Skip to content
Noroxi

Source code reviewCatch the flaw on the line it was written.

We verify automated analysis results one by one, then add manual review on top. What you’re left with isn’t a list of false positives, but fixable findings with line numbers.

Duration
5–15 business days
Standard
OWASP ASVS · CWE Top 25
Deliverables
Report, readout and retest within 30 days

What we test

  1. 01

    Authentication code

    Session, token and password handling.

  2. 02

    Authorization checks

    Access control on every endpoint.

  3. 03

    Data flow

    How user input travels through the system.

  4. 04

    Cryptography

    The right algorithm, used the right way.

  5. 05

    Dependencies

    Packages with known vulnerabilities, and licenses.

  6. 06

    Secrets

    Keys and passwords hardcoded in the source.

Vulnerabilities we often find

The ones we’ve run into most in recent engagements. You can’t know whether you have them until you test.

  • Endpoint missing an authorization checkCritical
  • Unvalidated user input passed into a queryHigh
  • Secret key hardcoded in source codeHigh
  • Weak or misused encryptionMedium
  • Outdated dependency with known vulnerabilitiesMedium

This is how a finding is delivered.

Clear enough for a developer to fix on their own. Plain enough for an executive to grasp at a glance.

NRX-2026-0141page 14 / 38
CriticalCVSS 4.0 · 9.1

Broken object-level authorization in the Orders API

Affected asset
api.ornek-sirket.com.tr
Category
OWASP API1:2023 · CWE-639
Discovered
September 12, 2026
Reported
Same day, by phone

Impact

A signed-in customer can view invoices that belong to other customers. Because the invoices include names and addresses, this may require notification under KVKK (Turkey’s personal data protection law).

Remediation

In the invoice lookup, verify that the record belongs to the signed-in user. Centralize authorization checks in a single middleware layer and apply it to every endpoint.

Retest · October 3, 2026 Resolved

How it works

  1. 011–2 days

    Scoping

    Repository access and a short architecture call.

  2. 021–2 business days

    Automated analysis

    Every result is verified and false positives are weeded out.

  3. 033–10 business days

    Manual review

    Critical flows are read line by line.

  4. 043 business days

    Report and developer session

    We walk through the findings with code examples.

Frequently asked questions

Does our code leave the company?
No. If you prefer, we work inside your environment with read-only access.
Which languages do you support?
TypeScript, JavaScript, Go, Java, Kotlin, Python, PHP and C#.
Should it be paired with a penetration test?
When they’re done together, the findings corroborate each other and the overall timeline gets shorter.

Often paired with

Let’s take a free look first

Leave us your domain. Within 2 business days, we’ll review your external surface and send the priority risks and a recommended scope on a single page.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing