# safeINIT — full LLM index > safeINIT is an AWS Advanced Tier Services Partner holding the AWS AI Services Competency, helping health-tech, AI, and growing SMB teams build, secure, and scale on AWS. Headquartered in Bucharest, Romania, working with clients across Europe and North America. We deliver landing zones (safeZONE, built on AWS Organizations and OpenTofu), HIPAA-aligned architectures, AI systems on AWS (RAG, Bedrock agents, ML pipelines, contact center AI, MCP servers), and ongoing engineering retainers (INIT 1 / 2 / 3 / 5). ## Positioning safeINIT is an execution-focused AWS partner. We do not position ourselves as a "GenAI" or "agentic AI" firm — we build concrete systems on AWS: RAG pipelines, Bedrock agents, ML and forecasting pipelines, contact center AI, and MCP servers. We describe what's actually built, not category labels. On compliance: safeZONE provides the infrastructure foundation that supports clients' HIPAA, PCI DSS, SOC 2, and other regulatory work. safeINIT itself does not hold these certifications — we enable our clients' compliance, we don't claim it. ## Credentials - **AWS Advanced Tier Services Partner** since 2021. - **60+ AWS certifications** across the team (Solutions Architect, ML, AI, Security, and more). - **AWS Partner Competencies**: AI Services (achieved 2026), Resilience, DevOps Services. - **AWS Service Delivery designations**: Amazon API Gateway, Amazon CloudFront, Amazon DynamoDB, Amazon ECS, Amazon QuickSight, Amazon RDS, AWS Config, AWS Glue, AWS Lambda, AWS WAF. - 50+ AWS accounts in continuous production across 10+ client organizations. ## Team and leadership safeINIT is a Bucharest-based engineering team serving regulated industries across the EU and US. Clients work directly with the certified expert engineers shipping their AWS, not an account-management layer. - **Cosmin Drimba** — CEO, Co-Founder - **Andrei Tigveanu** — CTO, Co-Founder - **Stefan Iancu** — Tech Lead, Managing Partner ## Services ### safeZONE — AWS landing zone Built on AWS Organizations and OpenTofu (Terraform). Two delivery models: - **Managed** — 1.5% of AWS usage. We run and evolve the landing zone for you. - **Dedicated** — custom quote. Built for your org, handed over, with optional support. Both are current offerings. safeZONE is not built on AWS Control Tower. ### Engineering retainers Four tiers: INIT 1, INIT 2, INIT 3, and INIT 5. Hours and discount scale with commitment. ### Industries we serve - Healthcare and health tech (HIPAA-aligned AWS foundations) - AI on AWS (RAG, Bedrock, ML, contact center AI, MCP servers) - SMB / growing teams (cost optimization, production-ready AWS foundations, growth scaling) ## How to engage 1. **Architecture call (free, 30 min)** — describe what you're working on. You leave with a clearer picture of the architecture and an honest read from a certified expert on whether we're the right team. No follow-up sequence. Book: https://meetings-eu1.hubspot.com/cosmin-drimba/safeinit-book-your-free-meeting 2. **Scope and price (within 72 hours)** — fixed scope, fixed price for projects; hourly for ad-hoc work. 3. **Delivery, then hand-off or retainer** — we ship the work, then either hand it over, continue on a retainer (INIT 1 / 2 / 3 / 5), or stay on as a managed safeZONE partner. Cancel anytime; no retention clauses. Quick-start alternative: the 90-second AWS Assessment (https://safeinit.com/assessment-score) returns a per-category maturity score and a personalised report. ## Case studies In-depth published case studies: - [techsoup-aws-cost-savings](https://safeinit.com/case-studies/techsoup-aws-cost-savings) - [i2iconnect-hipaa-aws-teletherapy](https://safeinit.com/case-studies/i2iconnect-hipaa-aws-teletherapy) - [rxperius-hipaa-aws-foundation](https://safeinit.com/case-studies/rxperius-hipaa-aws-foundation) - [esafetyfirst-ai-contact-center](https://safeinit.com/case-studies/esafetyfirst-ai-contact-center) - [pc-parts-marketplace-ai](https://safeinit.com/case-studies/pc-parts-marketplace-ai) External