Cloud architecture
Scalable, fault-tolerant design and reviews across AWS, Azure, and GCP.
Fixed-price · scoped after discovery
For enterprises
Citadel designs, secures, and operates production systems for enterprises, with fixed-price consulting and governed managed AI agents. Hire the architects who run this work every day.
Citadel Cloud Management delivers architect-led cloud, security, and AI work for enterprises across five areas: cloud architecture and review on AWS, Azure, and GCP; security and GRC aligned to SOC 2, ISO 27001, HIPAA, and FedRAMP controls; zero-trust identity and access governance; AI enablement from proof of concept through to governed production; and scoped 6R migration assessments with cost and risk called out before a commitment. Commercial terms are fixed-price under a written statement of work, typically inside a master services agreement for ongoing work, priced after a 30-minute discovery call rather than metered by the hour. Consulting engagements typically run from $10,000 to more than $500,000 depending on scope. The published entry point is the Agent Assurance Assessment, three weeks at $15,000. Ongoing work graduates into monthly retainers, starting at $8,000 a month for Managed AI Operations. Deliverables and the configuration built for the client environment belong to the client.
Depending on scope. Priced after a discovery call: no open-ended time-and-materials meter, no surprise invoices. You know what a first phase costs before you commit.
The fixed-scope front door to everything above. An inventory and risk map of the AI agents already running in your environment, a governance evidence pack mapped to NIST AI RMF and ISO/IEC 42001, one working governed agent deployed in your environment, and an executive readout with a prioritized rollout plan. A larger multi-environment tier is published at $40,000. No “contact us for a quote”.
See the assessment, scope and priceFive delivery areas, scoped and priced up front. Start with a discovery call to find the highest-value first step.
Scalable, fault-tolerant design and reviews across AWS, Azure, and GCP.
Fixed-price · scoped after discovery
SOC 2, ISO 27001, HIPAA, and FedRAMP-aligned controls and continuous compliance.
Fixed-price · scoped after discovery
Zero-trust identity, access governance, and least-privilege credential design.
Fixed-price · scoped after discovery
From proof-of-concept to governed, production AI with guardrails that hold.
Fixed-price · scoped after discovery
A scoped 6R assessment with cost and risk called out before you commit.
Fixed-price · scoped after discovery
A project is the start, not the end. Most engagements graduate into an ongoing retainer, so your governed AI keeps running, improving, and staying audit-ready. Monthly, scoped after discovery.
From $8,000 / mo
Run, monitor, and improve the agents you deployed.
$8,000 to $25,000 / mo
Senior AI leadership without a full-time executive hire.
Retainer
Stay audit-ready as your AI footprint grows.
From first call to operating in production: four steps, fixed-price, no black boxes.
A working call to map your stack, constraints, and the highest-value first step. No pitch deck.
A written SOW with deliverables, milestones, and a fixed price, no open-ended time-and-materials meter.
Senior architects execute against milestones, with governance applied to every AI-agent action from day one.
Monitored operation or a clean handoff with runbooks, SLA-backed where the engagement calls for it.
Software In A Service: production-ready agents across 8 domains: engineering, security, data, ops, and more. Each agent is its own principal with scoped credentials and full action logging, run at the autonomy tier you set. Designed, secured, hosted, and monitored by Citadel.
Explore SIASComposites of how Citadel scopes and governs work, not named clients. Named outcomes are published here as engagements clear for reference.
Engagements are scoped and priced after discovery, no open-ended time-and-materials meter.
Every AI agent is a first-class principal: its own identity, scoped credentials, full action logging.
Delivered by working architects across AWS, Azure, and GCP, not a bench of juniors.
The honest trade-offs against a Big-4 consultancy, staff augmentation, and building it yourself.
| Citadel | Big-4 consultancy | Staff augmentation | DIY / generic agent vendor | |
|---|---|---|---|---|
| Who does the work | Working architects | Junior bench, senior sales | Contractors you manage | Your team, stretched |
| Pricing | Fixed-price, up front | Time & materials | Hourly per head | Opportunity cost |
| AI-agent governance | First-class identity + T1 to T3 + full audit | Varies by team | Not included | Build it yourself |
| Speed to value | Scoped first step in weeks | Long ramp | Ramp per hire | Whenever capacity frees up |
| Lock-in | Runbooks + clean handoff | Retainer pull | Knowledge walks out | None |
The legal, data, and contract questions that decide a $250K engagement, answered up front.
Agents run in or adjacent to your tenancy, grounded in your corpora, which stay under your control and are tenancy-isolated per engagement. See the security & governance page for the full posture.
Yes. Corpora and agent identities are isolated per engagement, and privileged corpora are isolated per legal domain so one workstream cannot read another.
Deliverables and the configuration built for your environment are yours. The specific IP and license terms are set in the engagement agreement so your legal team reviews them before signing.
Consulting engagements are fixed-price under a written SOW, typically inside an MSA for ongoing work. Pricing is set after a discovery call, not metered by the hour.
Grounding data and issued credentials are decommissioned and access is revoked at exit, with retention and deletion terms defined in the agreement up front.
Writes happen only at supervised (T2) or human-gated (T3) tiers within scoped credentials. Every action is logged, attributable, and designed to be reversible, so a mistake is traceable and can be rolled back.
Most engagements start with a scoped, lower-risk first step, often a Tier-1 read-and-report agent or a fixed-price assessment, so there is a concrete deliverable early rather than a long ramp.
A 30-minute discovery call to find the highest-value, lowest-risk place to start. Or read the security & governance posture first.