Reid MorrisonEOL Remediation

Your Rails version is an audit finding. We close it at a fixed price.

Reid Morrison Inc. upgrades production applications off end-of-life software and hands them back on a supported version, in weeks rather than quarters. Rails and Ruby first. The same fixed-price model fits any upgrade, migration or maintenance backlog with a compliance date attached.

Rails 7.2 stopped receiving security patches on 9 August 2026. Rails 8.0 follows on 7 November 2026, and after that Rails 8.1 is the only series still receiving them. Ruby 3.2 went end of life on 1 April 2026.

If you are assessed against PCI DSS, SOC 2, HIPAA or ISO 27001, that is not a preference about upgrades. It is a control with a number attached, and an assessor who will ask you about it.

The trap most teams find halfway through

Old Rails versions impose a maximum Ruby version, not just a minimum. Rails 6.0 caps at Ruby below 3.0. Rails 5.2 caps at below 2.7. Every supported Rails release requires Ruby 3.2 or later.

So a company on Rails 6.0 or earlier cannot upgrade Ruby without first upgrading Rails, and cannot upgrade Rails without first upgrading Ruby. No single upgrade resolves it, and the gap widens on both axes at once. Teams routinely scope one axis, start work, and discover the other.

See the exact path your versions force, including the days each has gone unpatched and the controls it implicates.

Three ways to answer the finding

Costs nothing now

Leave it

The finding stays open and the days unpatched keep climbing. Under HIPAA, documented awareness without action is what moves an incident toward willful neglect, and the penalty tiers scale by culpability.

Recurring

Buy extended support

A third party backports patches to your unsupported version for an annual fee. The bill recurs for as long as you stay, and the framework is still not receiving vendor fixes, so the control language still applies.

Ends the finding

Get current

Move onto a supported version and the condition that created the finding is gone. Historically expensive and slow, which is the actual reason it keeps getting deferred. That is the part we have changed.

Start with the assessment

PCI DSS 12.3.4 requires a remediation plan approved by senior management for any component no longer receiving vendor security fixes. Most teams do not have that document. It is the first thing we produce.

$12,500 Fixed · Two weeks

The Remediation Assessment. Component inventory, the 12.3.4 remediation plan itself, the upgrade path across both Ruby and Rails, and fixed prices for each phase that follows.

If the assessment concludes you should not do this work, or should not do it with us, you pay nothing.

Remediation is quoted from the assessment findings. Every codebase is different, and anyone quoting an upgrade without reading your Gemfile.lock is guessing.

How an engagement works, and what the assessment contains

Why one engineer, and why this one

Twenty years building systems where being wrong was expensive: a real-time credit bureau at 99.99% availability, healthcare, payments, and an event-driven platform on Elixir and Kafka. Reid Morrison does that work himself. You are not being sold a principal engineer and handed a junior.

He maintains 11 open-source Ruby libraries with over 79 million combined downloads, and shipped new versions of four of them in July 2026 using agentic workflows. Those diffs are public. You can audit how he works, at what increment size and in what order, before you hire anyone. See the libraries.

The failure mode with AI tooling on a production upgrade is not that it is too slow. It is that it is too fast. The value is knowing which step happens first and how little to change in any one iteration, and that comes from having done this before on systems where a bad deploy had consequences.

Where the work happens is your choice, and there are three postures: our own managed machine, your Anthropic tenancy, or a virtual desktop you supply, on which your source code is never downloaded at all. Whichever applies goes into the agreement rather than being promised in a meeting. How we work with your code.

Who this is for

Mid-market companies in a regulated scope, weighted toward SaaS, healthcare, insurance and payments, running business-critical Rails applications on unsupported versions, with something forcing the timeline: an audit date, an enterprise deal blocked on a security review, a penetration test finding, or a specific unpatched CVE.