Capabilities
What we do
Five practice areas, staffed by engineers who have shipped production systems. We go deep in these areas rather than wide across everything, and we will tell you when a problem is outside them.
01
Accessibility & Digital Services
The Department of Justice's ADA Title II rule requires state and local government web content and mobile apps to meet WCAG 2.1 AA — April 2026 for larger entities, April 2027 for smaller ones. California state agencies have carried a similar obligation under AB 434 since 2019. We get agencies compliant and keep them there.
Audit & remediation
- WCAG 2.1 AA / Section 508 audits of websites, web applications, PDFs, and mobile apps, with prioritized findings
- Hands-on remediation of code, templates, and content management systems
- Document remediation (PDF, Word, forms) and templates that stay accessible
- Accessibility statements, VPAT / ACR authoring, and AB 434 certification support
Build
- Accessible public websites, citizen portals, permit and records applications
- Form and workflow digitization that replaces paper and PDF processes
- Design systems and component libraries that make accessibility the default for your staff
- Ongoing monitoring and staff training so compliance survives the next content update
Typical engagements: fixed-price site audit; remediation sprint; portal or application build; annual monitoring retainer.
02
Cybersecurity & Compliance
Security engineering for organizations that cannot afford a full-time security team but are held to the same standards as those that can.
Compliance & governance
- NIST SP 800-171 gap assessment, System Security Plan, POA&M, and SPRS scoring
- CMMC Level 1 and Level 2 readiness for defense suppliers and their subcontractors
- RMF / ATO package support (NIST SP 800-53), StateRAMP and FedRAMP alignment
- CIS Controls implementation for local governments; MS-ISAC alignment
- Virtual CISO: policy, risk register, vendor review, board-level reporting
Technical security
- Vulnerability assessment and authorized penetration testing of networks, web applications, and embedded devices
- Zero-trust architecture, identity and access management, MFA and conditional-access rollout
- Secure software development lifecycle, code review, and supply-chain (SBOM) practices
- Incident response planning, tabletop exercises, and response support
- Hardening and monitoring for Microsoft 365, Google Workspace, and cloud workloads
Typical engagements: 800-171 / CMMC readiness assessment; annual penetration test; vCISO retainer; incident response support.
03
Cloud, Modernization & IT Operations
Replacing systems that were old when the staff who understood them retired, and running the infrastructure that is left.
Modernization & cloud
- Legacy application assessment and incremental modernization (strangler-pattern migrations, API layers, data migration)
- Cloud migration and architecture on AWS (including GovCloud), Azure (including Azure Government), and Google Cloud
- DevSecOps: CI/CD pipelines, infrastructure as code, container platforms, automated compliance evidence
- Independent verification & validation (IV&V) and technical oversight for large state IT projects
- Custom software: web applications, integrations, internal tools, APIs
Managed IT for small governments
- Microsoft 365 / Google Workspace administration, migration, and security baselines
- Identity (Entra ID / Active Directory), endpoint management, and patching
- Backup, disaster recovery, and continuity planning that is actually tested
- Network design, firewalls, and secure remote access
- Help desk and on-call support sized for a city, district, or department
Typical engagements: modernization roadmap; cloud migration; managed services agreement; IV&V subcontract; staff augmentation.
04
Applied AI & Data
Practical machine learning and data engineering for agencies that are being asked to adopt AI responsibly, often with data that cannot leave the building.
AI solutions
- Document intelligence: OCR, extraction, and classification for records, permits, public-records requests, and case files
- Citizen- and staff-facing assistants grounded in your own policies and documents (retrieval-augmented generation)
- On-premises, air-gapped, and edge deployment of language and vision models for sensitive or disconnected environments
- Computer vision and predictive maintenance for fleets, facilities, and infrastructure
- AI governance: NIST AI RMF alignment, use-case inventories, risk assessments, and procurement language
Data engineering
- Data warehouses and pipelines that unify systems that were never meant to talk
- Dashboards, reporting, and open-data portals
- GIS integration (ArcGIS and open-source) with operational and financial systems
- Data quality, master data, and migration for modernization projects
Typical engagements: AI readiness and governance assessment; document-processing pilot; on-prem AI deployment; data platform build.
05
Embedded Systems, Electrical & OT
Electrical engineering is our hard-engineering discipline, and it is what sets us apart from other IT firms: we design the board, write the firmware, secure the network it sits on, and build the software that consumes its data.
Electrical & embedded
- Schematic capture, PCB layout, prototyping, bring-up, and small-batch production support
- Firmware and embedded Linux development; RTOS; secure boot and device identity
- Obsolescence (DMSMS) redesign and reverse engineering of legacy boards and test equipment
- Ruggedized and fielded electronics designed with MIL-STD-810 environmental and MIL-STD-461 EMI/EMC requirements in view
- Sensors, data acquisition, RF/SDR, FPGA, and edge-AI hardware
- Hardware-in-the-loop test rigs and automated test equipment
Operational technology
- ICS/SCADA assessment, network segmentation, and monitoring for water, wastewater, and municipal utilities (CISA and AWWA guidance)
- PLC, HMI, and telemetry modernization with IT/OT integration
- Smart-city and environmental IoT: traffic, air quality, metering, facilities
- Secure device fleets: provisioning, over-the-air updates, and lifecycle management
Typical engagements: board redesign or obsolescence replacement; prototype-to-pilot device program; OT security assessment; SBIR/STTR Phase I/II research.
Also available
- Staff augmentation — senior software, security, cloud, and embedded engineers on hourly or monthly terms.
- Training — accessibility, secure development, and cloud operations workshops for agency staff.
- Technical advisory — RFP and statement-of-work drafting, vendor evaluation, and architecture review for agencies that need an independent engineer in the room.