Timur Güvenkaya
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
For banks, exchanges, custodians, and protocol teams
You work directly with a principal who helps define the scope, brings in the right specialists, and stays involved through delivery.
Clients and ecosystems we have worked with.
Client feedback
“Timur is one of the most competent auditors, specialising in Rust-based smart contract environments. He has assisted several teams in the NEAR ecosystem over the past few years and it’s been a pleasure seeing him work with teams across many stages and domains.”
“We have been working with Timur Güvenkaya for years. One of the most qualified teams in space. If you're in crypto, your top priority should be making sure nobody looses money. Security is your job. If you want to do it well, you might want to reach out to Guvenkaya.”
“We worked with a few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than a one-off contract audit. They think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”
“Guvenkaya are The Auditors. Deep expertise in Rust and smart contracts combined with a hands-on, iterative approach makes them a go-to partner for serious projects. They don’t just look for bugs. They help to build robust systems from the ground up. We’ve trusted them with multiple audits across different stages and continue to rely on their judgment and precision.”
The team
Explore the team’s public profiles, experience, and published work.
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
Growth & Marketing Partner
Leads growth through performance marketing, data-led strategy, and audience planning. Her agency work spans healthcare and e-commerce brands across multiple markets.
Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Specialist Advisor
Head of Security at Gauntlet, with experience in product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.
Specialist Advisor
Security specialist with 60+ Web3 reviews across DeFi, L1s, bridges, oracles, and other critical infrastructure. At Kraken, worked on the security of funding services, custody, APIs, and on-chain systems.
Specialist Advisor
Cryptography engineer with a Ph.D. in Information Security and 13 published research articles. Worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada and wrote technical reports on threshold ECDSA.
Specialist Advisor
CEO at Inferara and designer of Inference, a language that combines executable code with formal specifications. Leads its Rust compiler development and previously built Code Inspector and security analysis tools at OpenZeppelin.
Specialist Advisor
Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.
Specialist Advisor
Security engineer and trainer with around 10 years of experience across application and protocol security. At ZKsync, reviewed Solidity and Rust code, including account abstraction, then built AI-assisted vulnerability-analysis workflows.
Team credentials
Public work
Full reports with findings, evidence, and remediation status.
NEAR Intents Security Review
Medium Potential Funds Stealing From Users Via Repeating Failed Intents
SWEAT NEP-141 Token Security Review
High LookupMap adapter can undercharge storage for selected accounts
Onchain Orderbook and Perpetual Trading Security Review
Critical Order Placement with Negative/Zero Margin Ratio Is Possible
Pallet Pass Security Review
High DoS of The Main Functionality Through Session Key Hijacking
Our approach
Your quote names the principal and specialists assigned to your engagement.
Your principal defines the scope with you, checks the findings, and stays involved through delivery.
Our team brings experience from exchanges, protocols, and security product companies. Our advisors also lead security teams at other companies.
We match your review team to what you are building. For a custody review, your team includes a custody specialist.
How an engagement runs
Once the scope is settled, we send a quote with the duration, the commit to be reviewed, and the names and bios of your review team. Every engagement has one principal and as many specialists as the scope needs.
You sign a master services agreement and a statement of work. Half the fee is due before the review starts, half when you receive the report. We then open a shared channel on your preferred platform, such as Slack or Telegram, for all communication with the team.
If the code is complex, we may ask your engineers for a call to walk us through it before the review starts.
On the first day, the team named in your quote maps attack paths, the invariants your system must hold, and its critical flows.
Specialists review the code by hand and run our own AI skills and test harnesses against it. The principal checks findings as they come in.
As we review, we add security tests and new invariants to your repository and record each check in an evidence bundle, so every finding can be traced back to what we ran.
We tell you about Critical, High, and Medium issues as soon as we find them, so you can start fixing before the review ends.
Specialists write the report, and the principal reviews it before it reaches you. It opens with a plain-language conclusion, then sets out every finding, the order to fix them in, and our assurance opinion on the reviewed commit.
Everything else goes into your repository. Tests for open findings fail on purpose and pass once the fix is in, so your team can track remediation by running the suite.
We help you plan and prioritize fixes. When they are in, we retest them at no charge and issue a public report that records each fix and carries the principal's signature. You can share it with your users and partners.
If the review points to other areas worth checking, we scope the next engagement with you. Teams that want us on hand for longer can move to a retainer or buy a block of days.
After the engagement ends, you can keep bringing us your security questions at no charge.*
* Within fair use: questions as they come up, not a daily queue.
What you receive
A report-only audit ends with a list of findings. Ours also adds security tests to your repository that your team can keep running after the engagement ends.*
| Deliverable | Guvenkaya | Report-only audit |
|---|---|---|
| Findings report | Yes | Yes |
| Threat model | Yes | No |
| Record of flows and security properties tested | Yes | No |
| Invariant register | Yes | No |
| Evidence appendix What we ran to reach each finding, so your team can check it. | Yes | No |
| Security tests in your repo Each test comes with docs on what it covers and how to run it. | Yes | No |
| Markdown copy of the report A plain-text version of the report that AI tools can parse. | Yes | No |
| Remediation skill for AI agents An optional skill that lets your AI agents recheck findings, verify fixes, and prioritize work. | Yes | No |
| Signed public report after retest Records each fix and carries the principal's signature. Yours to share. | Yes | No |
* These deliverables apply to code security reviews. For other engagements, we agree on deliverables when defining the scope.
Services
Describe your system or the change you are planning. We'll help define the scope.
Find flaws in contract logic, permissions, accounting, and upgrades before they put funds at risk.
ExploreReview custom chains, runtimes, nodes, consensus, and bridges beneath the application layer.
ExploreTest the attack paths that connect web, mobile, APIs, cloud, identity, and infrastructure.
ExploreReview key generation, signing approvals, key use, and recovery across MPC, HSM, multisig, and custody platforms.
ExploreFind security flaws in critical code, including authorization, business logic, and state changes.
ExploreDesign or assess critical systems, workflows, integrations, and operating controls before implementation or a major change.
ExploreReview ZK circuits, custom primitives, signature schemes, privacy protocols, and post-quantum designs before you build on them.
ExploreReview models, data, tools, memory, identity, permissions, approval gates, and high-impact actions.
ExploreGive leadership a prioritized view of where security risk concentrates and what to address first.
ExploreMake security, custody, vendor, and operating-model decisions across a broader digital asset program.
ExploreEvaluate the security and technical risks behind an investment, acquisition, partnership, grant, or vendor decision.
ExploreChoose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.
ExploreTell us your main concern and we’ll help you choose a starting point.
Training
Choose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.
Discuss trainingSolutions
Banks, asset managers, fintechs, payment firms, and financial infrastructure providers.
Exchanges, custodians, wallets, stablecoin operators, and asset platforms.
L1 and L2 systems, ecosystems, bridges, DeFi protocols, and on-chain products.
Web, mobile, cloud, backend, AI, and other critical software systems.
Describe your system, main concern, and deadline. We'll reply with scoping questions and a proposed next step.
Discuss your scope