Skip to content
All services
Architecture & Design

Cloud and data architecture, written down.

For teams about to build, replace, or scale a platform that has quietly outgrown its first design. A focused engagement that ends in a written architecture, an IaC scaffold, a security baseline, and a roadmap you can execute against.

What we cover

Architecture engagements are wide on purpose. The scope depends on what your platform actually needs — most engagements pick four to six of the following domains. The Discovery Sprint narrows it down.

  • Cloud landing zone. Multi-account / multi-subscription structure, OU layout, baseline guardrails, cross-account networking, IAM blueprint, secret management, tagging and FinOps allocation.
  • Multi-region & multi-cloud. Active-active vs active-passive, replication topology, failover sequencing, network topology, latency budgeting. Honest opinions about when multi-cloud is wrong (it usually is).
  • Data platform & lakehouse. Warehouse / lakehouse selection, medallion vs vault vs star, semantic layer adoption, dbt project structure, orchestration design, BI repointing strategy.
  • Security baseline. IAM least-privilege, encryption at rest and in transit, key rotation, audit logging, network isolation, secret management, SOC 2 / ISO 27001 / HIPAA / DPDP-ready posture.
  • Disaster recovery & BCP. RPO / RTO budgets per workload, backup strategy, cross-region failover, runbook authoring, tabletop exercise design, restore-test automation.
  • Observability. Logging, metrics, traces, SLOs, SLIs, error budgets, alerting policy, on-call rotation design. Tool-agnostic — we will tell you when Datadog is the right answer and when Prometheus + Grafana + Loki is.
  • CI/CD & platform engineering. Build pipelines, IaC modules, environment promotion, golden paths, internal developer platform design.
  • API & microservices. Domain boundaries, sync vs async, event-driven patterns, mesh vs ingress, contract testing, API gateway selection.

What you receive

  • Written architecture document (60 – 120 pages) covering the chosen domains, with rejected alternatives and reasoning.
  • IaC scaffold — Terraform organized by environment, modular, not pseudocode. Your team extends it on day one.
  • Security baseline with explicit gap remediation steps per relevant framework (SOC 2 CC, ISO 27001 Annex A, DPDP).
  • 12-month roadmap with sequenced milestones, headcount estimate, and budget bands per phase.
  • Vendor-neutral build estimate — what it will cost with your team, with us, or with a Big SI.

When to engage us

  • You are about to commit seven figures in platform spend and want a second opinion before signing.
  • Your current platform was built three years ago by people who have since left, and the team is afraid to touch it.
  • You need a credible architecture artifact to present to leadership, a board, or an auditor.
  • You are about to migrate or merge platforms (post-M&A) and need the target state designed before you start moving.

How we engage

Starts with the Discovery Sprint (₹2 – 3 L / $3 – 5k, 10 days) — we scope which architecture domains are load-bearing for you and quote the full engagement. Architecture Engagement itself runs 3 to 8 weeks depending on scope, fixed fee, two engineers, three working sessions with your team.

If you proceed to a build, migration, or platform-management engagement with us within 60 days, the 5% Combo discount applies on that follow-on SOW.

FAQ

Can you architect for a specific cloud only?

Yes. Single-cloud designs (AWS, GCP, Azure) are the common case. Multi-cloud designs are rarer and usually wrong — we will tell you if your case is the exception.

Do you cover compliance?

Security baseline covers SOC 2, ISO 27001, HIPAA-ready, and India DPDP-ready postures. We do not run the audits themselves — that is your auditor's role.

What if my team disagrees with the architecture?

That is what the three working sessions are for. The final architecture is a synthesis, not a delivery. If we genuinely disagree on a load-bearing decision, the document records both positions with reasoning.

Who this is for

Does any of this sound familiar?

If it does, the next section explains how the engagement model is structured to address each one.

You're about to commit seven figures to a platform build. The vendor gave you a reference architecture. You'd like a second opinion before signing.

An architecture engagement runs 3–8 weeks against a fixed fee. Output is a written architecture document with rejected alternatives and reasoning, an IaC scaffold, and a 12-month roadmap — not a vendor pitch deck with boxes.

Your platform was designed three years ago by engineers who have since left. The current team is afraid to touch it.

The Discovery Sprint maps what's there — dependency topology, blast-radius per change, the design decisions nobody wrote down. The architecture engagement produces the missing written baseline your team can actually work from.

