Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

How to Get $100K+ in Startup Cloud Credits (AWS, GCP, Azure, Cloudflare)

A practical, no-fluff guide to stacking $100K+ in cloud credits across AWS, GCP, Azure, and Cloudflare without burning weeks on applications.

Cloud credits are the closest thing to free money a startup gets before revenue. AWS Activate alone offers up to $100,000 in credits, and stacking GCP, Azure, and Cloudflare on top can push your runway extension past $250,000 in infrastructure spend. The catch: every program has different gates, different timelines, and different ways to disqualify you on a technicality. This guide covers what actually qualifies, when to apply, and the mistakes that cost founders their credits.

The four programs worth stacking

Most founders apply to one program, get approved for a smaller tier, and never revisit. The bigger move is stacking all four major providers at the highest tier each one will give you. Here is the realistic landscape in 2026.

AWS Activate

AWS Activate has two tiers: the self-service Founders tier ($1,000 credits, two years of Business Support) and the Portfolio tier ($5,000 to $100,000 in credits depending on your accelerator, VC, or incubator partner). The $100K tier requires you to be backed by a partnered VC or accelerator. Y Combinator, Techstars, 500 Global, and most tier-1 funds qualify. Without a partner, you cap out at $5K through the standard Founders pathway.

The application asks for your AWS account ID, company website, funding status, and the partner code from your accelerator or investor. Approval takes 5 to 10 business days. Credits expire two years from issuance, so applying before you have product-market fit is a waste. Burn the credits during the year you actually need GPUs and Bedrock tokens.

Google Cloud for Startups

GCP runs two tiers: the Start tier ($2,000 in credits over one year) and the Scale tier (up to $200,000 over two years for Series A companies, with $100,000 commonly approved for pre-seed and seed). You need a partner referral for Scale. Same pattern as AWS: your VC, accelerator, or a participating community organization issues the code.

GCP credits cover Vertex AI, BigQuery, and Gemini API usage, which is where they outperform AWS for AI-heavy stacks. Apply through the Google for Startups portal, attach your pitch deck, and expect 7 to 14 days for approval.

Microsoft for Startups Founders Hub

Azure runs Founders Hub, which gives self-service access to up to $150,000 in credits over four years with no VC referral required. You unlock more credits as you progress through milestones (post a website, sign your first customer, raise a round). The first $1,000 lands instantly on signup. Hitting $25K typically requires showing some traction. The full $150K usually requires Series A signals.

Founders Hub also bundles GitHub Enterprise, LinkedIn Premium, and OpenAI API credits through the Azure OpenAI Service. If you are building on GPT-4 or GPT-5 class models and want to avoid OpenAI's direct rate limits, this is the cleanest path.

Cloudflare for Startups

Cloudflare for Startups gives one year of Business plan ($2,400 value), Workers Paid, R2 storage credits, and Zero Trust seats. You apply through one of their accelerator partners (Techstars, Y Combinator, AWS Activate, Microsoft Founders Hub all qualify). The trick: enrolling in Microsoft Founders Hub or AWS Activate first unlocks Cloudflare for Startups eligibility for free.

This is the highest-leverage application of the four. If you are running anything edge-served (most modern web apps), Cloudflare credits cover your CDN, WAF, and serverless workloads in full for the first 12 months.

The application sequence that actually works

Order matters. Apply in this sequence:

  1. Microsoft Founders Hub first. Self-service, instant. Gets you a partner code that unlocks Cloudflare.
  2. AWS Activate second. If you have a VC or accelerator partner, push for the $100K tier in your application notes. Otherwise, take the $5K and revisit after raising.
  3. Google Cloud third. Apply through your accelerator, not the public portal. The public portal caps at $2K.
  4. Cloudflare last. Use your Microsoft or AWS partner code to qualify.

Total time from start to approvals: 2 to 3 weeks if you have all your documents ready. Total credit value if you hit every tier: roughly $250,000 to $450,000.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself. Talk to us

Eligibility traps that disqualify founders

Every program has fine print, and most rejections are technicalities, not judgment calls.

Existing spend disqualification

AWS Activate and GCP both refuse to grant new credits to accounts that have already accrued substantial billing. AWS specifically excludes any account that has spent more than $5,000 historically. If you have been running production workloads on a personal account, transfer your workloads to a brand new account in your company name before applying. You cannot retroactively add credits to a billed account.

Wrong entity type

Most programs require an incorporated entity (a C-corp, LLC, or international equivalent). Sole proprietors and unincorporated teams get rejected automatically. Delaware C-corps move through the fastest because the underwriting team has seen 10,000 of them.

