Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Code security

We review your source code, dependencies and repository history within the authorised scope. Every finding is reported with file, line, impact and a suggested fix; if you wish, we plan the fix together.

  • Code review
  • Dependency review
  • Secret review
  • Fix work plan
01 / What this service includes

We look at every layer, from code to release.

01

Line-by-line code review

We examine risky flows such as authentication, authorisation, input validation and data access with both tooling and manual review. Each finding is recorded with its file, line and impact.

02

Dependencies and supply chain

We scan the packages you use for known vulnerabilities, abandoned versions and licence risks, and suggest an upgrade order based on the risk of breaking changes.

03

Secret scanning

We find API keys, passwords and tokens left in the repository and in old commits, and provide a step-by-step plan to rotate the key and clean the history.

02 / How it works

The fix pipeline

A finding is closed in four steps that fit your development flow, and it is verified without skipping any of them.

  1. 01Repository access and scope
  2. 02Tool-assisted and manual review
  3. 03Fix work plan
  4. 04Retest and verification
03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Only explicitly authorized assets and agreed scope are assessed.

Deliverables

  • 01Code review
  • 02Dependency review
  • 03Secret review
  • 04Fix work plan
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Scope

    Together we put the goal, the boundaries and the acceptance criteria in writing.

  2. 02

    Assessment

    We assess the current state against agreed criteria and note gaps with evidence.

  3. 03

    Reporting

    We share what was done, the result and the next step in a plain report.

  4. 04

    Retest

    We retest fixed findings and confirm with evidence that they are closed.

05 / Scope

Test categories applied in this service

Which categories are applied is agreed together, based on your target and scope.

Code / development layer

We catch vulnerabilities inside the code, before the application goes live.
Number of categories: 4
  • Static source code security analysis

    We examine the code without running the application and find, line by line, the mistakes that lead to vulnerabilities.

  • Dependency and library vulnerability analysis

    We identify versions with known vulnerabilities among the ready-made libraries your code uses.

  • Infrastructure-as-code (IaC) analysis

    We catch insecure settings in the code files that build your servers and cloud resources, before those resources are even created.

  • Secret and key leak scan in code repositories

    We scan your code repository, including its history, for passwords, API keys and access details written into it by mistake.

The figures are the number of checks in our automated security engines. Not every category runs in every test; the ones that fit your target and scope are selected.

Every test runs with your written permission and within the scope we agree together. Tests that could disrupt a service, and social engineering, are planned only with separate written approval. No test proves that a system is completely secure; we report clearly what was and was not found.

06 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • Scanning of source code, third-party libraries and secrets left in the code.
  • A fix plan.
  • One retest within 30 days of the report is included in the price.

Not included

  • Fixing the findings (offered separately as Remediation).

What we need from you

  • A signed written authorisation.
  • Read access to the code repository.

What sets the price

  • Number of repositories and size of the code.

Payment and aftercare

  • For work agreed in person, the full fee is paid at the start.
  • For remote work, half is paid at the start and half on delivery.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
07 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
How do you access our source code?

We work only with the read-only access you grant, within the agreed repositories and branches. Access is time-limited and removed when the work ends; how the code is handled is set out in the contract.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Will testing affect my live system?

Scope, time window and methods are agreed in advance; risky steps require your separate approval.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.