AWS consulting
AWS consultants who stay to run it.
A senior engineer reviews your account on read-only access in week one. The fixes land as Terraform in your repositories. The same people stay on call under a fixed monthly fee, if you want them to.


- Sage AI
Account read on the cross-account role. 14 security groups and 2 IAM policies changed in the console, not in Terraform.
Listed for review - Finly AI
Primary RDS at 11% CPU and 23% memory over 30 days. One instance size down covers the peak with headroom.
Proposed with a rollback - ClearRisk
Bucket policy on exports-archive allows public list. Nothing sensitive inside, still wrong. Fix drafted.
Awaiting approval - Engineer
Reviewed the bucket policy fix and the RDS proposal. Bucket change approved for today, RDS for the Tuesday window.
Approved by the lead engineer - Summary
Scorecard delivered: architecture, identity, compute, cost, security and observability, with what we would fix first.
Sent to the CTO
What we review
What the consultant looks at in week one.
Six areas, read on a role you control, ranked by what to fix first. The people who write the scorecard are the ones who fix it and the ones on call for it afterwards.
Architecture review
Your account measured against the Well-Architected pillars: operational excellence, security, reliability, performance and cost, with findings ranked by what to fix first.
Sage AIAccount structure, IAM and identity
Organization layout, cross-account roles, SSO and MFA, and the permissions nobody remembers granting, reduced to what the workloads use.
ClearRiskCompute and autoscaling
EC2, ECS and EKS sized to real utilization, autoscaling bounds that match traffic, and instance families that fit the workload.
Sage AICost and commitments
Rightsizing, non-production schedules, storage tiers and Savings Plans matched to the measured floor, reconciled against your invoices.
Finly AISecurity baseline and compliance
Encryption, logging, public exposure and patching checked against the controls SOC 2, ISO 27001 and PCI DSS expect, with evidence exported.
ClearRiskObservability and on-call
Alerts tuned so a page means customer impact, SLOs on what customers see, and a rotation that answers under an SLA.
Iris AIHow it works
A review in week one, a fix by week four.
Read-only first, then pull requests you approve, then a handover or a handoff to the same engineers on call.
- Week 1
Read-only review and scorecard
A cross-account role you control. We read architecture, identity, compute, cost, security and observability and hand you a scorecard with what we would fix first.
- Weeks 2 to 3
Fixes as pull requests
Every change lands as a Terraform pull request in your repositories with the plan attached. Your team approves, we merge in your change window.
- Week 4
Handover, or the managed plan
Your engineers can run what we built. If you want the same people on call, the managed plan starts here under a fixed monthly fee.
- Ongoing
Monthly review
Cost reconciled against invoices, security posture re-checked, evidence kept current, and a roadmap for what changes next.
Engagement shapes
Three ways to work with us.
The free review
Read-only access, one week, a scorecard at the end. No commitment, and the scorecard is yours whether or not we go further.
A scoped project
A migration, a landing zone, an EKS build or a security remediation, with a fixed price and a date. It ends with your team able to run it.
The managed plan
Agents and engineers run your AWS month to month for one fixed fee. The pager, the upgrades, the cost work and the audit evidence are ours.
Consultant, hire or DevLift
What changes when the consultant also runs it.
| An AWS consultant | Hire in-house | DevLift | |
|---|---|---|---|
| Coverage | Engagement hours, then a handover document. | One engineer, business hours. Nobody when they are on holiday. | Agents around the clock. Engineers on call under an SLA. |
| Who does the work | Whoever is assigned this month. | The engineer, for as long as they stay. | Four agents carry the routine load. Senior engineers approve every change. |
| Price | Hourly or retainer, plus change orders. | $200K+ a year with benefits, tooling and recruiting. | One fixed monthly fee. Month to month. |
| Time to value | Weeks, then scope negotiations. | Three to six months to hire and ramp. | Review in week one. Live in four weeks. |
| Compliance | Usually a separate engagement. | Depends on the hire. | Enforced on every deploy, evidence exported continuously. |
| When you leave | Depends on the contract. | Knowledge leaves with them. | Everything is in your account and your Terraform. |
Pricing
The review is free. The rest is one fixed price.
No hourly billing and no change orders for routine work. A scoped project gets a fixed price and a date in the review. The managed plan is one fixed monthly fee, scoped to your footprint, month to month.
Starter
- All four agents under policy
- Terraform ownership and drift control
- CI/CD with security gates
- 24/7 incident response, 99.9% uptime SLA
- Monthly cost reconciliation
Growth
- Everything in Starter
- EKS operations and upgrades
- Compliance automation with evidence export
- SOC 2 readiness in six weeks
- Disaster recovery, tested on a schedule
Scale
- Everything in Growth
- A named lead engineer
- Custom response and resolution targets
- Migration and re-platforming projects
- Quarterly architecture reviews
Only need the bill fixed? The AWS cost audit is free and read-only, and the managed cost plan can run on its own.
From customers
What engineering leaders say.
“Since bringing DevLift's AI agents into our production environments, our infrastructure operates seamlessly. We established strict, automated security guardrails without slowing down our deployments, and Finly optimized our cloud waste by thousands of dollars automatically.”
“DevLift completely removed the ops toil from our sprint cycles. Instead of manually wrestling with IaC and chasing compliance drift, we rely on their platform to keep our environments stable and audit-ready. It's like having a senior SRE on staff 24/7.”
Case studies
What running it looks like.
Three engagements: what the review found, what changed, and what the invoices and the auditors saw next.
Security guardrails on every deploy, and cloud waste cut automatically.
Read the case study
Infrastructure chores out of the sprint, and environments that stay audit-ready.
Read the case study
Regulated money movement, without paying for two of everything.
Read the case studyTrack record
Built by operators, not theorists.
Our founder has been building on AWS since 2012 and is an AWS Community Builder. The team ran production for fintech and crypto companies for four years before encoding the recurring work into agents, and the engineers who did it are the ones who review your account.
The people behind the agents
DevLift is built by a small DevSecOps team in Dubai. Everyone touches production, everyone talks to clients, and the engineers who operate your accounts are the same ones who answer the page.
- Headquartered in Dubai. Runs production for fintech, crypto and AI companies across the UAE, the US and the UK.
- OSWE-certified engineers, DEF CON and Black Hat speakers and former CTF leads, with five discovered CVEs between them.
- Four years operating infrastructure by hand before the recurring work was encoded into the agents.
- A shared pager. Someone is reachable when it breaks, under an SLA, and the same engineers approve every agent change.


The DevLift team, 2026.
Founder
Harshil Olavakott
Founder and CEO, DevLift. LinkedIn
Cloud architect and DevSecOps specialist, building and running infrastructure on AWS and Azure since 2012. He has led engineering at Dentsu and ran production for fintech and crypto teams for four years before turning that work into DevLift.
Has built and run infrastructure for

Questions
Before you book.
Do you resell AWS or take a margin on the bill?
No. You keep your own AWS account and your own bill. We charge one fixed fee for the work, so lowering your spend costs us nothing and is usually the first thing we do.
What access do you need?
A read-only cross-account role you create and can delete at any time. Write access comes later, scoped to the changes you approve, and everything lands as pull requests. The exact policies are on the security and access page at devlift.ai/security.
Do we have to take the managed plan?
No. The review and a scoped project both end with your team able to run what we built. The managed plan is there if you want the same engineers on call, and it runs month to month.
Can you also do Azure or GCP?
Yes. Sage is multi-cloud and most of the same review applies. Most engagements are on AWS, which is where the deepest cost and compliance work is. See the cloud consulting page for the multi-cloud version of this review.
How fast can you start?
The read-only review starts the week after the demo and the scorecard arrives at the end of it. A scoped project gets its date in the review. Managed plans are live in four weeks.
Who does the work?
Senior engineers in Dubai, on call around the clock for teams in the UAE, the US and the UK. Four agents handle the routine work and a named engineer approves every change before it ships.
Start with a free review of your AWS account.
Book a free 30-minute demo with an engineer. Bring the thing that worries you most about the account and leave with the review scoped and a first read on what we would fix first.

