Everything your ColdFusion stack needs under one roof.

From emergency production fixes to multi-phase AWS migrations — senior-level delivery across the full lifecycle, from someone who has run a platform of his own.

Four disciplines. One practitioner. Zero hand-offs.

CF

ColdFusion Lifecycle Management

Legacy maintenance and emergency troubleshooting. Adobe ColdFusion version upgrades (CF 2016/2018/2021 → supported releases). CFML code review, refactoring, and documentation. CF Administrator lockdown, JVM/Tomcat review, hotfix validation. Retainer-based monitoring and production support.

Read the ColdFusion 2018/2021 upgrade guide →
Compare Adobe ColdFusion, Lucee, and BoxLang →

SEC

Security Audit & Hardening

OWASP-oriented application review for ColdFusion-specific risks. cfqueryparam enforcement and SQL injection remediation. Authentication, session, file upload, and deserialization review. Adobe security bulletin implementation. Server lockdown, WAF strategy, secrets management. Compliance support for government, healthcare, and finance.

Deliverable: written risk register and prioritized remediation plan. See the full ColdFusion security audit scope →

AWS

AWS Cloud Engineering

ColdFusion application migration to AWS, designed for phased cutover and rollback. EC2 or containerized CFML deployment. RDS for SQL Server migration, backup/restore, encryption, monitoring. AWS WAF, CloudFront, Route 53, Secrets Manager, IAM, and VPC hardening. Infrastructure as Code (CDK/CloudFormation).

Deliverable: target architecture, cutover runbook, and rollback plan.

SQL

SQL Server & Data Reliability

Query, index, stored procedure, and schema performance review. Connection pooling and datasource tuning for ColdFusion workloads. SQL Server migration to Amazon RDS. Backup, restore, high availability, and disaster recovery. Data cleanup and modernization planning.

Deliverable: findings ranked by impact, with the remediation script or plan for each.

The scale these methods came from.

500+ businesses

Production CRM serving 500+ businesses and 2,000+ users, migrated to AWS with no downtime.

100M+ files

Migrated from Microsoft DFS to Amazon S3 with no downtime, cutting storage cost by 60%.

30+ integrations

Enterprise API integrations delivered across REST, JSON, and XML, including dealer management systems and every major automotive OEM.

Multi-AZ

Production architecture on AWS designed for 99.999% availability, with the networking and security model to match.

Prior results from my tenure as co-founder and CTO of DealerPeak — not ColdFusion Café client engagements, and not a prediction of what your project will achieve. Every environment is different, which is why engagements start with an assessment rather than a proposal.

Work that comes with the same background.

Secondary to the ColdFusion work above, not an alternative to it. Each of these is bought by someone who already has a legacy application and a decision to make about it, each produces a written deliverable, and each is scoped and quoted before work begins.

ENG

CFML Engine Modernization

Adobe ColdFusion to Lucee assessment and migration — or the recommendation to stay where you are. A decision-first engagement covering support model, licensing, engine-specific dependencies, deployment fit, and codebase compatibility, before anyone spends money on a rewrite.

Deliverable: written engine recommendation, compatibility and risk register, migration approach, and roadmap. Read the Adobe ColdFusion-to-Lucee decision framework →

COST

Cloud Cost & Architecture Review

A fixed-scope written review of your AWS architecture, spend, and operational risk. I read the bill line by line, map it to what the architecture is actually doing, and rank what I find by savings opportunity against operational risk — because the cheapest change and the safest change are rarely the same one.

Deliverable: findings document, ranked, with the trade-off stated for each recommendation.

DD

Technical Due Diligence & Advisory

For acquirers, boards, and executives evaluating a legacy-dependent application: code and architecture condition, infrastructure and cost profile, security exposure, key-person and institutional-knowledge risk, and a modernization roadmap with estimated effort. Grounded in acquiring and integrating another company's application stack, and in current board advisory work.

Deliverable: written diligence report with a risk register and an effort-estimated roadmap.

API

Legacy Integration & API Modernization

Brittle third-party integrations are the usual reason a legacy ColdFusion application is described as unmaintainable — the language is rarely the problem. Replacing or stabilizing the integration layer around the application, with retry, logging, and failure isolation designed in. Built on delivering 30+ enterprise integrations across REST, JSON, and XML.

Deliverable: integration inventory, failure-mode analysis, and a staged replacement plan.

CTO

Fractional Technical Leadership

A small number of advisory days per month, or leadership of one defined initiative — architecture decisions, vendor selection, build-versus-buy, or getting a stalled modernization moving. Explicitly not a full-time embedded CTO role, and I'll say so if that's what you actually need.

Deliverable: decision memos and a written recommendation for each initiative.

AI

AI Agent Security & Governance Review

For teams already experimenting with autonomous agents. A written assessment of credential scope, sandboxing, prompt-injection exposure, human approval gates, logging, and data egress. Optionally, a sandboxed pilot design with explicit human-in-the-loop gates and a documented rollback. This is governance work, not deployment — agents are not safe by default, and I don't recommend them for regulated or public-sector environments.

Deliverable: controls assessment with findings ranked by exposure.

GOV

Government & Public Sector

Every service on this page is available to federal, state, and local agencies. 100% US-based delivery from Portland, Oregon, no offshore subcontractors, AWS GovCloud experience, and CISA KEV compliance support — with documentation written for an external reviewer rather than for the team that already understands the system.

Public-sector work in detail →

Engagement models that match your risk and budget.

Free Assessment

30-minute call. I review your version, licensing, and known-vulnerability exposure and send a short written summary. No obligation.

Free · 30 minutes · no obligation

Fixed-Scope Audit

Risk & Architecture Audit or Security Lockdown Audit. Produces a written risk register, remediation plan, and roadmap.

$3,500 – $12,000

Upgrade / Migration Project

Implementation of a ColdFusion upgrade, AWS migration, or database migration. Phased SOW with milestones, testing, cutover, and rollback.

$18,000 – $65,000+

Advisory / Emergency

Senior production troubleshooting, executive advisory, and specialized development. Billed hourly at architect rates.

$185 – $225/hr

Maintenance Retainer

Recurring patching, monitoring, advisory access, and defined response times. Predictable monthly cost and priority access.

From a fixed monthly retainer, scoped to coverage and response requirements

AI-Augmented Delivery

AI-assisted documentation and code comprehension for legacy CFML. Event-driven AWS serverless pipelines. AI-accelerated code modernization with evaluation checks around the output rather than trust in it.

Your code and your data are not used to train models, this work is covered by the same confidentiality terms as the rest of the engagement, and every production decision is reviewed by a person before it ships. Stated the same way in the privacy policy.

Code archaeology Serverless pipelines Evaluation checks

Every engagement begins with a free assessment.

No obligation, no sales pressure. Just a clear recommendation for the safest next step.

Book a free 30-min assessment