Your developers have the skills. Your customers want the proof.

Your developers take short assessments on real code. You see who needs training, and at what level. Your customer gets a progress report they open without an account, with no personal data at all. Free for up to ten developers, in four languages.

Create a company account See a sample report

Can you spot the vulnerability?

Four real questions, taken verbatim from the question bank. Three show code: that is the format of the “spot the vulnerability” challenges. Answer, check, read the explanation — exactly the experience your developers get.

What your developers, your managers and your customer see

An assessment developers are willing to take, indicators a CIO can act on, a document procurement can forward.

  • The assessment: 20 questions, 3 levels — Each assessment draws 20 questions from the chosen level. Of the 303 in the bank, 33 present a real code snippet to analyse — most often JavaScript, but also Python, PHP, Go, Java, SQL, YAML or C#; the others cover principles, mechanisms and design flaws. Every answer, right or wrong, is explained.
  • The level, OWASP family by OWASP family — Percentage score, grade from A+ to F, radar of the ten Top 10:2025 families, progress over time and daily streak. And, when the sample allows, where they stand among the other developers assessed.
  • The team dashboard — and your auditor’s export — Owner, admins, managers: a manager sees only their own team. Headcount, average score, inactive for thirty days or more, recommended level per developer, and a dated 25-column CSV export for your internal audit — included from the Free plan up.

Why CIOs and CISOs assess with NakamaCyber

  • A measurement, not a claim — Every question is tied to one of the ten families of the OWASP Top 10:2025. You replace “our teams are security-aware” with a score per family, comparable from one developer to the next and from one quarter to the next.
  • Who to train, at what level — and nothing else to sell you — A recommended level per developer — beginner, intermediate, expert — derived from the highest level passed at 80%. We sell no training: our only interest is that the measurement is accurate.
  • Proof for your customer, proof for your auditor — A revocable link, with no personal data, that your customer opens without an account — and a 25-column export, names included, for your internal audit. Two documents, two audiences.
  • Free up to ten developers, no credit card — The Free plan includes all 303 questions, the dashboard, admin and manager roles, the CSV export and the shareable report. Beyond ten developers: €40/month, billed yearly (€480/year excl. VAT).

Prove progress, not attendance

Your competitors attach proof of attendance. You send a measurement: engagement, regularity, progress over twelve months.

Your customer sends you a vendor security questionnaire. You generate a link; they open it without creating an account, in their language — French, English, Spanish or Portuguese. There they find your developers’ participation, their month-by-month regularity, their progress indexed to 100 and the measured coverage of the ten families of the OWASP Top 10:2025. No personal data enters the calculation, and below five active participants the document automatically falls back to a reduced version.

  • Answer a vendor questionnaire with a URL, not a hand-filled spreadsheet — and keep your dashboard’s export, names included, for your internal auditor.
  • Progress indexed to 100 over twelve months: your customer sees an overall curve, never the score of any one of your developers.
  • Measured coverage of the ten Top 10:2025 families — including those your team has not worked on — and an OWASP SAMM position. Nothing is published below five active developers.
  • Revocable link, server-side expiry at 30, 90 or 180 days as you choose, content frozen at publication: you decide on sharing, never on what it says after the fact.

This is not a certification. The assessments are multiple-choice questionnaires, online and unsupervised. The report measures engagement and progress, not competence validation — and it says so in plain words. That is what makes it credible in due diligence.

Open a sample report

Up and running in three steps

  • Create the company account — A professional email address, two minutes. The address is verified by email before the first login. No credit card, no mandatory demo.
  • Invite your developers — One link for the whole company, or one link per manager to build the teams. The developer creates an account, lands in the right team and takes a first assessment within ten minutes.
  • Measure, prescribe, prove — Scores by OWASP family, recommended level, inactive developers flagged, an export for your auditor. And, the day a customer asks you for evidence, a shareable report generated in one click.

Simple, public pricing

Free for individual developers and for companies up to ten developers. Beyond that, a published price.

  • Free — The whole product, up to ten developers (0€)
  • Pro — Beyond ten developers (€40)
  • Enterprise — Your instance, your rules (Tailored)

Select Your Challenge Level

  • Beginner — For those new to cybersecurity
  • Intermediate — For those with some experience
  • Expert — For security professionals