loopscience
cloud · kubernetes · devsecops · iam

Infrastructure that defends itself.

Loop Science is a hands-on consultancy for teams running serious infrastructure — AWS & GCP architecture, Kubernetes platforms, and the DevSecOps and IAM discipline that keeps it all defensible.

tim@loopscience — zsh

$ trivy image ghcr.io/loopscience/api:latest --severity HIGH,CRITICAL

openssl 3.0.2-0ubuntu1.10 — CVE-2024-6119 CRITICAL
libxml2 2.9.13 — CVE-2024-25062 HIGH
iam-policy: prod-deploy-role PASS

$ ▊

KUBERNETES/ OPEN POLICY AGENT/ TERRAFORM/ GITLAB/ GITHUB/ OAUTH2-PROXY/ ENVOY/ ISTIO/ CERT-MANAGER/ ZERO TRUST/ OPENID CONNECT/ SAML/ KEYCLOAK/ MCP/ CLAUDE/ LANGCHAIN/ LANGGRAPH/ KUBEFLOW/ MLFLOW/ LABEL STUDIO/ GO/ PYTHON/ GRPC/ REDIS/ DJANGO/ AWS/ GCP/ DOCKER/ BUILDPACKS/ OPERATOR FRAMEWORK/ CROSSPLANE/ POSTGRES/ OPENSEARCH/ SBOM/ SYFT/ GRYPE/ CYCLONEDX/ SLSA/ GUAC/ SEMGREP/ SONARQUBE/ OSV/ KUBERNETES/ OPEN POLICY AGENT/ TERRAFORM/ GITLAB/ GITHUB/ OAUTH2-PROXY/ ENVOY/ ISTIO/ CERT-MANAGER/ ZERO TRUST/ OPENID CONNECT/ SAML/ KEYCLOAK/ MCP/ CLAUDE/ LANGCHAIN/ LANGGRAPH/ KUBEFLOW/ MLFLOW/ LABEL STUDIO/ GO/ PYTHON/ GRPC/ REDIS/ DJANGO/ AWS/ GCP/ DOCKER/ BUILDPACKS/ OPERATOR FRAMEWORK/ CROSSPLANE/ POSTGRES/ OPENSEARCH/ SBOM/ SYFT/ GRYPE/ CYCLONEDX/ SLSA/ GUAC/ SEMGREP/ SONARQUBE/ OSV/

Areas of expertise

Hands-on, from the kernel to the pipeline

Four disciplines that tend to show up together in every engagement.

Cloud architecture — AWS & GCP

Multi-account/org design, landing zones, and infrastructure-as-code that your team can actually read.

multi-account & org design landing zones terraform / IaC cost & FinOps

Kubernetes & container platforms

EKS, GKE, or self-managed clusters — sized, secured, and built to recover from failure before anyone needs to be paged.

EKS · GKE · self-managed helm & GitOps service mesh autoscaling & reliability

DevSecOps

Security built into the pipeline, not bolted on after — from commit to production.

CI/CD pipeline security SAST / DAST / SCA supply chain (SBOM, signing) policy as code

Identity & access management

Least-privilege by default, provable at audit time — not a spreadsheet nobody trusts.

SSO / SAML / OIDC least-privilege IAM zero-trust architecture access reviews & audits

Secure by design

The frameworks behind the buzzword

"Secure by design" gets used as an unexplained buzzword often enough that it's worth being specific. These are the actual frameworks engagements get built against.

NIST SSDF (SP 800-218)

The US government's secure-software-development framework, organized into four practice groups: prepare the organization (roles, training, tooling before code is written), protect the software (source and build integrity), produce well-secured software (design and implementation practices), and respond to vulnerabilities (a real disclosure and remediation process, not a contact-us form).

OWASP ASVS

A tiered, checklist-style verification standard for application security controls — L1 for opportunistic risks every app should close, L2 for apps handling sensitive data, L3 for the controls a high-value target actually needs. Naming the level up front turns "we did a security review" into a claim someone can actually audit.

