Skip to content
Stribog

§00/Engagement

We build it with your team, then hand you the keys.

No recurring-revenue lock-in. No consultant dependency. Every engagement is designed to transfer ownership to your engineers — systems they understand, operate, and evolve without us.

§01/How We Work

Leadership commitments, not consulting boilerplate.

These are the commitments we make before an engagement begins. If they do not describe how you need a partner to work, we are probably not the right fit.

§01OWN-THE-PERIMETER

We speak to the board, not just the backlog.

Infrastructure decisions are strategic decisions. We translate architecture risk into business exposure — egress economics, vendor concentration, audit friction, M&A liability — in language your board and procurement function can evaluate. Then we build the system that answers it.

§02BUILT-FOR-DECADES

You run it after we leave. That is the point.

The engagement is complete only when your team can operate the system independently — not when we finish coding. We instrument for observability, write runbooks as first-class deliverables, and hand over systems your engineers can debug at 2 AM without calling us.

§03EVIDENCE-BY-DEFAULT

Every trade-off is documented.

Architecture Decision Records are not a nice-to-have. We write an ADR for every significant technical choice — why this approach, what was considered, what the reversibility cost is. An auditor, a new hire, or a future acquirer can open the repository and understand the system.

§04EXIT-RAMPS-DESIGNED-IN

Renewal cycles and budget windows shape the roadmap.

We sequence migration and build work to align with your contract renewals, compliance deadlines, and capital planning. Fast-follow wins reduce current-year exposure; strategic moves land in the next budget window. You do not pay for a transformation that outpaces your organization.

§05OSS-AS-DISCIPLINE

We build for the decade, not the quarter.

Every technology choice is evaluated against a ten-year horizon. We prefer battle-tested open-source foundations over fashionable managed services, and we say so honestly when the inverse is true. We optimize for durability, not demo impressiveness.

§02/The Engagement Model

Three phases. Clear deliverables. Ownership transferred at every milestone.

The model is deliberate: start narrow to earn the right to go deep, deliver a board-ready artifact before committing to execution, then build alongside your team with milestones your engineers own.

§01

Phase §01

Executive Briefing

90 minDuration
Candid conversationFormat

A 90-minute working session — not a sales deck. You walk us through your vendor footprint, regulatory constraints, and the infrastructure decisions that are keeping your CTO up at night. We tell you honestly where sovereignty creates leverage and where it does not. No prepared materials on our end. No pitch.

Deliverable

Risk & Opportunity Summary — a structured written read-out of the concentration risks, regulatory exposures, and optionality gaps we identified, plus a candid recommendation on whether a deeper engagement makes sense.

No obligationNo NDA requiredRemote or in-person
§02

Phase §02

Sovereignty Assessment

2–4 weeksDuration
Deep-dive engagementFormat

A structured deep-dive into your architecture, vendor contracts, compliance posture, and operational practices. We map every dependency against ownership, portability, and audit-readiness criteria. We quantify egress and lock-in economics, model TCO alternatives, and identify quick wins versus strategic moves.

Deliverable

Board-Ready Assessment Report — architecture maps, dependency analysis, TCO model with 3-year and 5-year projections, prioritized risk register, and a phased roadmap recommendation with milestone definitions. Built to be presented to your board or investment committee without translation.

Fixed scopeFixed feeNo retainer extension
§03

Phase §03

Roadmap & Execution

PhasedDuration
Embedded alongside your teamFormat

Execution of the prioritized roadmap, built in phases aligned to your renewal cycles and budget windows. We embed alongside your engineers — pair on implementation, lead architecture reviews, drive ADR discipline, and transfer ownership at every milestone. Each phase closes with a handoff: your team can operate what we built before we start the next phase.

Deliverable

Systems your team operates independently — IaC and GitOps repositories, runbooks, ADR catalog, compliance control mappings, SBOMs, TCO model updates, and an on-call handoff session. The exit ramp is designed into the engagement by default.

Milestone-basedOwnership transfer by defaultAligned to renewal cycles

§03/What You Keep

Ownership handoff by default.

Every artifact we produce is yours — not a vendor dashboard you lose access to, not a proprietary format that requires our tooling to read. These are the concrete deliverables included in execution engagements.

Architecture Decision Records (ADRs)

Every significant technical choice documented with context, alternatives considered, and reversibility cost. Your team inherits the reasoning, not just the outcome.

Network & Data-Flow Diagrams

Current-state and target-state architecture maps in version-controlled source (D2 or equivalent) — auditor-ready without scheduling a Q&A.

