Frequently asked questions.

Answers about Senueren, the Quesen deterministic decision layer, and Shinren evidence-first security research. Can't find your answer? Contact the studio — we reply within one working day.

Frequently asked questions

What does Senueren do?

Senueren builds deterministic decision, authority and evidence infrastructure for autonomous agents (Quesen), runs evidence-first security research and pre-audit smart-contract review (Shinren), and delivers premium legacy-infrastructure builds. It is a small, hands-on studio in Cape Town.

What is Quesen?

Quesen is a portable deterministic decision layer: it takes a typed security context and returns a reproducible PASS / REVIEW / BLOCK verdict with reason codes and a pinned ruleset, so the same inputs always produce the same output. It interoperates with identity, MCP, payment rails and execution frameworks rather than replacing them.

Do you do smart-contract audits?

Yes — evidence-first pre-audit and security review, including runnable proof-of-concept reproductions. We prefer fresh, low-duplication and niche-VM targets, and we never make a severity claim without a proof.

Where are you based and how do I reach you?

Cape Town, South Africa. Email or WhatsApp via senueren.co.za/contact; we reply within one working day.

What is Shinren?

Shinren is Senueren's protocol-intelligence and security-research practice. It reviews source and protocol design, reproduces issues with evidence, and reports them responsibly — one operational pillar of Senueren, not a separate agency.

What does Shinren assess?

Authorized technical surfaces, scoped per engagement: smart-contract and protocol source (including niche VMs such as Soroban/Rust, not only EVM), agent/MCP tool-execution and authority boundaries, and web/API application surfaces. It is not limited to smart-contract audits.

How does Shinren validate a finding?

Along an explicit evidence ladder — Observed, Reproduced, Runtime-confirmed, Reported, Remediated, Retested. A source-level observation is never presented as a runtime-confirmed vulnerability unless a proof-of-concept actually reproduces it; every severity claim carries the evidence that supports it.

Does Shinren publish vulnerabilities?

Findings follow responsible disclosure. Sensitive exploit detail is shared privately with the asset owner, not exposed publicly to look impressive. Active assessment of any system begins only inside a published program scope or a signed authorization.

How is this different from bug-bounty hunting?

Shinren is oriented to authorized assessments and reproducible engineering evidence — a scoped review with a findings log, remediation guidance and a retest path — rather than relying on public bounty marketplaces. Discovery records a request; it never starts an audit without authorization.