Enekui
New May 2026 pricing — 60% off

Engineering with judgement
for your cloud + AI platform.

We design, build and operate AWS infrastructure and Bedrock agents for European SMBs. Nine products in production, NIS2 / DORA compliance from day one, and a monthly retainer with no lock-in.

SOC 2 Q4 2026 16 sites · 3 public audits OEPM trademark 0 incidents 2026
9 products in production
9
Products in production
2k+
Qualified users / year
99.9%
Portfolio uptime 2026
~60%
Typical AWS bill reduction
Work in production

Every client, a live story today.

Seven of our own digital products and two external clients. All running, all verifiable.

Services & pricing · May 2026

Start small, scale when you see value.

We dropped prices 60% so an SMB CTO can sign without three meetings. No lock-in, cancel anytime.

Free · 24/7 Not sure which service fits? Talk to Kari, our AI qualifier — no email needed, reply in 30 s.

Cloud + AI diagnostic

Read-only audit · 1 week
€990
was €3,900
  • AWS audit · cost, security, DevOps
  • Top-3 AI opportunities with ROI
  • 60-min wrap-up session
  • 100% credits to full audit
Book

Full architecture audit

Well-Architected · 2 weeks
€2,900
was €8,900
  • AWS Well-Architected Review · 6 pillars
  • 12-month remediation roadmap
  • Prioritised risks table
  • 1 free follow-up session
Book

AI MVP sprint

Idea → production · 2 weeks
from€6,900
was from €18,000
  • Bedrock + Lambda + DynamoDB + Next.js
  • Same architecture as Enekui verticals
  • Deployed to your AWS account
  • Documentation + technical handover
Book sprint

Tech Partner retainer

Fractional CTO · 10h/week · web infra included
€1,900/mo
was €4,500/mo
  • Fractional CTO + async DevOps
  • Your web infra operated by us · A+ Mozilla + Internet.nl 100%
  • Shared Slack + weekly code review
  • Light on-call (Mon–Fri) · no lock-in
Activate

Security & compliance

Productised hardening · 1 week
€1,990
was €5,900
  • DKIM strict + SPF + DMARC reject
  • DNSSEC + MTA-STS + CAA + HSTS
  • WAFv2 OWASP top 10 + rate limit
  • Public verification SSL Labs A+
Book

Web + conversational AI bot

Technical site + Bedrock agent · starter or pro · 2-4 weeks
from€1,490 + €49/mo
one-off + optional care plan · pro complete €2,500
  • Starter €1,490: site + Bedrock Haiku bot + WAFv2 + strict CSP
  • Pro €2,500: adds RAG over docs/catalog, multilingual, calendar
  • Edge SSR + Core Web Vitals 90+ + schema.org
  • DNSSEC + DKIM strict + SSL Labs A+ from day one
  • Care €49/mo: hosting + bot monitoring + 1h/mo prompt tweaks
  • Live case: bubabeautystudio.com (A Coruña salon)
Start

Web + Mobile app with AI

MVP PWA · Growth iOS+Android · Bedrock embedded
from€4,900 + €149/mo
MVP 4-6 weeks · Growth Capacitor 8-12 weeks · enterprise on request
  • MVP App €4,900: PWA installable + offline + Bedrock Haiku bot · 4-6 weeks
  • Growth Capacitor €14,900+: same code → App Store + Play Store + push APNS/FCM · 8-12 weeks
  • Bedrock AI bot embedded · RAG over your docs · multilingual ES/EN/PT
  • Magic-link auth + biometric login + offline-first sync
  • AWS serverless backend · 100% IaC handover · CSP A+ + Internet.nl 100%
  • Need native Swift + Kotlin? Talk to Kari · enterprise scope on request
Start

Kari-as-a-Service · public

Bedrock bot embedded on your existing website
€890+ €49/mo
setup + monthly · already have a website
  • Bedrock Haiku bot · system prompt tuned to your services
  • Email-verified leads (OTP) → straight to your inbox
  • Calendly / Outlook integration · self-service booking
  • Embed widget on any web stack (1 line of script)
Start
Hall of Fame · public audits

16 sites at 100% — every one publicly verifiable.

Spanish agencies sell hardening. We leave it open in three independent public audits. Dutch government Internet.nl, Mozilla Observatory, Chromium HSTS preload list. No marketing — just scores you can re-run yourself in 30 seconds.

Every domain we own or operate is at 100% on the Dutch government's Internet.nl public test. DNSSEC chain of trust, TLS 1.3 only, ECDSA P-256, all security headers, RPKI authorised routes, security.txt RFC 9116. Total cost: 0€ over Free tier — pure AWS architecture, no Cloudflare Pro, no premium plans. Same baseline ships with our Security & compliance package · 1.990€.

Security & compliance · publicly verifiable

The posture you want your CTO to see before signing.

We don't claim to be secure — we leave it verifiable. Anyone can run our domain through Internet.nl, SSL Labs or mxtoolbox and see the score live. Same baseline applies to our clients from day one.

Defense in depth · 3 layers

Every request hits three firewalls before reaching storage.

WAFv2 with OWASP Top 10 in front. CloudFront with TLS 1.3 only and DNSSEC chain in the middle. S3 with KMS-encrypted objects behind. An attacker has to get through all three before reaching anything — and even then, objects are AES-256 at rest with rotated CMK.

Legitimate traffic · reaches S3 Attacker · blocked at CloudFront
Conversational AI · 5 layers

Every /chat message touches Bedrock through a hardened pipeline.

Origin check at the edge. Bedrock Guardrails redact PII before reaching the model. Haiku 4.5 with prompt caching answers in <800ms p50. Session memory in DynamoDB with 24h TTL. Lead notification via SES with DKIM signed.

Verified message · reaches Bedrock PII / jailbreak · redacted by Guardrails
Internet.nl
100%

Public domain verification. Last measured on enekui.io: 100/100 across email auth, web security and modern HTTPS.

See live score
WAFv2 · last 7 days
47,214
legitimate requests
1,247
blocked · OWASP + rate-limit

Bots, SQL injection attempts, aggressive scrapers, scanners hunting for /wp-admin. None reach your Lambda.

Email auth

SPF strict · DKIM rotated · DMARC p=reject

RUA/RUF reporting active, MTA-STS enforce, TLS-RPT. No one cold-spoofs your domain.

TLS 1.3 only
$ openssl s_client -connect enekui.io:443 -tls1_2
Error: TLSv1.2 not supported

$ openssl s_client -connect enekui.io:443 -tls1_3
SSL handshake · 0-RTT · ChaCha20-Poly1305
Cert · Let's Encrypt · ECDSA P-256
HSTS · max-age 63072000 · preload
Bedrock Guardrails
# Before reaching the model
redact: [PII, NIE, IBAN-ES, AWS_KEYS]
deny_topics: [jailbreak, legal, medical]
strength: HIGH

# Result
→ "My NIE is {NIE}, can you..."
→ blocked: PII detected
DNSSEC + chain of trust

Chain signed with KMS · ECDSA P-256

DS records published to the TLD verify nobody has hijacked your DNS zone. CAA records limit which CA can issue certs.

Regulatory frameworks we prepare clients for

GDPR NIS2 DORA Cyber Essentials UK ENS Spain SOC 2 Type I (Q4 2026)