Plan custody, vendors, and operations as one program.

Senior advisory for institutions and operators whose custody, settlement, and tokenization decisions span several systems, several vendors, and more than one team.

Advisory scope

What we advise on

We connect custody, vendor, operational, and governance decisions across the program.

01

Custody and wallet architecture

We work through where keys live, who controls them, and what the chosen model commits you to for years.

02

Vendors and inherited trust

We assess which controls remain with you and which depend on the vendor.

03

The operating model

We define who runs what, which procedures have to exist, and what evidence the program produces as it operates.

04

Sequencing and readiness

We sequence decisions and readiness checks for launch, migration, and external review.

Timing

Best used before you choose architecture or vendors.

Decisions cross systems

Several systems or vendors need one security view.

The program is expanding

An institution is entering or growing digital assets.

Independent judgment

Leadership needs challenge across multiple workstreams.

Boundaries blur

Technical, operational, and governance questions cannot be separated.

Our approach

How we turn program choices into a roadmap.

01

Define the decisions and criteria

Agree the products, operating model, risk appetite, and stakeholders. Set the criteria for comparing architecture, custody, and vendor options.

02

Map risks and dependencies

Document how vendors, systems, and operations connect. Identify inherited trust assumptions, failure scenarios, and gaps in control ownership.

03

Compare options and record tradeoffs

Assess each option against the agreed criteria. Document its costs, risks, and control owners in a decision framework.

04

Build the program roadmap

Sequence security priorities and dependencies in executive and technical sessions. Set owners and decision points for delivery.

What you receive

A framework and roadmap for your program.

Decision framework

The options, what each one costs you, and who ends up owning the control.

Risk and dependency view

How vendors, systems, and operations connect.

Program roadmap

Security priorities in order, worked through in executive and technical sessions.

Your engagement team

Specialists for this scope

A principal leads each engagement. Your proposal names the specialists assigned to the scope.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Timur founded Guvenkaya after seeing teams reduce security to code review while their real risk spans architecture, infrastructure, operations, custody, and launch decisions. Before Guvenkaya, he established and led a security engineering practice for complex blockchain systems, specializing in Rust-based and non-EVM ecosystems including Substrate and NEAR. Earlier at Invicti, he helped build enterprise vulnerability-scanning and security detection engines used by Fortune 50 companies and public-sector organizations.
LinkedIn
Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Piotr is Head of Security at Agora, where he oversees information security, data protection, and corporate IT risk management. He brings both industry and consulting experience, having led information security advisory engagements and security program development for global financial institutions and large organizations. Earlier in his career, Piotr was a Senior Cybersecurity Consultant at Ernst & Young (EY), leading security assessments across financial services, healthcare, and government. He holds CEH, OSCP, and OSWE certifications, has contributed to the CVE program, and is the inventor of multiple U.S. patents related to information security and blockchain technology.
LinkedIn
Meet the full team

FAQ

Frequently asked questions

How is this different from the individual reviews?

A review takes one system and examines it. This takes the program: several systems, several vendors, and the decisions that cross between them. Advisory work usually identifies which reviews are worth running, and when.

Do you implement, or only advise?

We advise, design, and review. We do not operate your program and we do not resell custody or security platforms, which is what lets us assess a vendor without holding a stake in the answer.

We have already chosen a custody vendor. Is it too late?

No. That is one of the more common starting points. The questions simply move to integration, operating model, key ceremony design, role separation, and what your exit looks like if the relationship ends.

Who from our side needs to be involved?

Usually more than one function: engineering, operations, risk or compliance, and someone who can decide when those three disagree. Include the people who can approve decisions across these functions.

Can we focus the engagement on one decision?

Yes. A custody model, vendor choice, integration, or migration can be the starting point. We consider the dependencies relevant to that decision and agree how far the advisory scope extends.

Put the whole program in view.

Describe the program, open decisions, and deadline. We will define the advisory scope.

Discuss your scope