Engagements documented by the engineers who built them
Every case study below is anonymized but otherwise as-is: architecture decisions, control mappings, code patterns, what shipped, and what we would do differently.
Lucas Jones
Every engagement on this page was scoped, designed, built, and handed off by the same engineer who wrote up the case study. Six years across HIPAA, FedRAMP, HITRUST, and SOC 2 environments. Senior engineers only, all US citizens.
Read the full bio →
Zero downtime, white-label ready: production GCP for TapTab
Published with client permission, naming the company. TapTab was expanding through white-label restaurant pages, but every new partner brand meant hand-built routing, a single expired domain had taken down dev and production together, and database spend was climbing unwatched. We rebuilt routing as Terraform so partners onboard by configuration, eliminated the outage failure class, and cut database spend 60 percent. The engagement became a multi-year retained relationship.
Read the case study →FedRAMP Moderate architecture for an AI SaaS vendor
A federal customer was ready to procure contingent on a Moderate authorization path with a tight fiscal-year deadline. We architected the AWS GovCloud boundary, federated identity from the existing IdP, codified the boundary in Terraform with policy gates, and wrote control narratives alongside every module.
Read the case study →HIPAA-aligned multi-stage CI/CD pipeline for a healthcare SaaS
A monolithic GitLab pipeline had become the bottleneck on every deploy and every audit cycle. We decomposed it into parent/child stages, layered Ansible-driven HIPAA control validation across 32+ production hosts, and built audit-ready evidence emission into every deploy. The next audit stopped being a reconstruction project.
Read the case study →HIPAA CI/CD overhaul for an AI SaaS vendor
A returning client. Third engagement following the FedRAMP boundary build and the Kubernetes migration. This time the HIPAA-side pipeline was the long pole: unsigned artifact promotion, manual security scanning, and an audit trail that did not survive its own deploys. We rebuilt with Cosign signing, OPA Gatekeeper admission control on EKS, and audit-grade evidence emission inheriting the FedRAMP boundary.
Read the case study →Pick a time. Skip the back-and-forth.
30-minute discovery call. We walk your current architecture and compliance posture, talk about the engagement that fits, and you get a written proposal within 48 hours.