β€” CASE STUDY

Creating a reusable DevSecOps path to faster federal delivery

Using Agile discovery to plan ED.gov digital services modernization

theta. integrated automated testing, deployment, observability, and security controls into batCAVE’s platform delivery path. The work gave product teams a repeatable way to move software toward authorization and production while inheriting established controls and strengthening software-supply-chain visibility.

β€” CASE STUDY

Creating a reusable DevSecOps path to faster federal delivery

theta. integrated automated testing, deployment, observability, and security controls into batCAVE’s platform delivery path. The work gave product teams a repeatable way to move software toward authorization and production while inheriting established controls and strengthening software-supply-chain visibility.

customer

Centers for Medicare & Medicaid Services (CMS)

Contract Role

Subcontractor

Mission

Secure federal software delivery

Delivery Focus

DevSecOps integration, platform automation, and continuous authorization readiness

Capabilities

Build & Integrate | Secure, Test & Release | Enable & Transfer

Mission Context

CMS’s Information Security and Privacy Group was creating batCAVE as a platform-as-a-service environment for secure software delivery. Product teams needed a consistent route from code to authorized cloud deployment, with automated testing, inherited controls, observability, and supply-chain protection built into the path. theta. integrated the platform components and delivery practices that made that route repeatable.

Why it mattered

Federal teams often lose time rebuilding pipelines, documenting the same controls, and resolving security requirements late in delivery.

Federal teams often lose time rebuilding pipelines, documenting the same controls, and resolving security requirements late in delivery. A shared platform can reduce that friction only when its controls, tooling, and operating guidance work together as a usable product.

The Challenge

Make secure delivery repeatable, not project-specific
1

High-friction authorization

Security evidence and approval steps often arrived late or required repeated manual coordination.

2

Reusable control inheritance

Product teams needed a dependable way to inherit established controls without treating every deployment as a new platform.

3

Software-supply-chain risk

The delivery path required visibility across build, test, deployment, runtime, and dependency activity.

How theta. Delivered

A usable platform path from code to production
1

Integrated the delivery pipeline

theta. connected GitLab runners, Argo CD, containers, Kubernetes, and Amazon EKS into a repeatable DevSecOps workflow.

2

Codified platform deployment

theta. used Helm and infrastructure-as-code practices to make environments more consistent and reproducible.

3

Built in observability and protection

theta. integrated Grafana, Loki, Prometheus, Istio, and Falco to improve runtime visibility and security monitoring.

4

Advanced continuous-ATO readiness

theta. researched and implemented automation patterns that brought testing, control evidence, and authorization activities closer to everyday delivery.

Outcomes

Security controls became part of everyday delivery
theta. turned a collection of platform tools and controls into a clearer, reusable path for secure federal software delivery.

More automated authorization readiness

Testing and evidence activities moved closer to the delivery pipeline, reducing avoidable late-stage friction.

Reusable inherited controls

Product teams gained a clearer way to build on controls already established within the platform environment.

Stronger delivery visibility

Integrated observability and security tooling improved insight across deployment and runtime operations.

Built for What Comes Next

A reusable foundation for secure product teams
The platform patterns give CMS product teams a foundation they can reuse, extend, and govern as secure delivery practices and authorization expectations continue to evolve.

Technical environment

Technology and delivery practices

YAML, Python, Shell, GitHub, GitLab, Grafana, Loki, Prometheus, AWS, Docker, Kubernetes, Amazon EKS, Istio, Falco, GitLab Runners, Argo CD, Helm, Linux, and Windows Server

Have a complex mission to turn into a usable digital product?

Let us start with the policy, people, systems, and operating realities that shape the work.

Related work

Related case studies

01-cdoc-case-study-hero

CDOC

theta. kept essential corrections workflows moving while CDOC transitioned from aging custom applications to a modern enterprise suite. By resolving data issues, restructuring backend logic, and improving applications that would remain in place, theta. reduced friction in the legacy environment and created a safer path through a complex, multi-system transition.
02-va-pact-act-case-study-hero

VA

theta. expanded VA’s Rapid Ready for Decision approach to PACT Act claims, connecting claims workflows with existing health data so eligible cases could move forward with less manual retrieval and fewer avoidable exams. The work paired product strategy, prototyping, secure integration, and iterative delivery around the needs of Veterans and claims processors.
03-bcda-dpc-case-study-hero

CMS

theta. advanced product direction and delivered API, authentication, and credentialing capabilities for CMS’s BCDA and DPC products. The work gave authorized organizations a more dependable way to receive Medicare claims data for care coordination, performance analysis, and value-based care.
Scroll to Top