Canonical page: <https://www.guvenkaya.co>

For banks, exchanges, custodians, and protocol teams

# Security for digital assets and financial infrastructure.

You work directly with a principal who helps define the scope, brings in the right specialists, and stays involved through delivery.

[Discuss your scope](https://www.guvenkaya.co/contact)

**$30B+** volume secured

**200+** audits across the team

**13** published cryptography papers

Clients and ecosystems we have worked with.

[near.com](https://near.com/)

[NEAR Foundation](https://near.foundation/)

[SWEAT](https://sweateconomy.com/)

[enjin.io](https://enjin.io)

[Alliance Program](https://www.circle.com/alliance-program)

[immunefi.com](https://immunefi.com/)

[invicti.com](https://www.invicti.com/)

[aurora.dev](https://aurora.dev)

[PAL Polkadot Assurance Legion](https://dotpal.io/)

[quantum.systems](https://quantum.systems/)

Client feedback

## What clients say about the work.

> “Timur is one of the most competent auditors, specialising in Rust-based smart contract environments. He has assisted several teams in the NEAR ecosystem over the past few years and it’s been a pleasure seeing him work with teams across many stages and domains.”

**@chronear** VP of Growth, NEAR Foundation

> “We have been working with Timur Güvenkaya for years. One of the most qualified teams in space. If you're in crypto, your top priority should be making sure nobody looses money. Security is your job. If you want to do it well, you might want to reach out to Guvenkaya.”

**Alex Shevchenko** Co-founder and CEO @ Aurora Labs and NEAR Intents

> “We worked with a few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than a one-off contract audit. They think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”

**Oleg Fomenko** Co-Founder and CEO at Sweat Economy

> “Guvenkaya are The Auditors. Deep expertise in Rust and smart contracts combined with a hands-on, iterative approach makes them a go-to partner for serious projects. They don’t just look for bugs. They help to build robust systems from the ground up. We’ve trusted them with multiple audits across different stages and continue to rely on their judgment and precision.”

**Arseny Mitin** Protocol Tech Lead, Aurora, NEAR Protocol

The team

## Meet the team.

Explore the team’s public profiles, experience, and published work.

![Timur Güvenkaya portrait](https://www.guvenkaya.co/v2/portraits/timur-guvenkaya.png)

### Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

[LinkedIn](https://www.linkedin.com/in/timur-guvenkaya/)

![Müjde Nur Asgarli Güvenkaya portrait](https://www.guvenkaya.co/v2/portraits/mujde-guvenkaya.png)

### Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

Leads growth through performance marketing, data-led strategy, and audience planning. Her agency work spans healthcare and e-commerce brands across multiple markets.

[LinkedIn](https://www.linkedin.com/in/m%C3%BCjde-nur-asgarli-g%C3%BCvenkaya-7a7a47170/)

![Piotr Cielas portrait](https://www.guvenkaya.co/v2/portraits/piotr-cielas.png)

### Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

[LinkedIn](https://www.linkedin.com/in/piotr-cielas/)

![Paul Vijender portrait](https://www.guvenkaya.co/v2/portraits/paul-vijender.png)

### Paul Vijender

Specialist Advisor

Head of Security at Gauntlet, with experience in product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.

[LinkedIn](https://www.linkedin.com/in/paulvijender/)

![Michal Bajor portrait](https://www.guvenkaya.co/v2/portraits/michal-bajor.png)

### Michal Bajor

Specialist Advisor

Security specialist with 60+ Web3 reviews across DeFi, L1s, bridges, oracles, and other critical infrastructure. At Kraken, worked on the security of funding services, custody, APIs, and on-chain systems.

[LinkedIn](https://www.linkedin.com/in/michal-bajor/)

![Manuel B. Santos portrait](https://www.guvenkaya.co/v2/portraits/manuel-santos.png)

### Manuel B. Santos

Specialist Advisor

Cryptography engineer with a Ph.D. in Information Security and 13 published research articles. Worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada and wrote technical reports on threshold ECDSA.

