Everything your ColdFusion stack needs under one roof.
From emergency production fixes to multi-phase AWS migrations — senior-level delivery across the full lifecycle, from someone who has run a platform of his own.
Four disciplines. One practitioner. Zero hand-offs.
ColdFusion Lifecycle Management
Legacy maintenance and emergency troubleshooting. Adobe ColdFusion version upgrades (CF 2016/2018/2021 → supported releases). CFML code review, refactoring, and documentation. CF Administrator lockdown, JVM/Tomcat review, hotfix validation. Retainer-based monitoring and production support.
Security Audit & Hardening
OWASP-oriented application review for ColdFusion-specific risks. cfqueryparam enforcement and SQL injection remediation. Authentication, session, file upload, and deserialization review. Adobe security bulletin implementation. Server lockdown, WAF strategy, secrets management. Compliance support for government, healthcare, and finance.
AWS Cloud Engineering
ColdFusion application migration to AWS, designed for phased cutover and rollback. EC2 or containerized CFML deployment. RDS for SQL Server migration, backup/restore, encryption, monitoring. AWS WAF, CloudFront, Route 53, Secrets Manager, IAM, and VPC hardening. Infrastructure as Code (CDK/CloudFormation).
SQL Server & Data Reliability
Query, index, stored procedure, and schema performance review. Connection pooling and datasource tuning for ColdFusion workloads. SQL Server migration to Amazon RDS. Backup, restore, high availability, and disaster recovery. Data cleanup and modernization planning.
The scale these methods came from.
Production CRM serving 500+ businesses and 2,000+ users, migrated to AWS with no downtime.
Migrated from Microsoft DFS to Amazon S3 with no downtime, cutting storage cost by 60%.
Enterprise API integrations delivered across REST, JSON, and XML, including dealer management systems and every major automotive OEM.
Production architecture on AWS designed for 99.999% availability, with the networking and security model to match.
Prior results from my tenure as co-founder and CTO of DealerPeak — not ColdFusion Café client engagements, and not a prediction of what your project will achieve. Every environment is different, which is why engagements start with an assessment rather than a proposal.
Work that comes with the same background.
Secondary to the ColdFusion work above, not an alternative to it. Each of these is bought by someone who already has a legacy application and a decision to make about it, each produces a written deliverable, and each is scoped and quoted before work begins.
CFML Engine Modernization
Adobe ColdFusion to Lucee assessment and migration — or the recommendation to stay where you are. A decision-first engagement covering support model, licensing, engine-specific dependencies, deployment fit, and codebase compatibility, before anyone spends money on a rewrite.
Cloud Cost & Architecture Review
A fixed-scope written review of your AWS architecture, spend, and operational risk. I read the bill line by line, map it to what the architecture is actually doing, and rank what I find by savings opportunity against operational risk — because the cheapest change and the safest change are rarely the same one.
Technical Due Diligence & Advisory
For acquirers, boards, and executives evaluating a legacy-dependent application: code and architecture condition, infrastructure and cost profile, security exposure, key-person and institutional-knowledge risk, and a modernization roadmap with estimated effort. Grounded in acquiring and integrating another company's application stack, and in current board advisory work.
Legacy Integration & API Modernization
Brittle third-party integrations are the usual reason a legacy ColdFusion application is described as unmaintainable — the language is rarely the problem. Replacing or stabilizing the integration layer around the application, with retry, logging, and failure isolation designed in. Built on delivering 30+ enterprise integrations across REST, JSON, and XML.
Fractional Technical Leadership
A small number of advisory days per month, or leadership of one defined initiative — architecture decisions, vendor selection, build-versus-buy, or getting a stalled modernization moving. Explicitly not a full-time embedded CTO role, and I'll say so if that's what you actually need.
AI Agent Security & Governance Review
For teams already experimenting with autonomous agents. A written assessment of credential scope, sandboxing, prompt-injection exposure, human approval gates, logging, and data egress. Optionally, a sandboxed pilot design with explicit human-in-the-loop gates and a documented rollback. This is governance work, not deployment — agents are not safe by default, and I don't recommend them for regulated or public-sector environments.
Government & Public Sector
Every service on this page is available to federal, state, and local agencies. 100% US-based delivery from Portland, Oregon, no offshore subcontractors, AWS GovCloud experience, and CISA KEV compliance support — with documentation written for an external reviewer rather than for the team that already understands the system.
Engagement models that match your risk and budget.
Free Assessment
30-minute call. I review your version, licensing, and known-vulnerability exposure and send a short written summary. No obligation.
Fixed-Scope Audit
Risk & Architecture Audit or Security Lockdown Audit. Produces a written risk register, remediation plan, and roadmap.
Upgrade / Migration Project
Implementation of a ColdFusion upgrade, AWS migration, or database migration. Phased SOW with milestones, testing, cutover, and rollback.
Advisory / Emergency
Senior production troubleshooting, executive advisory, and specialized development. Billed hourly at architect rates.
Maintenance Retainer
Recurring patching, monitoring, advisory access, and defined response times. Predictable monthly cost and priority access.
AI-Augmented Delivery
AI-assisted documentation and code comprehension for legacy CFML. Event-driven AWS serverless pipelines. AI-accelerated code modernization with evaluation checks around the output rather than trust in it.
Your code and your data are not used to train models, this work is covered by the same confidentiality terms as the rest of the engagement, and every production decision is reviewed by a person before it ships. Stated the same way in the privacy policy.
Every engagement begins with a free assessment.
No obligation, no sales pressure. Just a clear recommendation for the safest next step.
Book a free 30-min assessment