Stale website or no product

The reviewers click your website. If it is a landing page with no product, no pricing, and no team, you get pushed to the lower tier or rejected. A working product demo, a logged-in dashboard screenshot, or a public beta signup all materially raise approval odds.

Vague application copy

"We are building an AI platform for enterprise" gets rejected. "We are building a SOC 2 compliance automation tool for Series B SaaS companies, currently in private beta with 12 design partners, raising a $1.5M pre-seed" gets approved. Specificity wins.

Timing the applications around your runway

Cloud credits expire. Burning them during the wrong phase is one of the more common founder mistakes. You spend $40K of AWS credits running pre-launch testing and then have nothing left when you actually need to scale to paying customers.

Apply when you are 90 days from production

Most credits have a one-to-two year window. Applying right after incorporation means a year of the credit window passes during pre-product development, when your monthly burn is $500. Apply when you are within a quarter of going to production and you will capture the full credit value during the high-burn growth phase.

Re-apply at funding milestones

AWS Activate, GCP, and Founders Hub all have escalation tiers triggered by funding rounds. If you raise a seed or Series A after your initial application, log back into each portal and apply for the upgraded tier. Most founders forget to do this and leave $50K+ on the table.

Negotiate before credits expire

Six months before your AWS credits expire, get on a call with your AWS startup rep. If you are running real workloads and have a credible Series A pipeline, you can often negotiate a credit extension or a transition to a private pricing agreement. Same with GCP. The reps have discretion and they want you on the platform long-term.

What to actually spend credits on

Credits are not a license to over-engineer. The best use cases:

  • Production database hosting. RDS, Cloud SQL, or Cosmos DB. The cost adds up fast and credits cover it cleanly.
  • AI inference. Bedrock, Vertex AI, and Azure OpenAI tokens are where credits stretch furthest. A startup running 100M tokens a month on GPT-4 class models can burn $30K of credits a quarter without trying.
  • Data warehouses. BigQuery and Redshift queries get expensive once you have any analytics traction. Credits cover the first year.
  • CDN and edge. Cloudflare credits make this effectively free for the first year.

What not to use credits on: personal side projects, exploratory R&D unrelated to your core product, or compute for things you should be doing on a $20/month VPS. Once credits expire, those workloads become your monthly burn.

The accelerator multiplier

If you get into Y Combinator, Techstars, or 500 Global, your credit access roughly doubles. YC alone bundles $500K+ in credits across AWS, GCP, Azure, OpenAI, Anthropic, Datadog, Stripe, and more. If you are even close to accelerator readiness, applying is worth the two weeks of time even if the equity dilution is steep. The credit and discount stack pays for itself within 18 months.

If you are not in an accelerator, your VC firm's platform team is the next-best path. Most tier-1 funds maintain a perks portal with pre-negotiated credit codes. Ask your investor's platform manager directly. Do not wait for them to send you a portal link.

The bottom line

Cloud credits are a stackable, repeatable resource that most founders under-claim. Apply to all four major programs in the right sequence, time your applications to your production timeline, and re-apply at every funding milestone. Done well, this is six to nine months of effective infrastructure burn covered before you spend a dollar. Done poorly, it is a few thousand in credits that expire while you are still in the design phase.

Set up the account structure before the credits land

The single decision that determines whether credits help you or haunt you is how you organize accounts on day one. Credits are granted to a billing account, and once granted they are extremely hard to move. Founders who apply from a personal account, or who create a fresh account per project because that was the fastest path to the credit, end up with infrastructure spread across billing entities they cannot consolidate later.

Do it in this order. Create an organization (AWS Organizations, a GCP organization tied to your Workspace domain, or an Azure tenant) owned by a company email address that is a shared mailbox rather than a founder's personal address. Put the management account aside as a billing and identity account with nothing running in it. Create separate member accounts for production, staging, and any sandbox work. Apply for credits against the management or billing account so the credits pool across members rather than stranding in whichever account happened to receive them. Enable organization-level logging (CloudTrail organization trail, or the equivalent) at the same time, because turning it on later means you have no history from the period you will eventually be asked about.

This takes an extra afternoon and saves a painful migration. The alternative is what we usually walk into: production sitting in an account created by an ex-contractor, root credentials on a Gmail address nobody controls, and the credits attached to a different account entirely.

How credits distort your financial picture

Credits are not revenue and they are not really cost savings either. They are a deferral, and the deferral shows up in three places that matter to anyone doing diligence on you.

The first is gross margin. If your hosting is paid in credits, your reported cost of revenue is understated for as long as the credits last. A company showing 88% gross margin on credited infrastructure that will really run at 71% once it pays cash is going to have an uncomfortable conversation during a Series A data room review. Track your fully burdened infrastructure cost as a separate internal figure from day one, using the list price of what you consumed, and present both numbers when asked. Investors who have seen this before will ask anyway, and having the number ready reads as competence.

