Free platform audit
A senior engineer reviews your platform. You keep the report either way.
Five business days, fixed scope, no cost and no obligation. You get a written findings report with severities, effort estimates and the recoverable spend we can identify — whether or not you ever hire us.
- Duration
- 5 business days
- Your time
- About 2 hours
- Cost
- $0, no obligation
- Performed by
- A senior engineer
What this is, and what it is not
What it is
- A read-only review of your platform by an engineer who has run systems like yours in production.
- A written report with each finding rated by severity, blast radius and remediation effort.
- A costed view of where your cloud spend is leaking, with the query or portal blade that proves each number.
- Yours to keep, act on internally, or hand to another vendor.
What it is not
- A discovery call dressed up as a deliverable.
- A tool report. Advisor and Trusted Advisor output is a starting point, not an audit.
- A commitment. There is no clause, no trial and no auto-renewal to cancel.
- A change window. We request read-only access and make no modifications to your environment.
What we examine
Four areas, because these are where the expensive problems live. We go deeper on whichever one you tell us hurts most.
Cloud cost and commitment coverage
- Non-production environments running outside working hours
- Right-sizing candidates from 30 days of utilization percentiles
- Idle GPU and oversized node pools, including scale-to-zero opportunity
- Orphaned disks, public IPs, snapshots and unattached NICs
- Reservation and savings-plan coverage against steady-state baseline
- Storage tiering, log retention and egress patterns
Delivery pipeline and developer friction
- Lead time from merge to production, and where it is actually spent
- Deployment failure rate and mean time to restore
- Manual gates, snowflake steps and undocumented release rituals
- Environment parity and drift between dev, staging and production
- Build cache, test flake rate and pipeline queue depth
- Time for a new engineer to reach their first production deploy
Security and compliance posture
- Identity: standing privilege, service principal sprawl, missing PIM
- Secrets in pipelines, repositories and configuration
- Network exposure: public endpoints, permissive NSGs, missing private endpoints
- Supply chain: image provenance, dependency and container scanning coverage
- Policy-as-code coverage against CIS or your own baseline
- Audit logging completeness and retention against your obligations
Reliability and operational readiness
- Single points of failure and untested failover paths
- Backup coverage, and whether restores have ever been proven
- Alert quality: signal-to-noise, ownership and actionability
- Capacity headroom and autoscaling behaviour under load
- Infrastructure-as-code coverage versus portal-created resources
- On-call load, escalation clarity and post-incident practice
How the five days run
You are involved on day one and day five. The middle is our problem.
Day 0
Scoping reply
A senior engineer replies to your request within one business day with a short scoping note: which of the four areas we will weight, what read-only access we need, and confirmation of the delivery date.
Day 1
Kickoff, 45 minutes
One call. You walk us through your architecture and tell us what hurts. We set up read-only access — a Reader role plus Cost Management Reader on Azure, or a read-only IAM role on AWS. No agents, no write permissions.
Days 2–4
Review
We work through the scope against your live estate, your pipelines and your repositories. Every finding is evidenced with the query, blade or log line that produced it, so nothing in the report rests on our word alone.
Day 5
Report and walkthrough
You receive the written report, then a 60-minute walkthrough if you want one. We answer questions on the findings whether or not there is any further work.
What lands in your inbox
One document, written to be forwarded to both an engineering lead and a CFO without translation.
Prioritized findings register
Every finding rated critical, high or medium, with blast radius, remediation effort in engineer-days, and the evidence behind it. Typically 30–50 findings on an estate that has not been reviewed before.
Recoverable spend summary
A monthly and annual figure for the waste we can substantiate, broken down by cause, with the specific resources listed. Each line is verifiable in your own portal before you act on it.
90-day remediation roadmap
The findings sequenced by return on effort, split into what one engineer can land in a fortnight and what needs a project. Includes what we would deliberately not do yet, and why.
Executive one-pager
The version you forward upward: risk, cost and delivery impact in plain language, with figures that survive scrutiny.
See the actual deliverable first
Read a redacted example report before you decide whether to hand over read access. It is the same structure and depth you would receive.
Who actually does the work
The engineer who writes your report is the engineer who would do the remediation. There is no analyst tier, no offshore handoff and no template with your logo dropped into it. That is also the honest reason the audit is free and the slots are limited: it costs us three to four days of senior time, which is the most expensive thing we own.
Open source
Rather check the numbers yourself first?
We open-sourced the scanner we use on engagements. It finds unattached disks, stopped-but-billing VMs, GPU pools that cannot scale to zero and five other leaks, and prices each one against the public Azure rate card. Read-only, needs nothing but Reader.
npx github:stefanjovanovic0714/azure-cost-leaks
Run it on your own estateQuestions before you hand over read access
- Why is it free? What is the catch?
- It is the cheapest way for both of us to find out whether the engagement makes sense. We would rather spend four days learning your estate than write a proposal from a discovery call, and you would rather read findings than a capability deck. If the report says your platform is in good shape, we say so and there is nothing to sell. That happens, and it costs us nothing but time.
- What access do you need?
- Read-only, scoped as narrowly as you like. On Azure: Reader at the subscription or management-group level, plus Cost Management Reader for the spend analysis. On AWS: a read-only IAM role, plus Cost Explorer access. Read access to your pipeline definitions and infrastructure repositories helps considerably. We make no changes to your environment at any point.
- What if we cannot grant access at all?
- We can still run most of the review from exports and a screen-share: a cost export, resource inventory, pipeline definitions and your architecture diagrams. The cost analysis loses precision without utilization data, and we will say so in the report rather than quietly estimating.
- Will you sign an NDA?
- Yes, before kickoff, and we will sign yours rather than insisting on ours. Every client name on this site is withheld under exactly that arrangement.
- How is this different from Azure Advisor or Trusted Advisor?
- Advisor sees resources; it does not see your delivery process, your on-call load, or the fact that your staging environment has drifted from production. We start from the tool output because it is free and useful, then spend the remaining days on the things a rules engine cannot evaluate — and we tell you which findings you could have got for nothing.
- Do we have to take a sales call to get the report?
- No. The walkthrough on day five is optional and the report is sent regardless. If you take it, it is with the engineer who wrote the report.
- How large an estate can you cover in five days?
- Up to a few hundred subscriptions or accounts, because the review is depth-first on the areas that matter rather than exhaustive. Above that we will tell you at scoping which parts of the estate we sampled and what a full review would take.
Request your audit
Two minutes. A senior engineer — not a sales rep — replies within one business day with the scoping note.
Rather just talk it through?
Book 30 minutes with a senior engineer. No sales rep, no deck — bring your architecture.
or send details first