Running and securing a software company's cloud, across Azure and AWS
How AnAr operates a US-based software product company's cloud as an embedded part of their engineering team: defined in Terraform, shipped through automated pipelines several times a week, watched across both clouds, and held to the technical controls their SOC compliance depends on.
An embedded partner for the cloud, so the product team stays on the product
A US-based software product company needed its cloud run and secured every day, without pulling its own engineers off the product to do it. AnAr took ownership of that work. We operate the company's platform across Microsoft Azure and AWS as an embedded part of their engineering team.
The estate is defined in Terraform, shipped through automated pipelines several times a week, watched through a single observability layer, and operated to the technical controls the company's SOC compliance depends on. Their engineers stay on the product. We keep the platform running, secure, and ready for the auditors' questions.
Two clouds, one model
Azure as the primary platform, plus production workloads on AWS, operated the same way.
Everything as code
The estate defined in Terraform across four consistent environments.
Ships every week
Multiple production deployments a week through automated CI/CD with rollback.
Built for the audit
Operated to the access, change, logging, and remediation controls SOC relies on.
Running a cloud well competes with building the product
For a software company, every hour an engineer spends on infrastructure, pipelines, monitoring, and security findings is an hour not spent on what customers pay for. Three problems tend to arrive together.
Infrastructure built by hand drifts
When environments are stood up and changed manually, they stop matching each other. What works in staging surprises you in production, and every release carries risk nobody can fully see. The estate needs to be defined once and provisioned the same way every time.
Shipping often and safely is hard
Deploying several times a week without breaking things takes real pipelines: build, test, provision, validate, and a way to roll back. Without that discipline, teams either ship slowly out of fear or ship fast and pay for it in incidents.
Compliance never stops
SOC-level expectations are continuous, not a one-time project. Access control, change management, logging, monitoring, and vulnerability remediation all have to hold day after day, with evidence ready when the auditors ask. That is ongoing operational work.
One team running the whole platform, across both clouds
AnAr runs and secures the company's cloud as an embedded extension of their engineering team. The work spans two clouds and one shared control plane, and it groups into five areas.
Microsoft Azure (primary)
AWS (production workloads)
The platform, defined in Terraform
On Azure: App Service as primary compute, virtual machines for specific workloads, Azure SQL, Blob and managed disks, and the networking that ties it together (VNets, Front Door with WAF, NSGs, DNS, and an OpenVPN gateway on Entra ID). On AWS: the production workloads (EC2, ECS, Auto Scaling Groups, ALB, S3, ECR, Route 53, AWS WAF). All of it is defined in Terraform across four consistent environments: development, QA, staging, and production.
Automated pipelines with a way back
Deployments run through automated CI/CD, primarily GitHub Actions across both clouds, with Azure DevOps for specific legacy products and release management. Pipelines build, validate, provision through Terraform, and support rollback. Autoscaling is configured on Azure App Service where the application supports it and through AWS Auto Scaling Groups. The platform takes multiple production deployments per week.
One view across both clouds
Azure Monitor, Application Insights, Log Analytics, and AWS CloudWatch feed a single layer in Datadog: infrastructure monitoring, APM, logs, and dashboards in one place. AnAr sets up the monitoring and alerts, builds the dashboards, and watches health. When something breaks, we investigate the incident, run root-cause analysis, and work with the client's developers to close it. Backups are in place and verified.
An estate kept efficient
AnAr reviews Azure spend through Cost Management, right-sizes resources, removes what is unused, and acts on the platform's own recommendations. Budget ownership stays with the client; we keep the estate lean so the bill reflects what the product actually needs.
Secured, and operated to the controls SOC depends on
Access is governed through Microsoft Entra ID with role-based access control on a least-privilege model, and MFA. Secrets live in Azure Key Vault. The network is protected with NSGs, Azure Front Door and AWS WAF, and segmented, private connectivity. AnAr manages security configuration and infrastructure hardening, holds the environment to Azure Policy, and remediates the vulnerability and compliance findings surfaced by Vanta, AWS Inspector, and internal security reviews.
On compliance, the boundary matters. The SOC certification and audit belong to the client. AnAr operates the environment to the technical controls a SOC-audited platform relies on, and provides technical evidence when it is requested.
The client owns the SOC audit and certification
AnAr keeps the technical controls in good order and hands over evidence when the auditors ask. The audit itself, and the certification, stay with the client.
AnAr operates the technical controls; the client owns the audit and certification.
A platform the client does not have to run themselves
We do not publish the client's business metrics. What we can state plainly is what the engagement put in place, and what that means for the team.
What is in place
Build facts, stated plainly.
- The estate across Azure and AWS is defined in Terraform, provisioned and changed the same way every time.
- Four consistent environments (dev, QA, staging, production) instead of hand-built, drifting ones.
- Multiple production deployments per week through automated CI/CD with validation and rollback.
- Unified observability across both clouds via Azure Monitor, Application Insights, Log Analytics, CloudWatch, and Datadog.
- Access governed through Entra ID with least-privilege RBAC and MFA; secrets held in Key Vault.
- Security and compliance findings from Vanta, AWS Inspector, and internal reviews are remediated.
- The environment is operated to the technical controls the client's SOC compliance depends on, with evidence on request.
What it means
Directional, from how the platform now runs.
- The client's own engineers stay on the product while AnAr runs the platform.
- Changes go out repeatably and often, not by hand.
- Compliance findings get closed rather than accumulating.
- Problems are caught through monitoring, rather than discovered by customers.
- One partner is accountable for the platform, embedded in the client's deployments and incidents.
One partner to run and secure your cloud
This is not hands-off managed hosting. AnAr works inside your deployments, incidents, and change process as part of your team, and takes ownership of the parts of the platform that would otherwise pull your engineers away from the product: infrastructure, pipelines, monitoring, security, compliance support, and cost.
Download the full case study to see:
- The multi-cloud platform diagram: Azure and AWS under one control plane
- The commit-to-production and cross-cloud observability flows
- The SOC control map, and the boundary AnAr keeps with the client's audit
- The full technology stack and the AnAr-versus-client ownership split
The PDF lands in your inbox in a minute. You get the case study to read and forward internally, not a sales sequence.
Download the Case Study
The full write-up plus every diagram, as a PDF.
Planning a move to the cloud first? See Cloud Migration →
Need an existing application looked after too? See Application Maintenance →
Prefer to talk it through? Contact our team →
