About

The people behind Guvenkaya.

Discuss your scope

Every specialist on your engagement is named in the proposal, with public work you can read before you sign. We review custody and key management, blockchain systems, and the applications and infrastructure built around them.

Founded

2022

Origin

Timur Güvenkaya founded Guvenkaya in 2022. Previously, he established and led a security engineering practice for complex blockchain systems. Earlier at Invicti, he helped build vulnerability-detection engines used by Fortune 50 companies and public-sector organizations. Today, Guvenkaya reviews the code, architecture, and operations that control digital assets.

Why Guvenkaya?

How we work with you.

You work directly with a principal

Your principal defines the scope with you, leads communication, and reviews the report before delivery.

You get the expertise your review needs

We choose specialists for the systems under review. For a custody review, your team includes a custody specialist.

You see risks beyond the code

We examine your architecture, infrastructure, and release process to explain how weaknesses can put funds and operations at risk.

You work with experienced security leaders

Our advisors lead security teams at other companies and bring experience from Kraken, Binance, OpenZeppelin, ZKsync, Gauntlet, Tensor, Nillion, and Invicti.

Team

Our leadership & advisory team

Explore the team’s public profiles, published work, and experience.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Timur founded Guvenkaya after seeing teams reduce security to code review while their real risk spans architecture, infrastructure, operations, custody, and launch decisions. Before Guvenkaya, he established and led a security engineering practice for complex blockchain systems, specializing in Rust-based and non-EVM ecosystems including Substrate and NEAR. Earlier at Invicti, he helped build enterprise vulnerability-scanning and security detection engines used by Fortune 50 companies and public-sector organizations.
LinkedIn
Müjde Nur Asgarli Güvenkaya portrait

Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

Leads growth through performance marketing, data-led strategy, and audience planning. Her agency work spans healthcare and e-commerce brands across multiple markets.

Müjde Nur Asgarli Güvenkaya portrait

Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

Müjde leads growth and marketing, bringing hands-on agency experience in performance marketing, data-led strategy, and audience-specific campaign planning. On the agency side she has worked with major brands across healthcare, e-commerce, and other sectors, translating business goals into focused growth strategies for different markets and audiences. She holds a Bachelor's degree in International Affairs and a Master's in Business Administration.
LinkedIn
Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Piotr is Head of Security at Agora, where he oversees information security, data protection, and corporate IT risk management. He brings both industry and consulting experience, having led information security advisory engagements and security program development for global financial institutions and large organizations. Earlier in his career, Piotr was a Senior Cybersecurity Consultant at Ernst & Young (EY), leading security assessments across financial services, healthcare, and government. He holds CEH, OSCP, and OSWE certifications, has contributed to the CVE program, and is the inventor of multiple U.S. patents related to information security and blockchain technology.
LinkedIn
Paul Vijender portrait

Paul Vijender

Specialist Advisor

Head of Security at Gauntlet, with experience in product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.

Paul Vijender portrait

Paul Vijender

Specialist Advisor

Paul is Head of Security at Gauntlet, a hands-on security leader experienced in building and operating security teams for digital asset systems. His experience spans product security, identity and access management, cloud and network security, data loss prevention, DevSecOps, blockchain security, and compliance. He has advised and delivered engagements for Fortune 500 firms, big-tech companies, and frontier-technology startups across crypto and AI. Earlier he was Head of Security at Tensor and a Senior Cybersecurity Manager at EY, and held security roles at Broadcom and ADP. He holds the CISM certification.
LinkedIn
Michal Bajor portrait

Michal Bajor

Specialist Advisor

Security specialist with 60+ Web3 reviews across DeFi, L1s, bridges, oracles, and other critical infrastructure. At Kraken, worked on the security of funding services, custody, APIs, and on-chain systems.

Michal Bajor portrait

Michal Bajor

Specialist Advisor

Michal is a security expert with a Master's in ICT, three published research papers, and active academic research in blockchain technology. He has reviewed 60+ Web3 projects across DeFi, L1 systems, bridges, oracles, and other critical ecosystem components. At Kraken, he was responsible for security across crypto and fiat funding services, custody, B2B APIs, on-chain monitoring, smart-contract risk, and architectural and compliance reviews. Earlier at EY, he conducted web application penetration tests, participated in red-team activities, and worked across defensive security responsibilities; at Cisco, he supported Security Advisory penetration-testing work and internal cybersecurity training.
LinkedIn
Manuel B. Santos portrait

Manuel B. Santos

Specialist Advisor

Cryptography engineer with a Ph.D. in Information Security and 13 published research articles. Worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada and wrote technical reports on threshold ECDSA.

