Skip to content
Noroxi

Where to start?Testing that fits your risk.

From applications to the cloud, from code to the audit file. We define the scope together and back every result with evidence.

Which one sounds like you?

Seven services. One reporting language.

Every engagement is reported the same way: scored findings, evidence, remediation guidance and a retest.

  1. 01

    Web and API penetration testing

    Hands-on manual testing focused on the OWASP Top 10 and business logic flaws.

    • Authentication and authorization
    • Payment and business logic flows
    • REST and GraphQL endpoints
    Duration
    5–10 business days
    Standard
    OWASP ASVS · PTES
    Details
  2. 02

    Mobile application testing

    iOS and Android apps, tested together with the APIs behind them.

    • Data stored on the device
    • Network traffic and certificate validation
    • Session and payment flows
    Duration
    5–8 business days
    Standard
    OWASP MASVS
    Details
  3. 03

    Infrastructure and network penetration testing

    Internal and external networks, Active Directory, VPN and endpoints.

    • External attack surface discovery
    • Active Directory configuration
    • Segmentation and lateral movement risk
    Duration
    5–15 business days
    Standard
    PTES · NIST SP 800-115
    Details
  4. 04

    Cloud security assessment

    Configuration and permissions review across AWS, Azure and GCP.

    • IAM and excessive privileges
    • Exposed storage and network rules
    • Logging and monitoring coverage
    Duration
    5–10 business days
    Standard
    CIS Benchmarks
    Details
  5. 05

    Red team

    An objective-driven exercise that measures how well you detect and respond.

    • Written scope and rules of engagement
    • Approved social engineering and physical access
    • Joint review with your blue team
    Duration
    3–6 weeks
    Standard
    MITRE ATT&CK · TIBER-EU
    Details
  6. 06

    Source code review

    Static analysis plus manual review, with every finding tied to a line number.

    • Authentication and authorization code
    • Input validation and data flow
    • Dependency and secrets scanning
    Duration
    5–15 business days
    Standard
    OWASP ASVS · CWE Top 25
    Details
  7. 07

    KVKK and ISO 27001 compliance

    With you from gap analysis all the way to the certification audit.

    • Gap analysis and risk assessment
    • Policies and control set
    • Evidence file and audit rehearsal
    Duration
    6–16 weeks
    Standard
    ISO 27001:2022 · KVKK
    Details

The report is the product.

Not a pile of false positives. Every finding is written clearly enough for a developer to fix it on their own.

  • One-page executive summary
  • CVSS 4.0 score and business impact
  • Evidence and reproduction details
  • Prioritized remediation guidance
  • Free retest within 30 days
NRX-2026-0141page 14 / 38
CriticalCVSS 4.0 · 9.1

Broken object-level authorization in the Orders API

Affected asset
api.ornek-sirket.com.tr
Category
OWASP API1:2023 · CWE-639
Discovered
September 12, 2026
Reported
Same day, by phone

Impact

A signed-in customer can view invoices that belong to other customers. Because the invoices include names and addresses, this may require notification under KVKK (Turkey’s personal data protection law).

Remediation

In the invoice lookup, verify that the record belongs to the signed-in user. Centralize authorization checks in a single middleware layer and apply it to every endpoint.

Retest · October 3, 2026 Resolved

Anatomy of an engagement.

Who does what, and when, is in writing from day one.

01

Scoping call

30 minutes

From youTarget systems and testing window

From usWritten scope and proposal within 2 business days

02

Testing

5–15 business days

From youTest accounts and a point of contact

From usDaily status notes; a same-day call for any critical finding

03

Report and readout

3 business days

From youOne hour of your development team’s time

From usExecutive summary, technical report and a finding-by-finding walkthrough

04

Retest

Within 30 days

From youA list of the findings you’ve fixed

From usFree retest and an audit-ready closure report

Frequently asked questions

If your question isn’t here, we’ll answer it on the scoping call.

How is pricing determined?
By scope: the number of applications, endpoints or IP addresses to test, and the days required. Within 2 business days of the scoping call, we send a fixed-price proposal. There are no extra charges during testing.
Do you test in production?
We can, but we recommend a test environment first. If we work in production, load-heavy steps are scheduled outside business hours, and nothing that could disrupt service happens without written approval.
What happens if you find a critical vulnerability during testing?
We call you the same day, without waiting for the report. If you like, we pause testing while you fix it, then pick up where we left off.
How are our data and findings protected?
An NDA is signed before work begins. Reports are delivered over an encrypted channel, test data is deleted 30 days after the project closes, and we share a record of the deletion.
Which standards do your reports follow?
Findings are scored with CVSS 4.0 and mapped to OWASP, CWE and MITRE ATT&CK. Reports are formatted so they can be used directly as evidence in ISO 27001 and KVKK audits.

Let’s pick your first test together

We’ll review your external attack surface within 2 business days, recommend priorities on a single page and scope the work accordingly. No commitment.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing