Every specialist on your engagement is named in the proposal, with public work you can read before you sign. We review custody and key management, blockchain systems, and the applications and infrastructure built around them.
Founded
2022
Origin
Timur Güvenkaya founded Guvenkaya in 2022. Previously, he established and led a security engineering practice for complex blockchain systems. Earlier at Invicti, he helped build vulnerability-detection engines used by Fortune 50 companies and public-sector organizations. Today, Guvenkaya reviews the code, architecture, and operations that control digital assets.
Why Guvenkaya?
How we work with you.
You work directly with a principal
Your principal defines the scope with you, leads communication, and reviews the report before delivery.
You get the expertise your review needs
We choose specialists for the systems under review. For a custody review, your team includes a custody specialist.
You see risks beyond the code
We examine your architecture, infrastructure, and release process to explain how weaknesses can put funds and operations at risk.
You work with experienced security leaders
Our advisors lead security teams at other companies and bring experience from Kraken, Binance, OpenZeppelin, ZKsync, Gauntlet, Tensor, Nillion, and Invicti.
Team
Our leadership & advisory team
Explore the team’s public profiles, published work, and experience.
Timur Güvenkaya
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
Leads growth through performance marketing, data-led strategy, and audience planning. Her agency work spans healthcare and e-commerce brands across multiple markets.
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Head of Security at Gauntlet, with experience in product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.
Security specialist with 60+ Web3 reviews across DeFi, L1s, bridges, oracles, and other critical infrastructure. At Kraken, worked on the security of funding services, custody, APIs, and on-chain systems.
Cryptography engineer with a Ph.D. in Information Security and 13 published research articles. Worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada and wrote technical reports on threshold ECDSA.
CEO at Inferara and designer of Inference, a language that combines executable code with formal specifications. Leads its Rust compiler development and previously built Code Inspector and security analysis tools at OpenZeppelin.
Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.
Security engineer and trainer with around 10 years of experience across application and protocol security. At ZKsync, reviewed Solidity and Rust code, including account abstraction, then built AI-assisted vulnerability-analysis workflows.