Book a call

hello@enclave.maxdcloudops.us

Fintech and healthcare · AWS, GCP, Azure

Cloud infrastructure that passes the audit.

Your team can harden the estate. What costs them a quarter is producing evidence an assessor accepts while still shipping product. Enclave does both, because the decisions that stand a platform up and the evidence an auditor asks for six months later are the same decisions.

We build cloud infrastructure for regulated workloads on AWS, GCP, and Azure, and we secure the AI and ML platforms that run on top of it.

  • 20,000+ servers managed at once across AWS, GCP, and Azure
  • PCI DSS through audit and annual recertification

What we have already done

  • PCI DSS taken through audit and annual recertification; HIPAA infrastructure that passed inspection
  • 20,000+ servers managed at once across AWS, GCP, and Azure
  • 12 certifications between us, and both of us sat the Terraform exam independently
  • 100+ microservices moved onto daily deploys

Four pillars

Four kinds of work. Every number under them names the engagement it came out of.

  • AI Platform & AI Security

    Putting a model into production means someone has to decide who can reach the training data and what the model is allowed to answer. We oversaw security of a proprietary LLM infrastructure on Kubeflow across the ML lifecycle — access governance, training-data protection, pipeline integrity, and model-artifact and inference-API controls. The Kubernetes underneath is ours too. Those clusters carried 2M+ daily API requests for a multi-tenant e-commerce platform.

    Read more →

  • Cloud & Platform Security

    Two questions decide a cloud security review, and neither is about the tooling: who can reach what, and whether you can prove it to an assessor six months later. We drove ISO 27001 and NIST 800-53 readiness across a multi-account AWS environment, and led PCI DSS compliance through successful audits and annual recertification. One piece of this is live client work rather than employment history: a US financial-services company has us under contract, through Volonaris Security, to design the cloud security controls they are examined on.

    Read more →

  • DevOps & Platform Engineering

    A deployment pipeline is where the decisions about isolation and access either hold or quietly stop holding. We migrated about 300 business-critical services from Docker Swarm to Kubernetes with zero downtime, on AWS with Terraform and Vault. That platform scales to 10x transaction volume without a redesign. On another platform, a GitOps workflow on ArgoCD and GitHub Actions spanned 8+ teams and put through 50+ safe deployments a day.

    Read more →

  • SRE & Reliability

    A reliability number means nothing until the region you were relying on stops answering. On a payments platform, cross-region failover held a sub-minute recovery time objective, backed by disaster-recovery runbooks covering 30+ documented failure scenarios and monthly failover tests. Peak hit 3x normal load and payments kept clearing, because the autoscaling was keyed to payment throughput rather than CPU.

    Read more →

Where we are the wrong firm

We don't sign up for compliance theater — an engagement that produces a report saying you are compliant, with no authority to change the architecture the finding names. A report nobody can act on is a liability with a cover page.

We don't take on builds with nothing in production yet. There is nothing to secure until something is running, and no traffic to size an SLO against. Pre-production architecture advice is a different business from the one we run. Someone else should be selling it.

Estates we have run

  • Identity and keys inside a top-5 US bank with $2.9T+ in assets

    We ran AWS Identity Center access for 500+ banking users across 50+ AWS accounts. Access provisioning went from days to hours. The KMS encryption strategy covered 200+ TB of sensitive data, key rotation ran automatically every quarter, and logging captured 10,000+ infrastructure changes a month.

  • A security function that did not exist yet

    We built the cloud security and DevSecOps functions at a high-volume transaction platform under NDA, then directed the AWS Security Improvement Program and CIS Benchmark hardening there. Cloud configuration and security tooling costs came down about 30%.

  • A HIPAA-compliant platform built from zero

    We built Kubernetes infrastructure from zero for a HIPAA-compliant, multi-tenant doctor-patient communication platform on GCP and Azure, using Vault and Terraform. It passed regulatory inspections.

These were jobs. We were on other companies' payrolls, and not one of those companies was ever a client of ours. Volonaris Security is the exception — Volodymyr's own consultancy, where a financial-services client is under contract today.

More partner background

Partners

Max Derbenov

Principal, Cloud & Platform Engineering

Max has spent 20 years designing cloud infrastructure at scale and leading the teams that run it, out of Charlotte, NC. He holds the AWS Solutions Architect – Professional, DevOps Engineer – Professional, and Advanced Networking – Specialty certifications, the Certified Kubernetes Administrator, and the HashiCorp Terraform Associate. His master's is in computer science, from the State University of Information and Communication Technologies.

Volodymyr Vasylenko

Principal, Cloud & Platform Security

Volodymyr has spent 10+ years securing cloud-native platforms — financial services, gaming, enterprise technology — out of Florida. At a game development studio, he built the hybrid IT security architecture spanning two offices and Azure. He holds the AWS Security – Specialty. Behind it: Solutions Architect – Associate, KCSA, KCNA, Cilium Certified Associate, HashiCorp Terraform Associate, CompTIA Security+. He is pursuing the CISSP, expected 2026. His PhD in information technology is from the State University of Telecommunications in Kyiv, where he has taught cybersecurity as an associate professor since 2014; he is an IEEE Senior Member.

Partner, Business & Legal

Farid has spent 10+ years on contracts and commercial disputes. He has led legal matters, negotiated commercial transactions, and represented clients in litigation and international dispute resolution. Contracts and commercial terms sit with him, which is what keeps the engineering conversations about engineering.

How we work

The name is the work. An enclave is a segment nothing reaches by default, and standing one up is a sequence of decisions about network isolation, IAM boundaries, and which workload is allowed to talk to which.

  1. Assess. We start by mapping what is running against what the inventory claims is running. Those two lists rarely match. Findings are then scored through a risk-based vulnerability management program — CVSS and EPSS, with SLA enforcement on the fixes.
  2. Design. We decide IAM boundaries and network isolation up front, with the audit in mind, before a line of Terraform is written.
  3. Build. Pipelines carry SAST, DAST, SCA, container image scanning, and policy-as-code on the IaC.
  4. Operate. We stay on after go-live. That has meant automated patching across 1,000+ EC2 instances in multiple regions with AWS Systems Manager, and a Prometheus and Grafana stack processing 1M+ fraud-detection events a day.

Could you do this in-house?

Some of it, and probably most of it. A good platform engineer will stand up EKS and write the Terraform, and most teams we meet already have that person.

The second half is where it gets expensive. An IAM boundary has to hold up when an assessor pulls on it, and the evidence trail has to be written during the build rather than the week before the audit. Failover has to have been run, not documented. Volodymyr took PCI DSS through audit and annual recertification. Max built HIPAA infrastructure that passed regulatory inspection.

A failed assessment does not cost you the report. It costs you the quarter you spend rebuilding the IAM model under it.

Your team can learn all of it. They are also currently shipping product, and the version they learn on is the version an assessor sees. Hiring the skill in is a second role, a search, and a first audit the new hire learns on. We come in for the stretch where those decisions get made, and hand it back.

Ten questions that settle it →

Start here

Tell us what is already running and who is auditing it. That is enough for a first reply. One of us answers — not a coordinator — usually within one business day. No sales layer sits between you and the engineers who do the work.

Send us what's running