Overview

Compliance shouldn't slow your team down. It should be invisible.

After six years building cloud infrastructure across HIPAA, FedRAMP, and SOC 2 environments, I kept seeing the same pattern: engineering teams treating compliance as a bolted-on process rather than a property of the system.

The result is predictable. Pipelines slow down. Engineers fight compliance instead of shipping. Audit windows turn into fire drills. Findings stack up. The next audit is worse than the last. Three weeks before each assessment, somebody is reconstructing six months of operational history into PDFs that describe a system the auditor cannot independently verify.

Stonebridge exists because regulated engineering doesn't have to work this way. Built right, compliance is a property of how the infrastructure works, not a checklist humans run before each release. Evidence emits continuously. Controls enforce structurally. Audits become queries instead of projects. Engineers ship at full speed inside a boundary the architecture itself maintains.

That's the work we take on. Not policy documents. Not assessment narratives. Engineering.

The how, documented

The Evidence-Driven Infrastructure framework

Every Stonebridge engagement applies the same four-principle methodology: Boundary First, Continuous Evidence, Policy as Code, and Founder-Led. The framework is documented in detail, with its heritage, its cross-framework application, and what it explicitly rejects.

Read the methodology →
Key Personnel

Built by an engineer who's shipped in regulated environments

Lucas Jones, Founder and Principal Engineer at Stonebridge Tech Solutions
Lucas Jones
Founder & Principal Engineer
Cloud Infrastructure · Data Platforms · Software Engineering

I've spent the last six years building cloud infrastructure and CI/CD pipelines for healthcare and federal engineering teams. The work spans HIPAA-aligned deployment pipelines, FedRAMP and GovCloud infrastructure, Kubernetes platforms in regulated environments, and the compliance posture that holds up when auditors actually look.

Before founding Stonebridge, I worked across Systems Engineer, DevOps Engineer, and Principal Platform Engineer roles, including remediation work for federal energy infrastructure and platform engineering for healthcare SaaS. I started Stonebridge to do this work the way I've always thought it should be done: senior-led, opinionated, focused on the engagements where compliance posture and engineering velocity have to coexist. The same engineer, scope to handoff.

The work goes beyond infrastructure. I write production Python: services, APIs, data pipelines, and the internal tooling that holds a platform together. That means I build the application layer myself instead of handing you an architecture diagram and wishing you luck. The same engineering background carries into data and AI. I design and build data engineering and AI platforms, including retrieval-augmented generation systems that run against regulated data: ingestion and transformation pipelines, vector stores that sit inside the compliance boundary, identity-scoped retrieval so a query cannot return records the caller is not entitled to, prompt and response logging, and evaluation built into the platform rather than a notebook someone runs by hand.

Most recently published the HIPAA CI/CD audit checklist for engineering teams: the same control map I use during 2-week audit engagements, with each Security Rule control mapped to a specific pipeline touchpoint. Earlier work includes the 2026 implementation guide for HIPAA-compliant CI/CD pipelines and the five patterns I keep seeing fail HIPAA audits, drawn from active client work.

BasedSacramento, CA AvailableEngagements across North America Directlucas@stonebridgetechsolutions.com
Certifications
  • AWS Solutions Architect Associate
  • GCP Professional Cloud Architect
  • CompTIA Network+
  • Linux LPI Essentials
  • ITIL 4 Foundation
Specializations
  • HIPAA Security Rule (incl. 2026 update)
  • FedRAMP Moderate / High
  • FedRAMP 20x KSIs
  • HITRUST CSF
  • SOC 2 Type II
  • CMMC 2.0
  • DoD IL5
  • NIST 800-53 & 800-171
Software & Data Engineering
  • Python (services, APIs, tooling)
  • Data pipelines & ETL / ELT
  • AI RAG platform architecture
  • Vector stores & identity-scoped retrieval
  • Model serving & evaluation pipelines
  • Prompt / response logging & provenance
Stack
  • Python
  • Terraform
  • Kubernetes (EKS · GKE · AKS · OKE)
  • GitLab CI/CD
  • GitHub Actions
  • Argo CD
  • Open Policy Agent / Rego
  • AWS · GCP · Azure · OCI
Technical Approach

The engineering positions behind every engagement

Compliance is an engineering problem

It is not a policy problem. It is not a documentation problem. It is not a problem that can be solved by buying a GRC platform. The infrastructure either satisfies the controls or it does not, and the only people who can change that are engineers.

If your auditor can't query your evidence, you don't have evidence

You have screenshots. Screenshots describe operational state from the moment they were captured. They describe nothing about right now. Evidence is queryable, signed, and continuously emitted by the systems being audited. Anything less is theater.

Senior engineers should do senior work

The standard consulting firm model puts senior people on sales calls and junior people on delivery. The math works for the firm and fails for the client. Stonebridge inverts this: the founder runs the discovery call, designs the architecture, writes the Terraform, and trains your team. No exceptions.

Saying no is part of the service

Most consultants take any engagement that pays. That's how clients end up with delivery teams who don't know the domain. We turn down work that doesn't fit, even when budgets are healthy. If you're outside our specialization, we'll tell you in the first call and point you somewhere that fits.

Founder-led is a structural advantage, not a stage

Some consultancies are founder-led because they haven't grown yet. Stonebridge is founder-led because founder-led delivery is the product. We grow by adding senior US-citizen engineers to the bench, not by putting a partner in front of the client and juniors behind the work. We are interested in compounding our depth across a small number of engagements per year.

Engagement Principles

Four engagement principles that guide every project

Senior engineering, end to end

Every engagement is led by the founder. Senior engineers only, all US citizens. No offshore delivery, no learning on your dime. The engineer you talk to on the discovery call is accountable for the work that ships.

Fixed scope, fixed price

Most engagements are scoped as fixed-fee deliverables with clear acceptance criteria. We absorb the schedule risk, not you. Three engagement models exist: a 2-week fixed-fee audit, a fixed-fee build engagement, and a Managed Compliance Retainer for ongoing work after the build.

Evidence-Driven Infrastructure, always

We apply the same documented methodology across every engagement. Four principles: Boundary First, Continuous Evidence, Policy as Code, Founder-Led. Compliance becomes a property of how the system operates, not a checklist humans run before each audit.

Honest about fit

We don't take engagements outside our specialization. We don't pretend to be a full-service agency. If your work fits, we'll tell you. If it doesn't, we'll point you somewhere it will. That's a feature, not a limitation.

6+
Years in
regulated infra
100%
Founder-led
delivery
7+
Compliance
frameworks
100%
Founder-led
engagements
Past Performance

Selected work in regulated environments

Have a project that fits?

Most discovery calls take 30 minutes. We come back with a written proposal within 48 hours. If we're not the right fit, we'll tell you in the first call and point you somewhere that is.

Book a 30-minute call