • Prometheus and Grafana with baseline dashboards
Tier 02

Scale

High availability and a real promotion path.

For production traffic that cannot wait for someone to fix it by hand.

Everything in Launch, plus
  • Worker nodes spread across multiple availability zones
  • Full pipeline: build → security → scan → publish → deploy
  • GitOps promotion across dev, staging and prod
  • Admission policy enforcement and network policies
  • Centralised log aggregation
  • Horizontal autoscaling
  • Acceptance test: we kill a node in front of you and workloads reschedule unattended
Tier 03

Comply

An audit-ready chain of evidence.

For teams heading into SOC 2, ISO 27001 or Cyber Essentials Plus.

Everything in Scale, plus
  • Static application security testing in the pipeline
  • Dependency and supply-chain scanning, per language
  • Infrastructure-as-code scanning
  • Encrypted secrets committed safely to Git
  • Disaster recovery runbook, plus a timed recovery dry-run on your infrastructure
  • Control mapping and evidence your auditor can actually use

Pricing depends on your cloud, cluster size and support level. We quote it after a scoping call, never off a rate card.

Cloud coverage

Every tier, on every cloud we support.

Each combination below has been built and verified on live infrastructure. Provisioned, deployed to, and torn down again. None of it is derived from a reference architecture we have never run.

Cloud Launch Scale Comply
Amazon Web Services EKS
Google Cloud GKE
Microsoft Azure AKS
Oracle Cloud OKE

† Oracle Cloud, Scale and Comply. High availability is currently delivered across fault domains within a single availability domain. That survives rack and hardware failure and rolling maintenance, but not the loss of an entire availability domain. The multi-zone resilience described under Scale applies as written on AWS, Google Cloud and Azure. If Oracle Cloud is your target and you need multi-zone redundancy, raise it on the scoping call. It changes the architecture, and we would rather say so now than in month three.

Support

How it is run is a separate decision.

The tier decides what gets built. Support decides who operates it afterwards. The two are independent. Any tier can be handed over to your team or fully operated by us, and support is quoted separately.

Deploy and hand over

We build it, document it, train your engineers on it, and step back. The platform is yours to run.

Managed

We operate it as an extension of your team: version upgrades, security patching, alert response and regular health reporting.

Premium

Extended coverage hours, tighter response targets, and a standing architecture review as your platform grows.

Straight answers

What these packages don't do.

The limits are easier to read now than to discover during an engagement. This is the list we would give you on a call anyway.

We do not publish a delivery date.

You get a committed timeline on the scoping call, measured against your cloud and your scope, rather than a number pulled from a pricing page.

Recovery targets are measured, not promised.

Comply includes a timed disaster-recovery dry-run on your own infrastructure. That measurement is where a recovery-time commitment comes from, and we will not quote one before it exists.

Failover is not instant on every cloud.

Scale guarantees that workloads reschedule automatically when a node dies. Load-balancer failover behaviour differs between providers, and we share the measured numbers for yours during scoping.

Dynamic testing is not included.

Comply covers static, dependency, image and infrastructure scanning. Dynamic application security testing (DAST) is outside its scope. We are also not an audit firm. We build the controls and produce the evidence, but we do not issue certifications.

Tell us about your cluster.

A free 30-minute call. No slides, no pitch. We look at your actual stack and tell you honestly what we would build.