Built onPrinciple
Spleet Inc is an engineering firm, not a consulting house. We do the work. We don't resell it, repackage it, or staff it out.
How we think
Precision Over Throughput
We take on fewer engagements to give each one the rigour it deserves. Our senior practitioners are on every job — not delegated to junior staff once the contract is signed.
Evidence-Driven Everything
Every finding ships with a reproducible proof of concept. Every recommendation includes a cost/risk trade-off. We do not report theoretical issues without demonstration.
Transparency as a Default
Clients receive working access to our tooling output, raw scanner logs, and the exact commands we ran. No black boxes. No mystery methodology.
Continuous Technical Investment
Our team publishes CVEs, contributes to open-source security tooling, and maintains research programs across DeFi, cloud infrastructure, and distributed systems. We stay at the edge.
How we operate
Non-negotiable standards applied consistently across every engagement, regardless of size or budget.
Scoping Discipline
Every engagement is defined by a signed Statement of Work with explicit scope boundaries, success criteria, and out-of-scope declarations before a single keystroke of work begins.
Data Handling Protocol
Client data and findings are encrypted at rest and in transit, stored on isolated engagement infrastructure, and destroyed on a defined schedule post-delivery. NDA is standard on all engagements.
Report Standards
All deliverables follow a defined format: executive summary, technical findings (severity-ranked by CVSS v3.1), remediation roadmap with effort estimates, and a mandatory retest credit for critical findings.
Team Continuity
The same engineers who scope the engagement execute it and author the report. No bait-and-switch staffing. The practitioner you meet in the kickoff call is the one delivering findings.
SLA Commitments
Draft reports delivered within the agreed window, no exceptions. If scope creep is discovered mid-engagement, we surface it immediately with options — we never silently overrun.
Retest Policy
All critical and high-severity findings include a complimentary retest within 90 days of remediation. We verify the fix actually works — not just that the code changed.
Standards we build on
We align every engagement to industry-recognised frameworks. Not because clients require it — because it makes our work better.
Web Application Security Testing Guide (WSTG), Smart Contract Security Verification Standard (SCSVS), API Security Top 10.
Cybersecurity Framework used for risk assessment structure, control mapping, and executive reporting.
Penetration Testing Execution Standard governs our offensive engagement methodology from pre-engagement to post-exploitation reporting.
Smart Contract Weakness Classification used as the canonical taxonomy for all on-chain vulnerability findings.
Center for Internet Security hardening benchmarks applied to all cloud and infrastructure configuration reviews.
Common Vulnerability Scoring System used to severity-rank every finding with a reproducible, objective score.
Senior practitioners only
Engineering Leadership
Former staff engineers from Tier-1 protocol teams and financial infrastructure. Deep in distributed systems, smart contract runtimes, and adversarial ML.
Security Research
CVE-publishing offensive security practitioners with backgrounds in red teaming Fortune 500 infrastructure and auditing high-value DeFi protocols.
Automation & Platform
Infrastructure engineers who have built and operated delivery platforms at scale. Authors of open-source Terraform modules with tens of thousands of downloads.
Aligned with our standards?
We work best with organisations that value depth over speed, and correctness over checkboxes. If that's you, let's talk.