Cloud Services · Case Study

Running and securing a software company's cloud, across Azure and AWS

How AnAr operates a US-based software product company's cloud as an embedded part of their engineering team: defined in Terraform, shipped through automated pipelines several times a week, watched across both clouds, and held to the technical controls their SOC compliance depends on.

Azure and AWS under one operating model The whole estate defined in Terraform Multiple production deployments per week Operated to SOC-grade controls
Overview

An embedded partner for the cloud, so the product team stays on the product

A US-based software product company needed its cloud run and secured every day, without pulling its own engineers off the product to do it. AnAr took ownership of that work. We operate the company's platform across Microsoft Azure and AWS as an embedded part of their engineering team.

The estate is defined in Terraform, shipped through automated pipelines several times a week, watched through a single observability layer, and operated to the technical controls the company's SOC compliance depends on. Their engineers stay on the product. We keep the platform running, secure, and ready for the auditors' questions.

Two clouds, one model

Azure as the primary platform, plus production workloads on AWS, operated the same way.

Everything as code

The estate defined in Terraform across four consistent environments.

Ships every week

Multiple production deployments a week through automated CI/CD with rollback.

Built for the audit

Operated to the access, change, logging, and remediation controls SOC relies on.

The Challenge

Running a cloud well competes with building the product

For a software company, every hour an engineer spends on infrastructure, pipelines, monitoring, and security findings is an hour not spent on what customers pay for. Three problems tend to arrive together.

Infrastructure built by hand drifts

When environments are stood up and changed manually, they stop matching each other. What works in staging surprises you in production, and every release carries risk nobody can fully see. The estate needs to be defined once and provisioned the same way every time.

Shipping often and safely is hard

Deploying several times a week without breaking things takes real pipelines: build, test, provision, validate, and a way to roll back. Without that discipline, teams either ship slowly out of fear or ship fast and pay for it in incidents.

Compliance never stops

SOC-level expectations are continuous, not a one-time project. Access control, change management, logging, monitoring, and vulnerability remediation all have to hold day after day, with evidence ready when the auditors ask. That is ongoing operational work.

What AnAr Does

One team running the whole platform, across both clouds

AnAr runs and secures the company's cloud as an embedded extension of their engineering team. The work spans two clouds and one shared control plane, and it groups into five areas.

Operated by AnAr one embedded team

Microsoft Azure (primary)

App Service Virtual Machines Azure SQL Blob / Disks VNet, Front Door + WAF, NSGs, DNS, VPN

AWS (production workloads)

EC2 ECS Auto Scaling ALB S3 / ECR Route 53, AWS WAF
▼    ▼
One control plane AnAr runs
TerraformInfrastructure as code, both clouds
CI/CDGitHub Actions, Azure DevOps
ObservabilityDatadog + native monitors
SecurityEntra ID, Vanta, Azure Policy
Runs it, as code

The platform, defined in Terraform

On Azure: App Service as primary compute, virtual machines for specific workloads, Azure SQL, Blob and managed disks, and the networking that ties it together (VNets, Front Door with WAF, NSGs, DNS, and an OpenVPN gateway on Entra ID). On AWS: the production workloads (EC2, ECS, Auto Scaling Groups, ALB, S3, ECR, Route 53, AWS WAF). All of it is defined in Terraform across four consistent environments: development, QA, staging, and production.

Ships to it safely

Automated pipelines with a way back

Deployments run through automated CI/CD, primarily GitHub Actions across both clouds, with Azure DevOps for specific legacy products and release management. Pipelines build, validate, provision through Terraform, and support rollback. Autoscaling is configured on Azure App Service where the application supports it and through AWS Auto Scaling Groups. The platform takes multiple production deployments per week.

Watches it

One view across both clouds

Azure Monitor, Application Insights, Log Analytics, and AWS CloudWatch feed a single layer in Datadog: infrastructure monitoring, APM, logs, and dashboards in one place. AnAr sets up the monitoring and alerts, builds the dashboards, and watches health. When something breaks, we investigate the incident, run root-cause analysis, and work with the client's developers to close it. Backups are in place and verified.

