Platform

The portal is the product

Distributors do not win on catalog alone. They win on how quickly a partner can order, activate, bill, and get an answer. Here is what Elev8 Cloud is building, and what it runs on.

Capabilities

Six subsystems partners actually touch

Each one exists because a partner hits it on a normal Tuesday, not because it looked good on a roadmap slide.

Catalog and storefront

One searchable catalog across every vendor Elev8 Cloud carries.

  • Partner pricing visible before you order
  • Side by side comparison inside a category
  • Vendor terms, minimums, and support scope on every listing
  • Saved carts and repeatable client bundles

Provisioning and automation

Ordering and activation are the same action, not two.

  • Per vendor API connectors for tenant and seat creation
  • Queue based sync so a vendor outage retries instead of dropping
  • Seat changes pushed from one screen
  • Provisioning state visible per client, per product

Billing and invoicing

One statement that reconciles to what you deployed.

  • Consolidated monthly invoice across all vendors
  • Proration on mid cycle seat changes
  • Usage reconciliation against vendor reporting
  • Client level cost breakdown for your own billing

Partner enablement

The commercial tooling around the catalog.

  • Markup and margin rules you control
  • Partner branded quoting
  • Revenue and margin reporting by client and product
  • Knowledge base and deployment notes per product

Support and ticketing

Escalation that already knows your account.

  • Partner support workflow with stated response targets
  • Tickets joined to billing and provisioning records
  • Vendor escalation handled by Elev8 Cloud, not handed back to you
  • Named contact once you pass the second tier

Admin and operations

The back office that keeps the other five honest.

  • Catalog and vendor onboarding management
  • Pricing rule administration
  • Reconciliation tooling across vendor statements
  • Audit trail on every commercial change
Architecture

What it runs on

A pragmatic stack chosen for operational surface area rather than novelty. Fewer moving parts means fewer things to secure and fewer things to explain during an audit.

Elev8 Cloud platform architecture by layer
LayerApproach
Cloud infrastructureAWS, using ECS Fargate, RDS PostgreSQL, and infrastructure as code
Backend servicesFastAPI services split by domain: catalog, provisioning, billing, partner management
Partner portalReact and Vite front end with a separate admin console
IdentityManaged identity provider with SSO, MFA, and role based access for partner accounts
Billing and paymentsStripe for partner billing, with a usage reconciliation layer above it
Vendor integrationPer vendor API connectors for provisioning and usage, synchronised through a queue
NotificationsTransactional email for orders, provisioning events, and billing
ObservabilityCentralised metrics, error tracking, and immutable audit logging
Build versus buy. Not every subsystem gets written from scratch. The plan is a lean custom portal over the curated security catalog, integrated with proven billing and provisioning components, then migrating subsystems in house as volume justifies it. Time to market beats architectural purity at this stage.
Platform security

A security distributor has to model it

Selling security tooling on a platform with weak controls would be self defeating. The platform's own posture is part of the offer, and partners are welcome to test the claim.

Identity and access

SSO and MFA on partner accounts, role based permissions, and least privilege by default. A partner technician should not be able to see another partner's client list, and the model enforces it rather than trusting it.

Audit logging

Every commercial and provisioning action is logged immutably: who ordered, who changed a seat count, who adjusted a price. Regulated partners are asked to evidence this, so it exists from the first release.

Data protection

Encryption in transit and at rest, secrets held in a managed store rather than configuration, and a documented data retention position before the first partner is live.

SOC 2 readiness

Partners handling regulated client data will ask for a report. Controls are designed in from the start and the audit is a scheduled milestone, not a retrofit.

See it when it opens

Founding partners get access as each subsystem lands, and their feedback decides what gets built next.