Cloud & DevOps

Cloud infrastructurebuilt to scalewith your business.

We design, automate and manage secure, reliable and cost-efficient cloud environments, with DevOps built in from day one.

  • Cloud strategy
  • Infrastructure as code
  • CI/CD
  • Observability
  • Cloud security
Amazon Web Services
Microsoft Azure
Google Cloud

Multi-cloud. Your choice. Our expertise.

  • Faster releasesCI/CD pipelines
  • Higher reliabilityMonitoring and alerting
  • Cost optimisationRight-sized infrastructure
  • Stronger securityGovernance and compliance
  • ISO/IEC27001
  • ISO/IEC42001
  • DPA andBAA ready
  • AWS, Azure,Google Cloud
  • All cloudregions

OrbitNexa designs, migrates and runs cloud platforms on AWS, Microsoft Azure and Google Cloud, as Terraform, with GitOps delivery gated by security scans, Kubernetes on EKS, AKS or GKE, and FinOps that attributes every workload's spend to an owner. India regions by default, UK and EU regions where the data requires it, under ISO/IEC 27001 and ISO/IEC 20000 certified operations.

What we build

Six disciplines, and what each one means on each cloud.

The same Terraform, GitOps and DevSecOps disciplines on AWS, Azure and Google Cloud; the managed services differ and the cards name them.

  • Landing zones & architecture

    Accounts, networks, identity and guardrails as Terraform, on whichever cloud you run.

    AWS Control Tower · Azure Cloud Adoption Framework landing zone · Google Cloud foundation · region pinning by policy

    DPDP · RBI localisation · NHS UK residency · DORA exit plans

    TerraformAWSAzureGoogle Cloud
  • Migration & re-architecture

    Lift-and-shift where it is right, rebuild to cloud-native where it pays, with reconciliation before cutover.

    VMware exit · Windows and SQL Server modernisation · databases to RDS, Aurora, Cloud SQL or Azure SQL · DR with a tested restore

    Assess · mobilise · migrate, wave by wave

    TerraformDockerVeleroAWS
  • Kubernetes platforms

    Clusters with autoscaling, ingress and health-checked rollouts, where a rollback is a revert.

    EKS, AKS or GKE · Helm and Argo CD · Karpenter · Cilium · cert-manager · a platform assessment scored on five dimensions

    GitOps maturity · multi-tenancy · Backstage where it fits

    KubernetesHelmArgo CDKarpenter
  • CI/CD, GitOps & supply chain

    Build once, scan, sign, attest, promote the same artefact, reconcile the cluster to the repository.

    GitHub Actions · SBOM per build · SLSA provenance · Sigstore-signed images verified at admission with Kyverno · Trivy, Checkov and SonarQube as merge gates

    A critical finding blocks the merge · secrets in Vault, never in the repo

    GitHubTrivySonarQubeVault
  • FinOps & cost optimisation

    Spend attributed per workload, findings shipped as Terraform changes rather than slides.

    Allocation and tagging policy · unit economics per transaction, tenant or model call · anomaly management with an owner per alert · rate and usage optimisation · GPU and token attribution

    FinOps Framework 2026 · Kubecost, OpenCost, Infracost in pull requests

    KubecostInfracostAWSAzure
  • Monitoring, SRE & AI infrastructure

    SLO-based alerting, on-call that reaches an engineer, and GPU workloads on the platform you already run.

    Prometheus, Grafana, Loki, Tempo · CloudWatch, Azure Monitor, Cloud Monitoring · GPU node pools with Karpenter or KEDA · vLLM and KServe serving · Kueue scheduling

    DR runbooks and tested restores · cost attributed per model

    PrometheusGrafanaOpenTelemetryvLLM

Cloud & DevOps

Commit to production.

  • Declared
  • Gated
  • Attributed
  • Cost attributionPer workload, owned.

Our process

From a review to a platform you operate.

A structured programme with a named artefact per phase: the findings list, the landing-zone design, the pipeline definitions, the DR test record, the monthly cost and reliability review.

  1. 01

    Review

    Discovery & Strategy

    1-2 weeks

    We map your ecosystem, constraints and KPIs before any engineering starts, so every technical decision has a reason on record.

  2. 02

    Design

    Architecture & Design

    2-3 weeks

    Architects draw the system and designers prototype the interface, both reviewed and signed off before a line of code is written.

