“Timur is one of the most competent auditors, specialising in Rust-based smart contract environments. He has assisted several teams in the NEAR ecosystem over the past few years and it’s been a pleasure seeing him work with teams across many stages and domains.”
@chronearHead of Ecosystem Strategy, NEAR Foundation
“We worked with few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than one-off contract audit, they think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”
Oleg FomenkoCo-Founder and CEO at Sweat Economy
“Guvenkaya are The Auditors. Deep expertise in Rust and smart contracts combined with hands-on, iterative approach make them a go-to partner for serious projects. They don’t just look for bugs, they help to build robust systems from the ground up. We’ve trusted them with multiple audits across different stages, and continue to rely on their judgment and precision.”
Arseny MitinProtocol Tech Lead, Aurora, NEAR Protocol
The team
Meet the people who will actually do the work.
Every specialist on your engagement is named in the proposal, with a LinkedIn you can check and published reports you can read.
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
Leads growth through performance marketing, data-led strategy, and audience planning. Agency experience with major healthcare and e-commerce brands across different markets.
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Head of Security at Gauntlet, with depth across product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.
Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.
Offensive security specialist with 10+ years and 100+ public audits across eight ecosystems. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.
Security engineer and trainer with around 10 years across application and protocol security. At ZKsync, reviewed Solidity, account abstraction, and Rust, then built AI-assisted vulnerability-analysis workflows.
A principal scopes the work, QAs the findings, and stays reachable for the whole engagement.
Practitioners, not consultants
2 of the team are Heads of Security at other companies today. Others came from exchanges, protocols, and security product companies.
Matched to the system
A custody review gets the custody specialist. The named team changes with what you are building.
What an engagement looks like
Six engagement stages: scope, review, report, QA, remediation, retest. The principal leads scoping, QA and remediation, and assists during review, reporting and retest. Specialists lead the review and write the report, which the principal QAs before it reaches you, and they lead remediation and retest.
Stage
Principal
Specialists
Scope
Leads the stage
Assists
Review
Assists
Leads the stage
Report
Assists
Leads the stage
QA
Leads the stage
Assists
Remediation
Leads the stage
Leads the stage
Retest
Assists
Leads the stage
Leads the stage
Assists
One principal, plus the specialists the system needs. Specialists write the report; the
principal QAs it before it reaches you.
Highlighted findings from published reports, not the reports themselves. Each card opens the
full report it came from, where every finding and its severity is listed.
Share the system, repository, architecture, target date, and your main concerns. We will
reply with the next questions, a likely scope, and the engineers who would join the first
call.