Draft
Launch & Manage
We build your cloud foundation and run it for you — under a clear SLA — while your developers ship on top of it.
Is this the right fit?
This is for you if:
- You want us to build and operate — one accountable partner for the platform.
- You want your product engineers shipping features, not managing infrastructure.
- You need someone on call with defined response times and uptime commitments.
- Your data must stay in your environment.
If you want to own and run it yourself after the build, see Launch.
How it works
flowchart LR
subgraph P["Propel — control plane only"]
REG[(Reusable module library)]
OBS[Dashboards · alerting
· on-call]
end
subgraph C["Your AWS accounts"]
LIVE[Your infrastructure repo]
CICD[Deploy pipeline]
INFRA[Landing zone + workloads]
STATE[(State · logs · secrets
stay here)]
RUNNER[Deploy runner
in your account]
end
REG -->|proven building blocks| LIVE
LIVE --> CICD --> RUNNER --> INFRA
INFRA --> STATE
STATE -.we view in place, never copy.-> OBS
OBS -.alerts → on-call → we fix.-> INFRA
We build in your accounts, then operate it continuously. Your data never leaves your environment — we hold only the control plane (dashboards and alert routing) and act by securely assuming access when needed. Deploys and logs stay inside your account.
Who owns what
| Area | Responsibility |
|---|---|
| Account ownership | You |
| Building & maintaining infrastructure | Propel |
| Deploys, patching, upgrades | Propel |
| Monitoring & incident response (SLA) | Propel |
| Backups & tested restores | Propel |
| Security implementation | Propel |
| Security risk acceptance & data decisions | You |
| Your application code | You |
Service levels (example — set with you)
| Commitment | Target |
|---|---|
| Production uptime | 99.9% |
| Critical incident acknowledgement | 15 min, 24×7 |
| Critical incident resolution target | 4 h |
| Recovery point / recovery time | 1 h / 4 h |
| Cost-anomaly alert | < 24 h |
How we handle each piece
- Accounts & landing zone — Secure multi-account foundation with guardrails, audit logging, and network baseline, in your organization.
- Access — Least-privilege, time-boxed elevation for production changes, with break-glass — every action logged in your audit trail.
- Infrastructure as code & deployments — Everything as code; deploys run on a runner inside your account so execution and state never leave your environment. Your developers self-serve through paved, guard-railed paths.
- Monitoring, logs & data residency — We monitor by querying your telemetry in place — nothing is copied to us. You get your own view (dashboards scoped to you), and your logs stay in your account with enforced retention.
- Security & compliance — Security baseline plus continuous monitoring and response. We can support SOC 2 / HIPAA scopes (BAAs where PHI is involved).
- Cost management — Ongoing FinOps: budgets, spend-anomaly detection, rightsizing, and a monthly cost report you can see. (This is exactly what catches a forgotten service quietly burning money.)
- Backups & disaster recovery — We own backup plans and run periodic restore tests so recovery targets are real, not assumed.
- Incident response — 24×7 on-call with severity-based response, a status page, and blameless postmortems.
What you get
- One partner accountable for building and running your platform.
- Defined SLAs you can hold us to — and see proven in dashboards.
- Your developers shipping end-to-end on safe, paved paths.
- Your data, state, and logs staying entirely in your environment.
At the end
There's no lock-in. If you ever bring it in-house, exit is clean by design: your infrastructure is already code in your accounts, your data is already yours — we transfer the repos and runbooks and step out.