  3. 03

    Build

    Agile Development

    4-12 weeks

    Iterative sprints on modern frameworks, with a senior engineer reviewing every pull request before it merges.

  4. 04

    Harden

    Quality Assurance

    2-4 weeks

    Automated unit, integration and acceptance tests, plus performance and security checks against real-world scenarios.

  5. 05

    Operate

    Launch & Evolution

    Ongoing

    A zero-downtime deployment, then continuous monitoring and iterative enhancement as your standing technical partner.

The first thirty days.

Discover, stabilise, document, operate.

  1. Week 1Read access, an architecture and bill walk-through, tagging and ownership gaps listed.
  2. Week 2Alerts that page a person, backups verified by a restore, the first Terraform imports.
  3. Weeks 3–4Runbooks, escalation matrix, asset register, on-call rota; the first findings shipped as pull requests.
  4. Day 30 onMonthly cost and reliability review; the retainer, or the hand-back with everything in your accounts.
  5. Every quarterCommitment and reservation review, a disaster-recovery test, the platform assessment re-scored.

Who is on the engagement.

Overlap with UK and Indian working hours every day, a shared channel, a weekly call and a monthly cost and reliability review.

  • Engagement leadA senior platform engineer, not an account manager
  • Two to three platform engineersTerraform, Kubernetes, pipelines
  • Security engineerScanning gates, supply chain, policy
  • FinOps practitionerAttribution, unit economics, the monthly review
  • On-call rotaA stated acknowledgement window per tier
The full process, phase by phase

Let’s build together

Have an idea?
Let’s make it real.

Tell us about your goals. We’ll help you find the right way forward.

  • Share your idea

    Tell us what you're looking to build.

  • Explore possibilities

    We'll understand your goals and suggest the right approach.

  • Plan the next steps

    Together we define the roadmap.

  • Build what's next

    Turn ideas into real impact.

Let’s discuss
your project

Whether it’s a new product, a platform upgrade or a complex challenge, we’re here to help.

Get in touch

Engagement models

Start with the review. Everything after it is optional.

Shapes described by what happens, how long they run and what you hold at the end. Managed tiers by scope, never by price.

  • Migration or Re-architecture

    Lift-and-shift or rebuild to cloud-native: landing zone, Kubernetes or serverless, CI/CD and GitOps wired from the first week.

    TeamLead, two to three platform engineers, security engineer
    Timeline8 – 16 weeks for the first wave
    Key deliverablesA Terraform-defined platform with the delivery pipeline live and gated
  • Kubernetes Platform Assessment

    For a platform that already exists but is not working well: scored on security, reliability, cost, GitOps maturity and multi-tenancy.

    TeamLead and a platform engineer, with your platform team
    Timeline2 – 3 weeks
    Key deliverablesA scorecard with the evidence used and a remediation plan brought under Terraform incrementally
  • DevOps & SRE Retainer

    Three tiers by scope: business-hours advisory; on-call with a stated acknowledgement window; 24×7 with a named SLO after a baseline period.

    TeamA named engineer and the on-call rota
    TimelineOngoing, cancellable with notice
    Key deliverablesIaC ownership, scanning gates kept in the pipeline, a monthly reliability report, a quarterly DR test

Start with a cloud architecture review

2 – 4 weeks

Six pillars — operational excellence, security, reliability, performance, cost, sustainability. A senior engineer reads the architecture and the bill together, runs the question set for your cloud, and scores each pillar. You leave with a findings list ranked by risk, a remediation roadmap, and the infrastructure findings shipped as reviewed Terraform pull requests. On AWS it follows the Well-Architected review format. No commitment beyond it.

Request the review

Yours, from the first commit.

Your Git, your accounts, your state file, your runbooks.

  • Everything in your Git and your cloud accounts

    Terraform lives in your repository and applies against your accounts; nothing is held anywhere else.

  • Terraform state in your backend

    Ending the retainer changes nothing about where the platform lives.

  • Documented handover at any point

    Runbooks, the asset register and the escalation matrix are written for your team first.

  • Notice-based cancellation, no exit fee

    The retainer stops with notice. More capable, not more dependent, is the test.

Regulated cloud

Region pinning, DPDP, RBI, NHS and DORA exit plans, built into the landing zone.

