Skip to content
Pricing

Platform Reliability Retainer

Fractional Principal DevOps function: Kubernetes + automation + databases + incident prevention — without hiring full-time.

Compare Graded Audit Packages

Stabilization Sprint

One-time infrastructure audit and quick wins

$2,500-$7,500 one-time

Based on infrastructure complexity

  • Infrastructure audit + risk assessment
  • Top 10 reliability issues addressed
  • Backup verification + recovery testing
  • Deploy pipeline sanity check
  • Quick wins documentation
Most Popular

Core

Essential platform reliability retainer

$5,000 /month

3-month minimum commitment

  • Weekly reliability planning + prioritized backlog
  • CI/CD improvements + release safety
  • K8s hygiene: resources, HPA, observability basics
  • DB reliability: backups, restores, performance triage
  • Security baseline + SMB automation (QuickBooks/CRM)

Plus

Full platform engineering with on-call support

$8,500 /month

3-month minimum commitment

  • Everything in Core, PLUS:
  • On-call window / faster response
  • Deeper observability + custom image advisory (builds scoped separately)
  • DR runbooks + game days
  • Infrastructure cost optimization + executive reviews
Scoped custom image services

Custom image packages and pricing anchors

Choose the smallest package that matches the outcome. Every band is a planning anchor and is finalized only after the target matrix, evidence, access, licensing, and support boundaries are reviewed.

Price bands are planning anchors, not offers to sell. Final pricing and every customer-specific statement of work require scoped review and human approval.

image_assessment

Image Assessment

$750-$2,500

Planning anchor

Inspect the current image and build process and recommend a maintainable path.

Deliverables

  • Short findings memo
  • Current artifact and build-process inventory
  • Prioritized risk list
  • Recommended package and maintainable path

Prerequisites

  • Access to representative current artifacts, build sources, and available build or release notes
  • A customer technical owner available to walk through the current process
  • An initial list of target environments and known entitlement constraints

Explicit exclusions

  • Production artifact changes or a production-ready replacement image
  • Certification, marketplace listing, or commercial OS redistribution approval
  • Remediation, pipeline implementation, or ongoing CVE response unless separately scoped

Quote factors

  • OS bases and versions
  • Artifact targets
  • Cloud, region, account, and publishing scope
  • Compliance controls and evidence
  • Runtime validation depth
  • Customer-private software and license entitlements

Maintenance / SLA boundary

  • This is a point-in-time assessment with no rebuild, patching, response-time, or release-cadence commitment.
  • Any remediation or ongoing support starts under a separately approved package and SOW.

Human review required before a customer-specific SOW is released.

  • Customer-specific SOW: A human must approve scope, assumptions, price, acceptance criteria, and legal boundaries before a customer-specific SOW is released.
  • Marketplace listing or private offer: A human must approve any marketplace listing, listing change, software-premium price, or private offer before publication.
  • Compliance claim: A human must approve every public or customer-facing compliance claim and verify that its wording matches the evidence.
  • Commercial OS redistribution: A human must verify documented redistribution rights before TacitSoft distributes an image containing a commercial OS or customer-private software.

This package is not available through self-service checkout.

one_off_build

One-Off Custom Image Build

$1,500-$5,000

Planning anchor

Build one customer-approved target image from a known and lawfully usable base.

Deliverables

  • One customer-approved target artifact
  • Published artifact checksums
  • Basic build and reproduction notes
  • Recorded smoke-test result tied to the delivered artifact

Prerequisites

  • A known base with customer-confirmed OS and software usage rights
  • One written target specification and one written acceptance test set
  • Controlled access to required private software and the delivery destination

Explicit exclusions

  • A reusable production pipeline, additional bases, versions, architectures, or target artifacts
  • Ongoing rebuilds, CVE response, rollback support, or release operations
  • Certification, marketplace publication, and redistribution-rights determinations

Quote factors

  • OS bases and versions
  • Artifact targets
  • Cloud, region, account, and publishing scope
  • Compliance controls and evidence
  • Runtime validation depth
  • Customer-private software and license entitlements
  • Marketplace listing or private-offer requirements

Maintenance / SLA boundary

  • Delivery and acceptance end the one-off engagement; no future compatibility or vulnerability-response SLA is included.
  • Post-acceptance changes or rebuilds require written change control or a Maintained Image Lane.

