CUSTOMER STORY / ASSIDUOUS

Corporate finance SaaS on AWS six accounts, six weeks, ongoing partnership.

StationOps helped Assiduous strengthen platform reliability, tighten security posture, and reduce cloud costs for their AI-enabled corporate finance platform — delivering an AWS Landing Zone with six dedicated accounts spanning governance, security, and workload isolation in weeks instead of months so the team could spend more time on roadmap work and less on firefighting.

Customer
Assiduous
Sector
Corporate finance SaaS
Engagement
6 weeks deployment + ongoing partnership
Focus
Reliability, security, cost optimization, ongoing management
6 wks

Click-ops to production-ready cloud infrastructure

Ongoing

Cost optimization and quarterly reviews delivering continuous savings

6

AWS accounts (Landing Zone) — up from one

25%

AWS cost savings with ongoing optimization

Results from this customer engagement. Starting conditions, scope, and outcomes vary between environments.

THE ENGAGEMENT

A clear scope of responsibility.

Engagement
6 weeks deployment + ongoing partnership
Team
Platform lead, SRE, Cloud architect
Focus areas
Reliability, security, cost optimization, ongoing management
Engagement model
Rapid build, then managed operations

This engagement combined a six-week platform delivery with ongoing AWS operations under StationOps—the same cadence we describe for managed service.

01 / THE STARTING POINT

Situation

Assiduous is building an AI-enabled corporate finance platform that helps SMB owners prepare for capital raises, IPOs, succession, and exit events. As the platform scaled — ingesting sensitive financial data, running proprietary algorithms, and serving an expanding base of business owners — operational complexity was outpacing the team’s capacity.

  • Account structure

    Single AWS account for all workloads, no environment isolation, no centralised governance or guardrails.

  • Infrastructure

    Manual click-ops builds, no Infrastructure as Code, no environment separation (Dev/Staging/Prod).

  • Reliability

    Incidents hard to triage, no SLOs, alerting based on infrastructure noise rather than user impact.

  • Security

    No alignment with AWS security benchmarks, limited access controls for a platform handling sensitive financial data.

  • Cost

    Climbing infrastructure spend with no ownership model, over-provisioned compute for AI workloads.

The team needed a reliability model that could keep pace with product growth without introducing security or data-handling risk — changes that would typically take months to remediate internally.

02 / THE WORK

What we did.

  • 01

    Reliability baseline & SLO architecture

    Defined service-level objectives across Assiduous’s core platform services — assessment engine, reporting dashboards, and data ingestion pipelines. Rebuilt alerting around user impact rather than infrastructure noise, cutting false positives and giving on-call engineers a clear signal during incidents.

  • 02

    Security & data-handling controls

    Strengthened access controls, deployment pipelines, and audit evidence for a platform handling sensitive financial and corporate data. Aligned the AWS environment with CIS benchmarks and tightened infrastructure guardrails without slowing release velocity.

  • 03

    AWS Control Tower Landing Zone

    Deployed an AWS Control Tower Landing Zone as the governance platform across six dedicated accounts. Control Tower automated the account structure, OU hierarchy, and security baseline; Account Factory provisioned each account to a standardised template. Preventive controls (SCPs) block non-compliant actions, detective controls (Config rules) flag drift, and proactive controls (CloudFormation hooks) reject non-compliant resources at deploy time — all visible through a centralised compliance dashboard. IAM Identity Center provides federated access, and every account is backed by Terraform modules with policy validation in CI.

  • 04

    Cost-resilient capacity model

    Right-sized compute for AI workloads and data processing, removed idle capacity, and introduced spend-accountability dashboards so the team had clear ownership of infrastructure costs as the user base grew.

Technologies & architecture

AWS Control Tower and Account Factory; AWS Organizations with six accounts — Management, Log Archive, and Audit for governance; Development, Staging, and Production for workload isolation. Core services on AWS Fargate, Amazon Aurora, Amazon S3, and Amazon SES with integrated monitoring. Infrastructure as Code through Terraform modules and policy validation in CI/CD. Org-wide GuardDuty, AWS Config, AWS CloudTrail, and AWS Security Hub with a centralised compliance view; IAM Identity Center for federated access.

What the team received

  • AWS Control Tower Landing Zone
  • Six accounts provisioned via Account Factory: Management, Log Archive, and Audit for governance; Dev, Staging, and Production for workload isolation — all under AWS Organizations with Fargate, Aurora, S3, SES, and monitoring.
  • Incident operations playbook — runbooks covering triage, escalation, and post-incident learning loops.
  • Reusable infrastructure standards — Terraform modules with policy validation and release guardrails in CI.
  • Platform reliability scorecards — weekly reliability and cost tracking aligned to platform and product owners.
  • Centralised security & governance baseline — preventive, detective, and proactive controls enforced by Control Tower; GuardDuty, Config, CloudTrail, and Security Hub across all accounts; compliance dashboard with org-wide visibility of violations and drift.
  • Internal enablement workshops — hands-on sessions so internal teams could run the model independently.
  • 24/7 monitoring & incident response — continuous platform monitoring with rapid incident detection, triage, and resolution to maintain 99.95% uptime.
  • Quarterly business reviews — regular reporting on platform performance, cost trends, and strategic recommendations for continuous improvement.
  • Continuous cost optimization — monthly cost reviews, rightsizing recommendations, and ongoing infrastructure optimization to deliver sustained savings.
  • Security & compliance management — ongoing security posture management, vulnerability assessments, and compliance support for the regulated financial platform.

