We build cloud infrastructure for regulated workloads on AWS, GCP, and Azure, and we secure the Kubeflow platforms that run on top of it.

One of us builds the platform, the other takes it through the audit. Fintech and healthcare teams get both sides of the table from the same two people.

Proof strip

  • 25+ years combined
  • 20,000+ servers managed at once across AWS, GCP, and Azure
  • 11 core certifications between us — cloud, security, Kubernetes
  • 100+ microservices moved onto CI/CD, with daily deploys replacing a monthly release cycle

Four pillars

Four kinds of work, each backed by a partner who has shipped it in production.

  • AI Platform & AI Security

    We oversaw security of a proprietary LLM infrastructure on Kubeflow across the ML lifecycle — access governance, training-data protection, pipeline integrity, and model-artifact and inference-API controls. We also build the Kubernetes those workloads run on — general platform work, like the clusters that carried 2M+ daily API requests for a multi-tenant e-commerce estate. Neither of us has trained a model.

    Read more →
  • Cloud & Platform Security

    We drove ISO 27001 and NIST 800-53 readiness across a multi-account AWS estate, and led PCI DSS compliance through successful audits and annual recertification. A CNAPP and CSPM proof-of-value, plus one scoped DSPM project on cloud object storage, ran through Volonaris Security.

    Read more →
  • DevOps & Platform Engineering

    We migrated about 300 business-critical services from Docker Swarm to Kubernetes with zero downtime, on AWS with Terraform and Vault. The platform it left behind scales to 10x transaction volume with no redesign. On another estate, a GitOps workflow on ArgoCD and GitHub Actions spanned 8+ teams and put through 50+ safe deployments a day.

    Read more →
  • SRE & Reliability

    On a payments platform, cross-region failover held a sub-minute recovery time objective, backed by disaster-recovery runbooks covering 30+ documented failure scenarios and monthly failover tests.

    Read more →

Partner background

These were jobs. We were on other companies' payrolls, and not one of those companies was ever a client of ours. Volonaris Security is the exception — Volodymyr's own consultancy, where a financial-services client is under contract today.

  • Identity and keys inside a top-5 US bank

    At a US bank with $2.9T+ in assets, we ran AWS Identity Center access for 500+ banking users across 50+ AWS accounts. Access provisioning went from days to hours. The KMS encryption strategy covered 200+ TB of sensitive data, key rotation ran automatically every quarter, and logging captured 10,000+ infrastructure changes a month.

  • Cloud security functions built from inception

    We built the cloud security and DevSecOps functions from inception at a high-volume transaction platform under NDA, then directed the AWS Security Improvement Program and CIS Benchmark hardening there. Cloud configuration and security tooling costs came down about 30%.

  • A HIPAA-compliant platform built from zero

    We built Kubernetes infrastructure from zero for a HIPAA-compliant, multi-tenant doctor-patient communication platform on GCP and Azure, using Vault and Terraform. It passed regulatory inspections.

More partner background

Partners

Max Derbenov

Principal, Cloud & Platform Engineering

Max has spent 15 years designing cloud infrastructure at scale and leading the teams that run it, out of Charlotte, NC. He holds the AWS Solutions Architect – Professional and DevOps Engineer – Professional certifications, the Certified Kubernetes Administrator, and the HashiCorp Terraform Associate. His master's is in computer science.

Volodymyr Vasylenko

Principal, Cloud & Platform Security

Volodymyr has spent 10+ years securing cloud-native platforms in financial services and other regulated industries, including gaming. He works out of Florida. He holds AWS Security – Specialty and Solutions Architect – Associate, KCSA, KCNA, the Cilium Certified Associate, HashiCorp Terraform Associate, and CompTIA Security+, with CISSP expected in 2026. His PhD is in information technology; he teaches cybersecurity as an associate professor and is an IEEE Senior Member.

How we work

  1. Assess. We start by mapping what is actually running against what the inventory says should be there, then score findings through a risk-based vulnerability management program — CVSS and EPSS, with SLA enforcement on the fixes.
  2. Design. We decide IAM boundaries and network isolation up front, with the audit in mind, before a line of Terraform is written.
  3. Build. Pipelines carry SAST, DAST, SCA, container image scanning, and policy-as-code on the IaC.
  4. Operate. We stay on after go-live. That has meant automated patching across 1,000+ EC2 instances in multiple regions with AWS Systems Manager, and a Prometheus and Grafana stack processing 1M+ fraud-detection events a day.

What we don't do

We don't take on greenfield startups with no production workload yet. There is nothing to secure or operate until something is running, and pre-revenue architecture guidance is a different business than the one two working partners run in their spare capacity.

We don't do hourly staff augmentation. Renting a body to sit in someone else's sprint is a different service than the one this firm sells, and pricing by the hour rewards slower work, not better work.

We don't sign up for compliance theater — an engagement that produces a report saying the client is compliant without any authority to change the architecture underneath the finding. A report nobody can act on is a liability with a cover page.

CTA

Book a call. Fintech and healthcare teams get a reply first, because that is the work we have actually done. No sales layer sits between you and the two partners who would run the engagement.

Book a call