You need a credible architecture document to present to your board, your auditors, or a Series C investor. Your current 'architecture' is a whiteboard photo.

Architecture documents from this engagement are 60–120 pages. They cover the chosen domains, explicitly document rejected alternatives with reasoning, and include a security baseline mapped to SOC 2 / ISO 27001 / DPDP controls. Designed to be read by someone who wasn't in the room.

The team keeps debating warehouse vs. lakehouse. Medallion vs. data vault. The conversation has been running for two quarters without a decision.

That decision gets made in the Discovery Sprint based on your data volumes, query patterns, team maturity, and build economics — not on vendor marketing. The architecture document records the reasoning, not just the answer.

You're post-acquisition and need to merge two platform stacks. Nobody has written down what the target state looks like.

Post-M&A platform design is a defined engagement. Target state is designed before any data moves — which platform wins per domain, which stays dual-run, which gets retired. Written architecture first, execution second.

The Migration Engine

One discipline, every engagement.

Every migration runs the same six-stage pipeline: Inventory, Plan, Convert, Validate, Reconcile, Report. Human sign-off gates enforce the stage boundaries that matter.

STAGE 1 INVENTORY Read-only sweep STAGE 2 PLAN Wave + dependency map HUMAN GATE STAGE 3 CONVERT Rule library + handlers STAGE 4 VALIDATE Checksums + diffs STAGE 5 RECONCILE Daily diffs, parallel run STAGE 6 REPORT Co-signed cutover doc Scope sign-off required before conversion begins
Read how the engine works stage by stage
Why us

The rest of the market vs. what we do differently.

Every promise in this table lives in the contract, not the pitch deck.

Dimension Traditional T&M SI Replatform
Pricing model Time & materials — final cost unknown at project start Fixed-fee against a written Appendix A — no surprises
Staffing Senior pitched, junior delivered — bench economics drive the swap The engineer on the first call is the engineer in the repo
Validation Verbal sign-off or sampling — "it looks right" Deterministic row counts, checksums, query diffs — signed artefact you keep
Scope creep Absorbed into T&M — change orders often verbal, billed later Anything out-of-scope is a written Change Order before work begins
Timeline Months of ramp, discovery, re-discovery, re-scoping Fixed Discovery Sprint produces inventory + wave plan before you commit to execution
How to engage

How to start an architecture engagement.

A cost read to understand the current state, a sprint to scope the domains, then a written architecture engagement. Each step is a standalone deliverable.

01 · Free

FinOps Quick-Check

Free
2 minutes · no email

If cost is a driver in your architecture decision — which platform or cloud to land on — the Quick-Check gives you a waste range on your current setup before you commit to a target state.

Run the Quick-Check
02 · Cost review

Cloud Cost X-Ray

Free
through Q3 2026 · 90-min live session

A live working session on your current warehouse or cloud bill. Useful before an architecture engagement to understand the cost shape of the current state and the economics of alternatives. After Q3 2026 reverts to $100.

Send me your bill
03 · Scoped sprint

Discovery Sprint

Fixed-fee
₹2–3 L / $3–5k · 10 business days

Maps your current platform: topology, dependencies, design constraints, gaps. Scopes which architecture domains are load-bearing for your situation and produces the fixed quote for the architecture engagement.

Start with a Discovery Sprint
04 · Engagement

Architecture Engagement

Contact
scope-quoted, fixed-fee · 3–8 weeks

Written architecture (60–120 pages), IaC scaffold, security baseline, 12-month roadmap, vendor-neutral build estimate. Domains: landing zones, lakehouse, DR/BCP, security, observability, CI/CD, API design.

Talk to us
Founder-led delivery

The people doing the work.

Yash Maheshwari
Founder · Replatform

Cloud and data platform engineer with 6+ years across migrations, lakehouse architecture, FinOps, and managed platform operations on AWS, GCP, Azure, Snowflake, Databricks, BigQuery, and Redshift. The engineer on your first call is the engineer in your repo — no bench hand-offs, no junior substitutions.

Not ready to talk?

Download the Migration Readiness Checklist

A structured pre-engagement checklist covering platform topology, security constraints, compliance requirements, and the questions to answer before an architecture engagement starts.

Get the checklist