03 / THE DELIVERY

Timeline

From initial infrastructure review to a production-ready, three-environment AWS platform took just six weeks. The remaining ten weeks of the engagement focused on embedding the operating model, cost optimisation, and enabling the Assiduous team to run it themselves, compressing work that would typically span multiple quarters (3–5 months) and €60k–€150k of internal effort into a single implementation window.

  • Weeks 1–2

    Review, design & Control Tower Landing Zone

    Well-Architected review of the existing estate and service mapping. Deployed AWS Control Tower with Account Factory for standardised account provisioning, OU hierarchy, preventive/detective/proactive controls, IAM Identity Center, centralised CloudTrail and Config, and network baseline across all accounts.

  • Weeks 3–4

    Platform build & multi-environment rollout

    Provision Development, Staging, and Production environments via Infrastructure as Code, deploy core services (Fargate, RDS/Aurora, S3, SES, monitoring), and wire CI/CD.

  • Weeks 5–6

    Hardening, testing & go-live

    End-to-end testing, security and resilience checks, cutover to the new stack, and initial runbooks and dashboards in place.

  • Weeks 7–16

    Transition to ongoing partnership

    Establish the operating cadence, drive down initial cloud costs, and transition to managed service model with 24/7 monitoring and continuous optimization.

  • Ongoing

    Managed service partnership

    Continuous platform management with quarterly business reviews, cost optimization, security management, and proactive reliability improvements.

04 / THE OUTCOME

Impact & ROI

The new platform materially improved stability and efficiency: higher availability, faster recovery from incidents, and a safer path to ship changes meant fewer unplanned interruptions for the Assiduous engineering team. ROI comes from sustained platform performance and predictable costs through the ongoing partnership model. Instead of spending months rebuilding this manually and then bearing the full operational burden, Assiduous reached a production-ready platform in six weeks and transitioned to a managed service that maintains peak performance while the internal team stays focused on product innovation. The comparison below shows the typical internal path versus the StationOps approach.

Illustrative comparison from the customer case study
DimensionTypical internal approachWith StationOps
Timeline3–5 months elapsed across Dev, Staging, and Prod.6-week implementation to production-ready Dev/Staging/Prod.
Engineering effort4–7 person-months (≈ 640–1,100 hours) of senior/platform engineers.Internal team stays focused on roadmap work with ongoing expert management of platform operations.
Fully-loaded costRoughly €60k–€150k in engineering time, before opportunity cost.Engagement paid for itself within the first few months through lower spend and reclaimed capacity.

Figures shown are typical ranges for comparable work and will vary by baseline maturity, constraints, and team size.

  • Reduced incident drag — fewer high-severity incidents with 24/7 expert monitoring and response, cutting the cost and stress of outages.
  • Reclaimed engineering capacity — internal team focuses entirely on product features while StationOps manages platform operations, eliminating operational drag without hiring additional platform engineers.
  • Predictable cost to scale — continuous optimization and expert management ensure costs scale with business growth rather than infrastructure complexity, with quarterly reviews validating ongoing ROI.

Measured outcomes.

  • Six-account AWS Landing Zone (up from one)
  • ~25% AWS cost savings with ongoing optimization
  • Six weeks to production-ready Dev, Staging, and Prod
  • SLO-led reliability and CIS-aligned controls
  • 24/7 managed operations toward 99.95% uptime

05 / CONTINUOUS RESPONSIBILITY

Ongoing partnership

Following the successful platform build, Assiduous transitioned to an ongoing managed service partnership with StationOps. This model ensures the platform continues to meet reliability, security, and cost targets while the Assiduous team focuses on product development and customer value.

  • 24/7 monitoring & incident response

    Continuous platform monitoring with rapid incident detection, triage, and resolution. StationOps maintains watch over all critical services, ensuring the 99.95% uptime target is consistently met with minimal business impact.

  • Continuous cost optimization

    Monthly cost reviews identify optimization opportunities, rightsizing recommendations, and architectural improvements. Quarterly business reviews track cost trends and validate ongoing ROI from the managed service partnership.

  • Security & compliance management

    Ongoing security posture management, compliance monitoring, and audit support for the regulated financial platform. Regular security assessments, vulnerability management, and compliance reporting ensure the platform maintains industry standards.

  • Platform reliability management

    Proactive reliability improvements and SLO monitoring with continuous refinement of alerting, runbooks, and incident procedures. Regular reliability reviews ensure the platform scales gracefully with business growth.

  • Infrastructure updates & maintenance

    Regular infrastructure updates, patching, and modernization to keep the platform secure and performant. Strategic infrastructure evolution supports new product features and changing business requirements.

The managed service partnership operates on clear service level agreements with defined response times, uptime guarantees, and quarterly business reviews to ensure alignment with Assiduous’s business objectives.

More operating stories.

All customers

THE NEXT ADVANTAGE IS YOURS

Make CloudOps an
advantage for your business.

Your cloud. Our responsibility.

Talk to a Cloud Expert

Talk to a cloud expert

Optional analytics help us understand how the site is used. You can accept or decline them. Your preference is saved on this device.

Read the cookie notice