cloud.consulting.sa
Cloud Division

Enterprise Cloud Infrastructure & Managed Provisioning

Design, automate, and secure dedicated cloud environments tailored to your business. Independent cloud architecture consulting for the Saudi market — built for performance, compliance, and scale.

Architecture

Cloud Architecture & Provisioning

We provision dedicated cloud environments that are isolated, reproducible, and built on proven infrastructure-as-code principles. Every customer gets their own Virtual Private Cloud, network segmentation, and a deployment pipeline that treats infrastructure the same way we treat application code.

  • Dedicated Virtual Private Clouds (VPCs) per customer
  • Linux/Windows VM environments with custom sizing
  • Container orchestration via Docker & Kubernetes
  • Infrastructure as Code with Terraform & Ansible
  • Multi-region failover and high availability
  • Private networking with no shared tenancy
Dedicated VPCs
Fully isolated network environments with private subnets, NAT gateways, and security groups scoped to each customer.
Containers
Docker and Kubernetes orchestration for portable, scalable workloads with rolling updates and self-healing.
Infra as Code
Terraform and Ansible modules versioned in Git, so every environment is reproducible and auditable.
Multi-Region
Active-active or active-passive failover across regions to meet aggressive RTO/RPO targets.
Security

Security & Compliance

Security is engineered in from day one — not bolted on later. Every environment ships with encrypted traffic, hardened network rules, and controls aligned to the Saudi Personal Data Protection Law (PDPL).

Encryption Everywhere
Caddy terminates TLS automatically and rotates certificates. Data is encrypted at rest with AES-256 and in transit across every hop.
PDPL Controls
We map controls to Saudi PDPL requirements — data minimization, access logging, consent tracking, and breach-notification readiness.
Zero Public DB Exposure
Databases bind to localhost or private subnets only. No data store is ever reachable from the public internet without an authenticated proxy.

What's enforced in every deployment

  • Automatic TLS via Caddy reverse proxy
  • Encryption at rest (AES-256) and in transit
  • Saudi PDPL compliance controls & audit logs
  • Strict firewall rules and network segmentation
  • Zero public database exposure (bind to localhost only)
  • Secrets management with rotation policies
Recovery Readiness
Backups are worthless if you can't restore them. Every backup strategy we ship comes with a tested runbook, defined RTO/RPO targets, and a quarterly drill schedule so recovery is muscle memory, not guesswork.
  • Point-in-time database snapshots (PITR)
  • Cross-region snapshot replication
  • Documented and tested rollback runbooks
  • Automated daily backup policies with retention
  • RTO / RPO targets defined per workload
  • Quarterly disaster recovery drills
Resilience

Backups & Disaster Recovery

Data loss is not an option. We implement point-in-time recovery, geo-replicated snapshots, and — critically — we actually test restores. A backup you've never restored from is a hope, not a strategy.

PITR
Point-in-time recovery
Q4×
Restore drills / year
Migration

Migration & Managed Cloud

Moving off an existing provider — or out of a server closet — shouldn't mean downtime. We plan cutover in phases, validate parity, then take on the day-to-day operations so your team can focus on the product, not the plumbing.

Migration from AWS, Azure, Alibaba Cloud & on-prem
Zero-downtime cutover planning and execution
Fully managed environments post-migration
24/7 monitoring, alerting and incident response
Capacity planning and resource right-sizing
Cost optimization and utilization reporting
Transparency

Third-Party Provider Independence

Consulting.sa is an independent cloud consultancy — we are not an Alibaba Cloud, AWS, or Azure reseller, and we are not a substitute for those providers. Here's exactly how the relationship works.

Account ownership

The underlying cloud provider account (Alibaba Cloud, AWS, etc.) remains owned and controlled by you or your chosen provider. We architect and operate within it — we do not hold your account hostage.

Billing responsibility

You are responsible for all resource consumption billed by the upstream provider. Consulting.sa fees cover architecture, setup, and management — they are separate from provider infrastructure charges.

Resource limits & dependencies

Quotas, rate limits, regional availability, and SLAs are governed by the upstream provider's terms. We design around them and surface them transparently — we cannot override a provider's platform limits.

The Cloud Division operates under dedicated cloud service terms (docs/legal/CLOUD_SERVICES_TERMS.md).

t("cloud.inc")
  • Architecture design and infrastructure-as-code repository
  • Dedicated VPC, VMs, and container orchestration setup
  • Caddy TLS termination and reverse-proxy configuration
  • Automated backup schedules and tested restore procedures
  • Monitoring dashboards and alerting (uptime, disk, CPU, errors)
  • Saudi PDPL-aligned security hardening documentation
t("cloud.exc")
  • Direct payment or ownership of the underlying cloud provider account
  • Hardware procurement or colocation rack leasing
  • Third-party SaaS application licensing fees
  • Domain name registration and renewal costs
  • Out-of-scope custom application development (quoted separately)
  • Guaranteed uptime beyond what the upstream provider offers
Process

How to Start

Six clear steps from first conversation to a hardened, managed environment.

1

Consultation

Deep-dive into your workloads, compliance needs, and growth trajectory.

2

Architecture Design

We design a dedicated topology — VPC layout, regions, failover, and budgets.

3

Provisioning

Infrastructure as Code brings the environment up reproducibly in hours, not weeks.

4

Security Hardening

Firewall rules, TLS, PDPL controls, least-privilege access, and audit logging applied.

5

Deployment

Applications, databases, and services deployed with rollback-ready pipelines.

6

Ongoing Management

Monitoring, backups, patching, and cost review continue under a managed agreement.

Ready to build your cloud the right way?cloud.consulting.sa

Book a no-obligation architecture review. We'll map your workloads, identify risks, and deliver a provisioning plan you can take to any provider.