Migrations
New environments built properly from the start, or existing ones migrated: between clouds, off bare metal, or away from a setup that grew by accident and nobody fully understands.
We would like to measure which pages get read, using PostHog (EU, Frankfurt). It sets a cookie. Nothing is measured unless you agree. See our privacy page.
We help engineering teams build, fix and run reliable cloud infrastructure: architecture, migrations, security, cost and AI reliability.
Written reply within one business day. Fixed prices, invoiced on delivery.
What we do
Pick one piece or hand over the whole thing. Most teams start with an audit and keep us on for the parts they'd rather never think about again.
Run
New environments built properly from the start, or existing ones migrated: between clouds, off bare metal, or away from a setup that grew by accident and nobody fully understands.
Build and deployment pipelines in GitHub Actions, GitLab CI or ArgoCD. Automated tests, staged rollouts, one-click rollback, and deploys that any engineer on the team can run safely.
Cluster design, upgrades, autoscaling, GPU node pools, resource limits and cost control on EKS, GKE or self-managed Kubernetes. Also honest advice about whether you need Kubernetes at all.
Your environment described in Terraform or Pulumi: version controlled, reviewable, reproducible. No more configuration that exists only in the console and in one person's memory.
PostgreSQL and MySQL tuning, connection pooling, replication, failover and slow-query work, for teams whose database has quietly become the thing everything waits on.
Backups that are verified by actually restoring them, documented recovery procedures, and a tested answer to how long you'd be down in the worst case.
Protect
Cloud security review covering IAM permissions, public exposure, secrets management, unpatched images and MFA gaps, each finding ranked by real risk rather than scanner severity.
The technical controls auditors ask for, access control, logging, encryption and change management, put in place before the audit rather than during it.
High-risk record-keeping (Article 12) now applies from December 2027, and transparency duties are already live. Six-month retention means the logs must exist well before the deadline. We build it calmly now, not in a 2027 panic.
Measure
AWS and GCP bills cut by rightsizing instances, removing idle and orphaned resources, fixing egress and NAT charges, and buying the right commitments. Typically 20–40% off the monthly bill.
Metrics, logs and traces in one place using Prometheus, Grafana and OpenTelemetry, LLM and agent traces included. Alerts tied to things that actually matter, so you hear about problems before your customers do.
Your agents report success on every run. We instrument what they actually did, claimed against actual, so a job that loops forever while logging "completed successfully" shows up on a dashboard instead of in an incident.
Who we are
We're a small group of infrastructure engineers, each with more than ten years running production systems. No account managers, no juniors learning on your infrastructure. The person who scopes your work is the person who does it, and you'll know them by name.
Most infrastructure problems aren't unique. We've seen the same patterns across high-traffic, high-stakes production systems: runaway cloud costs, fragile deployments, weak observability, security gaps and infrastructure nobody wants to touch.
What we work in
How it works
A free 30-minute call, or three lines by email: what you are running, what is bothering you, which audit fits. We confirm the scope and the fixed price in writing.
A scoped read-only role on one account, or an export of your traces. We change nothing. What we receive and when it is deleted is on the trace handling page.
Findings ranked by what they cost you, each with a reproduction, plus the checks or queries we used. A 30-minute walkthrough of what we would fix first.
The fixed price agreed in step one, invoiced when the report lands. Anything you want done after that is quoted as a fixed price before it starts.
Pricing
Start with an infrastructure audit. We spend a week on your cloud, security, reliability, delivery pipeline and costs, then hand you a ranked list of what we'd fix and why. Implement it yourself, give it to someone else, or bring us in to do the work. The report is yours either way.
Both audits are a fixed price, invoiced when the report is delivered. Anything beyond an
audit is scoped and quoted as a fixed price before it starts. Nothing is billed that was
not agreed in writing.
We invoice from Portugal. EU business-to-business services are invoiced under the applicable
reverse-charge rules. Bank transfer or card; USDC on request.
Contact
Three lines is enough: what you are running, what is bothering you, and which audit you want. We reply in writing within one business day with a price or a straight no.
This is the front door. Most work starts and finishes by email.
Or just email hello@staysup.io
A free 30-minute review of your setup. Video call, no preparation needed.
Open the calendarTypically available within 2–3 working days
FAQ
If yours isn't here, email it. You get a straight answer either way.
No. Email what you run and which audit you want; we confirm scope and price in writing, we start, and you are invoiced when the report is delivered. Read-only access is arranged by email too. The free review call exists for people who prefer to talk, and skipping it changes nothing about the work.
Three things, on your real traces. Whether the agent's completion claims match the state it left behind. Whether it loops, stalls or keeps working after it has lost the thread, and how many steps before anything visible happens. And how its tool use fails: tools skipped, results ignored, outputs fabricated, forbidden state changes reported as success. You get the findings with reproductions, and the detectors stay with you.
For the audit, read-only is enough: a scoped role with no write permissions, which you can revoke the day the report lands. For work we actually carry out we need write access to the parts we're responsible for, scoped to those. You keep the root account throughout.
Then you probably want the audit, or a fixed-price piece now and then. A second pair of eyes on someone else's work is worth €500 once a year, and we'll tell you honestly if there's nothing to do. Plenty of our work is for teams who already have infrastructure people and need a specialist for one problem.
Then you've paid €500 for a clean bill of health and can stop thinking about it. It happens, though not often. Usually the cost findings alone cover the fee within a month or two.
No. The audit is a one-off and any further work is quoted as a fixed price per piece. There's no contract to cancel and nothing renews on its own.
We're not a 24/7 NOC and won't pretend otherwise. One small team can't honestly promise that. What we do instead is set things up so 3am incidents mostly stop happening, and so the ones that do have a runbook your team can follow without us.
AWS, GCP and Azure; Kubernetes, Terraform, Pulumi, Docker, Helm, Ansible, GitHub Actions, GitLab CI, ArgoCD, Datadog, Grafana, Prometheus, OpenTelemetry, Vault and PostgreSQL. If you're on something unusual, say so on the call and we'll tell you straight whether we're the right people.
If you ship AI features to EU users: transparency obligations (Article 50: telling users they're talking to AI, machine-readable marking of generated content) apply since 2 August 2026. High-risk record-keeping (Articles 12, 19 and 26) was deferred to 2 December 2027 by the Digital Omnibus. But the six-month retention requirement means the logging has to be running well before that date. Whether a given system is high-risk is a question for your lawyer; we build the technical side from their answer, and the same logging is worth having either way.