AWS Cloud Health Check
I’m booking engagements from October 2026. Want to talk sooner? Scoping calls are open right now, so grab a 30-minute slot below.
Give me five working days, and I’ll show you where your AWS bill is quietly leaking money, which security gaps are stalling your enterprise deals, and exactly what to fix first.#
It’s a fixed-price AWS Cloud Health Check, built for seed to Series B B2B SaaS teams. Five angles, one prioritized report, done in a week. €1,800, flat. Everything runs read-only, so nothing in your account changes. Not one thing.
Book a 30-minute scoping call →
Two headaches this takes off your plate#
💸 Your AWS bill is climbing faster than your revenue. Idle resources, oversized instances, that staging environment nobody turned off, no Savings Plans in sight. It adds up to thousands of euros a month, quietly bleeding out while the team ships features. I’ll find it and rank it by what it’s actually costing you, so you know exactly what to kill first.
🔒 Security gaps are getting in the way of real deals. SOC 2, ISO 27001, that security questionnaire a big customer just dropped in your inbox. Deals stall when your AWS setup has obvious holes, and for B2B SaaS that’s often the pain that stings the most, because it isn’t a cost line, it’s a revenue line. I’ll surface the gaps that fail those reviews before your prospect’s security team finds them for you.
One Health Check covers both. You don’t have to choose.
Is this you?#
- You’re a seed to Series B B2B SaaS team, somewhere around 10 to 80 people.
- You’re running on AWS, but there’s no dedicated SRE, platform lead, or cloud architect watching it full-time.
- The bill, the security backlog, or honestly both, are growing faster than anyone has time to deal with.
- You’re in the DACH region, or comfortable working in English.
If that sounds familiar, this review tends to pay for itself before the report even lands in your inbox.
You’ll especially feel this if you’ve caught yourself thinking…#
- “Our AWS bill jumped again this quarter and nobody can fully explain why.”
- “A prospect’s security team sent a questionnaire and I’m not sure how we’d answer half of it.”
- “SOC 2 or ISO 27001 is coming, and we have no idea what we’re walking into.”
- “We had an outage, or nearly did, and realized no one actually owns this.”
- “We’re about to hire our first platform engineer, and I’d love to hand them a map instead of a mess.”
What you’ll actually get#
A 15 to 25 page report you can act on the same week, plus an hour on a call with me to talk it through. Here’s what’s inside:
- A one-page summary your CEO or CTO can read in three minutes flat.
- Your top 10 findings, ranked by euro impact and by effort, so you tackle the highest-leverage stuff first.
- Quick wins: the fixes that each take less than a day.
- A prioritized P0 / P1 / P2 backlog that you (or your next hire) can just work straight through.
- A 60-minute walkthrough call to go over everything and answer whatever’s on your mind.
- An optional fixed-price quote to implement the fixes, if you’d rather hand that to me than do it yourselves.
No 80-page PDF you’ll skim once and forget. Just a clear, ranked, do-this-next list.
The five angles I’ll look at#
Every Health Check walks through your account from five directions:
- Cost. Spend trends, idle and oversized resources, Savings Plan and Reserved Instance coverage, and the real euros you’re leaking every month.
- Security. IAM exposure, public access, encryption gaps, and the findings that quietly fail customer security reviews and SOC 2 / ISO 27001 readiness.
- Reliability. Single points of failure, missing backups, unencrypted volumes, missing alarms. The stuff that turns into a 2 a.m. phone call.
- Operations. Logging, configuration tracking, tagging hygiene, and what you can (and can’t) see when something breaks.
- EU-compliance posture. Data residency, region usage, public buckets, encryption defaults. The GDPR-relevant signals that matter over here.
How the week actually goes#
| Day | What happens |
|---|---|
| Day 1 | A 30-minute kickoff. You set up one read-only IAM role I give you, in whatever form suits your stack. Takes about 15 minutes. |
| Days 2 to 4 | I run the five-angle review against your account. Nothing more needed from your team. |
| Day 5 | The report lands and we hop on the 60-minute walkthrough together. |
All in, you’re looking at about 2 to 3 hours of your time across the whole week. That’s it.
What I’ll need from you#
- One read-only IAM role. I’ll hand you whatever fits your setup: a one-click CloudFormation stack, a Terraform snippet, or plain step-by-step console instructions. It can read your config and billing, and nothing else. No write permissions, not ever. And you can look over exactly what it’s scoped to before you apply it.
- Around 2 to 3 hours of one person’s time across the week (kickoff, role setup, walkthrough).
That’s genuinely all. Your production environment never gets touched.
What it costs#
€1,800, flat. No hourly billing, no scope creep, no surprise invoice at the end.
And here’s my promise to you: if I don’t find at least three times my fee in annual savings, or a security gap that’s actively holding up a deal, the review is on me.
Book a 30-minute scoping call →Why work with me#
I’ve spent 20-plus years building and securing cloud platforms, and I’ve sat right where you’re sitting.
As co-founder and CTO of CINE.BOX, I built and shipped the streaming platform that took one of Germany’s biggest film festivals, the Filmfestival Max Ophüls Preis, fully online during COVID. It was DSGVO-compliant, cost-controlled, and delivered under a brutal deadline in about three months: over 11,000 tickets sold, roughly 12,800 registered users, around 39,000 film views. Funded under a Saarland state innovation programme, it was held up as a “Leuchtturmprojekt” (a lighthouse project) for digital innovation in the German Mittelstand.
Before that, I owned the AWS IoT cloud platform of a global industrial manufacturer: a fleet of connected devices across multiple regions, with everything that means for cost, security, and reliability at real scale.
These days I help SaaS startups get to that same place, an AWS setup that doesn’t quietly leak money and won’t fall over in an enterprise security review. I’m based in Munich and work in both German and English. And I’m security-first by default, which is why every audit I run is read-only.
A few things people usually ask#
Will this touch our production environment? Nope. The whole audit runs through a read-only IAM role that you deploy yourself. It has zero write permissions of any kind. It can look, it can’t change a thing. And I’ll show you exactly what it’s scoped to before you apply it.
Our AWS bill isn’t that big. Is it still worth it? Often, yes, because the bigger win is usually the security and deal-unblocking side, not raw cost savings. If an enterprise prospect’s security review is sitting on a contract, finding and fixing those gaps is worth €1,800 no matter what your bill looks like. That’s exactly why my promise covers annual savings and deal-blocking gaps.
When can you actually start? I’m taking on engagements from October 2026. You can book a scoping call now and hold a slot. The calendar is filling up, and early conversations get first pick of dates.
What happens on the scoping call? Thirty minutes, no charge, no pressure. I get to understand your setup and what’s hurting, you get a straight answer on whether this is a fit. If it’s not, I’ll tell you honestly.
Can you implement the fixes too, not just find them? Absolutely. There’s an optional fixed-price Remediation Sprint that picks up right where the Health Check leaves off, if you’d rather not do it in-house. Either way, the report stands on its own.
Let’s talk#
Grab a 30-minute call and let’s see if the Health Check is right for you. No charge, no obligation, no hard sell.
Pick a time that works →Booking from October 2026 · scoping calls open now · Munich · DE / EN
Not ready for a full review? Start with the free guide: the 17 AWS bill leaks I find most often.
