Choose the review your system needs.

Each targets a different layer of the system. Find yours below, or tell us the scope and a principal will point you to the right review.

Timing

When to bring Guvenkaya in

During design

Challenge trust assumptions before they become expensive to reverse.

Before launch

Review the system once its behavior and critical paths are stable enough to test.

Before a major change

Reassess after an upgrade, a migration, or a change to who holds the keys.

After an incident or concern

Reconstruct failure paths and identify the changes needed to prevent recurrence.

Our approach

How we scope and run your review.

01

Define the scope and outputs

Identify the system or change to review. Agree the boundaries, exclusions, and evidence needed for your decision.

02

Map the threats

Document the actors, assets, trust assumptions, and failure scenarios relevant to the scope.

03

Review and record the evidence

Assign specialists for the system under review. Examine the controls and document findings with supporting evidence.

04

Verify fixes and deliver conclusions

We always verify fixes through retesting and record unresolved findings. Deliver the agreed outputs with conclusions tied to the reviewed scope.

Your review team

Meet the specialists

A principal leads each engagement. Your proposal names the specialists assigned to the scope.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Timur founded Guvenkaya after seeing teams reduce security to code review while their real risk spans architecture, infrastructure, operations, custody, and launch decisions. Before Guvenkaya, he established and led a security engineering practice for complex blockchain systems, specializing in Rust-based and non-EVM ecosystems including Substrate and NEAR. Earlier at Invicti, he helped build enterprise vulnerability-scanning and security detection engines used by Fortune 50 companies and public-sector organizations.
LinkedIn
Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Piotr is Head of Security at Agora, where he oversees information security, data protection, and corporate IT risk management. He brings both industry and consulting experience, having led information security advisory engagements and security program development for global financial institutions and large organizations. Earlier in his career, Piotr was a Senior Cybersecurity Consultant at Ernst & Young (EY), leading security assessments across financial services, healthcare, and government. He holds CEH, OSCP, and OSWE certifications, has contributed to the CVE program, and is the inventor of multiple U.S. patents related to information security and blockchain technology.
LinkedIn
Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Łukasz is a security researcher with 10+ years in offensive security and a public portfolio of 100+ audits across 8+ ecosystems. His smart-contract work spans EVM/Solidity, Move, Rust-based ecosystems, CosmWasm, Solana, Substrate, and TON, including assessments for Coinbase, MegaETH, Kyber, Jupiter, Zilliqa, IOTA, and Initia Move. At ING, he worked across web application and infrastructure penetration testing, red-team work, exploit development, reverse engineering, mobile security, adversary simulation, and smart-device testing. At Binance, he worked on security concerns for high-scale digital asset systems. He holds the OSCP, OSCE, eWPT, and eWPTX certifications and has CVE disclosures affecting IBM, Oracle, F5, Dell, and Red Hat.
LinkedIn
Meet the full team

Published reports

Reports from related reviews

Each report includes the full findings and severity ratings.

NEAR Intents

NEAR Intents Security Review

Medium Potential Funds Stealing From Users Via Repeating Failed Intents

  • NEAR
  • Intents
  • Rust
View report

Sailor Lend

Web Application Security Review

Critical Vulnerable to React2Shell

  • Web application
  • TypeScript
View report

Virto Network

Pallet Pass Security Review

High DoS of The Main Functionality Through Session Key Hijacking

  • Polkadot
  • Substrate
  • Rust
View report

Spin Finance

Onchain Orderbook and Perpetual Trading Security Review

Critical Order Placement with Negative/Zero Margin Ratio Is Possible

  • NEAR
  • Smart contract
  • Rust
View report
View all public reports

FAQ

Frequently asked questions

Do you verify fixes?

Yes. We always provide remediation guidance and verify fixes through retesting. The final report records the remediation status and any unresolved findings.

Which review does our system need?

Start with the system or change you want assessed. A principal helps identify the relevant code, infrastructure, cryptography, or operational scope. Work spanning several areas can be combined in one engagement.

What do you need to scope the work?

Describe the system, your main concerns, and your deadline. Share architecture documentation and details of the environment. For any review that includes code, we need access to that code to define the scope and estimate the work. We agree how to exchange confidential material during scoping.

What determines the price and duration?

The scope, technical complexity, available documentation, and depth of testing determine the effort. Access requirements and the included retesting also affect the schedule. The proposal sets out the scope, timing, and fee.

Who will carry out the review?

Your proposal names the principal and specialists assigned to the engagement. A principal stays involved from scoping through delivery.

Discuss your security review.

Describe your system, main concern, and deadline. We will help define the scope.

Discuss your scope