Skip to content
Noroxi

Who finds it first?You, or the attacker?

An attacker only has to succeed once.You have to succeed every time.So we try first.

CREST member · ISO 27001 certified · Istanbul

Trusted by security teams in finance, healthcare and logistics

  • Kuzey Sigorta
  • Anadolu Fintek
  • Marmara Sağlık
  • Demir Lojistik
  • Ege Enerji
  • Boğaz Medya

01

We attack first.

We test web apps, APIs and infrastructure by hand, using real attacker techniques. You get a list of exploitable findings, not automated scanner output.

  • OWASP and PTES methodology
  • Reproduction steps for every finding
  • Same-day notice on critical findings
noroxiIDORapi-gatewayauthpostgrespublic-reads3-bucketvpn

02

How long until your blue team notices?

A controlled exercise measures your detection and response times. Which alerts fired, which stayed silent, where to invest next: all in one report.

  • Written scope and rules of engagement
  • Findings mapped to MITRE ATT&CK
  • Joint debrief with your blue team
Avg. detection
6 days
Target
<24 h
Detected · 4 Missed · 2

03

We point to the exact line.

Static analysis plus manual review. Not a pile of false positives, but exploitable findings flagged by line number.

  • TypeScript, Go, Java, Python, PHP
  • Re-scans built into your CI pipeline
  • Fixes closed out with your developers
src/routes/invoices.ts1 critical · IDOR
39async function getInvoices(req, res) {
40 const user = await findUser(req);
41 if (!user) return res.status(404);
42 // TODO: authorization check
43 return res.json(user.invoices);
44}
45
46app.get("/invoices/:id", getInvoices);

04

Walk into your audit with evidence.

ISO 27001 and KVKK (Turkey’s personal data protection law) gap analysis, control set and evidence file. For each of the 93 controls: what’s in place, what’s missing, who owns it. On one screen.

  • ISO 27001:2022, KVKK, PCI DSS
  • Evidence file for every control
  • Pre-audit rehearsal

ISO 27001:2022 · Annex A

71 / 93

  • done
  • in progress
  • missing
A.5 · Organizational
37 controls
A.6 · People
8 controls
A.7 · Physical
14 controls
A.8 · Technological
34 controls

400+ tests in seven years. Every one verified.

412
penetration tests completed
97%
of critical findings closed within 30 days
38
CVEs credited to our team
30 days
of free retesting

Four steps. No surprises.

Timeline, communication and deliverables in writing from day one.

  1. 011–2 days

    Scope

    Targets, testing window, communication channel and emergency protocol are agreed in writing.

  2. 025–15 business days

    Testing

    Primarily manual testing. If we find something critical, we don’t wait for the report: you hear the same day.

  3. 033 days

    Report

    Executive summary and technical appendix, plus a finding-by-finding session with your developers.

  4. 04Within 30 days

    Verification

    Fixed findings are retested free of charge. The closing report is audit-ready.

CVE tracking

What should you patch first?

CVSS, CISA KEV and EPSS combined into a single action score. Every entry comes with analysis, detection and remediation steps.

Pentest tools

Test it yourself first.

Security headers, SSL/TLS, email security and subdomain discovery. No sign-up, public information only.

“The first report had 14 findings, three of them critical. Every one came with reproducible steps. We were audit-ready two weeks early.”
Selin Yıldırım, CTO · Anadolu Fintek
“We learned about the critical finding the day it was found, not on report day. That one phone call saved us weeks.”
Barış Erdem, Head of Information Security · Kuzey Sigorta

Free mini assessment

We review your external attack surface within 2 business days and summarize the top risks on a single page. No commitment.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing