Skip to main content
CozyHawk

Platform engineering, governed end to end

Compose your cloud platform from battle-tested blueprints.Approve every change before it lands.

Start from a blueprint, bring your own modules, or compose something custom, and read the exact infrastructure as code before anything exists.Every change is planned, reviewed, and approved before it lands: a teammate’s sign-off, or your own, on the record.Cloud-agnostic by design.

ProposePlanReviewApplyEvidence

Destroy passes the same gate.

Founder-led by a senior platform engineering practitioner.

One lens over your toolchain

Your tools in. Reviewable platform action out.

CozyHawk sits between the tools you already run and your cloud. Signals flow in; reviewed, approved, evidenced changes flow out.

What you gain: one lens over all of it, and one gate every change passes.

Your toolchain keeps running

  • Cloud accounts
  • Infrastructure as code
  • Kubernetes & runtimes
  • Delivery & GitOps
  • Identity & access
  • Observability
  • Cost & usage
  • Security posture
  • Audit & compliance
  • Docs & knowledge
Your tools feed in
CozyHawk Lens

The control plane

Normalized visibilityPlatform modelingStandards & baselinesChange reviewChange planningEvidence mappingBacklog generationOwnership by teamSource-system links
Reviewable work out

What comes out

  • Implementation plan
  • Draft standard
  • Suggested backlog item
  • Evidence map
  • Cost opportunity
  • Rollout plan
  • Reviewable change plan
  • Deep link to source tool
Nothing here replaces your toolchain. Your platform keeps running on the tools you already trust.

Watch one real change land. End to end.

Follow one change from blueprint to applied infrastructure: composed, planned, reviewed, approved, applied, and recorded.

1 Choose
2 Tune
3 The code
4 Plan and review
5 Applied, on the record
One governed change, end to end.

Compose. Preview. Govern.

Compose

Pick a blueprint, bring your own modules, or describe what you need, and tune real settings. Nothing is created yet.

Preview

Read the exact infrastructure as code and the plan it generates, before anything exists.

Govern

1. A plan locks the exact code you reviewed. 2. Approval grants specific environments. 3. Apply opens for exactly those.

See the whole run, step by step →

Your code, not our black box.

Every blueprint composes into plain infrastructure as code you can read and edit, in a guided form or a full editor. Your app settings too: Helm values, visible and editable, versioned with everything else. Standard modules, standard files, in Git. No proprietary language to learn, nothing to migrate away from.

The real infrastructure as code: upstream module source visible, nothing hidden.
Edited by hand: the same setting you could change in the editor.
ProposePlanReviewApplyEvidence

The code you reviewed is the code that runs.

Run a plan and the change locks to exactly what you’ll review. Review unlocks apply, for the environments you grant and nothing else. Nothing lands unapproved. Not a teammate’s change. Not even your own.

Destroy passes the same gate.

Every change gets a second look.

Reviewers see the plan output and the locked code, then approve per environment. Working solo? Your self-review is recorded, so the discipline, and the paper trail, start on day one.

The locked flow: the exact code you reviewed is the code that applies.
The gate at work: only what was approved can apply, in the environment you choose. Nothing runs without an approval.

Start from a blueprint, not a blank page.

Battle-tested module combinations with smart settings, every one of them editable. Starting fresh or bringing what you already run, both are day-one paths.

Available now · our first blueprints run on AWS
  • Governed cloud foundation: accounts, network, guardrails, and identity, the foundation everything else lands on.
  • Kubernetes workload platform: clusters, access, registry, and observability, where your apps run.
  • Encrypted data service: a managed database with encryption at rest and governed secrets, a data tier by the book.

Every one editable, every change through the same gate.

Coming next

New module combinations

Admitted onto the same gate and evidence machinery.

On the roadmap

Beyond the first cloud

The gate and the evidence layer don’t care which cloud is underneath.

Don’t see what you need? Bring your own modules and Helm charts, governed the same, or request it: we turn requests around in 24 to 48 hours.

See what’s inside every blueprint →

Three reasons to relax

See what your cloud is wasting. Free, in every tier.

Quantified findings: idle capacity, oversized instances, forgotten resources, each one in a table you can act on. Fixing them is a governed change like any other, and always your call.

A failed apply doesn’t leave you stranded.

If a run fails, you choose the way back: roll back to your last good version, or fix forward with one small, re-reviewed change. Your call, never automatic.

Every change answers who, what, when, and why.