[LinkedIn](https://www.linkedin.com/in/manel1874/)

![Georgii Plotnikov portrait](https://www.guvenkaya.co/v2/portraits/georgii-plotnikov.png)

### Georgii Plotnikov

Specialist Advisor

CEO at Inferara and designer of Inference, a language that combines executable code with formal specifications. Leads its Rust compiler development and previously built Code Inspector and security analysis tools at OpenZeppelin.

[LinkedIn](https://www.linkedin.com/in/0xgeorgii/)

![Łukasz Mikuła portrait](https://www.guvenkaya.co/v2/portraits/lukasz-mikula.png)

### Łukasz Mikuła

Specialist Advisor

Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

[LinkedIn](https://www.linkedin.com/in/lukaszmikula/)

![José C. Ramírez portrait](https://www.guvenkaya.co/v2/portraits/jose-ramirez.png)

### José C. Ramírez

Specialist Advisor

Security engineer and trainer with around 10 years of experience across application and protocol security. At ZKsync, reviewed Solidity and Rust code, including account abstraction, then built AI-assisted vulnerability-analysis workflows.

[LinkedIn](https://www.linkedin.com/in/jcramirezv/)

Team credentials

- ![OSCP](https://www.guvenkaya.co/v2/certifications/oscp.svg)
- ![OSCE](https://www.guvenkaya.co/v2/certifications/osce.svg)
- ![OSWE](https://www.guvenkaya.co/v2/certifications/oswe.svg)
- ![CREST Registered Tester (CRT)](https://www.guvenkaya.co/v2/certifications/crest-crt.svg)
- ![CISM](https://www.guvenkaya.co/v2/certifications/cism.svg)
- ![AWS Certified Security Specialty](https://www.guvenkaya.co/v2/certifications/aws-security.svg)
- ![AWS Certified Solutions Architect Associate](https://www.guvenkaya.co/v2/certifications/aws-architect.svg)
- ![eWPT](https://www.guvenkaya.co/v2/certifications/ewpt.svg)
- ![eWPTX](https://www.guvenkaya.co/v2/certifications/ewptx.svg)

Public work

## Read the findings before you hire us.

Full reports with findings, evidence, and remediation status.

### NEAR / Defuse Labs

NEAR Intents Security Review

Medium Potential Funds Stealing From Users Via Repeating Failed Intents

- NEAR
- Intents
- Rust

[View report](https://www.guvenkaya.co/reports/near-intents)

### Sweat Economy

SWEAT NEP-141 Token Security Review

High LookupMap adapter can undercharge storage for selected accounts

- NEAR
- Smart contract
- Rust

[View report](https://www.guvenkaya.co/reports/sweat-token)

### Spin Finance

Onchain Orderbook and Perpetual Trading Security Review

Critical Order Placement with Negative/Zero Margin Ratio Is Possible

- NEAR
- Smart contract
- Rust

[View report](https://www.guvenkaya.co/reports/spin)

### Virto Network

Pallet Pass Security Review

High DoS of The Main Functionality Through Session Key Hijacking

- Polkadot
- Substrate
- Rust

[View report](https://www.guvenkaya.co/reports/virto)

[All reports](https://www.guvenkaya.co/work)

Our approach

## Named before you sign.

Your quote names the principal and specialists assigned to your engagement.

### You scope the work with a principal

Your principal defines the scope with you, checks the findings, and stays involved through delivery.

### You work with experienced security leaders

Our team brings experience from exchanges, protocols, and security product companies. Our advisors also lead security teams at other companies.

### You work with specialists who understand your system

We match your review team to what you are building. For a custody review, your team includes a custody specialist.

How an engagement runs

### From quote to ongoing support.

1. [01–03 Before work starts](#engagement-phase-1)
2. [04 Day one](#engagement-phase-2)
3. [05–07 During the review](#engagement-phase-3)
4. [08–09 At delivery](#engagement-phase-4)
5. [10–12 After delivery](#engagement-phase-5)

1) #### Before work starts

   1. ##### A quote that names your team

      Once the scope is settled, we send a quote with the duration, the commit to be reviewed, and the names and bios of your review team. Every engagement has one principal and as many specialists as the scope needs.