SLSA (supply-chain levels)

Levels (0–3) for how provable and tamper-resistant your build pipeline actually is — who could have modified an artifact between source and deployment, and whether you could prove they didn't. This is the standard the SBOM/Syft/Grype tooling below exists to satisfy, not a separate concern from it.

CISA Secure by Design

Three published principles, not a vibe: take ownership of customer security outcomes (a breach from a default-insecure setting is the vendor's failure, not the user's), embrace radical transparency and accountability (real CVE disclosure, real postmortems), and lead from the top (security as a business priority set by leadership, not delegated entirely to one engineer).

The toolchain

What's actually in the toolchain

What "DevSecOps" actually means in this practice, grouped by where each tool sits in the stack.

The filter underneath the list: does this tool answer to an open specification, or to one vendor's roadmap? OAuth2, OpenID Connect, SAML, and Open Policy Agent's Rego are published standards any vendor can implement; a proprietary identity or policy control plane tied to one company's API isn't, and that's a lock-in risk as much as a technical one.

Identity & zero trust

SSO and zero-trust access control, from the identity provider to the proxy sitting in front of every internal service.

Keycloak OAuth2-Proxy OpenID Connect SAML

Policy & runtime enforcement

Policy-as-code and mTLS enforced at the mesh layer, not just checked at the edge and trusted after that.

Open Policy Agent cert-manager Istio Envoy

Supply chain security

Know what's actually in your build, and catch what's wrong with it before it ships, not after an audit asks.

SBOM Syft Grype CycloneDX OSV Semgrep SonarQube

CI/CD & infrastructure as code

Where policy actually gets enforced — in the pipeline, gating a merge, not in a document nobody rereads.

GitLab GitHub Terraform Kubernetes

Selected engagements

Work delivered across cloud, platform & engineering teams

A sample of past engagements, spanning technical leadership to consulting and engineering.

Connected Investors logo

DevOps / Engineering / CTO · US

Cronally logo

DevOps / Engineering · US

Turret.IO logo

DevOps / Engineering · US

Obelus Media logo

DevOps / Engineering · US

myfunctionroom logo

DevOps · Australia

Full Force Financial logo

Consulting / CTO · US

glassy logo

DevOps · Spain

KidMix logo

DevOps / Engineering · US

Task Science logo

DevOps / Engineering · US

Independent Ad Specialties logo

Engineering · US

AgQuote logo

Consulting / Project Management · Australia

The Shade logo

Consulting / Project Management · Australia

TellusLabs logo

DevOps / Engineering · US

ReTrans logo

DevOps · US

Environr logo

DevOps / Engineering · US

AnyRoom.io logo

DevOps / Engineering · US

Tend logo

Consulting · US

Dark Cubed logo

DevOps · US

Passio AI logo

Engineering · US

Hextrap logo

Hextrap

Platform Eng / AI Tooling · US

Expiring.at logo

Expiring.at

Platform Eng / AI Tooling · US

ASET Partners logo

Consulting · US

How we work

Fixed scope. Direct access. No relay.

// 01

Assess

Architecture, IAM, and pipeline review against real threat models — not a generic checklist. Fixed scope, written up front.

// 02

Build

Infrastructure as code, reviewed in the open. You get a direct line to the engineer doing the work — always.

// 03

Operate

We stay on for hosting, monitoring, and hardening as things evolve — billed simply through your Loop Science account.

Designed so the pager doesn't have to ring

The goal isn't faster incident response — it's systems that catch and correct their own failures before a human needs to. Loop Science builds on proven cloud-native resilience (redundancy, graceful degradation, auto-scaling, circuit breakers) and layers AI-driven anomaly detection and automated remediation on top, so a 3am page is the exception, not the operating model.

// autoremediate.yaml

on: alert.triggered

when:

severity: high

pattern: known_signature

actions:

- run: playbook/restart_pod

- run: playbook/scale_out

- escalate: if unresolved_after(10m)

Have infrastructure to build, fix, secure, or scale?

Existing client? Log in to your account. New engagement? Tell us about it and grab time on the calendar.