SECURITY REVIEWS

Seven reviews. The hard part is knowing which one your system needs.

Each targets a different layer of the system. Find yours below, or tell us the scope and a principal will point you to the right review.

Review targets

What do you need reviewed?

Find your system below, and the review that covers it. If your scope crosses categories, we combine the right specialists into one engagement.

A connected ecosystem of applications, APIs, cloud services, identity, infrastructure, and data stores

Applications & infrastructure

  • Web applications
  • Mobile applications
  • APIs
  • Backend services
  • AWS / GCP / Azure
  • Kubernetes & containers
  • CI/CD pipelines
  • Identity & SSO
  • Internal networks

Timing

When to bring Guvenkaya in

During design

Challenge trust assumptions before they become expensive to reverse.

Before launch

Review the system once its behavior and critical paths are stable enough to test.

Before a major change

Reassess upgrades, migrations, new integrations, custody, or infrastructure changes.

After an incident or concern

Reconstruct failure paths and determine what must change before confidence is restored.

Process

From the right review target to a decision-ready result.

  1. 01

    Choose the review target

    Identify the system, workflow, or change that needs independent security judgment.

  2. 02

    Set the boundaries

    Confirm the assets, trust boundaries, critical paths, evidence, exclusions, and decision the work must support.

  3. 03

    Run the right review

    Match the target to reviewers with the relevant code, protocol, cryptography, infrastructure, custody, or AI expertise.

  4. 04

    Resolve and decide

    Work through findings, verify agreed fixes, and deliver the technical or executive readout.

Typical engagement team

Who typically leads this work

The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Currently

Head of Security, Agora

$45B+ in volume

Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Offensive security specialist with 10+ years, 100+ public audits across eight ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

Meet the full team

Inspectable proof

Relevant public work

Each card shows one highlighted finding, not the full result. Open the report for every finding and its severity.

Protocol Public report

NEAR / Defuse Labs

NEAR Intents Security Review

Selected public finding Medium

Potential Funds Stealing From Users Via Repeating Failed Intents

  • NEAR
  • Intents
  • Protocol
View report ↗
Web application Public report

Sailor Lend

Web Application Security Review

Selected public finding Critical

Vulnerable to React2Shell

  • Web
  • Application
  • Security review
View report ↗
Substrate pallet Public report

Virto Network

Pallet Pass Security Review

Selected public finding High

DoS of The Main Functionality Through Session Key Hijacking

  • Polkadot
  • Substrate pallet
  • Rust
View report ↗
Smart contract Public report

Spin Finance

Onchain Orderbook and Perpetual Trading Security Review

Selected public finding Critical

Order Placement with Negative/Zero Margin Ratio Is Possible

  • NEAR
  • Smart contract
  • Rust
View report ↗
View all public reports

Related services

Next step

Put the system in front of the right reviewers.

Share the target, architecture, repo, timeline, and the decision you need the review to support.

Discuss your scope