Work that stands up to the next question.
A record of AVM client delivery: what the problem was, what we built, and what it produced. Every entry traces to internal source documentation, available under NDA during diligence.
Some clients are described by profile rather than name where naming approval is pending or contractually restricted. Outcome data is unchanged.
Case study catalog
Showing 23 of 23
| Engagement | Industry | Challenge | What AVM delivered | Capabilities | Documented outcome | Period |
|---|---|---|---|---|---|---|
![]() eHarmonyOracle release automation |
Consumer technology / Online dating | A critical Oracle environment lacked release tooling, blocking fully automated CI/CD deployments. | Cloned Oracle data with EBS snapshots, masked and mapped data, automated incremental apply and rollback flows, and integrated them into CI/CD. | AWS EBS · Oracle · Bash · Go · Ruby on Rails · GitHub · CI/CD | Repeatable rollouts and rollbacks, automated database releases, and a GitHub audit trail for database state changes. | Documented Jan 2024 |
![]() Capital OneEnterprise metadata discovery |
Financial services | Find data-catalog concepts across 1,200 financial systems and enable self-service ETL supply chains. | Connected enterprise data-model terms to data-lake registration, captured business and technical metadata, and shifted from synonym search to dataset registration. | Collibra · Ab Initio EDM · Teradata · Hadoop · Metadata automation | Improved search precision through dataset registration and automatic metadata capture across a roughly 500 TB data lake. | Historical; documented Jan 2024 |
![]() Western AssetLegal document intelligence |
Asset management / Financial services | Inbound legal-document volume exceeded analyst capacity and reduced review quality. | Built AI search and classification for legal keywords and patterns across scanned documents. | Amazon Textract · BERT · GPT-2 · EMR · Databricks · Kafka · SageMaker | Delivered 70% retrieval, classification and prediction accuracy, and reduced human effort by one third. | Historical; documented Jan 2024 |
![]() Georgia-PacificKnowledge retrieval |
Manufacturing | Highly trained staff spent substantial time locating compliance and standards information in thousands of internal documents. | Created an NLP application that returns and highlights the three most relevant answers from internal content. | OCR · BERT · NLP · Deep learning · Google Cloud Platform | Cut paragraph-finding time ten-fold, freed five full-time resources, and returned answers at more than 80% accuracy. | Historical; documented Jan 2024 |
| AIRR AIRREnd-to-end SaaS observability |
Financial technology / SaaS | A fully serverless AWS product needed unified visibility into frontend experience and backend operations. | Instrumented frontend and backend services, added synthetic monitoring, and integrated AWS telemetry in Datadog. | Datadog RUM · APM · Synthetics · AWS · React · Node.js · Serverless | Established end-to-end correlation, platform-state dashboards, user-experience insight, and faster identification of bugs and performance issues. | Historical; documented Jan 2024 |
| FN FinchDatadog instrumentation standards |
Financial technology / SaaS | Existing Datadog instrumentation lacked useful context and was hard to correlate with AWS-generated parameters. | Reviewed source code, improved logging middleware, repaired serverless integrations, and standardized dashboards, monitors and alerts. | Datadog · AWS · Serverless observability · Logging · Monitoring | Improved telemetry context, platform-state visibility, alerting coverage, and source-code logging standards. | Historical; documented Jan 2024 |
![]() IntuitThreat modeling at service scale |
Financial software | Standardize and sustain threat models across 220 services while integrating the work into engineering delivery. | Rolled out ThreatModeler, dynamic model updates, attack-surface visualization, pipeline integration, KPIs, and a threat-modeling center of excellence. | ThreatModeler · Secure SDLC · CI/CD · Security KPIs · Threat modeling | Increased coverage ratio by 73%, covered critical systems, and improved threat-model accuracy and detection by 12 times. | Documented Apr 2024 |
| CK CloudKnoxMulti-cloud security by design |
Cybersecurity software | Embed threat modeling across 23 services and support SOC and ISO compliance without adding excessive cost or friction. | Integrated Microsoft Threat Modeling Tool and STRIDE into design, built a shared threat framework, and advanced least-privilege controls across clouds. | Microsoft TMT · STRIDE · AWS · Azure · GCP · VMware · Compliance | Reached 100% threat-model coverage, advanced compliance work, and discovered a significant Google sign-in authentication-flow defect. | Documented Apr 2024 |
| M MetraAWS migration threat modeling |
Public transit | Migrate transit workloads to AWS while applying consistent application-centric threat modeling across delivery teams. | Created Microsoft TMT templates and migration patterns for AWS service combinations, then coached scrum teams through implementation and automation. | AWS · Microsoft TMT · STRIDE · Migration patterns · Security design | A repeatable threat-modeling process and reusable AWS migration patterns were established across participating teams. No quantitative result was documented. | Documented Apr 2024 |
| NB National bankSHIELD threat platform |
Banking | Apply asset-centric threat analysis and strengthen security across CI/CD and related governance processes. | Co-developed the custom SHIELD platform using PASTA and paired with the bank throughout adoption. | PASTA · Asset-centric threat analysis · CI/CD security · Data cataloging | Automated threat modeling and strengthened security integration across delivery and business processes. No quantitative result was documented. | Documented Apr 2024 |
![]() Riot GamesRDS MySQL optimization |
Gaming | Improve performance and cost efficiency across an RDS MySQL fleet and evaluate Aurora migration economics. | Partnered with database engineering on tuning, cost optimization, sizing, and operational-cost reviews for potential Aurora moves. | Amazon RDS · MySQL · Amazon Aurora · Performance engineering · FinOps | Recommendations and migration-cost analysis were documented as active work. A completed quantitative outcome was not recorded. | Active as documented Apr 2024 |
![]() Riot GamesKubernetes platform modernization |