Who proposed it, who approved it, the exact plan, the exact run: one durable record per change, exportable when someone asks.

Leaving is always possible. Everything keeps working.

Your Git and your code are yours. Leave anytime, with everything handed off.

CozyHawk composes standard infrastructure as code from standard modules, in Git you can take with you: the repositories, the state, and the evidence record, handed off whenever you say. We’d rather earn the renewal than lock the door.

Free to build and preview, always. Pay for what you govern.

Pick a tier. Your price grows in predictable bands as CozyHawk governs more of your infrastructure, never per resource and never per change.

From one engineer to a full platform team, every change passes the same review gate.

Live today

Solo

$1,500/mo per platform

Launch pricing: our early rate. Final pricing is set at general release, and we’ll tell you before anything changes.

One builder, the full governed flow.

20 governed modules included

+$750/mo per 15 more. No ceiling.

Reviewers free, always.

  • Most starter platforms fit inside the included 20.
  • Add up to 2 more builders at $250/mo each.

Ticket support with fast turnaround.

Build and preview free today. Ready to apply? We activate your subscription and you’re governed-live.

Start free
Early access

Team

$4,500/mo per platform

Early access, onboarded hands-on. Final pricing is set at general release.

The same gate, with real reviewers.

50 modules + 3 builders included

+$1,000/mo per 25 more.

Reviewers free, always.

  • SSO, the full catalog, and multiple accounts.
  • Add more builders at $250/mo each.

You work directly with the founder.

Talk to us
Let’s scope it

Enterprise

From $10,000/mo per platform

Custom bands, annual terms.

One platform, however large.

Around 150 modules standard

Then 50-module packs. Custom bands.

Reviewers free, always.

  • Dedicated, isolated database option.
  • A flat Optimization line negotiated from documented savings. Never a percentage, never a guarantee.

Dedicated support, founder at the table.

Book a working session

Done-with-you

Greenfield or brownfield, engineers stand it up with you: assessment, blueprint, import, pilot. Fixed-price quotes, starting at $7,500. Book an Assessment first and half its fee comes off your Blueprint within 30 days.

See the four engagements →

Book a working session
  • Predictable bands, never per resource. Each tier includes a governed-module allowance, and bands are sized so a whole blueprint fits comfortably inside one. Growth moves you one band at a time, never a surprise bill. Before you approve a change, you see the billable delta: “adds 5 modules: 42 → 47, within your band.”
  • A module counts once. Promote it through dev, staging, and production and it is still one module, not three bills. A genuinely separate region is its own module. You pay for what’s live under governance, never per change, never per review.
  • Reviewers are free. Reviewer, approver, and read-only seats cost nothing, in every tier.
  • The savings finder is free, everywhere. Findings and dollar amounts visible in every tier, laid out in a table you can act on. Acting on them is governed work you control.
  • Private modules and AI compose, in every tier. Bring your own modules and Helm charts and CozyHawk reads their variables and makes them editable, or describe what you need and let CozyHawk compose it. Metered fairly, never gated.
  • Your own Git org is free, forever. Or we run it for you: your org and repos provisioned, hosted, and wired into the governed loop for a flat $150/mo per org, every tier. Group your platforms into orgs however you like. Leave whenever you want; every repo goes with you. CI runners are a separate choice.

Fair questions

What counts as a governed module?

One top-level thing CozyHawk governs: a network, a cluster, a database. The pieces inside never count, and promoting a module through dev, staging, and production counts it once, not once per environment. Imported resources you’re only observing are free until you turn governance on.

What is always free?

Building and previewing, in every tier, always. The savings finder shows its dollar amounts in every tier, and connecting your own Git org is free forever. Free means free, not a trial.

When am I charged?

You build, plan, and review free; your subscription starts when you’re ready to apply. From then on you pay for what’s live under governance, in predictable bands, and every change shows its billable delta before you approve it. Decommission a module and the slot frees up, prorated.

Can I leave? Whose Git is it?

Yours. Everything CozyHawk composes is plain infrastructure as code in your own Git org, and it keeps working if you walk away. If we host Git for you, every repo goes with you when you leave.

If billing ever lapses, new applies pause. Your code, your state, and your evidence are never held hostage.

Founder-led by a senior platform engineering practitioner with deep hands-on experience across cloud, infrastructure, GitOps, security, and delivery systems.

Govern every platform change before it lands.

Two ways in: watch a real change land, or build it with us.

Watch a change land

One governed run, end to end.

Book a working session

30 minutes, engineer to engineer