Skip to content
Noroxi

One team.More than 400 tests in seven years.

We are an Istanbul-based offensive security team. We don’t use subcontractors or freelancer networks: every finding in your report was found by someone who sits in your meetings.

14
people on the team
11
certified testers
412
tests completed
38
CVEs assigned

Why we started

In 2019, all three of us worked at large consulting firms, and we kept seeing the same thing: automated scan output with a logo slapped on it, delivered as a report. The client paid, and the vulnerability stayed right where it was.

We founded Noroxi on a single rule: the person who runs the test writes and presents the report. Today we are 14 people. The rule hasn’t changed.

We report the vulnerabilities we find not only to our clients but also to the vendors who build the software. The 38 CVEs assigned to our team are the result of that responsible disclosure work.

Our path

  1. 2019

    Founded

    Three founders, one room in Maslak.

  2. 2020

    First red team

    Our first full-scope exercise, for an insurance company.

  3. 2021

    ISO 27001

    We certified our own processes.

  4. 2022

    CREST

    International membership.

  5. 2023

    Academy

    Our first OSCP prep cohort, 24 participants.

  6. 2024

    Responsible disclosure

    We began reporting the vulnerabilities we find to vendors.

  7. 2026

    Today

    14 people, more than 400 tests, 38 CVEs.

The team that will run your test

In your scoping call, you talk to one of these people. Not a sales rep.

Join the team
  • Elif Kaya

    Co-founder · Head of offensive security

    • OSCP
    • OSWE
    • OSEP

    Web and API security. 14 CVEs.

  • Can Yıldız

    Co-founder · Red team lead

    • OSCP
    • CRTO
    • CRTL

    Active Directory and adversary simulation.

  • Mert Aslan

    Co-founder · Director of compliance and risk

    • ISO 27001 LA
    • CISA

    ISO 27001 and KVKK (Turkey’s personal data protection law) programs.

  • Deniz Arslan

    Senior infrastructure security specialist

    • OSCP
    • CRTP

    Internal networks, cloud and segmentation.

  • Zeynep Demir

    Application security specialist

    • OSWE
    • eMAPT

    Mobile applications and source code review.

  • Ahmet Koç

    Director of the Academy

    • OSCP
    • OSEP

    Curriculum and lab environments.

Certifications

Not multiple-choice exams: hands-on exams lasting 24 to 48 hours, against real systems.

9
OSCPOffSec
3
OSWEOffSec
2
OSEPOffSec
2
CRTOZero-Point Security
2
ISO 27001 LAPECB
1
CISAISACA
  • ISO/IEC 27001:2022

    Information security management system certification

  • CREST

    International penetration testing membership

  • TSE

    Penetration testing company qualification certificate

Our commitments

Four clauses we write into every contract.

  1. 01

    We stay in scope.

    Not a single step outside the written rules of engagement. Every test action is logged with a timestamp.

  2. 02

    We don’t inflate findings.

    Every finding in the report is reproducible. Severity is rated by business impact, not to make a sale.

  3. 03

    We tell you the same day.

    A critical vulnerability doesn’t wait for the report. We call you the day we find it.

  4. 04

    We don’t keep your data.

    Test data is deleted 30 days after project close-out, and we share a record of deletion.

Free mini assessment

We review your external attack surface within 2 business days and summarize the top risks on a single page. No commitment.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing