Enterprise Cloud Platforms & Hybrid Cloud Infrastructure
Azure, AWS, and Google Cloud — sized against the workload and the compliance line
Most cloud migrations move workloads first and discover governance, cost and data residency later. We start from the compliance line — where the provider's duty ends and yours begins — and build the landing zone before the first server moves. Below is the architecture we build toward, and what sits at each point in it.
The architecture we build toward
One line decides everything on this page. Above it, the provider is responsible. Below it, you are — and no contract moves that line as far as most people assume.
- Physical data centre and access
- Hypervisor and host hardware
- Network fabric and backbone
- Hardware refresh and failure
- Data, and where it is allowed to sit
- Identity, access and privilege
- Every configuration choice you make
- Retention, logging and evidence
What we build on them, and the problem each one solves
Seven areas, and the same three platforms across all of them. We do not have a preferred hyperscaler — we have a preferred sequence.
Landing Zone & Governance
Someone opened an account with a credit card, workloads followed, and there is now no policy, no tagging and no way to say who owns what or why it exists.
Compute & Infrastructure
Servers lifted to cloud at the same size they ran on-premises, running continuously, costing more than the hardware they replaced and no faster.
Cloud Storage & Archive
Storage buckets and shares created ad-hoc, permissions widened to make something work, and nobody has audited who can reach what since.
Backup & Disaster Recovery
Cloud used as a backup target with no immutability and no tested restore, or a DR plan that exists as a diagram nobody has ever failed over to.
Identity & Access Management
Standing administrator access in the cloud console, no MFA on privileged roles, and joiners and leavers handled separately from the on-premises directory.
Data Residency & Indian Regions
Resources deployed to whichever region the console offered first, with logs and personal data sitting outside the jurisdiction that CERT-In requires them to stay in.
Cost Governance & Optimisation
A monthly bill nobody can explain, growing steadily, with no owner per line and no idea which resources could be switched off tonight without anyone noticing.
How we design and migrate it
Four stages, and the order is the whole point. Most cloud estates that are painful today were migrated before stage two was completed.
Assess and decide what moves
Not everything should. Plant and OT systems stay put, latency-sensitive workloads stay put, and anything with a licence that punishes virtualisation gets costed both ways before a decision is made.
Build the landing zone
Region chosen deliberately, policy and guardrails applied, identity federated with MFA on privileged roles, network segmented with private endpoints. Before any workload moves, not after.
Migrate in waves
Lowest-risk workloads first, right-sized against measured utilisation rather than historic spec, cutover off-peak, with a rollback plan that has been rehearsed.
Govern it monthly
Cost reviewed with an owner per line, configuration drift checked against policy, access recertified, and the evidence pack kept current for whoever audits you next.
What this changes
Three outcomes that separate a cloud estate from a collection of subscriptions.
The bill stops being a surprise
Tagged resources, an owner per workload and a monthly review turn cloud spend from an unexpected line item into something a finance director can forecast. Rightsizing at migration is where most of the saving actually is.
Residency is a decision you made
Region selected on purpose, logs held inside Indian jurisdiction, and a written answer ready when a customer or an auditor asks where the data physically sits. Very few organisations can prove that today.
The contract matches reality
Rule 6(1)(f) requires the security obligation in the processor agreement. Having a clause, and knowing which side of the line each control sits on, is what turns a cloud migration into something defensible.
What you receive
Documentation is part of the supply, not an extra. All of it is yours.
- Workload assessment with a move, keep or retire decision per system
- Cost model comparing on-premises against each platform over five years
- Identity and access design with privileged roles defined
- Processor agreement clauses aligned to Rule 6(1)(f)
- Landing zone design covering region, policy, identity and network
- Migration plan sequenced by risk, with rehearsed rollback
- Data residency statement naming the region for every workload
- Monthly governance pack: cost, drift, access recertification
Where to go next
The service that implements it, and the obligation that requires it.
Questions buyers ask us
Including the ones nobody enjoys answering.
Which platform do you recommend?
Does moving to cloud transfer our DPDP obligation?
Can our logs legally sit in a cloud region outside India?
Will cloud be cheaper than buying servers?
Should everything move?
Who holds the administrator credentials?
Need Help Sizing and Sourcing Enterprise Cloud Platforms & Hybrid Cloud Infrastructure?
Get a written 3-OEM BoQ comparison, sizing worksheet with telemetry validation, and DPDP/CERT-In compliance mapping from our certified architects.
