Case Studies / Ohio Department of Rehabilitation and Correction (ODRC) – Legacy Application

State Government
Data Management
Government Solutions
Process Management
Web App Development

Ohio Department of Rehabilitation and Correction (ODRC) - Legacy Application



Image

The Challenge

Secure 20 years of mission-critical systems with zero operational downtime.


ODRC operated a portfolio of 7+ business-critical applications on legacy .NET Framework and SQL Server. A third-party security assessment identified findings across the portfolio, including outdated dependencies with known CVEs, deprecated TLS, and runtimes past end-of-support.

Retirement was not an option. These applications encoded more than 20 years of institutional business logic and supported continuous operations across multiple facilities – systems where staff at every institution depend on daily, with no tolerance for extended outages. ODRC needed every vulnerability closed without interrupting operations, and wanted the remediation to move the platform onto supported, forward-looking technology rather than simply restore compliance.


Our Approach

Triage high-risk threats first while modernizing the platform in parallel.


Triaged all scan findings by exploitability and business impact, then sequenced remediation so the highest-risk items closed first while broader modernization ran in parallel.


What We Built

Upgraded security and migrated code to .NET 8 using AI acceleration.


Image

Patched and replaced vulnerable dependencies, updated authentication and transport to current standards, and hardened configuration and secrets handling.

Platform modernization. Migrated applications from .NET Framework to [.NET 8], resolving breaking changes and retiring deprecated APIs to place the portfolio on a supported runtime with an ongoing patch path.

AI-assisted engineering. Applied AI tooling to the work that traditionally makes legacy remediation expensive: reverse-engineering undocumented business logic, generating regression test coverage for code that had none, and drafting migration changes for repetitive patterns across the portfolio. Every AI-generated change passed developer review and our standard QA gate before merge.


The Results

Eliminated 100% of critical vulnerabilities with zero unplanned downtime.


Findings remediated, including 100% of critical and high severity items. Clean re-scan verified and all applications running on supported list, actively patched with zero unplanned production downtime during migration.

At a Glance

Client

Ohio Department of Rehabilitation and Correction (ODRC)

Industry


State Government

Services


Data Management
Government Solutions
Process Management
Web App Development


Start a Conversation

Scaling one experience across a lot of locations?


That is the kind of problem we like. Let's talk about what it could look like for you.

Start a Conversation