About SoftGEM
SoftGEM Global Technologies LTD is an AWS Advanced Consulting Partner with a small-and-medium-business (SMB) practice. We design, build, and operate AWS platforms for customers under 500 employees and under $100M annualized revenue. Our customer profile is regulated financial services, traditional services businesses, and SMB corporate clients in Nigeria, West Africa, and the United States.
Customers reach us at support@softgem.org or via the contact form at softgem.org. A first sizing call typically runs 30 minutes; an AWS Pricing Calculator estimate in the customer's chosen Region follows within five business days.
Our service offerings
We organise customer engagements around four flagship service lines:
| # | Offering | What it covers |
|---|---|---|
| 1 | Cloud Migration & Modernisation | Moving SMBs off legacy infrastructure onto AWS, with modernisation onto containers where the workload supports it. |
| 2 | Cloud Consulting & Cost Optimisation | Cloud strategy advisory plus measurable cost reduction on AWS run-rate. |
| 3 | Cloud Security | Security posture deployment and operation for regulated SMBs. |
| 4 | Artificial Intelligence | Generative AI advisory, RAG pattern design, and MVP build on Amazon Bedrock. |
Each offering is a fixed-price professional services engagement under a Statement of Work. AWS infrastructure is passed through to the customer at AWS list rates with no markup. Ongoing operations are optional under a separate Managed Services Agreement.
1. Cloud Migration & Modernisation
Who this is for
SMBs moving off legacy or under-sized infrastructure onto AWS for the first time, or modernising an existing AWS footprint that has grown ad-hoc. Typical workload size $800 – $5,000 per month in steady-state AWS spend after the migration.
Use case
Customer needs to move production workloads onto AWS without putting the business at risk in a single cutover. Where the application supports it, we modernise onto Amazon ECS on AWS Fargate to right-size compute per service rather than per VM. Where the application does not, we lift-and-shift onto right-sized Amazon EC2 with Auto Scaling, then sequence a modernisation backlog for follow-on engagements. We routinely split migrations into a lower-risk storage phase followed by a higher-risk application phase when the customer's risk profile demands it.
What you receive
- Migration assessment — application inventory, dependency map, target AWS architecture documented in a Solution Design Record signed off by an AWS Certified Solutions Architect – Professional.
- Phased migration plan — sequenced cutovers with rollback paths; storage-first migration where appropriate; named migration windows agreed with the customer.
- Storage migration to Amazon S3 with lifecycle policies (Standard-IA at 90 days, Glacier at one year, Object Lock for regulated content where retention is set by a regulator).
- Application-tier modernisation to Amazon ECS on AWS Fargate where the application supports containerisation; right-sized Amazon EC2 with Auto Scaling where it does not.
- Data tier — Amazon RDS Multi-AZ (PostgreSQL or SQL Server) with at-rest encryption under customer-managed KMS keys; automated backups via AWS Backup; tested cross-AZ restore path.
- Database migration — AWS Database Migration Service for in-place engine moves and ongoing replication during cutover; AWS Application Migration Service for VM-level rehost where used.
- CI/CD — AWS CodePipeline + CodeBuild + CodeDeploy with named-approver manual gates before production. Amazon ECR scan-on-push for container images.
- Documentation, training, and a first end-to-end disaster-recovery drill against the AWS Backup vault.
2. Cloud Consulting & Cost Optimisation
Who this is for
SMBs at the start of their AWS journey who need a strategy and a roadmap before they commit to a build, and SMBs already on AWS whose run-rate has drifted upward and needs an audit + remediation plan. Typical engagement length: 4–8 weeks for the advisory; rolling for ongoing cost optimisation reviews.
Use case
Customer needs a written AWS strategy and architecture they can sign off on before any build begins, and a 6-month cost-optimisation roadmap with named actions and projected savings. We work the strategy half (Well-Architected reviews, landing zone design, target architecture, Solution Design Record) and the cost half (Pricing Calculator baseline, audit of the existing run-rate where one exists, named actions for Savings Plans, S3 tiering, right-sizing, idle resource cleanup).
What you receive
- AWS Well-Architected review across all six pillars (Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, Sustainability). Output: AWS Well-Architected Tool report with prioritised remediation backlog.
