Retail
Large US retailers, where the calendar is not negotiable and PCI DSS scope shapes the architecture.
What makes retail different
The calendar is fixed and everyone knows it. Capacity has to be proven well before peak, and the change freeze around it means work either lands early or waits a quarter.
PCI DSS is the other shaping force. Compliance is the requirement; the target worth aiming at is a smaller scope — fewer systems subject to the standard in the first place, which is an architecture problem rather than a policy one.
How we work here
We plan delivery backwards from the freeze date, and we treat scope reduction as the primary compliance lever. Fewer systems touching cardholder data means a cheaper audit every year, not just this one.
What we’ve done in this sector
In prior roles, our people spent three years on the AWS and Linux platform behind one of the busiest retail websites in North America — weekly test, stage, and production deployments against a site that had to stay up 24x7.
The measure that mattered there was the annual peak: performance testing processes and disaster recovery playbooks built for the Thanksgiving plan carried a five-day peak period with zero downtime.
Let's talk about your cloud.
Our first conversation is about your problem, not a proposal.