What we build for healthcare and banking clients in India and the UK, and the supply-chain baseline every pipeline carries.

India · United Kingdom and EU

  • India — region pinning enforced by policy (SCPs, Azure Policy, organisation policies); DPDP Rules 2025 controls with the May 2027 deadline named; RBI payment-data localisation; CERT-In logging retention; MeitY-empanelled sovereign options when a regulator requires them
  • UK and EU — UK-region residency for NHS data; DTAC v2 and DSPT evidence; FCA/PRA SS2/21 and DORA Article 28 exit-plan documentation delivered as a runbook; EU sovereign regions where required

Supply chain: every image signed, every build attested, every merge scanned

  • SBOM generated per build
  • SLSA provenance attested
  • Images signed with Sigstore cosign and verified at admission with Kyverno or OPA Gatekeeper
  • Trivy, Checkov or tfsec and SonarQube as merge gates
  • Secrets in Vault or the cloud secrets manager with external-secrets, never in the repository

AI in our workflow.

We use it, we say so, and nothing it writes merges without a person.

  1. 01We use AI coding tools — GitHub Copilot, Cursor, Claude Code — for scaffolding, tests and migrations, and we say so.
  2. 02Nothing they produce merges without a human review and a passing test suite: the same gate as any other change.
  3. 03The review trail shows who approved what, so an auditor cannot tell a generated line from a typed one, and does not need to.

FAQ

Questions?
We're here to help.

Straight answers for a platform lead and a CFO. Still have a question? We're just a message away.

Get in touch
  1. 01Which clouds do you work on?
    AWS, Microsoft Azure and Google Cloud. India regions by default for data residency: AWS Mumbai (ap-south-1), Azure Central India (Pune) and Google Cloud Mumbai (asia-south1). The same Terraform, GitOps and DevSecOps disciplines apply on all three; the managed services differ and the coverage list on this page names them.
  2. 02What does a cloud cost audit actually produce?
    A bill where every line resolves to an owner, a per-workload attribution rather than an account total, and a written remediation plan whose findings arrive as reviewed Terraform pull requests. It takes one to two weeks and carries no commitment to engage further.
  3. 03Who owns the Terraform when you leave?
    You do. It lives in your repository, applies against your accounts, and its state is in your backend. The retainer keeps an engineer on it; ending the retainer changes nothing about where it lives.
  4. 04How do you keep our data in India?
    Region pinned in the landing zone and enforced by policy: AWS Service Control Policies, Azure Policy or Google Cloud organisation policies deny resources outside the chosen region. Backups and logs stay in-region too, and the DPDP Act controls are drawn into the architecture diagram your security team reviews.
  5. 05Can you take over an existing platform rather than build a new one?
    Yes, and most retainers start that way. The audit reads what is there first; the retainer then brings the platform under Terraform incrementally, adds the scanning gates to the existing pipeline, and puts an engineer on call for it.
  6. 06EKS, AKS or GKE?
    The one on the cloud you already run. The Terraform, GitOps and security disciplines are identical; the managed add-ons differ and the review names them.
  7. 07How long does a migration take?
    Assess in two to four weeks, mobilise the landing zone and pipeline in four to eight, then migrate workload by workload with reconciliation before each cutover. Most programmes run eight to sixteen weeks for the first wave.
  8. 08Can you fix a Kubernetes platform that already exists but isn't working well?
    Yes. The platform assessment scores it, and the retainer brings it under GitOps and Terraform incrementally.
  9. 09What is your on-call commitment?
    A stated acknowledgement window per tier, and an SLO agreed after a baseline period rather than promised on day one.
  10. 10Consulting or managed service?
    Both, in sequence: the review and the build are projects; the retainer is the managed service, and you can stop it with notice.
  11. 11How do you keep our software supply chain secure?
    SBOM per build, SLSA provenance, signed images verified at admission, scans as merge gates, secrets never in the repository.
  12. 12Can you run GPU workloads for our models?
    Yes, on the same Kubernetes platform: GPU node pools, vLLM or KServe serving, Kueue scheduling, and cost attributed per model.

Want your cloud bill read line by line?

A senior engineer reads your architecture and your bill together, then hands over a written remediation plan. No commitment to engage further.

+91 912-195-7728Hyderabad, IndiaEvery brief gets a senior review. Reply within 1 business hour, 9 AM-7 PM IST.