      - Principal leads

   2. ##### Contracts and a shared channel

      You sign a master services agreement and a statement of work. Half the fee is due before the review starts, half when you receive the report. We then open a shared channel on your preferred platform, such as Slack or Telegram, for all communication with the team.

      - Principal leads

   3. Optional

      ##### Kickoff walkthrough

      If the code is complex, we may ask your engineers for a call to walk us through it before the review starts.

      - Specialists lead
      - Principal assists

2) #### Day one

   4. ##### Threat model first

      On the first day, the team named in your quote maps attack paths, the invariants your system must hold, and its critical flows.

      - STRIDE
      - NIST SP 800-30
      - Guvenkaya assessment framework

      * Principal leads
      * Specialists assist

3) #### During the review

   5. ##### Manual review, backed by AI tooling

      Specialists review the code by hand and run our own AI skills and test harnesses against it. The principal checks findings as they come in.

      - Specialists lead
      - Principal assists

   6. ##### Tests, invariants, and evidence

      As we review, we add security tests and new invariants to your repository and record each check in an evidence bundle, so every finding can be traced back to what we ran.

      - Specialists lead
      - Principal assists

   7. ##### Serious findings, reported early

      We tell you about Critical, High, and Medium issues as soon as we find them, so you can start fixing before the review ends.

      - Specialists lead
      - Principal assists

4) #### At delivery

   8. ##### Confidential report

      Specialists write the report, and the principal reviews it before it reaches you. It opens with a plain-language conclusion, then sets out every finding, the order to fix them in, and our assurance opinion on the reviewed commit.

      - Threat model
      - Invariants and flows tested
      - Scope boundaries
      - Evidence appendix

      [See a sample report](https://www.guvenkaya.co/reports/sample)

      - Specialists lead
      - Principal assists

   9. ##### Security package

      Everything else goes into your repository. Tests for open findings fail on purpose and pass once the fix is in, so your team can track remediation by running the suite.

      - Security tests
      - Test documentation
      - Markdown copy of the report
      - Remediation skill (optional)

      * Specialists lead
      * Principal assists

5) #### After delivery

   10. ##### Remediation and a free retest

       We help you plan and prioritize fixes. When they are in, we retest them at no charge and issue a public report that records each fix and carries the principal's signature. You can share it with your users and partners.

       - Specialists lead
       - Principal assists

   11. Optional

       ##### Next scope or ongoing work

       If the review points to other areas worth checking, we scope the next engagement with you. Teams that want us on hand for longer can move to a retainer or buy a block of days.

       - Penetration testing
       - OpSec review
       - Key management review
       - Infrastructure review

       * Principal leads

   12. ##### Ongoing support

       After the engagement ends, you can keep bringing us your security questions at no charge.\*

       - Principal leads
       - Specialists assist

\* Within fair use: questions as they come up, not a daily queue.

What you receive

### More than a findings report.

A report-only audit ends with a list of findings. Ours also adds security tests to your repository that your team can keep running after the engagement ends.\*

| Deliverable                                                                                                                     | Guvenkaya | Report-only audit |
| ------------------------------------------------------------------------------------------------------------------------------- | --------- | ----------------- |
| Findings report                                                                                                                 | Yes       | Yes               |
| Threat model                                                                                                                    | Yes       | No                |
| Record of flows and security properties tested                                                                                  | Yes       | No                |
| Invariant register                                                                                                              | Yes       | No                |
| Evidence appendix What we ran to reach each finding, so your team can check it.                                                 | Yes       | No                |
| Security tests in your repo Each test comes with docs on what it covers and how to run it.                                      | Yes       | No                |
| Markdown copy of the report A plain-text version of the report that AI tools can parse.                                         | Yes       | No                |
| Remediation skill for AI agents An optional skill that lets your AI agents recheck findings, verify fixes, and prioritize work. | Yes       | No                |
| Signed public report after retest Records each fix and carries the principal's signature. Yours to share.                       | Yes       | No                |

\* These deliverables apply to code security reviews. For other engagements, we agree on deliverables when defining the scope.

