For banks, exchanges, custodians, and protocol teams

Principal-led security for digital assets and financial infrastructure.

Six senior specialists you can look up before you sign. A principal on the work from scope to fix.

$24B+ volume secured
24M+ users protected
65+ critical & high findings
0 anonymous reviewers 6 named senior specialists

Client feedback

What clients say about the work.

“Timur is one of the most competent auditors, specialising in Rust-based smart contract environments. He has assisted several teams in the NEAR ecosystem over the past few years and it’s been a pleasure seeing him work with teams across many stages and domains.”
@chronear Head of Ecosystem Strategy, NEAR Foundation
“We worked with few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than one-off contract audit, they think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”
Oleg Fomenko Co-Founder and CEO at Sweat Economy
“Guvenkaya are The Auditors. Deep expertise in Rust and smart contracts combined with hands-on, iterative approach make them a go-to partner for serious projects. They don’t just look for bugs, they help to build robust systems from the ground up. We’ve trusted them with multiple audits across different stages, and continue to rely on their judgment and precision.”
Arseny Mitin Protocol Tech Lead, Aurora, NEAR Protocol

The team

Meet the people who will actually do the work.

Every specialist on your engagement is named in the proposal, with a LinkedIn you can check and published reports you can read.

200+ audits between them
2 Heads of Security on the advisory team
1 principal on every engagement

OSCP · OSWE · CREST CRT · CISM · AWS Security · CVE disclosures · U.S. patents

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

  • Rust
  • NEAR & Substrate
  • Custody
Müjde Nur Asgarli Güvenkaya portrait

Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

Leads growth through performance marketing, data-led strategy, and audience planning. Agency experience with major healthcare and e-commerce brands across different markets.

  • MBA
  • Performance marketing
  • Growth strategy
Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Currently

Head of Security, Agora

$45B+ in volume

  • OSCP
  • OSWE
  • U.S. patents
Paul Vijender portrait

Paul Vijender

Specialist Advisor

Head of Security at Gauntlet, with depth across product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.

Currently

Head of Security, Gauntlet

$1.6B+ TVL

  • CISM
  • Cloud & IAM
  • DevSecOps
Michal Bajor portrait

Michal Bajor

Specialist Advisor

Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

  • Exchange & custody
  • 60+ reviews
  • 3 research papers
Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Offensive security specialist with 10+ years and 100+ public audits across eight ecosystems. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

  • 100+ audits
  • 8+ ecosystems
  • CVE disclosures
José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

Security engineer and trainer with around 10 years across application and protocol security. At ZKsync, reviewed Solidity, account abstraction, and Rust, then built AI-assisted vulnerability-analysis workflows.

  • OSCP
  • CREST CRT
  • AWS Security

Named before you sign. Not after.

You scope it with an engineer

A principal scopes the work, QAs the findings, and stays reachable for the whole engagement.

Practitioners, not consultants

2 of the team are Heads of Security at other companies today. Others came from exchanges, protocols, and security product companies.

Matched to the system

A custody review gets the custody specialist. The named team changes with what you are building.

Public work

Read the findings before you hire us.

Full reports, not summaries. Most contain critical or high severity findings.

Protocol Public report

NEAR / Defuse Labs

NEAR Intents Security Review

Selected public finding Medium

Potential Funds Stealing From Users Via Repeating Failed Intents

  • NEAR
  • Intents
  • Protocol
View report ↗
Smart contract Public report

Sweat Economy

SWEAT NEP-141 Token Security Review

Selected public finding High

LookupMap adapter can undercharge storage for selected accounts

  • NEAR
  • Smart contract
  • Rust
View report ↗
Smart contract Public report

Spin Finance

Onchain Orderbook and Perpetual Trading Security Review

Selected public finding Critical

Order Placement with Negative/Zero Margin Ratio Is Possible

  • NEAR
  • Smart contract
  • Rust
View report ↗
Smart contract Public report

Cleopetra

Solana Trading Bot Security Review

Selected public finding Medium

Incorrect Use of Async in Reward Distribution

  • Solana
  • Smart contract
  • TypeScript
View report ↗
Smart contract Public report

Sailor Lend

NEAR Smart Contract Security Review

Selected public finding Critical

Race Condition in Borrow Functionality

  • NEAR
  • Smart contract
  • Rust
View report ↗
Substrate pallet Public report

Virto Network

Pallet Pass Security Review

Selected public finding High

DoS of The Main Functionality Through Session Key Hijacking

  • Polkadot
  • Substrate pallet
  • Rust
View report ↗
All reports →

Services

Start with what you need to secure.

Show us the code, system, workflow, or planned change. We will recommend the right review, test, or design work.

Not sure which one fits?

Send the repo or the architecture and we will tell you.

Ask us what to scope

Find the right starting point for your organization.

Financial Institutions

Banks, asset managers, fintechs, payment firms, and financial infrastructure.

Digital Asset Operators

Exchanges, custodians, wallets, stablecoin operators, and asset platforms.

Protocols & Networks

L1 and L2 systems, ecosystems, bridges, DeFi protocols, and onchain products.

Software & Infrastructure Teams

Web, mobile, cloud, backend, AI, and other critical software systems.

Contact

Tell us what you need to secure.

Share the system, repository, architecture, target date, and your main concerns. We will reply with the next questions, a likely scope, and the engineers who would join the first call.