Canonical page: <https://www.guvenkaya.co/services>

Services

# Start with what you need to secure.

We review what you have built, advise before you build or buy, and train the teams who run it.

[Discuss your scope](https://www.guvenkaya.co/contact) [See published reports](https://www.guvenkaya.co/work)

12 services

## [Smart Contract Security Reviews](https://www.guvenkaya.co/services/smart-contract-security-review)

Find flaws in contract logic, permissions, accounting, and upgrades before they put funds at risk.

- Permissions & accounting
- Protocol logic
- Integrations

Explore

## [Blockchain Protocol & Infrastructure Reviews](https://www.guvenkaya.co/services/blockchain-protocol-security-review)

Review custom chains, runtimes, nodes, consensus, and bridges beneath the application layer.

- Custom chains
- Runtimes & VMs
- Nodes
- Consensus

Explore

## [Penetration Testing](https://www.guvenkaya.co/services/penetration-testing)

Test the attack paths that connect web, mobile, APIs, cloud, identity, and infrastructure.

- Web & mobile
- APIs & backends
- Cloud
- Infrastructure

Explore

## [Signing & Custody Security Reviews](https://www.guvenkaya.co/services/signing-custody-security-review)

Review key generation, signing approvals, key use, and recovery across MPC, HSM, multisig, and custody platforms.

- MPC
- HSM
- Multisig
- Key lifecycle

Explore

## [Secure Code Reviews](https://www.guvenkaya.co/services/secure-code-review)

Find security flaws in critical code, including authorization, business logic, and state changes.

- Authorization
- Business logic
- State changes

Explore

## [AI & Agent Security](https://www.guvenkaya.co/services/ai-agent-security)

Review models, data, tools, memory, identity, permissions, approval gates, and high-impact actions.

- Agents
- LLMs
- RAG
- MCP

Explore

## [Secure Architecture & Process Design](https://www.guvenkaya.co/services/secure-architecture-process-design)

Design or assess critical systems, workflows, integrations, and operating controls before implementation or a major change.

- Trust boundaries
- System integrations
- Operating controls

Explore

## [Risk Assessment](https://www.guvenkaya.co/services/risk-assessment)

Give leadership a prioritized view of where security risk concentrates and what to address first.

- Risk register
- Remediation priorities
- Action plan

Explore

## [Digital Asset Program Advisory](https://www.guvenkaya.co/services/digital-asset-program-advisory)

Make security, custody, vendor, and operating-model decisions across a broader digital asset program.

- Custody
- Tokenization
- Operating model

Explore

## [Technical Due Diligence](https://www.guvenkaya.co/services/technical-due-diligence)

Evaluate the security and technical risks behind an investment, acquisition, partnership, grant, or vendor decision.

- Investment
- Acquisition
- Vendor selection

Explore

## [Technical Training & Security Exercises](https://www.guvenkaya.co/services/training-security-exercises)

Choose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.

- Workshops
- Tabletop exercises
- Key-ceremony rehearsals

Explore

## [Cryptography Reviews](https://www.guvenkaya.co/services/cryptography-security-review)

Review ZK circuits, custom primitives, signature schemes, privacy protocols, and post-quantum designs before you build on them.

- ZK circuits
- Primitives & schemes
- Post-quantum

Explore

## Not sure which engagement fits?

Describe your system, main concern, and deadline. We'll help define the scope.

[Discuss your scope](https://www.guvenkaya.co/contact)
