SS-07 · Cloud, migration and operation

Cloud infrastructure and migration

Cloud designed, migrated and operated by engineers, not salespeople. We take your infrastructure off the ageing physical server and move it to Terraform, with a phased plan that never stops your business: RTO < 30 min, RPO < 15 min.

ScopeSMEs with 15-250 employees
PlatformsAWS · Azure · GCP · OVH
RTO< 30 min
RPO< 15 min

A cloud bill that grows without the business growing, or a physical server that keeps ageing and can no longer take another patch, is the usual symptom of infrastructure that is poorly designed or has never been reviewed. We always start with an audit — current cost, latency, reliability, what is still on-premise for no real reason — and from there we propose a redesign, a migration, or both.

We operate AWS, Azure, GCP and OVH depending on the case. For regulated sectors in Spain and Europe, we first recommend options with in-territory data residency (Azure Spain, OVH, AWS Madrid).

We have been supporting industrial companies, distributors, professional firms and service SMEs in Castilla y León and the Canary Islands since 2017. We know the ERP systems they use —Sage, Holded, Odoo, Dynamics—, their integrations with e-commerce platforms and the compliance requirements that determine where and how data is hosted. We do not sell generic cloud: we design the architecture that fits your business, migrate within agreed maintenance windows and train your team to operate independently in the new environment.

Everything we touch is done with Terraform: infrastructure is code, it is versioned, and it can be reproduced. No manual clicks in consoles.

Security and regulatory compliance are built into the design from day one. Depending on your sector, we apply controls aligned with the National Security Framework (ENS), ISO 27001 or GDPR requirements for data in the cloud —including EU-based server location where the business requires it—. If you also need to incorporate ISO 27017 or ISO 27018 controls into the scope of your ISO 27001 certification —covering cloud-specific security or the protection of personal data in the cloud—, our Quality division can support you through that process in a coordinated way.

EU-WEST · primaryMadrid
  • API · active
  • DB primary
  • Queue
  • CDN origin
uptimealta disponibilidad
EU-WEST · standbyFrankfurt
  • API · standby
  • DB replica
  • Backup
  • Failover ready
RTO< 30min
EU-WEST · coldParis
  • Backup S3
  • Archive
  • DR site
RPO< 15min

The Cloud infrastructure process.

The process · four stages
01

Audit

We inventory your servers, applications, dependencies and data volumes; we measure current cost, latency and reliability. From that we decide whether the problem is design, sizing, or a migration.

02

Design

Target architecture, data residency and a phased migration plan where it applies. We deliver a report with what moves to public cloud, what stays on-premise and how both environments connect.

03

Migration

Lift-and-shift, re-architecture or hybrid. We provision the environment, replicate workloads and validate performance before routing real traffic; the final cut-over runs in an agreed window, with a documented rollback protocol and verification of data and backups before signing the migration off.

04

Operation

Terraform, observability and monitoring. The first few weeks focus on catching performance or cost anomalies; we right-size resources and train your team in day-to-day management of the environment.

What is included

What Cloud infrastructure includes.

The operational detail: what we deliver as part of the engagement and what we keep active afterwards.

  • AWS, Azure, GCP, OVH

    We operate all four. Azure Spain, OVH or AWS Madrid when data residency is required.

  • Server, ERP and database migration

    Migration of physical or virtual servers (VMware, Hyper-V) and of ERP systems —Sage, Holded, Odoo, Dynamics— with their SQL Server, MySQL or PostgreSQL databases to equivalent cloud instances, with performance validation before the final cut-over.

  • Hybrid architecture and multi-region design

    Mixed on-premise + cloud environments, or multi-region when the business justifies it, securely connected via VPN or ExpressRoute/Direct Connect.

  • Security and regulatory compliance

    Configuration of identity services (Azure AD / Entra ID), encryption in transit and at rest, least-privilege access policies and EU data residency. Alignment with ENS, GDPR and ISO 27001 based on the company's profile.

  • Backup, recovery and high availability

    Encrypted and verified backups, with RTO < 30 min and RPO < 15 min as default objectives tested with gameday drills, plus documented periodic restoration tests.

  • Terraform as standard

    Infrastructure as code, versioned and reproducible.

  • Cloud cost optimisation and governance

    Resource right-sizing, reserved or spot instances based on workload, overspend alerts and a consumption dashboard to control your monthly bill.

What we don't promise

What we don't promise.

So you can decide with real information, here is what we do not offer, even where the market sells it as standard:

  • Zero downtime on every migration

    When the case warrants it we use no-cut-over strategies (strangler-fig, blue-green); when it does not, the cut-over happens in an agreed window with a documented rollback protocol, so the business does not stop without warning.

  • 24×7 security monitoring as an in-house SOC

    We do not monitor in real time like a security operations centre; we apply access controls, encryption and alignment with ENS, GDPR and ISO 27001 based on your company's profile.

  • An availability SLA that depends only on us

    The uptime of Azure, AWS or GCP is set by each provider's own contract; we design to tolerate their outages —multi-zone, verified backups— but we cannot guarantee a third party's SLA.

  • Guaranteed bill savings without reviewing real usage

    We optimise sizing and instance type, but the final cost depends on actual consumption and the provider's own rates, which we do not control.

Summum cluster

How it intersects with related services.

Well-designed cloud is the foundation of security and reliability.

Frequently asked questions about Cloud infrastructure.

Which cloud provider is best for a Spanish SME — Azure, AWS or Google Cloud?

There is no single answer. Azure is the most common choice when the company already uses Microsoft 365 or Dynamics, because identity and tooling integration is native. AWS offers the broadest service catalogue and is a strong option when the company has custom-built applications that consume platform services. Google Cloud excels for analytics and machine learning workloads. In all cases, we evaluate data centre distribution within the EU to ensure data residency in line with GDPR.

Do I need my data in Spain, or is anywhere in the EU enough?

For sensitive data we first recommend the Spain region where the provider offers it (Azure Spain, AWS Madrid); if that specific residency is not required, any EU data centre meets GDPR requirements.

How long does a cloud migration take for a mid-sized SME?

It depends on the number of servers, applications and data volume. A typical environment of 10-50 users with an ERP, file server and email can be migrated in 6-12 weeks, including the parallel testing phase. More complex projects, with multiple integrations or very high availability requirements, can take 3 to 6 months. During the initial diagnosis we establish a realistic timeline and include it in the plan delivered to the client.

Can we migrate without downtime, and what happens if something goes wrong halfway through?

When the case warrants it, yes: we use a strangler-fig or blue-green strategy. In any case, the migration plan always includes a documented rollback protocol before the final cut-over; critical workloads are migrated in agreed windows — weekends or outside business hours — and the legacy environment stays operational until the new one is validated. In high-criticality projects we keep both environments running in parallel during a coexistence period to catch any anomaly before switching off the local systems.

Can I migrate only part of my infrastructure and keep the rest on-premise?

Yes. Hybrid architecture is a common solution when, for latency, cost or regulatory reasons, some systems must stay local. We design the secure connectivity between both environments — VPN, Azure ExpressRoute or AWS Direct Connect — and define which workloads go to the cloud and which stay, with documented technical and economic criteria.

Could the cloud migration be funded through the Kit Digital or Kit Consulting programmes?

Only with a voucher already granted: the calls for both programmes have closed (Acelera Pyme). With a valid Kit Digital voucher, part of the migration can fall within the «Cybersecurity» or «Process management» solutions, depending on the scope; Kit Consulting funded the prior strategic consulting. We assess your situation before starting the process.