Draft

Launch & Manage

We build your cloud foundation and run it for you — under a clear SLA — while your developers ship on top of it.

Is this the right fit?

This is for you if:

  • You want us to build and operate — one accountable partner for the platform.
  • You want your product engineers shipping features, not managing infrastructure.
  • You need someone on call with defined response times and uptime commitments.
  • Your data must stay in your environment.

If you want to own and run it yourself after the build, see Launch.

How it works

flowchart LR
    subgraph P["Propel — control plane only"]
        REG[(Reusable module library)]
        OBS[Dashboards · alerting
· on-call] end subgraph C["Your AWS accounts"] LIVE[Your infrastructure repo] CICD[Deploy pipeline] INFRA[Landing zone + workloads] STATE[(State · logs · secrets
stay here)] RUNNER[Deploy runner
in your account] end REG -->|proven building blocks| LIVE LIVE --> CICD --> RUNNER --> INFRA INFRA --> STATE STATE -.we view in place, never copy.-> OBS OBS -.alerts → on-call → we fix.-> INFRA

We build in your accounts, then operate it continuously. Your data never leaves your environment — we hold only the control plane (dashboards and alert routing) and act by securely assuming access when needed. Deploys and logs stay inside your account.

Who owns what

Area Responsibility
Account ownership You
Building & maintaining infrastructure Propel
Deploys, patching, upgrades Propel
Monitoring & incident response (SLA) Propel
Backups & tested restores Propel
Security implementation Propel
Security risk acceptance & data decisions You
Your application code You

Service levels (example — set with you)

Commitment Target
Production uptime 99.9%
Critical incident acknowledgement 15 min, 24×7
Critical incident resolution target 4 h
Recovery point / recovery time 1 h / 4 h
Cost-anomaly alert < 24 h

How we handle each piece

  • Accounts & landing zone — Secure multi-account foundation with guardrails, audit logging, and network baseline, in your organization.
  • Access — Least-privilege, time-boxed elevation for production changes, with break-glass — every action logged in your audit trail.
  • Infrastructure as code & deployments — Everything as code; deploys run on a runner inside your account so execution and state never leave your environment. Your developers self-serve through paved, guard-railed paths.
  • Monitoring, logs & data residency — We monitor by querying your telemetry in place — nothing is copied to us. You get your own view (dashboards scoped to you), and your logs stay in your account with enforced retention.
  • Security & compliance — Security baseline plus continuous monitoring and response. We can support SOC 2 / HIPAA scopes (BAAs where PHI is involved).
  • Cost management — Ongoing FinOps: budgets, spend-anomaly detection, rightsizing, and a monthly cost report you can see. (This is exactly what catches a forgotten service quietly burning money.)
  • Backups & disaster recovery — We own backup plans and run periodic restore tests so recovery targets are real, not assumed.
  • Incident response — 24×7 on-call with severity-based response, a status page, and blameless postmortems.

What you get

  • One partner accountable for building and running your platform.
  • Defined SLAs you can hold us to — and see proven in dashboards.
  • Your developers shipping end-to-end on safe, paved paths.
  • Your data, state, and logs staying entirely in your environment.

At the end

There's no lock-in. If you ever bring it in-house, exit is clean by design: your infrastructure is already code in your accounts, your data is already yours — we transfer the repos and runbooks and step out.