Cloud cost optimisation
AWS and GCP bills cut by rightsizing instances, removing idle and orphaned resources, fixing egress and NAT charges, and buying the right commitments. Typically 20–40% off the monthly bill.
We run cloud infrastructure for companies that have production systems and no dedicated DevOps engineer — the deploys, the monitoring, the security and the bill. Monthly retainer, a fraction of the cost of the hire.
No commitment. You'll leave the call knowing what's wrong whether or not you work with us.
What we do
Pick one piece or hand over the whole thing. Most teams start with an audit and keep us on for the parts they'd rather never think about again.
AWS and GCP bills cut by rightsizing instances, removing idle and orphaned resources, fixing egress and NAT charges, and buying the right commitments. Typically 20–40% off the monthly bill.
Cloud security review covering IAM permissions, public exposure, secrets management, unpatched images and MFA gaps — with each finding ranked by real risk rather than scanner severity.
Build and deployment pipelines in GitHub Actions, GitLab CI or ArgoCD. Automated tests, staged rollouts, one-click rollback, and deploys that any engineer on the team can run safely.
New environments built properly from the start, or existing ones migrated — between clouds, off bare metal, or away from a setup that grew by accident and nobody fully understands.
Metrics, logs and traces in one place using Prometheus, Grafana and OpenTelemetry. Alerts tied to things that actually matter, so you hear about problems before your customers do.
Cluster design, upgrades, autoscaling, resource limits and cost control on EKS, GKE or self-managed Kubernetes. Also honest advice about whether you need Kubernetes at all.
Your environment described in Terraform or Pulumi — version controlled, reviewable, reproducible. No more configuration that exists only in the console and in one person's memory.
On-call rotation, escalation policy, runbooks and postmortems. We can back up your team's rotation, or take first response entirely on the higher tiers.
Backups that are verified by actually restoring them, documented recovery procedures, and a tested answer to how long you'd be down in the worst case.
PostgreSQL and MySQL tuning, connection pooling, replication, failover and slow-query work — for teams whose database has quietly become the thing everything waits on.
Inference and training spend brought under control: right-sized GPUs, batching, autoscaling, spot capacity and caching — without losing throughput. The fastest-growing line item in most budgets.
The technical controls auditors ask for — access control, logging, encryption, change management — put in place before the audit rather than during it.
Who we are
We're a small group of infrastructure engineers, each with more than ten years running production systems. No account managers, no juniors learning on your infrastructure — the person who scopes your work is the person who does it, and you'll know them by name.
Founded by Dmitrii Branitskii, an infrastructure engineer with twelve years on production systems: most recently trading infrastructure where downtime is measured directly in money, and before that infrastructure at Consensys and engineering at the Ethereum Foundation.
Most of what we do is unglamorous and much the same everywhere — keeping the thing up, keeping the bill sane, keeping people out. You are almost certainly not the first team with the problem you have.
Certifications
Pricing
Start with an audit. If you like what's in it, put us on a retainer — and if you don't, take the report and fix things yourself. That's a perfectly good outcome.
Retainers are invoiced on the 1st for the month ahead, 14-day terms, 30 days' notice to cancel.
Unused hours roll over one month. Projects are 50% up front. Invoiced from Portugal, EU-compliant,
reverse charge for EU businesses. Bank transfer, card or USDC.
For comparison: a mid-level DevOps engineer in Western Europe costs €80–110k plus employer
contributions, takes three to six months to hire, and moves on after about two years.
Contact
Thirty minutes. We'll go through your setup and tell you what we'd look at first and what worries us — whether or not anything follows from it.
Pick a slot that suits you. Video call, no preparation needed.
Open the calendarTypically available within 2–3 working days
Tell us roughly what you're running and what's bothering you.
Or just email hello@staysup.io
For the audit, read-only is enough — a scoped role with no write permissions, which you can revoke the day the report lands. For retainer work we need write access to the parts we're responsible for, scoped to those. You keep the root account throughout.
Then you probably want the audit rather than the retainer. A second pair of eyes on someone else's work is worth €500 once a year, and we'll tell you honestly if there's nothing to do.
Then you've paid €500 for a clean bill of health and can stop thinking about it. It happens, though not often — usually the cost findings alone cover the fee within a month.
30 days' notice, any time, no reason needed. No annual contracts. If it isn't worth it in month three, you shouldn't be paying in month four.
Retainers include incident response within the stated window. We're not a 24/7 NOC and won't pretend otherwise. What we do instead is set things up so 3am incidents mostly stop happening, and so the ones that do have a runbook your team can follow without us.
AWS and GCP primarily; Kubernetes, Terraform, Docker, GitHub Actions, ArgoCD, Prometheus, Grafana, OpenTelemetry, PostgreSQL. If you're on something unusual, say so on the call and we'll tell you straight whether we're the right people.
If your cloud bill is under about €2,000/month, a retainer probably isn't worth it for you yet — the audit might still be. We'll say so rather than sell you something you don't need.