What we deliver
Twara Technologies takes responsibility for the routine and the unexpected work of running cloud infrastructure, so your teams can concentrate on the product. We monitor health and performance, apply updates, look after backups, handle incidents, review access and costs, and make controlled changes, all in accounts that remain yours. Everything we do is logged and reported, and the documentation stays current so your organisation never depends on knowledge held only by us.
Typical scope
- Virtual machines, container platforms, serverless functions and managed databases on the major cloud providers.
- Networking components such as load balancers, DNS, certificates, firewalls and VPN connections.
- Identity and access: user lifecycle, role reviews and multi-factor authentication enforcement.
- Backup and recovery for databases, file stores and configuration.
- Infrastructure as code and deployment pipelines, kept in working order as the estate changes.
- Coordination with software vendors and with the cloud provider’s own support channels.
Technologies we work with
- Native monitoring: Amazon CloudWatch, Azure Monitor and Google Cloud Monitoring are usually the starting point because they see provider services directly and need little set-up.
- Open-source observability: Prometheus and Grafana for metrics and dashboards, with OpenSearch or Grafana Loki for logs, when you want consistency across providers or more control over retention and cost.
- Commercial platforms: Datadog, New Relic and similar tools where you already hold licences or want a single hosted product with minimal upkeep.
- Instrumentation: OpenTelemetry, a vendor-neutral framework for traces, metrics and logs, so the choice of back end can change later.
- Patch and configuration management: provider tools such as AWS Systems Manager and Azure Update Manager, or Ansible for mixed estates.
- Incident alerting: on-call and paging tools such as PagerDuty or Jira Service Management, or simpler routing to email and chat where that is sufficient.
How we approach it
- Onboard. Review the estate, confirm access, record what exists and close any urgent gaps such as missing backups or unprotected administrator accounts.
- Agree the plan. Document scope, coverage, priorities, escalation contacts, maintenance windows and what is excluded.
- Instrument. Put monitoring in place around the four golden signals described in Google’s Site Reliability Engineering guidance: latency, traffic, errors and saturation. Alerts are tied to user impact wherever possible.
- Run. Carry out scheduled patching, backup checks, access reviews and cost reviews, and respond to alerts and requests under the agreed process.
- Review and improve. Report periodically on health, incidents, changes, security findings and spend, and agree the next set of improvements.
Quality and security
- Least privilege. Our engineers use individual, role-based access with multi-factor authentication. Shared administrator credentials are removed.
- Change control. Infrastructure changes go through code review and pipelines wherever possible, so there is a record and a route back.
- Logging and time. For organisations subject to Indian requirements, CERT-In’s Directions of 28 April 2022 require covered entities to keep logs of their ICT systems securely for a rolling 180 days within Indian jurisdiction, and to synchronise system clocks with NTP servers of NIC or NPL, or servers traceable to them. We configure log retention and time sources with these requirements in mind and confirm applicability with your advisers.
- Incident discipline. Incidents are recorded with a timeline, impact, cause and actions. The same CERT-In Directions require specified cyber incidents to be reported to CERT-In within 6 hours of noticing them, so our runbooks include a prompt to involve your designated point of contact early.
- Tested recovery. Restores are tested on a schedule and the results recorded.
What we need from you to start
- A list of the accounts, subscriptions and systems in scope, and which are business-critical.
- Named contacts for escalation and for approving changes.
- Your preferred maintenance windows and any periods when change must be avoided.
- Existing documentation, monitoring, backup arrangements and support contracts, however incomplete.
Engagement options
- Full operations: Twara Technologies runs the environment end to end under the operations plan.
- Co-managed: responsibilities are split with your in-house team, with clear ownership for each area.
- Advisory operations: periodic health, security and cost reviews with recommendations, while your team carries out the work.
Operations work pairs naturally with cloud cost optimisation and cloud security and compliance. Contact us to discuss the environment you need looked after.