Nairobi · AWS Certified SMEs

Your AWS bill is a
decision waiting
to be made.

MAKAO Labs finds what's burning money inside your AWS account — idle resources, overprovisioned services, gaps in your pipeline — and hands you a roadmap you can act on, with or without us.

Built for African founders No data leaves your cloud AWS Certified engineers
makao-audit · client-env · ap-east-1
$ ./makao_audit.sh --account acme-prod
──────────────────────────────────
Scanning 6 regions · EC2, RDS, S3, Lambda, EBS
Idle EC2 (3 instances) HIGH $420/mo
Oversized RDS (db.r5.2xl) HIGH $340/mo
Unattached EBS volumes MED $88/mo
S3 — no lifecycle policy MED $55/mo
Reserved Instance opportunity OPT $210/mo
Identified savings — $1,113 /month
Roadmap PDF ready. Zero raw data transmitted.
15–35%
avg AWS savings identified per audit
5 days
from kickoff to full cost roadmap
0
bytes of raw data leave your cloud
AWS
certified engineers, based in Nairobi
The real problem

AWS was built for enterprises.
You're running a startup.

AWS pricing and tooling assumes you have a FinOps team, a dedicated DevOps function, and weeks to read documentation. Most African startups have none of those. The bill grows. The engineers blame each other. The CTO has no visibility.

📊

No visibility into what's actually spending

Your billing dashboard shows a number. It doesn't tell you which team, which service, which decision made it grow 40% last quarter.

🔧

Pipelines that break in production

Fragile CI/CD, no rollback strategy, manual deployments at 2am — the infrastructure works until it doesn't. And when it doesn't, everyone finds out at once.

🌍

Enterprise pricing, startup runway

AWS's default configurations are optimised for companies with millions in ARR. Your staging environment costs almost as much as production and nobody notices.

Our services

Four services.
One clear path forward.

Most founders start with the audit and graduate to advisory. You don't have to buy them all — but they're designed to work together.

1Start here
2Assess infra
3Enable DevOps
4Long-term partner
02 — Cloud Infrastructure Assessment

Know exactly what's running and whether it's sound

Architecture · Security · Reliability

We map your full AWS environment — services, dependencies, IAM, networking — and assess it against production-readiness standards. You learn what's fragile, what's a security risk, and what can be simplified. Ideal before a funding round, a new CTO, or a major product launch.

  • Full architecture diagram of your AWS environment
  • Security posture assessment (IAM, public exposure, root MFA)
  • Reliability risk flags with severity ratings
  • Written recommendations your engineers can act on
Request an assessment →
03 — DevOps Enablement

From fragile pipelines to reliable, measurable delivery

CI/CD · DORA Metrics · Team Maturity

If your engineers are deploying manually, rolling back by luck, or can't tell you your deployment frequency — this is the service. We build or fix your pipelines, introduce DORA metrics tracking, and leave your team running independently. No lock-in, no dependency on us.

  • CI/CD pipeline audit and reconstruction
  • DORA metrics baseline (deployment frequency, MTTR)
  • Rollback strategy and runbook
  • Team training and handover documentation
Talk to us about DevOps →
04 — Quarterly Advisory

A fractional cloud partner — not a vendor

Strategic · Ongoing · Embedded

Monthly check-ins, quarterly deep dives, on-call access during critical moments. We review your infrastructure decisions before they become expensive mistakes, help you evaluate new AWS services before adoption, and track cost and reliability KPIs alongside your business metrics.

  • Monthly architecture review calls
  • Pre-commit review of major infra changes
  • Cost and reliability dashboard (quarterly)
  • AWS roadmap input aligned to your growth stage
Enquire about advisory →
MAKAO Agent

Cost intelligence that runs
inside your cloud.

The Agent deploys as an AWS Lambda inside your own account. It scans weekly, writes findings to your DynamoDB, and emails your team a digest. No raw data ever leaves your environment. No dashboard to log into. No vendor dependency.

🔒

Zero-trust architecture

The Agent runs with a bare-minimum IAM role inside your VPC. Your data never crosses the boundary. Modelled after the same design philosophy as Kubernetes-native tooling.

📬

Weekly digest, no login required

Every Monday your engineering lead receives a structured email: new waste found this week, total identified savings, and the top 3 recommended actions.

⚙️

Cost as part of your observability

Cloud costs should be observed like latency or error rate — continuously, not quarterly. The Agent makes cost a first-class signal in your engineering workflow.

