Engagements documented by the engineers who built them

Every case study below is anonymized but otherwise as-is: architecture decisions, control mappings, code patterns, what shipped, and what we would do differently.

Lucas Jones, Founder and Principal Engineer at Stonebridge Tech Solutions

Lucas Jones

Founder & Principal Engineer · Sacramento, CA
Cloud Infrastructure · Data Platforms · Software Engineering

Every engagement on this page was scoped, designed, built, and handed off by the same engineer who wrote up the case study. Six years across HIPAA, FedRAMP, HITRUST, and SOC 2 environments. Senior engineers only, all US citizens.

Read the full bio →
TapTab · Restaurant Fintech · GCP Named client
TapTab

Zero downtime, white-label ready: production GCP for TapTab

Published with client permission, naming the company. TapTab was expanding through white-label restaurant pages, but every new partner brand meant hand-built routing, a single expired domain had taken down dev and production together, and database spend was climbing unwatched. We rebuilt routing as Terraform so partners onboard by configuration, eliminated the outage failure class, and cut database spend 60 percent. The engagement became a multi-year retained relationship.

ClientTapTab · named, with permission
StackGCP · Cloud Run · Terraform · Cloud SQL
Outcome60% lower DB spend · multi-year retainer
Read the case study
AI SaaS · Federal Published

FedRAMP Moderate architecture for an AI SaaS vendor

A federal customer was ready to procure contingent on a Moderate authorization path with a tight fiscal-year deadline. We architected the AWS GovCloud boundary, federated identity from the existing IdP, codified the boundary in Terraform with policy gates, and wrote control narratives alongside every module.

FrameworkFedRAMP Moderate
CloudAWS GovCloud (US-West)
OutcomePassed 3PAO readiness review
Read the case study
Healthcare SaaS · HIPAA Published

HIPAA-aligned multi-stage CI/CD pipeline for a healthcare SaaS

A monolithic GitLab pipeline had become the bottleneck on every deploy and every audit cycle. We decomposed it into parent/child stages, layered Ansible-driven HIPAA control validation across 32+ production hosts, and built audit-ready evidence emission into every deploy. The next audit stopped being a reconstruction project.

FrameworkHIPAA Security Rule · SOC 2
StackGitLab CI/CD · Ansible · AWS
Outcome70% deployment time reduction
Read the case study
AI SaaS · HIPAA · Third Engagement Published

HIPAA CI/CD overhaul for an AI SaaS vendor

A returning client. Third engagement following the FedRAMP boundary build and the Kubernetes migration. This time the HIPAA-side pipeline was the long pole: unsigned artifact promotion, manual security scanning, and an audit trail that did not survive its own deploys. We rebuilt with Cosign signing, OPA Gatekeeper admission control on EKS, and audit-grade evidence emission inheriting the FedRAMP boundary.

FrameworkHIPAA Security Rule · SOC 2
StackGitHub Actions · EKS · Cosign · OPA
OutcomeZero pipeline findings on HITRUST i1
Read the case study

Pick a time. Skip the back-and-forth.

30-minute discovery call. We walk your current architecture and compliance posture, talk about the engagement that fits, and you get a written proposal within 48 hours.