One team.More than 400 tests in seven years.
We are an Istanbul-based offensive security team. We don’t use subcontractors or freelancer networks: every finding in your report was found by someone who sits in your meetings.
- 14
- people on the team
- 11
- certified testers
- 412
- tests completed
- 38
- CVEs assigned
Why we started
In 2019, all three of us worked at large consulting firms, and we kept seeing the same thing: automated scan output with a logo slapped on it, delivered as a report. The client paid, and the vulnerability stayed right where it was.
We founded Noroxi on a single rule: the person who runs the test writes and presents the report. Today we are 14 people. The rule hasn’t changed.
We report the vulnerabilities we find not only to our clients but also to the vendors who build the software. The 38 CVEs assigned to our team are the result of that responsible disclosure work.
Our path
2019
Founded
Three founders, one room in Maslak.
2020
First red team
Our first full-scope exercise, for an insurance company.
2021
ISO 27001
We certified our own processes.
2022
CREST
International membership.
2023
Academy
Our first OSCP prep cohort, 24 participants.
2024
Responsible disclosure
We began reporting the vulnerabilities we find to vendors.
2026
Today
14 people, more than 400 tests, 38 CVEs.
The team that will run your test
In your scoping call, you talk to one of these people. Not a sales rep.
Elif Kaya
Co-founder · Head of offensive security
- OSCP
- OSWE
- OSEP
Web and API security. 14 CVEs.
Can Yıldız
Co-founder · Red team lead
- OSCP
- CRTO
- CRTL
Active Directory and adversary simulation.
Mert Aslan
Co-founder · Director of compliance and risk
- ISO 27001 LA
- CISA
ISO 27001 and KVKK (Turkey’s personal data protection law) programs.
Deniz Arslan
Senior infrastructure security specialist
- OSCP
- CRTP
Internal networks, cloud and segmentation.
Zeynep Demir
Application security specialist
- OSWE
- eMAPT
Mobile applications and source code review.
Ahmet Koç
Director of the Academy
- OSCP
- OSEP
Curriculum and lab environments.
Certifications
Not multiple-choice exams: hands-on exams lasting 24 to 48 hours, against real systems.
- 9
- OSCPOffSec
- 3
- OSWEOffSec
- 2
- OSEPOffSec
- 2
- CRTOZero-Point Security
- 2
- ISO 27001 LAPECB
- 1
- CISAISACA
ISO/IEC 27001:2022
Information security management system certification
CREST
International penetration testing membership
TSE
Penetration testing company qualification certificate
Our commitments
Four clauses we write into every contract.
- 01
We stay in scope.
Not a single step outside the written rules of engagement. Every test action is logged with a timestamp.
- 02
We don’t inflate findings.
Every finding in the report is reproducible. Severity is rated by business impact, not to make a sale.
- 03
We tell you the same day.
A critical vulnerability doesn’t wait for the report. We call you the day we find it.
- 04
We don’t keep your data.
Test data is deleted 30 days after project close-out, and we share a record of deletion.
Free mini assessment
We review your external attack surface within 2 business days and summarize the top risks on a single page. No commitment.
- 01Leave your email and domain.
- 02We review your external surface within two business days.
- 03You get a one-page summary and a recommended first step.
- 14
- Subdomains
- 6
- Exposed services
- B
- TLS grade
- 3 / 7
- Security headers
Top three risks
- 1Admin panel exposed to the internetHigh
- 2Outdated TLS version still supportedMedium
- 3Content Security Policy missingLow