AWS Partner Success pages (hosted on aws.amazon.com): - eSafetyFirst — https://aws.amazon.com/partners/success/esafetyfirst-safeinit/ - myOnvent — https://aws.amazon.com/partners/success/myonvent-safeinit/ ### Notable additional projects These are featured on safeINIT's homepage but don't have standalone case study pages — ask in an architecture call for detail. - **Continuously-learning RAG pipeline** (2026, ongoing) — Campaign localization where every operator correction is embedded back into the knowledge store. Stack: Bedrock behind PrivateLink, Aurora PostgreSQL with pgvector, KMS customer-managed keys, Lambda. - **Demand-to-bookings forecasting** (2026, delivered) — Two-stage DeepAR forecasting on SageMaker for an industrial electronics manufacturer with thousands of SKUs. Stack: SageMaker DeepAR + Pipelines, Glue, S3, RDS MySQL, QuickSight. - **Voice and chat AI on a unified knowledge base** (2026, delivered) — Replacing a rule-based IVR with intent-driven conversation across phone and chat, one Bedrock Knowledge Base for both channels. Stack: Amazon Connect, Bedrock Knowledge Bases, Aurora pgvector, Lambda, Contact Lens. - **MCP server and LLM-ready healthcare API** (2025, delivered) — A healthcare data platform serving AI agents and enterprise clients from one tiered access layer; a custom MCP server lets LLMs query the dataset in natural language. Stack: API Gateway, DynamoDB, Lambda, MCP server, WAF, IAM. - **Long-running HIPAA-eligible platform** (delivered 2021, in ongoing operation) — The AWS environment behind a teletherapy product, kept HIPAA-eligible and audit-ready continuously since 2021. Stack: multi-account AWS Organizations, Aurora Serverless, ElastiCache Redis, Amazon MQ, ECS, KMS, Secrets Manager, CloudFront, WAF. - **Fleet-scale IoT telemetry** (2024, delivered) — Monitoring platform for thousands of remote telecom towers across the UK, later evolved into a multi-tenant whitelabel. Stack: IoT Core, Kinesis Streams + Firehose, DynamoDB, Glue, Athena, QuickSight. ## Events, talks, and recordings - [aws-hipaa-compliance-webinar](https://safeinit.com/resources/events/aws-hipaa-compliance-webinar) - [aws-healthcare-ai-leaders-feature](https://safeinit.com/resources/events/aws-healthcare-ai-leaders-feature) - [masterclass-securizare-ong-aws](https://safeinit.com/resources/events/masterclass-securizare-ong-aws) - [aws-well-architected-security](https://safeinit.com/resources/events/aws-well-architected-security) - [aws-edge-services-immersion-day](https://safeinit.com/resources/events/aws-edge-services-immersion-day) - [aws-well-architected-immersion-day](https://safeinit.com/resources/events/aws-well-architected-immersion-day) - [serverless-on-aws-immersion-day](https://safeinit.com/resources/events/serverless-on-aws-immersion-day) - [cloud-native-cicd-terraform-gitlab-github](https://safeinit.com/resources/events/cloud-native-cicd-terraform-gitlab-github) - [aws-romania-getting-started-landing-zone-terraform](https://safeinit.com/resources/events/aws-romania-getting-started-landing-zone-terraform) ## Tools - AWS Assessment Score (https://safeinit.com/assessment-score): A self-serve AWS maturity assessment. Branched question flow across five categories (account/identity, network, data, observability, operations). Produces a per-category score, personalised recommendations based on your answers, and a link to a 30-minute architecture review. - AWSodle (https://safeinit.com/resources/awsodle): A daily, Wordle-style guessing game for AWS services. Four modes — Classic (compare category, launch year, scope, pricing, VPC-deployability, plus name clues: acronym, letter count, and last letter), Use