DevSecOps partner · Dubai, UAE

Cloud infrastructure built to ship, secured to last.

Cloudlaunch designs, builds and runs AWS platforms for fintech, SaaS and AI companies across the UAE and GCC. Security and compliance go in at the first commit, not the week before the audit, and we carry the pager once it is live.

AWS me-central-1 24/7 on-call under SLA UAE PDPL ready

Track record

Built by operators, not theorists.

We did not build Cloudlaunch from a whiteboard. It comes from thousands of hours operating real infrastructure for fintech and crypto companies, and the engineers who did that work are the ones in your accounts.

$0B+in fintech and crypto transactions running on infrastructure we operate
0%uptime track record across AWS, GCP and Azure environments
0%cost reduction reached in production accounts
0weeksto SOC 2 readiness, with controls enforced on every deploy

Infrastructure we secure and run

  • AsporaYC W22US
  • CoinshiftUS
  • HatioBillDeskIN
  • StartGlobalUS
  • Winuyar LtdUK
  • BrownRice CapitalUS
  • PREDUS
  • HelloCounselUS

What we get called for

Six situations that turn into a first call. If one of them is yours, you are in the right place.

01

Developers are running the infrastructure

The backend lead is also the DevOps team. Deploys are a Friday risk and nobody has touched the Terraform since the person who wrote it left.

02

A customer asked for SOC 2, or the regulator asked for more

The questionnaire arrived and the honest answers are not the ones you want to give. You need evidence, not a policy document.

03

The DR plan is a Notion page

Backups exist. Nobody has restored from one. The recovery time objective was picked in a meeting and has never been measured.

04

The AWS bill doubled and nobody can say why

Three accounts, no tagging, reserved instances nobody remembers buying, and a NAT gateway doing most of the damage.

05

Data residency just became a contract term

A bank or a government customer wants the data in the UAE. Half the stack is in Frankfurt and the CDN is wherever it is.

06

You need security without slowing the team down

A pentest found things. Fixing them one by one is not a strategy. You want scanning and guardrails in the pipeline so it does not happen again.

Services

Design, build, run.
Then keep running.

Five things we do end to end. Most engagements start with one and grow into the others because the same team is already inside your accounts.

  • 01Cloud architecture
  • 02CI/CD & DevSecOps
  • 03Kubernetes & platform
  • 04Security & compliance
  • 0524/7 SRE & cost
01 / 05

Cloud architecture & migration

A landing zone built the way AWS says to build one: separate accounts per environment, one identity boundary, networks that are private by default, and a path from where you are to there without a big-bang cutover.

  • Multi-account AWS Organizations with SCPs and centralised logging
  • Terraform for everything, reviewed and applied through CI, never from a laptop
  • Migrations from a single account, another cloud or a data centre
  • UAE region design where residency is a requirement
AWS OrganizationsTerraformControl TowerTransit Gateway
02 / 05

CI/CD & DevSecOps pipelines

Pipelines that stop the bad change and let the good one through in minutes. Scanning, signing and approval gates live in the pipeline itself, so security is a property of the process rather than a person's memory.

  • GitHub Actions or GitLab CI with OIDC to AWS and zero long-lived keys
  • IaC, container and dependency scanning that blocks on real findings only
  • Signed artifacts and provenance so you can say what is running and where it came from
  • Plan-and-approve flows for infrastructure, with destructive changes flagged
GitHub ActionsArgo CDTrivySigstoreOIDC
03 / 05

Kubernetes & platform engineering

EKS when you need it, ECS when you do not, and an honest conversation about which one that is. A platform your developers deploy to without asking us, with the guardrails already in place.

  • EKS clusters with private endpoints, IRSA, network policy and pod security defaults
  • GitOps with Argo CD so the cluster matches the repo, always
  • Autoscaling, spot strategies and right-sizing that show up on the bill
  • Golden paths: a new service in production in an afternoon, not a sprint
EKSECSHelmKarpenterArgo CD
04 / 05

Security, compliance & audit readiness

SOC 2, ISO 27001, PCI DSS and the UAE's own requirements, treated as engineering constraints. We build the controls, collect the evidence continuously and sit in the auditor call with you.

  • IAM redesign: least privilege, permission boundaries, no shared credentials
  • Logging, retention and immutability that satisfy an auditor or a regulator's request
  • Secrets management with rotation, and the removal of the .env file from the server
  • Remediation of pentest and VAPT findings as patterns, wired into the pipeline
SOC 2ISO 27001PCI DSSUAE PDPLVault
05 / 05

24/7 SRE, monitoring & cost

Once it is live, we run it. Alerts tuned so a page means something is genuinely wrong, a rotation with a named engineer on it, a review after every incident, and a bill that goes down rather than up.