[Discuss your scope](https://www.guvenkaya.co/contact?source=team-differentiator) [See a sample report](https://www.guvenkaya.co/reports/sample)

Services

## Start with what you need to secure.

Describe your system or the change you are planning. We'll help define the scope.

### [Smart Contract Security Reviews](https://www.guvenkaya.co/services/smart-contract-security-review)

Find flaws in contract logic, permissions, accounting, and upgrades before they put funds at risk.

- Permissions & accounting
- Protocol logic
- Integrations

Explore

### [Blockchain Protocol & Infrastructure Reviews](https://www.guvenkaya.co/services/blockchain-protocol-security-review)

Review custom chains, runtimes, nodes, consensus, and bridges beneath the application layer.

- Custom chains
- Runtimes & VMs
- Nodes
- Consensus

Explore

### [Penetration Testing](https://www.guvenkaya.co/services/penetration-testing)

Test the attack paths that connect web, mobile, APIs, cloud, identity, and infrastructure.

- Web & mobile
- APIs & backends
- Cloud
- Infrastructure

Explore

### [Signing & Custody Security Reviews](https://www.guvenkaya.co/services/signing-custody-security-review)

Review key generation, signing approvals, key use, and recovery across MPC, HSM, multisig, and custody platforms.

- MPC
- HSM
- Multisig
- Key lifecycle

Explore

### [Secure Code Reviews](https://www.guvenkaya.co/services/secure-code-review)

Find security flaws in critical code, including authorization, business logic, and state changes.

- Authorization
- Business logic
- State changes

Explore

### [Secure Architecture & Process Design](https://www.guvenkaya.co/services/secure-architecture-process-design)

Design or assess critical systems, workflows, integrations, and operating controls before implementation or a major change.

- Trust boundaries
- System integrations
- Operating controls

Explore

[View all services](https://www.guvenkaya.co/services)

### Not sure which one fits?

Tell us your main concern and we’ll help you choose a starting point.

[Discuss your system](https://www.guvenkaya.co/contact?source=ask-what-to-scope)

Training

## Technical training & security exercises

Choose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.

[Discuss training](https://www.guvenkaya.co/contact?source=training-exercises)

[Rust Security](https://www.youtube.com/watch?v=q7yjmhxyvc0)

[**Rust security essentials:** Explore production Rust security issues through findings from our reviews.](https://www.youtube.com/watch?v=q7yjmhxyvc0)

[NEAR Security](https://www.youtube.com/watch?v=BRk334lBJ_A)

[**NEAR smart contract security:** Learn about NEAR contract and protocol security through findings from our published reviews.](https://www.youtube.com/watch?v=BRk334lBJ_A)

Solutions

## Find the right services for your organization.

### [Financial Institutions](https://www.guvenkaya.co/solutions/financial-institutions)

Banks, asset managers, fintechs, payment firms, and financial infrastructure providers.

- Digital asset advisory
- Signing & custody
- Risk assessment

Explore

### [Digital Asset Operators](https://www.guvenkaya.co/solutions/digital-asset-operators)

Exchanges, custodians, wallets, stablecoin operators, and asset platforms.

- Signing & custody
- Penetration testing
- Training & security exercises

Explore

### [Protocols & Networks](https://www.guvenkaya.co/solutions/protocols-networks)

L1 and L2 systems, ecosystems, bridges, DeFi protocols, and on-chain products.

- Smart contracts
- Blockchain & infrastructure
- Cryptography
- Secure code review

Explore

### [Software & Infrastructure Teams](https://www.guvenkaya.co/solutions/software-infrastructure)

Web, mobile, cloud, backend, AI, and other critical software systems.

- Penetration testing
- Secure code review
- AI & agent security
- Architecture & process design

Explore

## Tell us what you need to secure.

Describe your system, main concern, and deadline. We'll reply with scoping questions and a proposed next step.

[Discuss your scope ](https://www.guvenkaya.co/contact)<contact@guvenkaya.co>
