
Secure 20 years of mission-critical systems with zero operational downtime.
ODRC operated a portfolio of 7+ business-critical applications on legacy .NET Framework and SQL Server. A third-party security assessment identified findings across the portfolio, including outdated dependencies with known CVEs, deprecated TLS, and runtimes past end-of-support.
Retirement was not an option. These applications encoded more than 20 years of institutional business logic and supported continuous operations across multiple facilities – systems where staff at every institution depend on daily, with no tolerance for extended outages. ODRC needed every vulnerability closed without interrupting operations, and wanted the remediation to move the platform onto supported, forward-looking technology rather than simply restore compliance.
Triage high-risk threats first while modernizing the platform in parallel.
Triaged all scan findings by exploitability and business impact, then sequenced remediation so the highest-risk items closed first while broader modernization ran in parallel.
Upgraded security and migrated code to .NET 8 using AI acceleration.

Patched and replaced vulnerable dependencies, updated authentication and transport to current standards, and hardened configuration and secrets handling.
Platform modernization. Migrated applications from .NET Framework to [.NET 8], resolving breaking changes and retiring deprecated APIs to place the portfolio on a supported runtime with an ongoing patch path.
AI-assisted engineering. Applied AI tooling to the work that traditionally makes legacy remediation expensive: reverse-engineering undocumented business logic, generating regression test coverage for code that had none, and drafting migration changes for repetitive patterns across the portfolio. Every AI-generated change passed developer review and our standard QA gate before merge.
Eliminated 100% of critical vulnerabilities with zero unplanned downtime.
Findings remediated, including 100% of critical and high severity items. Clean re-scan verified and all applications running on supported list, actively patched with zero unplanned production downtime during migration.