production engineering / ai agents

Agents that survive contact with production.

We run a fleet of AI agents against our own production infrastructure every day, and have done through real outages, real deploys and real 3am pages. These services put that fleet, and the engineering behind it, to work inside your environment.

Scoped and priced before anything starts. You keep everything we build.

Assess

Start by finding out what is actually wrong.

Fixed-scope reviews that end in a written answer. Each one is useful on its own, whether or not you go further with us.

  • svc/assess

    AIOps and incident response assessment

    A fixed-scope review of your monitoring, alerting, on-call rotation and runbooks. We map where alerts come from, which ones nobody acts on, where the manual toil sits, and what could be automated safely today.

    • An alert audit: what fires, what gets acknowledged, and what is pure noise
    • A toil map: the repeated manual work your engineers do, ranked by hours and by risk
    • An automation roadmap: what to automate first, and what to leave alone
    • A report that stands on its own, useful whether or not you ever buy Nova
    From$9,500
  • svc/aispend

    AI spend audit and cost controls

    If you shipped an LLM feature in the last two years, you probably have unbounded spend, no per-request telemetry and no routing policy. We measure where the money actually goes, then install the controls that stop it running away.

    • Per-request accounting: model, tokens, latency and cost, for every call
    • Model routing, so cheap work stops going to expensive models
    • Caching and context trimming, the two changes that move the bill most
    • Hard budget ceilings and circuit breakers, so one retry loop cannot bill you overnight
    From$14,000
  • svc/agentsec

    AI agent security and governance review

    Your board will eventually ask what your agents are permitted to do to production. This is the review that answers it: what each agent can touch, what stops it, and what you could prove after the fact.

    • Blast radius: what each agent can reach, and the limits that hold it there
    • Prompt injection and data egress exposure across your agent surface
    • Approval gates and kill switches, tested rather than assumed
    • An audit trail good enough to reconstruct any decision six months later
    From$28,000
  • svc/data

    Data inventory and lineage mapping

    Most GDPR and DPIA work stalls because nobody can say where the data actually lives or where it flows. We build the inventory and the lineage map, then keep them current automatically.

    • Discovery and cataloguing across your databases, buckets and warehouses
    • Lineage tracking, so you can follow a field from source to report
    • Classification of the data that carries regulatory weight
    • A living map, refreshed on a schedule, rather than a spreadsheet that rots
    From$18,000
Build

Then put something in place.

Implementation work with a defined deliverable. You keep everything we build, including source and documentation.

  • svc/deploy

    Agent deployment and onboarding

    We install, configure and tune Nova against your real infrastructure, connect your existing monitoring and chat tools, and set the autonomy level each agent is allowed to operate at. You finish with agents doing useful work, not a trial account nobody logged back into.

    • Your cloud accounts, clusters, monitoring stack and alert routing wired up and verified
    • Trust tiers set per agent, so the fleet acts on what you approve and asks about the rest
    • Your existing runbooks imported so the agents work the way your team already does
    • A working session with your on-call engineers, plus written operating notes
    From$22,000
  • svc/build

    Custom agent development

    The most valuable automation is usually specific to one company. We build agents against your systems using the same framework, trust scoring and audit ledger that runs our own production fleet, so a custom agent is governed exactly like a built-in one.

    • Internal APIs, bespoke tooling and legacy services the standard integrations do not cover
    • Every custom action trust-scored, cost-tracked and written to the audit trail
    • Approval gates you control: what runs autonomously, and what waits for a human
    • Delivered with source and documentation so your team can extend it
    From$45,000
  • svc/runbook

    Runbook automation

    Most teams have runbooks that get followed by hand at three in the morning. We convert them into automated remediation workflows with proper guardrails, so routine cases resolve themselves and your engineers are only woken for the ones that need judgement.

    • We start from the runbooks you already trust, rather than rewriting them
    • Blast radius limits and rollback paths defined before anything is allowed to act
    • Reporting on how often each workflow fires, and how often it fixes the problem first try
    • Anything outside the defined envelope still reaches a human immediately
    From$16,000
  • svc/observe

    Observability consolidation

    Observability is usually the second largest infrastructure line after compute, and most of it is paid for data nobody queries. We run Nova alongside your incumbent, prove coverage on real incidents, then cut what you are no longer using.

    • Parallel run against Datadog, New Relic, Dynatrace, Splunk, Grafana, Prometheus or Elastic
    • Coverage proven on your real incidents before anything is switched off
    • Retention and cardinality reviewed, which is usually where the bill actually lives
    • A staged reduction plan with the numbers to take to finance
    From$55,000
  • svc/oncall

    On-call programme design

    Rotas, escalation paths, severity levels and service ownership, designed once and properly. Most on-call pain is a design problem rather than a tooling problem.

    • Rotations and escalation policies that match how your team actually works
    • SLOs and error budgets, with gates that hold releases when the budget is spent
    • Postmortems produced automatically from the incident record
    • Handover and wellbeing built in, so the rota survives its first bad month
    From$14,000
Govern and scale

And make it hold up under scrutiny.

The work that matters once agents are already doing something: proving control, restricting access, and running the platform for other people.

  • svc/comply

    SOC 2 and HIPAA evidence automation

    Most of the cost of an audit is collecting evidence by hand, every cycle, forever. We wire continuous evidence collection into the systems that already hold the truth, so the control either passes or it does not, visibly.

    • Continuous evidence for SOC 2, ISO 27001, HIPAA, GDPR and PCI-DSS controls
    • Feeds into Drata, Vanta or Secureframe if you already run one
    • Audit log forwarding to your SIEM, with integrity protection
    • Control coverage visible between audits, not discovered during one
    From$24,000
  • svc/access

    Governed production access

    Shared SSH keys and a bastion nobody has reviewed in two years is still how most teams reach production. We replace that with approval-gated, fully audited command execution across your cloud and cluster tooling.

    • Approval gates on destructive commands, with escalation paths
    • Every command, argument and result recorded against a named human
    • Per-role permissions across cloud, Kubernetes and database tooling
    • Access that satisfies an auditor without slowing your engineers down
    From$26,000
  • svc/partner

    MSP and partner enablement

    For managed service providers and consultancies who want to run Nova for their own clients. We set up the multi-tenant side properly: isolation, policy overlays, onboarding and billing separation.

    • Tenant isolation and per-client policy overlays, verified rather than assumed
    • A repeatable client onboarding path with its own audit trail
    • White-label surfaces where your brand needs to be in front
    • Commercial and partner structure worked out alongside the technical setup
    From$35,000
How it works

Scoped first, then priced.

No engagement starts with a blank cheque. We agree what finished looks like before any work begins.

  • step/01

    Scoping call

    Thirty minutes on your stack, your incident load, and what is actually hurting. Free, and we will tell you if the answer is that you do not need us yet.

  • step/02

    Written proposal

    Deliverables, timeline and a fixed price. If the work does not fit one of the four services, we say so rather than stretching one to fit.

  • step/03

    Delivery

    Working software and documentation, not a slide deck. Everything we build is yours to keep and run after we leave.

Contact

Tell us what you need.

Every engagement starts with a scoping call. Send this and we will reply with next steps, or tell you if we are not the right fit.