  • Metrics, logs and traces with the retention the compliance work needs
  • On-call under SLA with a fifteen-minute acknowledgement on production pages
  • Disaster recovery that has been restored from, on a schedule, with the timing recorded
  • Monthly cost review with the changes already made, not a slide of recommendations
PrometheusGrafanaDatadogCloudWatchPagerDuty

Approach

How an engagement runs

Four stages, each with something you can hold in your hand at the end. The first one is free and takes a week.

Start with a review
01 · Week one

Cloud review

Read-only access to your AWS accounts and your pipeline. We come back with what is actually wrong, ranked by how much it matters, and what it would take to fix. No slide deck.

You get: a written findings report and a 45-minute walkthrough
02 · Weeks two to three

Plan

A target architecture, the order to get there in, and a fixed-scope proposal for the first phase. If the right answer is a smaller engagement than you expected, we say so.

You get: an architecture document and a phase-one scope with a price
03 · Weeks four onwards

Build

We work inside your repos and your Slack, in Terraform, through your CI. Every change is a pull request your team can read. Nothing is applied that was not reviewed.

You get: infrastructure as code you own, with runbooks
04 · Ongoing

Run

A monthly retainer: the rotation, the monitoring, the patching, the cost review and the audit evidence. Or a handover to your own team, if that is the plan, with the documentation to match.

You get: an SLA, a named engineer and a monthly report

Why Cloudlaunch

A first DevOps hire costs the same, takes three months to find and is on holiday when the incident happens.

A team, for the price of a hire

You get an architect, a security engineer and an on-call rotation for roughly what one senior DevOps engineer costs in Dubai, and you get them next week.

Embedded, not advising

We sit inside your engineering team. We know why the system is shaped the way it is, and we are the ones who change it, in your repos, under review.

Regulated work is the default

Fintech, payments and anything a bank buys. Compliance is a constraint on every design decision here rather than a scramble the month before the audit.

Honest about what you do not need

Not every company needs Kubernetes, a service mesh or a second region. We will tell you which of these you can skip, even when it means a smaller engagement.

Who you will work with

The people behind the platform

Cloudlaunch is a small DevSecOps team in Dubai. Everyone touches production, everyone talks to clients, and the engineers who operate your accounts are the same ones who answer the page.

Harshil Olavakott, founder and CEO of Cloudlaunch

Founder & CEO

Harshil Olavakott

Founder and CEO, Cloudlaunch and DevLift · LinkedIn

Cloud architect and DevSecOps specialist, building and running infrastructure on AWS and Azure since 2012. He has led engineering at Dentsu and ran production for fintech and crypto teams for four years before turning that work into DevLift, and now Cloudlaunch for the UAE.

Since 2012AWS Community BuilderWINAIM Award 2016

Headquartered in Dubai

Runs production for fintech, crypto and AI companies across the UAE, the US and the UK.

Engineers with a record

OSWE-certified engineers, DEF CON and Black Hat speakers and former CTF leads, with five discovered CVEs between them.

Four years by hand first

Four years operating infrastructure by hand before the recurring work was encoded into automation and runbooks.

A shared pager

Someone is reachable when it breaks, under an SLA, and the same engineers approve every change that reaches your accounts.

From customers

What engineering leaders say.

Arun Engineering Manager, Coinshift

Since bringing Cloudlaunch into our production environments, our infrastructure operates seamlessly. We established strict, automated security guardrails without slowing down our deployments, and they optimized our cloud waste by thousands of dollars.

Sanjay Nediyara CEO, StartGlobal, Inc.

Cloudlaunch completely removed the ops toil from our sprint cycles. Instead of manually wrestling with IaC and chasing compliance drift, we rely on their team to keep our environments stable and audit-ready. It's like having a senior SRE on staff 24/7.

Built for the UAE

Residency and regulation, handled

The questions a UAE customer, bank or regulator will ask about where the data lives and who can reach it, answered in the architecture rather than in a meeting.

  • REGION

    AWS Middle East (UAE), me-central-1

    Workloads, backups and logs kept in-country when the contract asks for it, with a documented list of what still leaves the region and why.

  • PDPL

    Federal Decree-Law No. 45 of 2021

    Personal data mapped, access logged, retention enforced, and a cross-border transfer register you can hand to counsel.

  • DIFC / ADGM

    Free-zone data protection regimes

    Companies inside the DIFC or ADGM answer to their own data protection law. We build to whichever one applies to you, and to both where a group spans them.

  • FINANCIAL

    CBUAE, SCA and bank vendor reviews

    Outsourcing, information security and third-party questionnaires answered with evidence from the accounts, not with a policy PDF.

Start here

Ready to launch, without the 2am pages?

A free, read-only review of your AWS accounts and pipeline. One week, a written findings report, and a straight answer on whether you need us.