Solutions · Financial Institutions

Build a digital asset program whose controls hold in production.

We review custody, settlement, and wallet infrastructure for banks, asset managers, fintechs, and payment firms.

When this fits

Bring us in while the architecture can still change.

Before you choose architecture or vendors

Evaluate custody, settlement, and wallet options while the architecture can still change.

When adding a product or integration

Challenge a new custody provider, fintech partner, or core-system integration before it ships.

Before launch or external review

Test whether controls, recovery, and evidence hold up to production and outside scrutiny.

When security work has piled up

Findings, vendors, and open items have accumulated. We tell you what to fix first.

Where it breaks

A custody platform is only one part of the security model.

Risk sits across identity, signing, vendors, integrations, operations, and recovery. These are the four places we most often find it concentrated.

The custody lifecycle drawn as one continuous path from key generation through storage, approval, signing, monitoring and recovery, with the control failure most often found at each stage

Control is lost between the stages, not inside them.

01

Ownership & approvals

Who can approve what, who owns each control, and what happens when they leave.

02

Custody, signing & recovery

Custody architecture, MPC and HSM models, signing policy, key ceremonies, and break-glass access.

03

Platforms & integrations

Wallet, settlement, API, identity, and core-system boundaries reviewed as one system.

04

Launch & operating readiness

Monitoring, incident response, change control, and remediation ownership before you go live.

Recommended starting engagements

Choose the best starting point.

Typical engagement team

Who typically leads this work

Two of these three have led security inside operating companies, not only reviewed them from the outside.

The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Currently

Head of Security, Agora

$45B+ in volume

Michal Bajor portrait

Michal Bajor

Specialist Advisor

Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Meet the full team

Other organizations we work with

Tell us what you need to secure.

Share the products, architecture, vendors, and timeline. We will reply with the next questions and a likely scope. If a review is not the right next step, we will say so.

Discuss your scope