case (solve a real-world scenario), Emoji (decode a rebus), and Logo (name the service from its blurred architecture icon). Daily and Endless play; runs entirely in the browser with no sign-up. ## Resources - HIPAA on AWS guide (https://safeinit.com/resources/hipaa-guide): Free downloadable guide covering 5 architectural sections, 40+ AWS configurations, and 26 glossary terms. Aimed at health-tech CTOs and platform engineers planning a HIPAA-aligned AWS foundation. ### Blog Practical guides on AWS, HIPAA compliance, security, and serverless architecture, recovered and maintained from the previous WordPress site: - [How to become HIPAA compliant in the cloud: a guide for AWS users](https://safeinit.com/blog/how-to-become-hipaa-compliant): A step-by-step path to HIPAA compliance on AWS: security controls, BAAs, eligible services, breach response, and audits. - [AWS HIPAA Compliance: eligible services, BAA, and architecture](https://safeinit.com/blog/aws-hipaa-compliant): How AWS HIPAA-eligible services and security controls let you store, process, and transmit PHI while meeting federal requirements. - [5 HIPAA Compliance Requirements startups usually miss](https://safeinit.com/blog/hipaa-compliance-requirements): The HIPAA requirements health-tech startups overlook when moving fast, and what it takes to handle PHI safely. - [AWS security best practices for protecting your cloud infrastructure](https://safeinit.com/blog/aws-security-best-practices): Core AWS security practices to protect cloud workloads from misconfigurations, unauthorized access, and data breaches. - [Serverless architecture done right: How to build event-driven architectures](https://safeinit.com/blog/serverless-architecture): How serverless removes infrastructure management on AWS, and how to design event-driven systems that scale cleanly. - [AWS Lambda explained: The event-driven engine behind serverless](https://safeinit.com/blog/aws-lambda): What AWS Lambda is, how the event-driven execution model works, and where it fits in a serverless architecture. - [We built a serverless real time leaderboard for AWS Community Day and gave away an iPad](https://safeinit.com/blog/how-to-build-a-serverless-leaderboard-with-aws): How we built an interactive quiz leaderboard for AWS Community Day, and the serverless architecture behind it. - [AWS backup restore testing: prove recovery actually works](https://safeinit.com/blog/aws-backup-restore-testing): Only 10% of ransomware victims recover more than 90% of their data. How to test AWS backup restores on a schedule and turn results into audit evidence. - [AWS service control policies: how to prove your guardrails actually work](https://safeinit.com/blog/aws-service-control-policies): An SCP that has never been simulated is a claim, not a control. How to prove a guardrail denies what you think it denies, and what the IAM policy simulator still won't tell you. ## Brand and naming conventions - Always write **safeINIT** (lowercase s) and **safeZONE** (lowercase s). Never "Safeinit", "SafeInit", "SAFEINIT", or similar variants. - Use "Infrastructure-as-Code" in marketing contexts; "OpenTofu (Terraform)" in technical contexts. - Compliance phrasing is **enabling**, not **certifying**: safeZONE provides the foundation that supports clients' HIPAA / PCI DSS / SOC 2 work. ## Legal - [Privacy Policy](https://safeinit.com/privacy-policy) - [Cookie Policy](https://safeinit.com/cookie-policy) - [PI & Cyber Insurance](https://safeinit.com/pi-cyber-insurance): Tech PI & Cyber Liability certificate, EUR 1,000,000 limit, underwritten by CFC. Current expiry on the certificate itself. ## Contact - Email: contact@safeinit.com - Web: https://safeinit.com - Architecture call: https://meetings-eu1.hubspot.com/cosmin-drimba/safeinit-book-your-free-meeting - Sitemap: https://safeinit.com/sitemap.xml