Cloud-native security programs for healthcare, legal, and financial organizations. Built by someone who has done the work, not read about it.
Every engagement is scoped before work starts, documented as it progresses, and delivered against outcomes you can verify.
Baseline hardening and documentation for organizations getting their security posture off the ground.
Deep-dive security hardening aligned to CIS benchmarks with full audit-ready documentation.
Full HIPAA or SOC 2-aligned security program build-out for regulated industries.
End-to-end security program covering infrastructure, compliance, governance, and ongoing support.
Continuous security oversight for organizations that need a fractional security engineer.
Lafontaine Security was founded by a working IT and Cloud Security Engineer with hands-on experience securing HIPAA-regulated, cloud-native environments. Not a reseller repackaging vendor tools.
Real architecture decisions. Real documentation. Programs that hold up under audit scrutiny.
Sanitized engagements from production environments. No fabricated metrics.
Built a complete security program from zero for a 6-site diagnostic imaging organization with 83 users on M365 Business Premium. One engineer, five months, no prior documentation.
Hardened Meraki MX75 firewalls across 6 sites with consistent policy, IDS/IPS tuning, and segmentation aligned to HIPAA network controls.
Deployed Cisco Duo RADIUS MFA for legacy systems outside Entra ID Conditional Access scope, achieving 100% MFA coverage organization-wide.
We will review your submission and follow up within one business day with a scoping call or proposal.