Draft
Launch
We build you a clean, best-practice cloud foundation in your own accounts — then hand you the keys.
Is this the right fit?
This is for you if:
- You have (or are hiring) an engineering team that will run the infrastructure day-to-day.
- You want a proven, secure foundation delivered fast rather than assembled over months.
- You want to own everything at the end — no ongoing dependency on us.
If you'd rather we run it after we build it, see Launch & Manage. If you already have infrastructure you want us to take over, see Takeover.
How it works
flowchart LR
subgraph P["Propel"]
REG[(Reusable module library
versioned)]
BUILD[We build]
end
subgraph C["Your AWS accounts"]
LIVE[Your infrastructure repo]
CICD[Deploy pipeline]
INFRA[Landing zone + workloads]
STATE[(State · logs · secrets)]
end
REG -->|proven building blocks| LIVE
BUILD --> LIVE
LIVE --> CICD --> INFRA
INFRA --> STATE
BUILD -.we monitor during the build.-> INFRA
INFRA ==>|HANDOVER: repo, docs, runbooks, access| TEAM([Your team runs it])
We build in your accounts from day one, using our versioned library of proven infrastructure modules. You watch it come together, and at the end we hand over a working system plus everything needed to run it. The handover is the deliverable.
Who owns what
| Area | During build | After handover |
|---|---|---|
| Account ownership | You | You |
| Building the infrastructure | Propel | — |
| Deploys | Propel | You |
| Monitoring & incidents | Propel (watching) | You |
| Security decisions / risk acceptance | You | You |
| Everything, ongoing | Propel builds | You own & operate |
How we handle each piece
- Accounts & landing zone — A secure multi-account foundation (guardrails, audit logging, network baseline) built with AWS best practices, in your organization.
- Access — We use scoped, temporary access during the build; it's fully revoked at handover.
- Infrastructure as code & deployments — Everything is code (OpenTofu + Terragrunt). You get a clean repository and an automated deploy pipeline (GitHub Actions, keyless/OIDC) — no manual clicking, no static credentials.
- Monitoring, logs & data residency — Dashboards, alerting, and uptime checks set up and handed over. Your logs stay in your account with a sensible retention policy from day one.
- Security & compliance — A security baseline (guardrails, threat detection, config compliance, audit trail) is built in, not bolted on. You take ownership of risk decisions.
- Cost management — Budgets, spend-anomaly alerts, and enforced tagging so surprise costs get caught early — handed over so your team stays in control.
- Backups & disaster recovery — Backup plans for every data store with agreed recovery targets, and at least one tested restore before we leave.
- Incident response — Runbooks for known failure modes so your team can operate confidently from day one.
What you get
- A production-ready, secure, best-practice cloud foundation you fully own.
- Everything as code, in your repositories, with automated deploys.
- A documentation + runbook pack so your team can operate without us.
- No lock-in and no ongoing fees.
At the end
Full handover: your repos, your access, your runbooks. We revoke our access and rotate anything we touched. Optional break-fix support is available on request, and you can upgrade to Launch & Manage any time.