Independent engineering firm

Software that holds up in production.

We run security assessments, build websites and full-stack apps, and develop multiplayer games. We can also host, monitor, and patch what we ship. You work directly with the engineer.

What we build, secure, and run.

Four practices, one standard: code another engineer can read, and systems you can audit. Bring us in for one, or all four.

  1. Cybersecurity

    Applications, APIs, and cloud infrastructure, tested and hardened.

    We test applications, APIs, and cloud configurations the way an attacker would, authenticated and unauthenticated, strictly within a scope you authorize in writing. Each finding comes with a severity rating, reproduction steps, and a specific fix, which we can implement and retest.

    • Web app and API penetration testing
    • Secure code review
    • Authentication and access-control review
    • Cloud, Linux, and container hardening
    • Dependency and supply-chain audits
    • Remediation and retesting

    Languages and platforms

    • TypeScript
    • Node.js
    • Go
    • Rust
    • Python
    • Linux
    • Docker
    • Cloudflare
    • Amazon EC2
  2. Websites

    Fast, accessible company sites and storefronts, built and maintained.

    We build company sites as fast static pages with Astro, and storefronts as Next.js apps on PostgreSQL with Stripe checkout. We cover critical flows with Playwright end-to-end tests, and after launch we can host, monitor, and maintain the site.

    • Static company and marketing sites
    • Next.js storefronts with Stripe checkout
    • Core Web Vitals tuning
    • Accessibility testing with axe
    • Technical SEO and structured data
    • Hosting, monitoring, and maintenance

    Stack

    • Astro
    • Next.js
    • React
    • Vue
    • TypeScript
    • PostgreSQL
    • Stripe
    • Playwright
    • axe
    • Cloudflare
  3. Full-stack development

    Web apps, APIs, and real-time systems, typed from database to UI.

    We build web applications, APIs, and backend services in TypeScript on Node.js, backed by PostgreSQL, with Go or Rust where performance calls for it. Inputs are validated at every boundary, schema changes ship as versioned migrations, and critical flows have end-to-end tests.

    • Web applications and internal tools
    • API design with validated input
    • PostgreSQL schema design and migrations
    • Payments and third-party integrations
    • Real-time sync and web push
    • Passkey (WebAuthn) sign-in

    Stack

    • TypeScript
    • Node.js
    • React
    • Next.js
    • PostgreSQL
    • Prisma
    • Zod
    • Go
    • Rust
    • Python
    • Docker
    • Amazon EC2
  4. Game development

    Multiplayer games, built from scratch or alongside your team.

    We build games and work on existing ones, with a focus on multiplayer: server-authoritative gameplay, replication, persistent player data, and exploit-resistant in-game economies. We also build the backend services and website around a game, ship its live updates, and can host and run what we build.

    • Multiplayer gameplay systems
    • Networking and replication
    • Player data persistence
    • In-game economies and exploit hardening
    • Live updates and live ops
    • Game backends and websites

    Engines we support

    • Unity
    • Unreal Engine
    • Godot Engine
    • Roblox

Engagements

What we're building and running for clients today, across web, games, and security. Client names are withheld for confidentiality.

  1. Ongoing

    Web services

    Storefronts and websites

    We build and maintain an e-commerce storefront, a Next.js app on PostgreSQL with Stripe checkout and passkey sign-in, and the website for a multiplayer game.

    • Next.js storefront
    • Stripe checkout
    • Passkey sign-in
    • Game website
  2. Ongoing

    Games

    Multiplayer game development

    We develop two multiplayer games: gameplay systems, new features, and the live updates that keep them current for players.

    • Gameplay systems
    • New features
    • Live updates
    • Ongoing development
  3. Ongoing

    Cybersecurity

    Securing client systems

    We help secure the systems behind these engagements: secure code review, dependency audits, and hardening of access and infrastructure.

    • Secure code review
    • Dependency audits
    • Access hardening
    • Infrastructure hardening
    What our security reviews cover

How we work

  1. Security from the start

    We write a threat model and set up least-privilege access before the first feature ships. Code review and dependency audits run throughout development, so problems surface while they're cheap to fix.

  2. Talk to the engineer

    There are no account managers or handoffs between sales and delivery. The person who answers your email is the person doing the work.

  3. Plain, maintainable code

    We pick proven tools and simple patterns over novelty, with strict types, validated inputs, and tests on critical paths. The goal is code that stays easy to read and safe to change.

  4. We can host what we build

    The engineer who wrote the code handles deployment, monitoring, updates, backups, and security patching. Services we host run in Docker on Linux, behind Caddy and Cloudflare.

Tell us what you're building.

Send a few lines: what you need, rough timing, and a budget range if you have one. Links to an existing site, repository, or game build help.

Please don't email passwords, keys, or other secrets. If we need access, we'll set up a secure way to share it. To report a vulnerability in our own systems, write to security@plentex.app.