🌍

Multi-region, multi-service

Scans all your active regions automatically. Covers EC2, RDS, EBS, S3, Lambda, and Compute Optimizer recommendations — in a single weekly run.

makao-agent · weekly-scan · EventBridge trigger
08:00:01 [INIT] Agent started · account: acme-prod
08:00:02 [SCAN] Discovering active regions… 6 found
08:00:08 [SCAN] EC2 idle check complete → 3 findings
08:00:14 [SCAN] RDS rightsizing → 1 finding
08:00:19 [SCAN] EBS unattached → 4 volumes
08:00:23 [SCAN] Compute Optimizer pull → OK
08:00:25 [ALERT] New findings vs last week: +2
08:00:26 [STORE] DynamoDB write → 9 records
📧 WEEKLY DIGEST · acme-prod · 12 May 2025
Idle EC2 (us-east-1, ap-south-1) $420/mo
Oversized RDS db.r5.2xlarge $340/mo
4 unattached EBS volumes $88/mo
Total identified this week $848/mo
08:00:28 [DONE] Digest sent → cto@acme.io
All processing completed inside your AWS account. No external API calls made.

We go beyond the low-hanging fruit. We interview your teams, read your Terraform, and give you a backlog of tasks your engineers can execute on their own — whether you continue with us or not.

How it works

From discovery call
to deployed roadmap

Most engagements move from call to findings report within a week. Here's what to expect.

1

Discovery call

30 minutes. We learn your stack, your team, and what's keeping your CTO up at night. No sales deck, no pressure.

2

Script deployed to your account

You grant read-only access inside your own VPC. The audit script runs and writes findings to a local report. Nothing leaves your cloud.

3

Findings walkthrough

We present the findings to your engineering and product leads. Every item has a dollar value and a clear recommendation — not just a warning.

4

You decide what's next

Take the roadmap and run with it internally, continue with us for implementation, or deploy the Agent for ongoing monitoring. Your call.

Why MAKAO Labs

Built in Nairobi.
Designed for your context.

We're not a global consultancy with a generic AWS cost-optimisation playbook. We've built cloud infrastructure for African startups at seed, Series A, and Series B — we understand the constraints.

🌍

African startup economics

USD-denominated AWS bills on KES revenue. Lean engineering teams. Unpredictable traffic. We design for the actual constraints of scaling on this continent.

🔐

Your data stays in your cloud

Every tool we deploy runs inside your own AWS account. No credentials shared, no data transmitted to external systems. Increasingly important as African data regulation tightens.

📋

We leave behind a team, not a dependency

Every engagement ends with documentation your engineers can follow independently. We hand you a backlog, a runbook, and the knowledge to act without us.

Common questions

The things people
always ask us

You grant a read-only IAM role — no write permissions, no access to application data. The audit script runs inside your own account and writes a findings report locally. We never see your raw infrastructure data. The MAKAO Agent follows the same principle: it runs entirely inside your VPC with a minimum-permission role that we define together before deployment.
The audit script is a one-time diagnostic — you run it, get a report, and act on it. The MAKAO Agent is a Lambda function that runs automatically every week via EventBridge. It builds a history of findings, detects new waste that appeared since last week, and emails a digest to your team. Think of the script as a health check and the Agent as continuous monitoring.
Yes — arguably more so. The best time to instil cost discipline is before your bill becomes painful. We've seen teams go from $800/month to $12,000/month in six months because they scaled without any cost hygiene. An early audit sets the right foundations so growth doesn't automatically mean waste. The Infrastructure Assessment is particularly valuable at this stage — it finds the architectural decisions that become expensive later.
The cost audit is typically delivered within 5 business days of the discovery call. Infrastructure Assessment takes 1–2 weeks depending on environment complexity. DevOps Enablement is a 4–8 week engagement depending on scope. Quarterly Advisory is an ongoing retainer that begins with a full audit in week one.
For now, yes. Our tooling, certifications, and deep expertise are AWS-specific. Multi-cloud environments where AWS is the primary provider are fine, but we won't audit GCP or Azure resources at this stage.
We can implement for you. The audit is designed to be self-executable, but many clients prefer us to handle the changes — especially for IAM, RDS rightsizing, or Reserved Instance purchases. We always recommend you understand the change before it's made, and we document everything we do. Implementation engagements are scoped separately after the audit findings are reviewed.
Get started

Ready to see what your
AWS account is hiding?

The audit is free. The call is 30 minutes. The findings usually surprise people — not because the problems are unusual, but because nobody had looked before.

Prefer email? hello@makao-labs.com · Based in Nairobi, available across East Africa