- AWS landing zone design — Organizations + Control Tower with OUs for production, non-production, security, log archive, sandbox. Signed off by an AWS Certified Solutions Architect – Professional.
- Solution Design Record covering the target AWS architecture for the customer's workload — services, network, identity, data, observability, security, integrations, RTO/RPO targets, cost model.
- AWS Pricing Calculator estimate produced with assumptions documented; comparison to the customer's prior or alternative baseline (lift-and-shift if applicable).
- 6-month cost optimisation roadmap with named actions and projected savings per action. Typical actions: Compute Savings Plans purchase once 90 days of Fargate usage data is available; AWS Security Hub control suppression for non-applicable rules; S3 Intelligent-Tiering on buckets with uneven access patterns; RDS instance class right-sizing after observed CPU patterns; AWS Trusted Advisor recommendations remediated.
- Cost monitoring setup — Amazon CloudWatch cost dashboards; AWS Budgets alerts; AWS Cost and Usage Report (CUR) shipped to S3 and queried via Amazon Athena.
- Quarterly cost review cadence post-handover, aligned to the customer's governance review cycle.
3. Cloud Security
Who this is for
SMB banks, microfinance institutions, SEC-licensed asset managers, and other regulated firms whose security posture must hold up to a CBN, SEC, or equivalent regulator inspection. Also for SMBs whose existing AWS footprint is functional but has drifted (security findings accumulated, IAM sprawl, missing encryption, no audit trail).
Use case
Customer needs a security posture deployed, documented, and operating across every AWS account — not a theoretical security model. We deploy the full security stack at engagement start (Security Hub baseline, GuardDuty, WAF, KMS, CloudTrail, IAM Identity Center), tune it for the customer's workload, and hand it over with the runbooks, the operating model, and the quarterly review cadence to keep it healthy.
What you receive
- Security baseline — AWS Security Hub enabled with the CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices standards across every account. Findings triaged on engagement; non-applicable controls suppressed with justification; outstanding findings tracked with a named owner and close date.
- Threat detection — Amazon GuardDuty with VPC Flow Log, DNS log, CloudTrail Management Event, and S3 Protection analysis enabled. HIGH and CRITICAL findings paged to on-call.
- Edge protection — AWS WAF with AWS Managed Rule Groups (Common Rule Set, Known Bad Inputs, SQL Injection, Linux OS, IP Reputation), rate-based rules on customer-facing and authentication endpoints, and customer-specific custom rules for sensitive endpoints (KYC, payment, admin paths).
- Encryption posture — customer-managed AWS KMS keys per data domain (typically five: database, sensitive documents, statements, backups, EBS). At-rest encryption enabled on every data store; TLS 1.2+ enforced through AWS Certificate Manager.
- Identity — AWS IAM Identity Center for human access with permission sets per role; per-service IAM roles for workloads; no long-lived IAM users in workload accounts; MFA enforced.
- Audit posture — AWS CloudTrail enabled in all regions with log-file integrity validation; CloudTrail Insights enabled; logs delivered to a dedicated audit-log bucket with restrictive access.
- Vulnerability scanning — Amazon Inspector enabled for EC2 instances and ECR container images; findings routed alongside Security Hub.
- Secrets management — AWS Secrets Manager with rotation enabled where the integration supports it; no secrets in code, no secrets in environment variables outside Secrets Manager.
- Customer-specific runbook set — incident response, security-event triage, IAM access review, key rotation procedures.
- Compliance documentation — control inventory mapped to the customer's regulatory context (CBN, SEC, HIPAA, PCI DSS, GDPR — whichever apply).
4. Artificial Intelligence
Who this is for
SMBs evaluating generative AI on AWS for the first time, or moving from a small internal experiment to a production-grade pilot. Typical entry point: a customer with a specific business problem (customer-support deflection, document summarisation, knowledge-base Q&A) that a retrieval-augmented generation (RAG) pattern over the customer's existing data is well-positioned to address. Positioned as a starter engagement — not a large-scale ML platform build — to give the customer a working pilot they can decide to grow from.
