Overview

Security Engineering, Built by Practitioners

SiegePal is a cybersecurity and AI engineering company based in San Diego, California, founded in 2024. The team works across two connected disciplines: securing cloud infrastructure and identity systems, and building production AI applications.

In practice, that means writing code and configuring infrastructure directly, not only producing recommendations.

Cloud security infrastructure and AI application systems connected through a shared engineering architecture

Company

Overview

SiegePal works across two connected areas: cybersecurity engineering and AI engineering. Cybersecurity engineering focuses on securing systems that already exist. That includes cloud accounts, identity providers, encryption pipelines, and the software running on top of them. AI engineering focuses on building new AI-driven functionality, from generative AI features to automation agents that plug into existing products.

The two practices share a common approach. Problems are diagnosed by looking directly at configurations, code, and running infrastructure, not only at documentation. Where needed, SiegePal can also implement the fix directly, in addition to identifying it.

This does not mean every engagement includes implementation. Some clients want an independent assessment. Others need architecture design, and some need remediation carried out directly.

Multi-cloud infrastructure connected through identity federation, encryption, and key management layers

Practice

Cybersecurity Engineering

The cybersecurity practice centers on identity, encryption, and cloud infrastructure. On the identity side, work has included federated authentication across SAML and OIDC. It has also included automated user provisioning through SCIM and multi-protocol authentication, including JWT and Kerberos.

Cryptographic engineering is a distinct strength. The team has implemented TLS encryption and PKI lifecycle management in production systems. Key management work has supported AWS KMS, Azure Key Vault, and Google Cloud KMS. This work has extended into FIPS 140-2 controls for regulated environments.

The practice also covers cloud security across AWS, Azure, and Google Cloud. It includes vulnerability management integrated into CI/CD pipelines. Compliance engineering spans frameworks such as HIPAA, SOC 2, and FedRAMP. Compliance work is verified against live infrastructure rather than documentation alone.

Practice

AI Engineering

AI engineering is a distinct capability at SiegePal, demonstrated through delivered client projects. Projects have included generative AI systems built on large language models. Structured output has been used to generate reliable, schema-compliant results rather than free text.

The team has designed custom MCP servers to connect AI systems with external tools. It has also built self-hosted speech-to-text capability using OpenAI Whisper. Other delivered work includes computer vision systems and AI-powered image manipulation features deployed in production e-commerce and cloud platforms.

Separately, SiegePal is developing its own AI-driven cybersecurity platform. The platform is designed to orchestrate multiple specialized security agents across cloud and vulnerability management tasks. This platform is under active development. It is not yet a completed client product, and current AI engineering experience comes from separate delivered projects.

Production AI system connecting model orchestration, agents, structured outputs, speech, vision, and cloud tools

Approach

Engineering-First Approach

Engineering-first means the practice can operate at more than one stage of a security or AI problem. Depending on the engagement, that might mean an assessment, an architecture design, an implementation, or remediation.

Some clients bring in SiegePal purely to evaluate an existing environment. Others need code written, infrastructure configured, or a vulnerability fixed directly. The scope is set by what the client actually needs, not by a fixed methodology applied to every project.

What stays consistent is the ability to move from finding a problem to fixing it. That happens when fixing it is part of the engagement a client has chosen.

Experience

Experience That Shapes Our Work

SiegePal's cybersecurity work included a FedRAMP and PCI-DSS gap assessment for an enterprise cloud analytics platform. The assessment was verified against live infrastructure, not documentation alone. Related work on the same platform built a centralized identity federation service using SAML 2.0, OIDC, and SCIM provisioning. It also included encryption and key management infrastructure across multiple cloud key management systems.

Separately, the team completed a WaTech compliance audit for Aiperion, a government-facing AI platform. The audit was completed ahead of its rollout to a Washington State agency. It also completed a SOC 2 Type II gap assessment for a technology-focused family office.

On the AI side, delivered projects include Aiperion's generative AI engine, migrated to a custom MCP server architecture. Another is Shic AI, an e-commerce platform with AI-powered image generation and editing features running in production. These engagements are documented in more detail in the Security Portfolio and AI Portfolio.

Clients

Who We Work With

SiegePal is relevant wherever a cloud or security architecture problem needs direct engineering attention. That includes identity and access management, cryptographic engineering, and vulnerability remediation, along with DevSecOps gaps that surface during active development.

Compliance requirements are a common driver. Organizations preparing for HIPAA, SOC 2, or FedRAMP often need a gap assessment. Many also need the engineering work to close it.

AI-related work follows a similar pattern. Companies building AI-enabled products may need AI security review alongside AI implementation.

The common factor is not company size or industry. SiegePal is relevant when organizations need practical technical expertise to address a defined cybersecurity or AI engineering problem. That has included both smaller technology companies and enterprise environments.

Engagements

How We Engage

Engagements are typically structured as fixed-scope projects, such as a HIPAA, SOC 2, or FedRAMP gap assessment. Larger efforts, including FedRAMP assessment work, are usually structured as milestone-based deliverables instead.

From an assessment, some clients move directly into remediation support, addressing findings as part of the same engagement. Others maintain longer-term engineering support for cloud, identity, or cryptographic work.

Incident response support is also available for organizations that need specialist assistance.

Explore SiegePal

This page is meant as a starting point, not the full picture. The Services pages describe each engagement type in more detail. The Security Portfolio and AI Portfolio pages document specific work in cybersecurity and AI engineering.

For a specific requirement, the most direct next step is a conversation. A short call is usually enough to determine whether SiegePal is the right fit. It also clarifies what an engagement would actually involve.

Schedule a Consultation