Operate

Your systems are live. Who’s running them?

The person who built it moved on. The deploys are getting scary. The cloud bill keeps growing. Dwarves Operate is a DevSecOps practice for the ninety-first day — tiered, AI-augmented, and built around a single working principle: the engineers who shipped the system stay on the system.

See the tiers →

Service areas

Three layers we operate. Pick the ones that match what you run — we don’t charge for surfaces we’re not touching.

Platform Ops

The infrastructure layer. Monitoring, incident response, CI/CD health, cloud cost, security patching.

  • SRE & on-call coverage
  • CI/CD maintenance
  • Cloud cost & FinOps
  • Patch & vulnerability mgmt

Data Engineering

Pipelines that keep flowing. Schema drift handling, data quality, warehouse health, analytics support.

  • Pipeline monitoring & repair
  • Schema & migration support
  • Data-quality alerting
  • Warehouse maintenance

Process Automation

Agentic workflows in production. Cost guardrails, prompt tuning, model evals, automated remediation.

  • Agent & workflow health
  • LLM cost & token tracking
  • Model drift & evals
  • Auto-remediation runbooks

Watch · Guard · Run

Three tiers of engagement. The lighter the tier, the more you stay hands-on. The heavier the tier, the more we own the pager.

Watch

We see. You fix.

Teams that have their own engineers but want a second pair of eyes after dark.

  • 24/7 monitoring & alerting
  • Uptime, latency, cost dashboards
  • Monthly health report
  • Patch & CVE notifications
  • No incident response
  • Month-to-month

Guard

We see. We fix.

Teams without a dedicated SRE. You shipped the MVP; the original engineer moved on.

  • Everything in Watch
  • Incident response in business hours
  • Root-cause analysis on P1/P2
  • CI/CD upkeep & cost reviews
  • GMT+7 + US/EU overlap windows
  • Three-month minimum

Run

We own it.

Products where downtime hurts revenue. You'd rather your engineers build features than carry pagers.

  • Everything in Guard
  • 24/7 on-call with escalation
  • Engineering budget per month
  • Quarterly business reviews
  • Disaster-recovery rehearsals
  • Six-month minimum

Pricing scales with what you run and how many service areas you subscribe to. Most teams enter at Watch after a Build engagement and graduate as the system grows.


Why us

GMT+7 is the night shift.

When a US client's system pages at 2 a.m. Pacific, it's 4 p.m. in Da Nang. Our team is fresh, awake, and at their desk — not paged out of bed at home rates.

AI-augmented, not AI-replaced.

An internal stack of fifteen-plus Claude skills handles triage, deduplication and runbook lookup before a human reads the page. We pass the productivity gain through as price — not as headcount cuts.


Built first

Most clients arrive from Build.

Every Build engagement ends with a two-week handoff sprint — runbooks, monitoring, RCAs rehearsed. The same engineers who shipped the system are the ones operating it on day ninety-one. You can take it from there yourself, or you can hand us the pager.

Read build →

Talk to us

A short note about what you run and where it hurts is usually enough. We reply within three working days.

Read selected work