Fleet Lab
Embedded technical leadership across architecture, hiring, and product shaping
The stack underneath.
What changed.
Fulcro Labs transformed our scrappy prototype into an enterprise-grade platform. We're now confidently pitching Fortune 500 companies.— Fleet Lab Founder
The Frustration
Fleet Lab had a prototype that demoed beautifully. Enterprise prospects were leaning in. And then the security questionnaire arrived — and the deals stopped moving.
The prototype was single-tenant. No audit logging. Secrets in environment files. It was the right shape for a demo and the wrong shape for a SOC 2 review. Enterprise pilots were already on the calendar, and the team didn't have the runway to spend a quarter rebuilding infrastructure from scratch while sales conversations stalled out.
What had to be true
- SOC 2 readiness — audit logging, access controls, secrets management
- Existing prototype preserved — core application logic stays intact, infrastructure swaps underneath
- Hard deadlines — enterprise pilots already on the calendar
- Operable after handoff — whatever we built had to be run by the in-house team, not by us
The Fix
Eight weeks, split into four two-week sprints. The team kept shipping product features while we rebuilt the infrastructure underneath them.
Weeks 1–2 · Assessment & architecture
Security audit of the existing prototype. Enterprise requirements mapped against actual customer security questionnaires. Multi-tenant database schema redesigned. Architecture diagrams the team could defend in a security review without us in the room.
Weeks 3–5 · Core infrastructure
Dockerized deployment with proper secrets management. PostgreSQL re-tuned for multi-tenant workloads. API authentication and authorization rewritten end-to-end. Audit logging that satisfies compliance review.
Weeks 6–7 · DevOps & observability
Terraform infrastructure-as-code targeting AWS. CI/CD with automated tests on every merge. Monitoring and alerting with escalation paths the on-call could actually follow. Backup and disaster recovery procedures the team could rehearse.
Week 8 · Security & documentation
Penetration testing and remediation. Compliance documentation. Runbooks for the operations the team would now own. Knowledge-transfer sessions where the engineers got to drive while we watched.
The tech decisions worth noting
Why Docker over serverless? The existing Python application had specific runtime requirements and long-running processes that didn't fit the serverless model. Docker gave us portability, consistency across environments, and a deployment story we could explain to security teams.
Why Terraform? Enterprise deals come with deployment requirements — specific regions, dedicated infrastructure, sometimes their own VPC. Terraform let us parameterize deployments and spin up customer-specific environments without rebuilding the wheel each time.
The Future
Fleet Lab passed their first enterprise security review within two weeks of the engagement ending. The pilot deployments went smoothly. They closed their first six-figure enterprise deal shortly after.
The infrastructure foundation we built continued to serve them well — supporting multiple enterprise deployments without requiring significant rework.
The team that took over after handoff hasn't needed to re-architect any of the systems we installed. That's the bar for stays built.
Let's talk about how to get you there.
Every Fulcro engagement starts with a Reality-Check Audit — a focused diagnostic that maps where the leverage is in your business and what doing nothing actually costs.