Timur Güvenkaya
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
For banks, exchanges, custodians, and protocol teams
You work directly with a principal who helps define the scope, brings in the right specialists, and stays involved through delivery.
Clients and ecosystems we have worked with.
Client feedback
“Timur is one of the most competent auditors, specialising in Rust-based smart contract environments. He has assisted several teams in the NEAR ecosystem over the past few years and it’s been a pleasure seeing him work with teams across many stages and domains.”
“We worked with a few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than a one-off contract audit. They think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”
“Guvenkaya are The Auditors. Deep expertise in Rust and smart contracts combined with a hands-on, iterative approach makes them a go-to partner for serious projects. They don’t just look for bugs. They help to build robust systems from the ground up. We’ve trusted them with multiple audits across different stages and continue to rely on their judgment and precision.”
The team
Explore the team’s public profiles, experience, and published work.
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
Growth & Marketing Partner
Leads growth through performance marketing, data-led strategy, and audience planning. Her agency work spans healthcare and e-commerce brands across multiple markets.
Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Specialist Advisor
Head of Security at Gauntlet, with experience in product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.
Specialist Advisor
Security specialist with 60+ Web3 reviews across DeFi, L1s, bridges, oracles, and other critical infrastructure. At Kraken, worked on the security of funding services, custody, APIs, and on-chain systems.
Specialist Advisor
Cryptography engineer with a Ph.D. in Information Security and 13 published research articles. Worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada and wrote technical reports on threshold ECDSA.
Specialist Advisor
CEO at Inferara and designer of Inference, a language that combines executable code with formal specifications. Leads its Rust compiler development and previously built Code Inspector and security analysis tools at OpenZeppelin.
Specialist Advisor
Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.
Specialist Advisor
Security engineer and trainer with around 10 years of experience across application and protocol security. At ZKsync, reviewed Solidity and Rust code, including account abstraction, then built AI-assisted vulnerability-analysis workflows.
Team credentials
Public work
Full reports with findings, evidence, and remediation status.
NEAR Intents Security Review
Medium Potential Funds Stealing From Users Via Repeating Failed Intents
SWEAT NEP-141 Token Security Review
High LookupMap adapter can undercharge storage for selected accounts
Onchain Orderbook and Perpetual Trading Security Review
Critical Order Placement with Negative/Zero Margin Ratio Is Possible
Pallet Pass Security Review
High DoS of The Main Functionality Through Session Key Hijacking
Our approach
Your proposal names the principal and specialists assigned to your engagement.
Your principal defines the scope with you, checks the findings, and stays involved through delivery.
Our team brings experience from exchanges, protocols, and security product companies. Our advisors also lead security teams at other companies.
We match your review team to what you are building. For a custody review, your team includes a custody specialist.
| Stage | Principal | Specialists |
|---|---|---|
| Scope | | |
| Review | | |
| Report | | |
| Quality assurance | | |
| Remediation | | |
| Retest | | |
Your specialists write the report, and your principal reviews it before you receive it. We then provide remediation guidance and retest the fixes.
What you receive
A documented threat model and security tests your team can rerun as the code changes.
| Deliverable | Guvenkaya | Report-only audit |
|---|---|---|
| Findings report | Yes | Yes |
| Threat model | Yes | No |
| Record of flows and security properties tested | Yes | No |
| Invariant register | Yes | No |
| Security tests in your repo | Yes | No |
| Signed opinion on a reviewed commit | Yes | No |
* These deliverables apply to code security reviews. For other engagements, we agree on deliverables when defining the scope.
Services
Describe your system or the change you are planning. We'll help define the scope.
Find flaws in contract logic, permissions, accounting, and upgrades before they put funds at risk.
ExploreReview custom chains, runtimes, nodes, consensus, and bridges beneath the application layer.
ExploreTest the attack paths that connect web, mobile, APIs, cloud, identity, and infrastructure.
ExploreReview key generation, signing approvals, key use, and recovery across MPC, HSM, multisig, and custody platforms.
ExploreFind security flaws in critical code, including authorization, business logic, and state changes.
ExploreDesign or assess critical systems, workflows, integrations, and operating controls before implementation or a major change.
ExploreReview ZK circuits, custom primitives, signature schemes, privacy protocols, and post-quantum designs before you build on them.
ExploreReview models, data, tools, memory, identity, permissions, approval gates, and high-impact actions.
ExploreGive leadership a prioritized view of where security risk concentrates and what to address first.
ExploreMake security, custody, vendor, and operating-model decisions across a broader digital asset program.
ExploreEvaluate the security and technical risks behind an investment, acquisition, partnership, grant, or vendor decision.
ExploreChoose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.
ExploreTell us your main concern and we’ll help you choose a starting point.
Training
Choose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.
Discuss trainingSolutions
Banks, asset managers, fintechs, payment firms, and financial infrastructure providers.
Exchanges, custodians, wallets, stablecoin operators, and asset platforms.
L1 and L2 systems, ecosystems, bridges, DeFi protocols, and on-chain products.
Web, mobile, cloud, backend, AI, and other critical software systems.
Describe your system, main concern, and deadline. We'll reply with scoping questions and a proposed next step.
Discuss your scope