# Security Reviews

> Seven focused reviews across applications, blockchain systems, cryptography, custody, and AI workflows, matched to the layer your risk sits in.

Canonical page: https://www.guvenkaya.co/services/security-reviews

**Choose the review your system needs.** Each targets a different layer of the system. Find yours below, or tell us the scope and a principal will point you to the right review.

## What do you need reviewed?

Choose the closest review target. If your scope crosses categories, we can combine the relevant expertise into one engagement.

- [Smart Contract Security Reviews](https://www.guvenkaya.co/services/smart-contract-security-review): Contract logic, permissions, accounting, economics, upgrades, and integrations.
- [Blockchain Protocol & Infrastructure Reviews](https://www.guvenkaya.co/services/blockchain-protocol-security-review): Custom chains, rollup stacks, runtimes, node clients, consensus, and bridges.
- [Cryptography Reviews](https://www.guvenkaya.co/services/cryptography-security-review): ZK circuits, custom primitives, signature and threshold schemes, privacy-preserving protocols, and post-quantum designs.
- [Penetration Testing](https://www.guvenkaya.co/services/penetration-testing): Test exploitable paths across deployed web, mobile, APIs, cloud, identity, and privileged access.
- [Signing & Custody Security Reviews](https://www.guvenkaya.co/services/signing-custody-security-review): Keys, signers, approvals, recovery, vendors, and the procedures around them.
- [Secure Code Reviews](https://www.guvenkaya.co/services/secure-code-review): Read the source by hand for logic, trust boundaries, and critical paths across services, libraries, and clients.
- [AI & Agent Security](https://www.guvenkaya.co/services/ai-agent-security): Models, prompts, retrieval, tools, memory, and the permissions around each.

## When to bring Guvenkaya in

- **During design**: Challenge trust assumptions before they become expensive to reverse.
- **Before launch**: Review the system once its behavior and critical paths are stable enough to test.
- **Before a major change**: Reassess after an upgrade, a migration, or a change to who holds the keys.
- **After an incident or concern**: Reconstruct failure paths and identify the changes needed to prevent recurrence.

## How we scope and run your review.

1. **Define the scope and outputs**: Identify the system or change to review. Agree the boundaries, exclusions, and evidence needed for your decision.
2. **Map the threats**: Document the actors, assets, trust assumptions, and failure scenarios relevant to the scope.
3. **Review and record the evidence**: Assign specialists for the system under review. Examine the controls and document findings with supporting evidence.
4. **Verify fixes and deliver conclusions**: We always verify fixes through retesting and record unresolved findings. Deliver the agreed outputs with conclusions tied to the reviewed scope.

## Engagement team

- **Timur Güvenkaya**, Founder & Partner: Rust-based and non-EVM systems, protocol security, architecture, infrastructure, and custody.
- **Piotr Cielas**, Principal Advisor: Financial-services assessments, offensive security, risk leadership, CVEs, and patents.
- **Łukasz Mikuła**, Specialist Advisor: Offensive security, exploit development, mobile, infrastructure, and multi-ecosystem reviews.

## Published reports

- [NEAR Intents: NEAR Intents Security Review](https://github.com/Guvenkaya/public-reports/blob/master/NEAR-Defuse-Labs-NEAR-Intents-Security-Review.pdf)
- [Sailor Lend: Web Application Security Review](https://github.com/Guvenkaya/public-reports/blob/master/Sailor-Lend-Web-Application-Security-Review-Final.pdf)
- [Virto Network: Pallet Pass Security Review](https://github.com/Guvenkaya/public-reports/blob/master/Virto-Network-Pallet-Pass-Security-Review-Final-Report.pdf)
- [Spin Finance: Onchain Orderbook and Perpetual Trading Security Review](https://github.com/Guvenkaya/public-reports/blob/master/Spin-NEAR-Rust-Smart-Contract-Security-Assessment.pdf)

## Frequently asked questions

### Do you verify fixes?

Yes. We always provide remediation guidance and verify fixes through retesting. The final report records the remediation status and any unresolved findings.

### Which review does our system need?

Start with the system or change you want assessed. A principal helps identify the relevant code, infrastructure, cryptography, or operational scope. Work spanning several areas can be combined in one engagement.

### What do you need to scope the work?

Describe the system, your main concerns, and your deadline. Share architecture documentation and details of the environment. For any review that includes code, we need access to that code to define the scope and estimate the work. We agree how to exchange confidential material during scoping.

### What determines the price and duration?

The scope, technical complexity, available documentation, and depth of testing determine the effort. Access requirements and the included retesting also affect the schedule. The proposal sets out the scope, timing, and fee.

### Who will carry out the review?

Your proposal names the principal and specialists assigned to the engagement. A principal stays involved from scoping through delivery.

## Related services

- [Secure Architecture & Process Design](https://www.guvenkaya.co/services/secure-architecture-process-design.md): Design or assess critical systems, workflows, integrations, and operating controls before implementation or a major change.
- [Risk Assessment](https://www.guvenkaya.co/services/risk-assessment.md): Give leadership a prioritized view of where security risk concentrates and what to address first.
- [Technical Training & Security Exercises](https://www.guvenkaya.co/services/training-security-exercises.md): Choose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.

## Discuss your security review.

Describe your system, main concern, and deadline. We will help define the scope.

Discuss your scope: https://www.guvenkaya.co/contact