Controls cost

An estate kept efficient

AnAr reviews Azure spend through Cost Management, right-sizes resources, removes what is unused, and acts on the platform's own recommendations. Budget ownership stays with the client; we keep the estate lean so the bill reflects what the product actually needs.

Security & Compliance

Secured, and operated to the controls SOC depends on

Access is governed through Microsoft Entra ID with role-based access control on a least-privilege model, and MFA. Secrets live in Azure Key Vault. The network is protected with NSGs, Azure Front Door and AWS WAF, and segmented, private connectivity. AnAr manages security configuration and infrastructure hardening, holds the environment to Azure Policy, and remediates the vulnerability and compliance findings surfaced by Vanta, AWS Inspector, and internal security reviews.

On compliance, the boundary matters. The SOC certification and audit belong to the client. AnAr operates the environment to the technical controls a SOC-audited platform relies on, and provides technical evidence when it is requested.

Controls AnAr operates
Access controlEntra ID, RBAC, least privilege, MFA
Change managementTerraform, CI/CD, reviewed changes
Logging & monitoringDatadog, Azure Monitor, CloudWatch
Vulnerability remediationVanta, AWS Inspector, internal reviews
Backup verificationAzure SQL and service-level backups
HardeningAzure Policy, WAF, NSGs, Key Vault
Evidence on request

The client owns the SOC audit and certification

AnAr keeps the technical controls in good order and hands over evidence when the auditors ask. The audit itself, and the certification, stay with the client.

AnAr operates the technical controls; the client owns the audit and certification.

Outcomes & Benefits

A platform the client does not have to run themselves

We do not publish the client's business metrics. What we can state plainly is what the engagement put in place, and what that means for the team.

What is in place

Build facts, stated plainly.

  • The estate across Azure and AWS is defined in Terraform, provisioned and changed the same way every time.
  • Four consistent environments (dev, QA, staging, production) instead of hand-built, drifting ones.
  • Multiple production deployments per week through automated CI/CD with validation and rollback.
  • Unified observability across both clouds via Azure Monitor, Application Insights, Log Analytics, CloudWatch, and Datadog.
  • Access governed through Entra ID with least-privilege RBAC and MFA; secrets held in Key Vault.
  • Security and compliance findings from Vanta, AWS Inspector, and internal reviews are remediated.
  • The environment is operated to the technical controls the client's SOC compliance depends on, with evidence on request.

What it means

Directional, from how the platform now runs.

  • The client's own engineers stay on the product while AnAr runs the platform.
  • Changes go out repeatably and often, not by hand.
  • Compliance findings get closed rather than accumulating.
  • Problems are caught through monitoring, rather than discovered by customers.
  • One partner is accountable for the platform, embedded in the client's deployments and incidents.
Why AnAr

One partner to run and secure your cloud

This is not hands-off managed hosting. AnAr works inside your deployments, incidents, and change process as part of your team, and takes ownership of the parts of the platform that would otherwise pull your engineers away from the product: infrastructure, pipelines, monitoring, security, compliance support, and cost.

Download the full case study to see:

  • The multi-cloud platform diagram: Azure and AWS under one control plane
  • The commit-to-production and cross-cloud observability flows
  • The SOC control map, and the boundary AnAr keeps with the client's audit
  • The full technology stack and the AnAr-versus-client ownership split

The PDF lands in your inbox in a minute. You get the case study to read and forward internally, not a sales sequence.

Download the Case Study

The full write-up plus every diagram, as a PDF.

Planning a move to the cloud first? See Cloud Migration →
Need an existing application looked after too? See Application Maintenance →
Prefer to talk it through? Contact our team →

Privacy Preferences
When you visit our website, it may store information through your browser from specific services, usually in form of cookies. Here you can change your privacy preferences. Please note that blocking some types of cookies may impact your experience on our website and the services we offer.