The second is the expiry cliff. Credits typically run one to two years and they do not taper. The month after they end, a line that was zero becomes your second or third largest operating expense. Put the expiry date in the company calendar with a six month warning, and model the cash cost of the month after in your runway spreadsheet rather than the month you find out.

The third is behavioral. Free compute encourages architecture you would never choose on your own money: oversized instances that never get resized, a data warehouse queried without partitioning, three environments running around the clock, an ML experiment that nobody turned off. Set budget alerts on credit consumption at 50% and 80% even though the money is not yours, and hold one review a quarter looking at the top five line items. Teams that skip this discover at expiry that they have built a cost base they cannot afford and have no idea which parts of it are load-bearing.

Renegotiating before and after the cliff

When credits are ending and you are running real workloads, you have more leverage than you think, but only if you use it before you are locked in. The lever on AWS is a private pricing agreement or an enterprise discount arrangement, which trades a committed annual spend for a percentage discount; on GCP the equivalent is a committed use discount, and Azure has reservations and its own enterprise agreements. The discounts are meaningful at real volume, and the commitment is the risk, because you agree to spend a number whether or not you grow into it.

Two practical rules. Do not commit to more than roughly 60 to 70% of your current steady-state usage, so that a bad quarter or an efficiency project does not leave you paying for capacity you deleted. And separate the negotiation from the credit conversation, because a rep offering a credit extension in exchange for a same-week commitment is optimizing their quarter, not your runway. Ask for the extension, then take the pricing discussion on your own timetable with the numbers modeled.

Before you sign anything, spend a week on the boring efficiency work: right-size instances against actual utilization, delete unattached storage volumes and old snapshots, set lifecycle rules on object storage, and turn off non-production environments outside working hours. On a credit-funded estate that nobody has pruned, that pass usually removes a meaningful slice of the bill, and every dollar you remove first is a dollar you do not commit to for three years.

The compliance side effects nobody plans for

Chasing credits across four providers has consequences that surface later, usually the first time an enterprise buyer sends a security questionnaire or you begin SOC 2 or ISO 27001 readiness. Three of them are common enough to plan around.

The first is scope inflation. Your audit scope is defined by where customer data lives and what supports it. A company running production on one provider and an analytics pipeline on another because the credits were there has doubled the cloud estate an auditor will ask about: two sets of identity configurations, two logging arrangements, two encryption stories, two vendor risk reviews. That is not fatal, and sometimes it is a deliberate trade, but it should be a decision rather than a side effect of a free tier.

The second is orphaned accounts. Credit programs encourage account creation and nothing encourages account deletion. Six months later you have a sandbox with a public storage bucket, a demo environment holding a copy of production data, and a set of long-lived access keys issued to a person who has left. Every questionnaire you fill in asks for an inventory of systems and the honest answer requires you to know what exists. Keep a list of every cloud account with an owner and a purpose, review it quarterly, and close what nobody claims.

The third is data residency. Canadian buyers, particularly in public sector, financial services, and health, increasingly ask where data is stored and processed. Credit-driven region choices are usually made by whoever clicked first, which is often us-east-1. If you expect to sell into Canadian institutions or handle personal information under PIPEDA, Quebec's Law 25, or provincial health privacy law, decide your regions deliberately at the point you set up the accounts. Moving a production database between regions after you have customers is an entirely different piece of work from choosing correctly at the start.

When chasing credits is the wrong use of your week

The full application round described above is two to three weeks of founder attention. That is a real price, and there are situations where it is a bad trade.

If your infrastructure bill is under a few hundred dollars a month and will stay there for the next year, take the self-service tiers that require twenty minutes and skip the rest. Chasing an upper tier that requires partner codes, calls, and follow-ups to save $2,000 over eighteen months is not worth a founder week you could spend on customers. The math changes sharply once you are running GPU inference or a warehouse, and not before.

If you are pre-incorporation or still deciding on your stack, waiting is strictly better. Credits granted now start their expiry clock now, and applying against an entity or an account you will not keep wastes the eligibility you can only use once.

And if the reason you are reading this is that an enterprise deal is stalling, credits are not your problem. No procurement team has ever asked how your infrastructure is funded; they ask for an attestation, a completed questionnaire, and evidence of controls. Spending three weeks on credit applications while the security review sits untouched is a common and expensive substitution of easy work for the work that is actually blocking revenue. If that is your situation, find out precisely what the buyer requires and what it costs to satisfy it, which is the conversation we have when people tell us what their buyer is asking for. Our fixed-scope readiness work is published with prices so you can weigh it against a week of your own time.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.

Talk to usOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.