Public Sector & Defense
Public software should be as good as the private kind.
Government software carries a burden commercial software doesn’t: nobody can choose a competitor. A permitting system that takes forty minutes to complete isn’t a churn problem, it’s a citizen who gives up. We build to the standards this work demands (Section 508 and WCAG, plain language, FedRAMP-aligned boundaries, NIST 800-171 where CUI is in scope) and we build it to be genuinely usable. Three buyers sit here and they are not interchangeable: federal agencies, state and local government, and defense-adjacent suppliers whose real question is evidence rather than software. Public universities are a fourth, with their own procurement and authorization regime, covered separately under Higher Education & Research.
What we hear
The problems that actually show up.
Not a market overview. These are the specific failures that bring people to us in this sector.
Systems that outlived their documentation
Mission-critical applications built decades ago, maintained by a shrinking group, and impossible to change quickly when policy does.
Accessibility treated as an audit item
Section 508 conformance retrofitted at the end costs several times what building to it would have, and the result is still worse.
Data trapped by agency boundary
The same citizen is a separate record in six systems, and every interaction starts by asking them for information the agency already has.
Authority to operate as a bottleneck
Security authorization arrives at the end as a gate rather than being engineered in, and delivery timelines absorb the shock.
The suite that covers eighty percent of it
A platform is already in place, staff are trained on it, and abandoning it is not politically available. The gap is the workflow the suite does not model and the integrations nobody will own, which is a different project from the replacement a vendor would rather sell you.
A bid nobody can score
Past performance is the first thing evaluated and the one thing a new firm cannot manufacture. We do not have a federal record yet, so on federal work we expect to arrive as a subcontractor to a prime rather than lead a bid, and we will say which on the first call. If your acquisition strategy needs a prime with a scored record, that is a reason to use one.
What we build here
Systems we’ve shipped in this sector.
Some of these are whole products; some are one screen that removed a week of manual work. Both count.
- Citizen-facing application, licensing and permitting services
- Case management and eligibility determination workflows
- Inspection, enforcement and field-officer mobile tooling
- Grants management and sub-recipient reporting
- Records digitization and document intelligence pipelines
- Interagency data exchange and identity federation
- Mission dashboards and readiness reporting
- Modernization of COBOL, AS/400 and mainframe-era systems
Integrates with
The estate you already have.
We work through supported interfaces, not screen-scraping that breaks at the next upgrade.
Built to
The standards this sector answers to.
Engineered in from the start. Retrofitting conformance costs several times as much and produces a worse result.
Case studies
Work in this sector.
Further reading
Written up at length.
- Security5 min read
TX-RAMP § 6.2: the exemption a custom build may already have
A Texas university asks for your TX-RAMP certification and the project stops for a quarter. For software the institution commissioned, the program manual says certification does not apply — and then attaches four conditions that decide whether you actually get it.
- Security7 min read
CMMC on the shop floor: scope is the only lever that matters
A prime asked for your certification status and now the plant network is the problem. Almost all of the cost in a Level 2 assessment is decided before a single control is implemented — and since Phase 2 was suspended in July 2026, the person asserting your posture is you.
- Delivery5 min read
The statement of work is the contract
The legal terms get the lawyers and the weeks of redlining. The document that actually decides what you receive is usually written the night before signature.
Sources
- 1.SP 800-171 Rev. 3: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, NIST
- 2.32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program, Electronic Code of Federal Regulations
- 3.IT Accessibility Laws and Policies, Section508.gov
- 4.Web Content Accessibility Guidelines (WCAG) 2.2, W3C,
Next step
Working in public sector & defense?
Bring the specific failure, not a requirements document. Forty-five minutes and we’ll tell you what we’d do about it.