Security & Compliance

Security first, not last.

We design systems from the bottom up with security as a first-class citizen — the center of the design, not a checklist bolted on at the end. On many of our engagements the solutions architect owned all of security: identity, secrets, network segmentation, encryption, and the compliance posture. Formally OWASP-trained through enterprise security programs at Fortune-scale clients, and battle-tested in HIPAA healthcare, banking, and insurance.

Security Owned, Not Delegated

When we are the solutions architect, security is ours.

On many engagements the client put all of security in our hands — we designed the identity model, chose where the secrets lived, drew the network boundaries, reviewed the code against the design, and defended the whole posture in front of the client’s infosec team. That ownership came with formal training: OWASP secure-coding programs completed through multiple clients’ enterprise learning platforms, applied in code review and SAST remediation on real production systems.

What We Secure

Six security disciplines we bring to cloud, data, and AI platforms.

Identity & Access

OAuth2, OIDC, SSO, and PKCE done properly. We built an IdentityServer single-sign-on web application for a state pension platform, evaluated a Ping One → GCP OAuth2 migration for a healthcare enterprise, ran Azure AD B2C on a production Kubernetes platform, and ship Google OAuth with PKCE in our own SaaS product.

Regulated-Industry Compliance

HIPAA posture and multi-tenant isolation on a healthcare cloud migration, security architecture for a 10M-user banking modernization at Fiserv, and working shoulder-to-shoulder with FM Global’s infosec organization on a property-insurance platform. We speak auditor.

Secure SDLC & OWASP

Formal OWASP training through enterprise security programs, put to work daily: as primary PR approver we make security part of the review gate, and at FM Global we owned the Veracode SAST practice — maintaining scans, reading every report, and driving remediation in the code.

Cloud Platform Security

KMS and envelope encryption, Secrets Manager and Secret Manager, WAF, VPC segmentation, service accounts and least-privilege IAM — across AWS, Azure, and Google Cloud. Encryption in transit and at rest is the default, never the upgrade.

Kubernetes & Zero-Trust Networking

RBAC, network policies, cert-manager, and secrets operators that sync from cloud secret stores — plus immutable-OS cluster nodes and zero-trust mesh VPN networking between clusters and operators. The cluster assumes hostility and behaves accordingly.

Securing AI & Data Platforms

The newest attack surface. Least-privilege service accounts for model pipelines, PHI and PII governance in warehouse and lakehouse designs, and security review of MCP servers and AI agent tooling before they touch production data. AI velocity without AI exposure.

Security, Drawn Out

Two patterns behind every secure system we ship — defense in depth, and security in the delivery loop.

1 · Defense in depth — every layer earns its keep

No single control is trusted to hold. Identity gates the front door, the network assumes breach, workloads run least-privilege, data is encrypted either side of the wire, and the compliance posture is designed in — so an auditor reads the architecture, not an apology.

flowchart LR
    ID["Identity -- OAuth2, OIDC, SSO, MFA"] --> NET["Network -- segmentation, WAF, zero-trust mesh"]
    NET --> WL["Workload -- RBAC, least-privilege IAM, immutable nodes"]
    WL --> DATA["Data -- KMS, encryption in transit and at rest"]
    DATA --> COMP["Compliance -- HIPAA, banking, insurance infosec"]
                
Five layers, each designed to hold if the one before it fails.

2 · Security inside the delivery loop, not after it

Security that arrives at the end arrives too late. We put it in the loop: threat-aware design up front, OWASP-trained code review at the PR gate, static analysis on every scan cycle, and remediation that goes back into the code — the same loop we ran as Veracode owner on a Fortune-scale insurance platform.

flowchart TD
    DESIGN["Threat-aware design -- identity, secrets, boundaries chosen first"] --> CODE["Implementation -- OWASP secure-coding practices"]
    CODE --> PR["PR gate -- security review by the primary approver"]
    PR --> SAST["Static analysis -- Veracode scans and reports"]
    SAST --> FIX["Remediation -- findings fixed in code, not filed away"]
    FIX --> CODE
                
The loop that keeps findings from becoming incidents.

Security in the Wild — Real Engagements

Five engagements where the security architecture was ours to design and defend.

Healthcare · HIPAA

Healthcare Cloud Migration — HIPAA & Identity

On an enterprise healthcare AWS → GCP migration, we carried the security threads that could not break: the HIPAA regulatory posture, multi-tenant isolation topologies, and the evaluation of GCP’s OAuth2 capabilities against the incumbent Ping One identity provider.

Read the full case study
Banking · 10M Users

Fiserv — Security Architecture for 10M Users

As Business Solutions Architect on a mainframe-to-Azure banking modernization, we were responsible for the security architecture across distributed microservices serving ten million users — the identity model, the service-to-service trust, and the patterns sixty developers built against.

Insurance · SAST

FM Global — Infosec Partner & Veracode Owner

Solutions Architect on a property-risk GIS platform — the bridge between the build teams and FM Global’s infosec organization, owner of the Veracode static-analysis practice, author of the disaster-recovery plan, and primary security reviewer on the engineering database.

Identity · SSO

State Pension Platform — IdentityServer SSO

Designed and built a single-sign-on OAuth web application on IdentityServer for a state pension administration platform — an engagement that was identity work end to end: token flows, session management, and the trust boundaries around retirement data.

Our Own SaaS

Grade My Investments — We Ship What We Preach

Our own AI-powered SaaS platform runs the same playbook we sell: Google OAuth with PKCE, Stripe-isolated payment flows, secrets kept in the platform vault, and least-privilege keys around every Claude model call.

Read the full case study

Need an architect who treats security as the job, not the checkbox?

From HIPAA healthcare to 10M-user banking, Leopard Data designs the security in from the first diagram — identity, secrets, network, compliance, and the AI attack surface. Corp-to-Corp engagements out of Plano, TX.