RBAC & Access Matrix

Role definitions, permission boundaries, and access review procedures. Auto-generated from policy-as-code on every pull request.

Exit-Ramp Documentation

Documented migration paths away from every significant dependency — vendor pricing, API deprecation, or acquisition cannot leave you stranded.

IaC & GitOps Repositories

Terraform, Talos machine config, Helm charts, and Kustomize overlays — all in your version control, all portable across Kubernetes distributions.

Runbooks & Operational Procedures

Step-by-step recovery and maintenance procedures written for engineers who did not build the system. Tested in staging before handoff.

On-Call Handoff Session

A structured session where we walk your on-call rotation through the system live — failure modes, alert semantics, escalation paths — before we step back.

Observability Stack Configuration

Dashboards, alert rules, and SLO definitions in open formats (Prometheus, Grafana, OTLP). The backend is yours to replace; the signal is yours to keep.

TCO Model (3-yr & 5-yr)

Compute, storage, egress, licensing, and operational cost projections across current-state and sovereign-state scenarios. Board-presentable, auditor-readable.

Compliance Control Mappings

Policy-as-code controls mapped to SOC 2, HIPAA, GDPR, or applicable frameworks — with evidence collection automated into normal CI/CD operation.

Software Bill of Materials (SBOMs)

Component-level dependency inventory for every workload — supply chain posture visible at a glance, updated on every release.

Audit Log Integrity Configuration

Cryptographic integrity verification on log archives — tampering detectable, evidence chain intact for regulatory inquiry or incident investigation.

§04/Scoping & Pricing

Fixed scope. Milestone-based execution. No retainer lock-in.

We do not optimize for recurring revenue at the cost of your autonomy. The model is designed to be legible to your CFO and your procurement team.

Complimentary. No invoice, no obligation. If we cannot identify real leverage for you in 90 minutes, we will tell you — and the conversation ends there.

Fixed-scope, fixed-fee engagement. Scope, timeline, and fee are agreed in a statement of work before we begin. No scope creep, no hourly burn — you know the cost before we start.

Milestone-based pricing. Each phase of the execution roadmap has a defined scope, deliverable, and fee. You can pause between phases, bring in your own engineers at any milestone, or end the engagement. The exit ramp is designed in.

No retainers that renew automatically. No value-based pricing that scales with your cloud bill. No proprietary tooling that requires our involvement to maintain. Our business model is not threatened by your independence — it depends on it.

§05/What We Don't Do

A short list of things we refuse.

Technical buyers distrust consultants who will not define their limits. Here is ours — plainly.

Lock-in by design

We do not architect systems that require our continued involvement to operate. If the infrastructure we build cannot be maintained by a competent team without us, we have failed.

Undocumented magic

We do not build systems that only the person who built them can understand. Every non-obvious decision is documented. Every dependency is explicit. The system is readable.

Perpetual consultant dependency

We do not position ourselves as the long-term operational owner. We embed to build capacity, then step back. The goal is your team's independence, not our billable hours.

Hype-driven re-platforming

We do not recommend migrations for architectural elegance. We recommend them when the TCO, risk, or compliance calculation makes a compelling case. We will argue against a migration we cannot justify.

Slide decks instead of working infrastructure

Engagement deliverables are systems and documents — not decks. If you need a deck for your board, we will help you build one from the assessment report. But the work product is always the real thing.

§00/The Five Pillars

§01

Sovereignty

OWN-THE-PERIMETER

Engineering teams owning the full stack they depend on — no invisible landlords, no rented foundations.

§02

Open source as method

OSS-AS-DISCIPLINE

Open source is a discipline of review, contribution, and independence — not a license type to tick on an audit form.

§03

Audit-grade rigor

EVIDENCE-BY-DEFAULT

Security and compliance aren't retrofit — they are the bar that makes self-hosting safe in regulated, serious environments.

§04

Optionality

EXIT-RAMPS-DESIGNED-IN

Anti-lock-in by architecture: every layer has a documented exit ramp so no vendor can hold you hostage.

§05

The long game

BUILT-FOR-DECADES

Systems proportioned to outlast the tools, vendors, and leadership changes that will come in the decade after delivery.

Executive Briefing

Thirty minutes to clarify your infrastructure risk

Walk us through your vendor footprint and regulatory constraints. We will tell you honestly where sovereignty creates leverage — and where it does not. No pitch deck. No obligation.