DIGITAL ASSET PROGRAM ADVISORY
Make defensible security decisions across the whole digital asset program.
Senior advisory for institutions and operators whose custody, settlement, and tokenization decisions span several systems, several vendors, and more than one team.
Advisory scope
What we advise on
Program decisions rarely sit inside one system. This engagement holds the whole picture across custody, vendors, operations, and governance, so the choices stay consistent with each other.
-
01 Custody and wallet architecture We work through where keys live, who controls them, and what the chosen model commits you to for years. -
02 Vendors and inherited trust We assess what each platform, custodian, and integration genuinely gives you authority over, and what it quietly takes away. -
03 The operating model We define who runs what, which procedures have to exist, and what evidence the program produces as it operates. -
04 Sequencing and readiness We put the decisions in an order that survives launch, migration, and the audit that follows.
Timing
Best used before you choose architecture or vendors.
Decisions cross systems
Several systems or vendors need one security view.
The program is expanding
An institution is entering or growing digital assets.
Independent judgment
Leadership needs challenge across multiple workstreams.
Boundaries blur
Technical, operational, and governance questions cannot be separated.
Process
From cross-system decisions to a governed digital asset program.
- 01
Set the program decisions
Clarify the products, operating model, risk appetite, stakeholders, and decisions requiring independent challenge.
- 02
Connect the dependencies
Map custody, platforms, vendors, integrations, operations, governance, and inherited trust across workstreams.
- 03
Challenge the options
Evaluate architecture and vendor choices, failure scenarios, control ownership, and unresolved tradeoffs.
- 04
Govern execution
Set priorities, decision forums, owners, and a roadmap that keeps technical and leadership work aligned.
Outputs / What you receive
Decisions your program can be governed by.
Decision framework
Options, tradeoffs, and control ownership.
Risk and dependency view
How vendors, systems, and operations connect.
Program roadmap
Security priorities and executive and technical working sessions.
Typical engagement team
Who typically leads this work
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Timur Güvenkaya
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Piotr Cielas
Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Currently
Head of Security, Agora
$45B+ in volume
FAQ
Questions before scoping
How is this different from the individual reviews?
A review takes one system and examines it. This takes the program: several systems, several vendors, and the decisions that cross between them. Advisory work usually identifies which reviews are worth running, and when.
Do you implement, or only advise?
We advise, design, and review. We do not operate your program and we do not resell custody or security platforms, which is what lets us assess a vendor without holding a stake in the answer.
We have already chosen a custody vendor. Is it too late?
No. That is one of the more common starting points. The questions simply move to integration, operating model, key ceremony design, role separation, and what your exit looks like if the relationship ends.
Who from our side needs to be involved?
Usually more than one function: engineering, operations, risk or compliance, and someone who can decide when those three disagree. The value drops sharply when decisions have to be relayed second-hand.
What do we walk away with?
A decision framework with the tradeoffs made explicit, a view of how vendors and systems depend on one another, and a roadmap ordered by what unblocks what.
Related services
Next step
Put the whole program in view.
Share the target operating model, current decisions, vendors, timeline, and stakeholders. We will identify the right advisory workstream.
Discuss your scope