Human review required before a customer-specific SOW is released.

  • Customer-specific SOW: A human must approve scope, assumptions, price, acceptance criteria, and legal boundaries before a customer-specific SOW is released.
  • Marketplace listing or private offer: A human must approve any marketplace listing, listing change, software-premium price, or private offer before publication.
  • Compliance claim: A human must approve every public or customer-facing compliance claim and verify that its wording matches the evidence.
  • Commercial OS redistribution: A human must verify documented redistribution rights before TacitSoft distributes an image containing a commercial OS or customer-private software.

This package is not available through self-service checkout.

golden_image_pipeline

Production Golden Image Pipeline

$7,500-$15,000+ setup

Planning anchor

Create a reproducible image pipeline with tests, scanning, SBOM generation, signing, and release notes.

Deliverables

  • Reproducible build and release pipeline
  • First identified and tested image release
  • Evidence pack with checksums, scan results, SBOM, signature, tests, and release notes
  • Pipeline operations and handoff documentation

Prerequisites

  • Approved base, component inventory, and customer-confirmed entitlement position
  • Source-control, runner, signing, scanning, and target-environment access through controlled mechanisms
  • Written release, test, evidence, signing-key ownership, and artifact acceptance criteria

Explicit exclusions

  • Ongoing pipeline operation, scheduled rebuilds, or CVE response after the first release
  • Targets, regions, accounts, architectures, or control baselines not named in the SOW
  • Certification, marketplace publication, and commercial OS redistribution approval

Quote factors

  • OS bases and versions
  • Artifact targets
  • Cloud, region, account, and publishing scope
  • Compliance controls and evidence
  • Runtime validation depth
  • Customer-private software and license entitlements
  • Marketplace listing or private-offer requirements

Maintenance / SLA boundary

  • Setup includes the first release and handoff only; rebuild cadence and CVE response begin only when separately scoped.
  • Signing-key custody, rotation, revocation, and emergency-release responsibilities must be assigned in writing.

Human review required before a customer-specific SOW is released.

  • Customer-specific SOW: A human must approve scope, assumptions, price, acceptance criteria, and legal boundaries before a customer-specific SOW is released.
  • Marketplace listing or private offer: A human must approve any marketplace listing, listing change, software-premium price, or private offer before publication.
  • Compliance claim: A human must approve every public or customer-facing compliance claim and verify that its wording matches the evidence.
  • Commercial OS redistribution: A human must verify documented redistribution rights before TacitSoft distributes an image containing a commercial OS or customer-private software.

This package is not available through self-service checkout.

multi_cloud_program

Multi-Cloud / Appliance Image Program

$15,000-$40,000+

Planning anchor

Use one approved specification to produce multiple target artifacts or cloud releases.

Deliverables

  • Approved artifact, cloud, account, region, and architecture matrix
  • Defined build and promotion channels for each included target
  • Target-specific test results and consolidated evidence pack
  • Release, ownership, escalation, and support plan

Prerequisites

  • One approved source specification with documented target-specific variations
  • Customer-owned test accounts, quotas, networking, publishing permissions, and acceptance owners for every target
  • Confirmed entitlement and redistribution position for every OS, package, cloud, and appliance channel

Explicit exclusions

  • Any cloud, artifact, account, region, architecture, or promotion channel outside the approved matrix
  • Open-ended managed operations or support beyond the written support plan
  • Marketplace publication, certification, and redistribution approval without their human-review gates

Quote factors

  • OS bases and versions
  • Artifact targets
  • Cloud, region, account, and publishing scope
  • Compliance controls and evidence
  • Runtime validation depth
  • Maintenance and release cadence
  • CVE trigger thresholds and response SLA
  • Customer-private software and license entitlements
  • Marketplace listing or private-offer requirements

Maintenance / SLA boundary

  • The support plan must separate setup and handoff from any recurring release or incident-response commitment.
  • New targets and material target-specific changes use written change control and may change program pricing.

Human review required before a customer-specific SOW is released.

  • Customer-specific SOW: A human must approve scope, assumptions, price, acceptance criteria, and legal boundaries before a customer-specific SOW is released.
  • Marketplace listing or private offer: A human must approve any marketplace listing, listing change, software-premium price, or private offer before publication.
  • Compliance claim: A human must approve every public or customer-facing compliance claim and verify that its wording matches the evidence.
  • Commercial OS redistribution: A human must verify documented redistribution rights before TacitSoft distributes an image containing a commercial OS or customer-private software.

This package is not available through self-service checkout.

maintained_image_lane

Maintained Image Lane

$1,000-$3,000+/mo minimum

Planning anchor

Provide governed ongoing rebuilds, CVE response, scheduled releases, and rollback or revocation support.

Marketplace alternative: $0.03-$0.10/hr software premium

The applicable premium depends on standard versus hardened or compliance-evidence positioning and still requires marketplace and commercial review.

Deliverables

  • Scheduled rebuilds and releases at the contracted cadence
  • Release artifacts and agreed checksums, tests, scan, SBOM, signing, and release evidence
  • CVE triage and rebuild response when written trigger thresholds are met
  • Contracted rollback, artifact revocation, notification, and release-history support

Prerequisites

  • An accepted reproducible pipeline and identified baseline release under TacitSoft or customer ownership
  • A written vulnerability source, severity and applicability policy, response timer, rebuild deadline, and exception path
  • An approved release calendar, maintenance windows, access plan, acceptance owner, and escalation contacts

Explicit exclusions

  • Major OS migrations, new artifact types, new clouds, new control baselines, or material application changes
  • Twenty-four-by-seven response, guaranteed remediation, or emergency engineering unless explicitly contracted
  • Marketplace fees or publication, license costs, certification, and redistribution-rights determinations

Quote factors

  • OS bases and versions
  • Artifact targets
  • Cloud, region, account, and publishing scope
  • Compliance controls and evidence
  • Runtime validation depth
  • Maintenance and release cadence
  • CVE trigger thresholds and response SLA
  • Customer-private software and license entitlements
  • Marketplace listing or private-offer requirements

Maintenance / SLA boundary

  • The SOW must define scheduled cadence separately from event-driven CVE releases and state which clock begins at advisory publication, customer notice, or applicability confirmation.
  • Rollback and revocation scope must name retained versions, promotion channels, notification owners, response hours, and evidence expectations.

Human review required before a customer-specific SOW is released.

  • Customer-specific SOW: A human must approve scope, assumptions, price, acceptance criteria, and legal boundaries before a customer-specific SOW is released.
  • Marketplace listing or private offer: A human must approve any marketplace listing, listing change, software-premium price, or private offer before publication.
  • Compliance claim: A human must approve every public or customer-facing compliance claim and verify that its wording matches the evidence.
  • Commercial OS redistribution: A human must verify documented redistribution rights before TacitSoft distributes an image containing a commercial OS or customer-private software.

This package is not available through self-service checkout.

Inputs that drive a quote

A written response is required for each applicable input; “none” is valid when a requirement does not apply.

OS bases and versions
List each distribution or base, version, architecture, support channel, and lifecycle status.
Artifact targets
List every required output format and target, such as ISO, PXE, AMI, QCOW2, VDI, bootc, or appliance media.
Cloud, region, account, and publishing scope
Identify every destination cloud, region, account, registry, promotion channel, and customer handoff path.
Compliance controls and evidence
Name the control baselines, requested claim term, evidence artifacts, assessors, and retention requirements; use none when not applicable.
Runtime validation depth
Define smoke, boot, integration, security, performance, and application tests plus the environments in which they must run.
Maintenance and release cadence
State scheduled rebuild and release frequency, maintenance windows, blackout periods, and release-notice expectations.
CVE trigger thresholds and response SLA
Define severity source, score or advisory thresholds, affected-component rules, triage timer, rebuild deadline, emergency path, and exceptions.
Customer-private software and license entitlements
Identify private packages, entitlement owner, permitted sources, redistribution constraints, and controlled access method. Do not include credential or license-secret values.
Marketplace listing or private-offer requirements
Identify marketplace, listing owner, seller account, regions, pricing model, metering, support terms, legal review, and private-offer needs; use none when not applicable.

