# Cryptography Reviews

> Review ZK circuits, custom primitives, signature schemes, privacy protocols, and post-quantum designs before you build on them.

Canonical page: https://www.guvenkaya.co/services/cryptography-security-review

**Test the cryptographic guarantees your system relies on.** Manual review of zero-knowledge circuits, custom primitives, signature and threshold schemes, privacy-preserving protocols, and post-quantum designs. We separate what the paper claims from what the circuit, protocol, and implementation actually guarantee.

## A proof is only as strong as the assumption beneath it.

We review the claim, the construction, and the code. A correct paper does not make a correct circuit, and a correct circuit does not make a safe implementation.

- **ZK circuits & proof systems**: Constraints, completeness, soundness, trusted setup, witnesses, and the gap between the intended statement and what is actually proven.
- **Custom primitives**: New constructions, modified standards, parameter choices, and whether the claimed security reduction still holds.
- **Signatures, threshold & MPC**: Signature schemes, aggregation, threshold signing, multiparty computation, nonce handling, and key generation.
- **Privacy-preserving protocols**: Confidential transactions, anonymous credentials, zkTLS, private computation, and what still leaks under a realistic adversary.
- **Post-quantum cryptography**: Scheme selection, parameter sets, hybrid migrations, and implementation of lattice, hash-based, and other quantum-resistant primitives.
- **Implementation & composition**: Constant-time behavior, side channels, API misuse, randomness, domain separation, and unsafe composition of otherwise sound parts.

## When to schedule a review

- **While the primitive is still a draft**: A new construction, circuit, or protocol is about to be treated as a building block.
- **Before a privacy feature goes live**: Users, counterparties, or regulators will rely on a confidentiality or unlinkability claim.
- **Before a PQC or scheme migration**: The algorithm, parameters, or hybrid transition changes what every caller is trusting.
- **When primitives are composed**: Standard parts are being combined in a new way, and the composition has not been reviewed.

## How we review your cryptography.

1. **Document claims and assumptions**: Agree the scope and claimed security properties. Build a threat model that separates proven guarantees, design assumptions, and dependencies on standards or other components.
2. **Trace how the construction is used**: Follow the protocol, circuit, or primitive through the system. Document the properties each flow relies on and how leakage or weakened assumptions could break them.
3. **Review the implementation and write tests**: Challenge parameters, composition, and implementation against the claimed properties. Add regression tests to your repo and record results with supporting evidence.
4. **Verify fixes and document conclusions**: We always verify fixes through retesting and document which claims hold, fail, or remain unsupported. Tie the principal’s signed opinion to the reviewed commit and evidence.

## Deliverables

- **Findings report**: Breaks in the primitive, the circuit, the protocol, or the implementation, with impact and remediation.
- **Threat model**: What is proven, what is assumed, and which guarantees the rest of the system is inheriting. The register includes scenarios blocked by existing controls.
- **Record of flows and security properties tested**: How a weakened assumption, leaked witness, or implementation flaw becomes a practical break, and which properties along that path held.
- **Invariant register**: Each security property, its test result, and supporting evidence.
- **Security tests in your repo**: Regression tests for the reviewed circuit, primitive, or module, ready to rerun after fixes and future changes.
- **Signed opinion on a reviewed commit**: The principal’s conclusions, tied to the reviewed commit, cryptographic claims, and evidence.

## Engagement team

- **Timur Güvenkaya**, Founder & Partner: Rust-based and non-EVM systems, protocol security, architecture, infrastructure, and custody.
- **Manuel B. Santos**, Specialist Advisor: Post-quantum cryptography, secure multiparty computation, threshold signatures, and zkTLS.

## Frequently asked questions

### Do you verify fixes?

Yes. We always provide remediation guidance and verify fixes through retesting. The final report records the remediation status and any unresolved findings.

### How is this different from a smart contract or protocol review?

This review checks the cryptographic guarantees those systems rely on, including the construction, assumptions, and implementation. It can run alongside a contract or protocol review when the two depend on each other.

### What specifications and test material should we provide?

Provide the specification, claimed security properties, threat model, and relevant papers or security arguments. For a review that includes implementation, we need access to the code during scoping, alongside build instructions, test vectors, and known limitations.

### Can you review a custom or unpublished primitive?

Yes. We examine the construction, its security arguments, parameter choices, and implementation within the agreed scope. We identify assumptions or claims the available evidence does not establish.

### Do you cover post-quantum cryptography?

Yes. Reviews can cover scheme selection, parameter sets, hybrid classical-plus-PQC deployments, and the implementation of lattice, hash-based, and other quantum-resistant primitives.

### Do you review the design, the implementation, or both?

We can review the construction and its security arguments, the implementation, or both. The proposal defines the properties, assumptions, and depth of analysis covered.

## Related services

- [Blockchain Protocol & Infrastructure Reviews](https://www.guvenkaya.co/services/blockchain-protocol-security-review.md): Review custom chains, runtimes, nodes, consensus, and bridges beneath the application layer.
- [Smart Contract Security Reviews](https://www.guvenkaya.co/services/smart-contract-security-review.md): Find flaws in contract logic, permissions, accounting, and upgrades before they put funds at risk.
- [Signing & Custody Security Reviews](https://www.guvenkaya.co/services/signing-custody-security-review.md): Review key generation, signing approvals, key use, and recovery across MPC, HSM, multisig, and custody platforms.

## Put the claim, the circuit, and the code in the same review.

Describe the construction, the guarantee you need to check, and your deadline. We will propose a cryptography review.

Discuss your scope: https://www.guvenkaya.co/contact