Manuel B. Santos portrait

Manuel B. Santos

Specialist Advisor

Manuel is a cryptography engineer doing applied research in post-quantum cryptography, secure multiparty computation, and zkTLS. He holds a Ph.D. in Information Security from Instituto Superior Técnico, University of Lisbon, and an M.Sc. in Applied Mathematics from Imperial College London, with 13 published research articles across quantum oblivious transfer, privacy-preserving computation, and post-quantum blockchain design. He worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada, a language for secure multiparty computation, and authored technical reports on threshold ECDSA. Earlier he was a Quantum Cryptography Researcher at Tekever.
LinkedIn
Georgii Plotnikov portrait

Georgii Plotnikov

Specialist Advisor

CEO at Inferara and designer of Inference, a language that combines executable code with formal specifications. Leads its Rust compiler development and previously built Code Inspector and security analysis tools at OpenZeppelin.

Georgii Plotnikov portrait

Georgii Plotnikov

Specialist Advisor

Georgii is CEO at Inferara and the designer of Inference, a statically typed, high-assurance language built so executable programs and formal specifications can live in the same source. The language uses a deterministic, WebAssembly-aligned execution model with verification-only specification blocks. He led the Rust implementation of the infc compiler, which produces optimized WebAssembly for execution and Rocq theorem obligations for formal verification. He also leads development of a Stellar smart-contract decompiler. Previously, as Lead Security Tooling Developer at OpenZeppelin, he designed and implemented the foundation of Code Inspector, the Defender code-analysis module, shipping GitHub-integrated analysis that grew beyond 130 static-analysis rules. His work spans reentrancy and unsafe-call detection, vulnerable-dependency and standards checks, contract fingerprinting, fuzz-target identification, and LLM-driven vulnerability analysis, with static-analysis tools in Python and Rust for Solidity, Rust-based DSLs, and Midnight Compact.
LinkedIn
Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Łukasz is a security researcher with 10+ years in offensive security and a public portfolio of 100+ audits across 8+ ecosystems. His smart-contract work spans EVM/Solidity, Move, Rust-based ecosystems, CosmWasm, Solana, Substrate, and TON, including assessments for Coinbase, MegaETH, Kyber, Jupiter, Zilliqa, IOTA, and Initia Move. At ING, he worked across web application and infrastructure penetration testing, red-team work, exploit development, reverse engineering, mobile security, adversary simulation, and smart-device testing. At Binance, he worked on security concerns for high-scale digital asset systems. He holds the OSCP, OSCE, eWPT, and eWPTX certifications and has CVE disclosures affecting IBM, Oracle, F5, Dell, and Red Hat.
LinkedIn
José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

Security engineer and trainer with around 10 years of experience across application and protocol security. At ZKsync, reviewed Solidity and Rust code, including account abstraction, then built AI-assisted vulnerability-analysis workflows.

José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

José is a security engineer and technical trainer specializing in smart contract and blockchain security, with around 10 years of experience across offensive security, application security, and security review. At ZKsync, he reviewed code, architecture, and design across Solidity/EVM, account abstraction, protocol-level security, and Rust-based components, later building AI-assisted workflows for vulnerability discovery and protocol security analysis. He has participated in smart contract audits across CosmWasm, EVM, and NEAR and holds OSCP, CREST CRT, AWS Certified Security, and AWS Certified Solutions Architect certifications. José has also delivered university courses, guest lectures, and workshops on blockchain and smart contract security, including at the University of Málaga and with the University of Porto.
LinkedIn

Team credentials

13published cryptography research papers
200+audits across the team
2Heads of Security on the advisory team
  • OSCP
  • OSCE
  • OSWE
  • CREST Registered Tester (CRT)
  • CISM
  • AWS Certified Security Specialty
  • AWS Certified Solutions Architect Associate
  • eWPT
  • eWPTX

Discuss your scope.

Describe your system, main concern, and deadline. We'll reply with scoping questions and a proposed next step.

Discuss your scope