FAQ Questions, answered

Questions,
answered.

What ClearThought does, who we work with, and how an engagement runs.

A hand-drawn Amazon Bedrock RAG pipeline on AWS: Users to API Gateway to Lambda to Amazon Bedrock, with Guardrails, a Knowledge Base, SageMaker, OpenSearch, S3, DynamoDB, and CloudWatch Fig. 01 · A Bedrock RAG pipeline, drawn before it is built
What does ClearThought do?
We design and deploy secure, high-performance AI systems on AWS, Azure, and Google Cloud. The work spans three disciplines: AI/ML engineering (LLM selection, fine-tuning, RAG architectures, and evaluation harnesses), cloud architecture (reference architectures, infrastructure as code, and patterns for inference at scale), and security and compliance (zero-trust IAM, encryption strategy, and threat modeling for LLM-specific risks). The output is engineering, not slideware.
Who do you work with?
Engineering organizations at mid-market and enterprise companies that need to design, build, or harden production AI systems. Our engagements are principal-led, so we fit teams that want senior architects working directly on their systems rather than a staffing layer.
Which clouds do you work on?
All three majors. We hold certifications across AWS, Microsoft Azure, and Google Cloud, and we design for the cloud your workloads already run on. The right platform depends on your data, your compliance constraints, and your team's skills, not on a vendor relationship. We are cloud-neutral and vendor-neutral, and we do not resell anyone's models.
What does a typical engagement look like, and how long does it take?
We run three engagement models. An Architecture Sprint is two weeks: a focused review plus a reference architecture for a defined system or migration. An Embedded Build runs four to twelve weeks, with principal engineers designing, building, and hardening production systems alongside your team. Standing Advisory is a quarterly retainer for ongoing architecture review, security-posture monitoring, and on-call access to a principal.
How is pricing structured?
We lean toward fixed fees whenever the work allows it. We think knowing the cost up front is more client friendly than an open-ended hourly meter. The Architecture Sprint is a fixed fee. Embedded Builds are scoped after the technical review and quoted fixed-fee where possible. Standing Advisory is a flat quarterly retainer. We quote once we have seen the system, not before.
Do we own what gets built?
Yes. Everything is built to be owned: reference architectures, infrastructure as code, working pipelines, documentation, and runbooks are handed over to your team. We design the exit from day one, so you can operate and extend the systems without us.
How do you handle security and compliance?
Security is a first principle, not an add-on. We design zero-trust IAM and least-privilege access, encryption with cloud-native key management, and threat models for LLM-specific risks like prompt injection and data leakage. We also run readiness work for SOC 2, HIPAA, and ISO 27001. These services support your compliance goals; they are not certifications we hold ourselves.
Are you a reseller or a staffing shop?
No. We are independent: not a reseller, not a body shop, not a staffing layer. We do not resell anyone's models or platforms, so our recommendations stand on engineering merits. The work is principal-led with no layers and no handoffs.
Do you work alongside our existing engineers?
Yes, that is the default. The Embedded Build model puts principal engineers next to your team to design, build, and harden production systems together, and Standing Advisory gives your engineers on-call access to a principal. The point is knowledge transfer: everything is documented and handed over so your team runs it after we leave.
How do you handle RAG quality, evaluation, and guardrails?
Quality is engineered, not assumed. We build retrieval pipelines (vector store selection, embedding and retrieval tuning, grounding controls) and the evaluation and regression harnesses that keep them honest in production: automated quality, hallucination, and safety checks, plus guardrails and red-teaming against prompt injection and jailbreaks. Cost and latency are tuned in the same effort, so quality, performance, and spend move together.
Can you migrate AI workloads between clouds?
Yes, in any direction among AWS, Azure, and Google Cloud. We deliver landing zones, identity, and data-platform work on all three, which makes us a fit for multi-cloud estates, post-acquisition integration, and portability work where AI and data pipelines need to move or run across more than one cloud.
Do you do SOC 2 or HIPAA readiness for LLM applications?
Yes, as readiness and advisory work. We map controls to real architecture decisions, with encryption and key management designed in, so the documentation describes what is already true rather than papering over gaps. We support your path to SOC 2, HIPAA, and ISO 27001; we do not claim certification or partner status ourselves.
Still have a question?

Talk to a principal.

A 30-minute technical review, with the people who would do the work.

Book a technical review