SOW boundaries

These boundaries are required in every custom-image statement of work.

OS and software entitlements
The customer owns OS and software entitlement verification unless TacitSoft is explicitly contracted in writing to manage a named entitlement task.
Credentials and secrets
TacitSoft does not accept uncontrolled credential embedding. Access must use an approved secret manager, temporary role, or other controlled delivery method with rotation and revocation ownership.
Compliance language
Every compliance statement must use the catalog definitions for aligned to, tested against, or certified and must match the available evidence.
Written image acceptance
Acceptance is based only on written test and evidence criteria tied to an identified artifact; subjective production use or silence is not acceptance.
Maintenance triggers and cadence
Ongoing maintenance must name vulnerability trigger thresholds, severity source, response and rebuild timers, scheduled cadence, rollback or revocation path, and excluded events.
Artifact and target scope changes
A new OS version, artifact target, cloud, region, account, control baseline, or material test requirement is out of scope until approved through written change control.

Compliance claim language

Aligned to
The design or configuration maps to named controls. It does not state that tests passed or that certification was granted.
Tested against
Named tests were executed against an identified artifact and the recorded results are available. It does not state that certification was granted.
Certified
Use only when an authorized certifying body has granted a current certification for the stated scope and the claim has human approval.
Request a Scoped Review

No marketplace listing, compliance claim, redistribution decision, or customer SOW is released automatically.

Start with a consultation

Not sure which retainer fits? Let's discuss your infrastructure challenges and explore how platform engineering can help.

Free

15-Minute Discovery Call

Quick conversation to understand your current setup, biggest pain points, and whether fractional DevOps makes sense for your business.

  • Infrastructure quick assessment
  • Pain point identification
  • Next steps recommendation
Book Free Discovery Call

$100

1-Hour Deep Dive Consultation

Comprehensive review of your current infrastructure, automation opportunities, and detailed roadmap for platform reliability improvements.

  • Complete infrastructure audit
  • Automation opportunity mapping
  • Detailed improvement roadmap
  • Cost optimization recommendations
  • Written follow-up summary
Book Consultation

Both consultations can be credited toward any retainer engagement.

Custom capabilities & add-ons

Need something more specialized? Add these capabilities to any retainer or as standalone projects.

Custom Image Services

Separately scoped assessment, one-off build, golden image pipeline, multi-cloud program, or maintained lane with written acceptance and review gates

Multi-Cloud Architecture

Cloud-agnostic management platforms spanning AWS, Azure, GCP, and OCI

Enterprise CI/CD

CloudBees Jenkins, GitHub Actions, GitLab CI with advanced pipeline optimization

SMB Business Automation

QuickBooks & CRM integrations as part of comprehensive platform connectivity

Frequently Asked Questions

Everything you need to know about fractional DevOps and platform engineering

You get principal-level expertise (15+ years) without the $200K+ salary, benefits, and hiring time. Perfect for SMB SaaS companies who need senior platform engineering but can't justify or find full-time talent.
That's exactly what the Stabilization Sprint is for. We audit everything, identify the top 10 risks, and fix the most critical issues first. Then move to ongoing retainer for continuous improvement.
Yes, production-grade K8s is a core specialty. We handle everything from initial setup to advanced observability, security hardening, and cost optimization across AWS, Azure, and GCP.
Yes. Custom image work is offered through the scoped packages above. Each build starts from a customer-approved base and written acceptance criteria; marketplace, compliance, and commercial OS redistribution actions require separate human review.
We include business automation as part of our platform engineering approach. QuickBooks, CRM integrations, and other SMB tools are components we can connect into your broader infrastructure.
Immediate wins within the first week. Critical reliability issues get addressed in the Stabilization Sprint. Ongoing retainers show measurable improvements in deployment safety and incident reduction within 30 days.

Ready to stop fighting production fires?

Get principal-level platform engineering expertise without the full-time hire. Let's discuss which approach fits your infrastructure needs.