Gaming | Move to next-generation Kubernetes infrastructure while advancing security initiatives across the eSports organization. | Worked with the client platform team and Amazon Professional Services on migration and security-focused delivery. | Kubernetes · AWS · Platform engineering · DevSecOps · Security | Migration and security initiatives were documented as active engagements. A completed quantitative outcome was not recorded. | Active as documented Apr 2024 |
| T1 Tier 1 US financial institutionWorkday DevSecOps |
Financial services | Automate Workday integration releases while improving compliance visibility, audit support, and developer productivity. | Implemented automated release pipelines and observability, and helped shape the future DevSecOps strategy and roadmap. | Workday · DevSecOps · CI/CD · Observability · Audit automation | Active implementation and roadmap work documented. A completed quantitative outcome was not recorded. | Active as documented Apr 2024 |
| T1 Tier 1 US financial institutionERP integration-test modernization |
Financial services | Modernize a custom ERP SaaS integration-test application for concurrency, current dependencies, and cloud execution. | Re-architected the framework for concurrent testing, upgraded dependencies, and helped move execution from on-premises resources to AWS. | Test automation · Concurrency · Dependency modernization · AWS migration | A modernized concurrent test framework and movement toward AWS resources were documented. No quantitative result was recorded. | Documented Apr 2024 |
| T5 Top 5 global technology and media companyProduct analytics service |
Technology and media | Turn events and SIEM telemetry into broader insight on usage of a large media codebase. | Built a new analytics service and data source, then delivered consumable Tableau dashboards. | Data engineering · SIEM integration · Analytics services · Tableau · BI | Established a reusable analytics data source and dashboards. No quantitative result was documented. | Documented Apr 2024 |
| T5 Top 5 global technology and media companyEnterprise-scale dependency modernizationFlagship |
Technology and media | Manage upgrades across more than 1,000 interdependent Java modules with widespread outdated dependencies and security exposure. | Built analysis and validation pipelines, dependency freshness scoring, upgrade grouping, OpenRewrite recipes, automated tests, and monitoring. | Java · OpenRewrite · Maven · jAPI · jDeps · Neo4j · Splunk · JUnit · LLM interface | Documented 75% fewer security vulnerabilities, 40% faster releases, 60% less upgrade effort, and 90% automation of dependency updates. | Active; metrics documented Jan 2026 |
| T5 Top 5 global technology and media companyMulti-cloud cost observability |
Technology and media | Improve visibility into cloud spend across four major cloud providers. | Created cloud-cost data pipelines and reporting tools with the FinOps team and supported vendor evaluations. | FinOps · AWS · Azure · GCP · Data pipelines · Reporting | Cross-cloud spend pipelines and reporting were documented as active work. A completed quantitative outcome was not recorded. | Active as documented Apr 2024 |
![]() Paramount / Pluto TVStreaming observability |
Media and streaming | Handle high-volume observability data without harming application performance while unifying cost, operations and security insight. | Optimized Vector and OpenTelemetry pipelines, consolidated Kubernetes cost and telemetry in Datadog, and added security monitoring. | Datadog · Vector · OpenTelemetry · Kubernetes · Cloud cost · Security monitoring | Enabled real-time insight into spend, resource use and security posture, plus identification of waste and underused services. | Active as documented Apr 2024 |
![]() IntegraConnectWeb application observability |
Healthcare technology | Close monitoring gaps and identify performance issues across critical web applications and third-party dependencies. | Worked with the client and its vendors to improve monitoring and proactively isolate infrastructure and external-source issues. | Application observability · Performance monitoring · Vendor coordination | Monitoring improvements documented as active collaboration. A completed quantitative result was not recorded. | Active as documented Apr 2024 |
| ED EdmodoSecurity incident response program |
Education technology | Establish a formal incident-response policy as cyber risk increased. | Analyzed requirements and created an incident-response policy aligned with NIST SP 800-61 for the security incident response team. | NIST SP 800-61 · Incident response · SIRT enablement · Security policy | Created a structured process for faster detection, investigation and response while supporting operational continuity and stakeholder trust. | Documented Apr 2024 |
![]() Roc360Enterprise security-policy framework |
Financial services | Strengthen security governance during rapid growth while maintaining compliance and client trust. | Co-created tailored incident response, acceptable use, internet and social media policy frameworks. | Security governance · Policy engineering · Compliance · Risk management | Established a broader policy foundation aligned with regulatory expectations and cybersecurity best practices. | Documented Apr 2024 |
| H Fortune 500 hospitality companyLiving threat modelsFlagship |
Hospitality | Replace inconsistent, static threat reviews with reusable security patterns for GenAI and shared application components. | Analyzed architecture and data flows, extended STRIDE for GenAI risks, built a pattern library and traceability matrix, and created a continuously updated process. | STRIDE · GenAI threat modeling · Adversarial simulation · Secure design · Guardrails | Reduced threat-modeling time per application by 40%. Documented examples also report 22% faster time to market and 48% fewer API vulnerabilities across seven applications. | Documented Jan 2026 |
| EC Enterprise clientAgentic SDLC requirements and testsFlagship |
Enterprise technology | Consolidate scattered Jira stories and code into authoritative feature requirements, then increase test readiness and traceability. | Used LLM-assisted requirements consolidation and BDD test synthesis with human-in-the-loop review and manual verification. | LLM · Jira · BDD · Python · Human-in-the-loop review · Traceability | Processed 122 Jira stories, generated 2,849 requirements, reported 97% implementation coverage, and averaged 86.3% test accuracy. | Documented Jan 2026 |
Scroll horizontally to compare all fields. Source documentation is available under NDA during evaluation.








