Overview
The CirrusHQ AI Landing Zone is a multi-account AWS landing zone purpose-built for generative AI and machine learning workloads. It is designed and delivered to UK data residency, OFFICIAL/FCA/NHS expectations, and EU AI Act controls - giving regulated UK customers a foundation they can defend to their regulator.
What is included.
- Multi-account AWS Control Tower baseline with Organizational Units structured for AI workloads (build, evaluate, operate, audit).
- Amazon Bedrock and Amazon SageMaker deployed with private VPC endpoints and isolated subnets.
- KMS-managed encryption, Amazon Macie, Amazon GuardDuty, AWS Security Hub, and AWS Config conformance packs aligned to AWS Foundational Security Best Practices and CIS benchmarks.
- AWS IAM Identity Center with role-based access aligned to AI personas (builder, reviewer, operator, auditor).
- Pre-built Bedrock Guardrails policies for PII redaction, denied topics, and harmful-content filters.
- EU AI Act control mapping with a documented evidence trail.
- UK regulatory mapping: ICO AI guidance, FCA (where applicable), NHS DSP Toolkit (where applicable), and OFFICIAL handling guidance.
- Terrafor, CloudFormation or CDK Infrastructure-as-Code repository, handed to the customer.
- Knowledge-transfer workshops and a runbook.
Who buys this. UK-headquartered and UK-regulated enterprises in Financial Services, Public Sector, Healthcare/NHS, and Higher Education that need to run generative AI on AWS without breaching data residency, regulatory, or AI-governance obligations.
Why CirrusHQ. Premier Tier Services Partner with deep landing-zone and migration heritage (AWS Migration competency), 100% AWS focus, an existing UK customer base across regulated verticals (Public Sector, FSI, EdTech, Healthcare), and the Acuity platform layered on top for continuous Well-Architected and ISO 27001 compliance checks after handover. Optional handover to CirrusHQ Team-as-a-Service for ongoing operation.
Highlights
- Multi-account AWS Control Tower foundation with Bedrock and SageMaker behind private VPC endpoints, KMS, Macie, GuardDuty, Security Hub, IAM Identity Center, and Bedrock Guardrails policies for PII, denied topics, and harmful-content filters.
- Documented EU AI Act control mapping plus UK regulatory mapping for FCA, NHS DSPT, ICO AI guidance and OFFICIAL handling - giving regulated UK customers a foundation they can defend to their regulator.
- Delivered as Terraform, CloudFormation or CDK Infrastructure-as-Code that the customer owns, with knowledge-transfer workshops and runbook. Optional 24x7 managed operation via CirrusHQ Team-as-a-Service with Acuity-powered continuous compliance checks.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Vendor resources
Support
Vendor support
For enquiries about this offering, contact CirrusHQ at sales@cirrushq.com or visit [https://cirrushq.com/contact/ ]. Once a private offer is accepted, CirrusHQ provides a dedicated UK-based engagement manager and a delivery team led by AWS-certified architects. Service-desk cover: 9x5 standard, 24x7 available as an optional add-on under the CirrusHQ Team-as-a-Service model. Critical-alert response: 15 minutes (24x7 tier). Standard email response: 1 business day. Out-of-hours emergency escalation via phone. Refunds and changes are handled under the CirrusHQ Master Services Agreement signed at the start of the engagement and the AWS Marketplace Standard Terms. Cancellation and rescheduling terms are confirmed in the Statement of Work issued after the diagnostic call.
Software associated with this service