Use case
Customer has a defined business problem where generative AI is the candidate solution. We help the customer: (1) decide whether Gen AI is the right tool for the problem (some problems are better solved with conventional code); (2) design the RAG pattern over the customer's existing data — what data sources, what embedding model, what vector store, what retrieval strategy, what foundation model; (3) build the MVP — a working pilot deployed in an AWS account, with the customer's actual data; (4) plan the production rollout — guardrails, monitoring, cost control, security review.
What you receive
- Feasibility advisory — written assessment of whether generative AI is the right approach for the customer's problem, with the trade-offs of Gen AI vs conventional approaches documented. Where Gen AI is the right approach, the assessment names the foundation model family expected to perform best on the customer's task.
- RAG architecture design — pattern document covering data ingestion (source systems, document chunking strategy, embedding pipeline), vector storage (Amazon OpenSearch Service or Amazon Bedrock Knowledge Bases), retrieval orchestration, prompt engineering, and the response evaluation harness.
- MVP build — working pilot deployed in the customer's AWS account. Foundation model access through Amazon Bedrock. Knowledge base of the customer's actual data (subject to data-handling sign-off). Endpoint exposed through Amazon API Gateway; called from the customer's existing application or a thin demo front-end.
- Guardrails — Amazon Bedrock Guardrails configured for the customer's sensitive-content boundaries (PII handling, regulated terms, off-topic deflection).
- Cost model — observed cost per query during MVP testing; projection for production traffic; recommendations on model selection (e.g., Amazon Titan vs Anthropic Claude vs Meta Llama) based on cost per response and quality at the customer's task.
- Production rollout plan — written plan covering security review, monitoring, cost control, and the path from pilot to production, with named gates and timeline.
- Knowledge transfer — workshop with the customer's engineering team covering Bedrock, the RAG architecture, the evaluation harness, and the operating model.
How we engage
Every engagement runs through the same phases, regardless of which offering the customer chooses:
| Phase | What happens | Customer involvement |
|---|---|---|
| P0 Sizing call | Customer profile, workload, target AWS Region, customer fit confirmed | 30-min call with technical and business lead |
| P0 Pricing estimate | AWS Pricing Calculator estimate for the workload, with assumptions documented | Customer reviews and signs off the estimate |
| P0 Fact sheet | SoftGEM drafts the customer fact sheet — the single source of truth for the engagement | Customer reviews architecture and operational details |
| P0 SOW | Statement of Work under Master Services Agreement; fixed-price professional services; AWS pass-through | Customer signs the SOW |
| P1–P3 Build | AWS environment built per the SOW; weekly status; sprint demos every two weeks | Sprint review attendance; customer-side acceptance testing |
| P4 Handover | Documentation, runbooks, training delivered; first DR drill executed (where applicable) | Customer-side training cohorts attend; ops lead countersigns runbooks |
| Post-handover | Operate the AWS account under MSA; quarterly governance reviews; quarterly DR drills | Customer holds the AWS payer relationship; SoftGEM operates |
Adjacent services
The four flagship offerings above are our most-requested entry points. Adjacent services are available to existing customers under a separate Statement of Work:
- Managed AWS Operations under MSA — ongoing operation of the customer's AWS account post-handover, with on-call cover, incident response, deploy support, capacity tuning, and quarterly governance reviews.
- Quarterly DR Drill Execution — Tier-1 restore drills conducted against the AWS Backup vault, with a signed drill report capturing actual RTO and RPO.
- Architecture Health Check — single-engagement review of an existing AWS workload, with a written remediation backlog.
- AWS Well-Architected Review (full) — facilitated review across all six pillars with the customer's team, ending in a Well-Architected Tool report and a prioritised remediation backlog.
- Cost Optimisation Health Check — single-engagement review of an existing AWS run-rate, with a named-actions remediation backlog and a projected savings figure.
Who we work with
SoftGEM serves SMB customers — businesses under 500 employees and under $100M annualized revenue. Typical industry profiles in the active customer base: microfinance and Tier-3 banking, SEC-licensed asset management, payments and financial technology with regulator oversight, real estate, IT services, professional services. We confirm customer fit before drafting a Statement of Work and document it in the customer fact sheet.
Contact
support@softgem.org · softgem.org · Lagos, Nigeria