Your developers have the skills. Your customers want the proof.
Your developers take short assessments on real code. You see who needs training, and at what level. Your customer gets a progress report they open without an account, with no personal data at all. Free for up to ten developers, in four languages.
Create a company account See a sample reportCan you spot the vulnerability?
Four real questions, taken verbatim from the question bank. Three show code: that is the format of the “spot the vulnerability” challenges. Answer, check, read the explanation — exactly the experience your developers get.
What your developers, your managers and your customer see
An assessment developers are willing to take, indicators a CIO can act on, a document procurement can forward.
- The assessment: 20 questions, 3 levels — Each assessment draws 20 questions from the chosen level. Of the 303 in the bank, 33 present a real code snippet to analyse — most often JavaScript, but also Python, PHP, Go, Java, SQL, YAML or C#; the others cover principles, mechanisms and design flaws. Every answer, right or wrong, is explained.
- The level, OWASP family by OWASP family — Percentage score, grade from A+ to F, radar of the ten Top 10:2025 families, progress over time and daily streak. And, when the sample allows, where they stand among the other developers assessed.
- The team dashboard — and your auditor’s export — Owner, admins, managers: a manager sees only their own team. Headcount, average score, inactive for thirty days or more, recommended level per developer, and a dated 25-column CSV export for your internal audit — included from the Free plan up.
Why CIOs and CISOs assess with NakamaCyber
- A measurement, not a claim — Every question is tied to one of the ten families of the OWASP Top 10:2025. You replace “our teams are security-aware” with a score per family, comparable from one developer to the next and from one quarter to the next.
- Who to train, at what level — and nothing else to sell you — A recommended level per developer — beginner, intermediate, expert — derived from the highest level passed at 80%. We sell no training: our only interest is that the measurement is accurate.
- Proof for your customer, proof for your auditor — A revocable link, with no personal data, that your customer opens without an account — and a 25-column export, names included, for your internal audit. Two documents, two audiences.
- Free up to ten developers, no credit card — The Free plan includes all 303 questions, the dashboard, admin and manager roles, the CSV export and the shareable report. Beyond ten developers: €40/month, billed yearly (€480/year excl. VAT).
Prove progress, not attendance
Your competitors attach proof of attendance. You send a measurement: engagement, regularity, progress over twelve months.
Your customer sends you a vendor security questionnaire. You generate a link; they open it without creating an account, in their language — French, English, Spanish or Portuguese. There they find your developers’ participation, their month-by-month regularity, their progress indexed to 100 and the measured coverage of the ten families of the OWASP Top 10:2025. No personal data enters the calculation, and below five active participants the document automatically falls back to a reduced version.
- Answer a vendor questionnaire with a URL, not a hand-filled spreadsheet — and keep your dashboard’s export, names included, for your internal auditor.
- Progress indexed to 100 over twelve months: your customer sees an overall curve, never the score of any one of your developers.
- Measured coverage of the ten Top 10:2025 families — including those your team has not worked on — and an OWASP SAMM position. Nothing is published below five active developers.
- Revocable link, server-side expiry at 30, 90 or 180 days as you choose, content frozen at publication: you decide on sharing, never on what it says after the fact.
This is not a certification. The assessments are multiple-choice questionnaires, online and unsupervised. The report measures engagement and progress, not competence validation — and it says so in plain words. That is what makes it credible in due diligence.
Open a sample reportUp and running in three steps
- Create the company account — A professional email address, two minutes. The address is verified by email before the first login. No credit card, no mandatory demo.
- Invite your developers — One link for the whole company, or one link per manager to build the teams. The developer creates an account, lands in the right team and takes a first assessment within ten minutes.
- Measure, prescribe, prove — Scores by OWASP family, recommended level, inactive developers flagged, an export for your auditor. And, the day a customer asks you for evidence, a shareable report generated in one click.
Simple, public pricing
Free for individual developers and for companies up to ten developers. Beyond that, a published price.
- Free — The whole product, up to ten developers (0€)
- Pro — Beyond ten developers (€40)
- Enterprise — Your instance, your rules (Tailored)
Select Your Challenge Level
- Beginner — For those new to cybersecurity
- Intermediate — For those with some experience
- Expert — For security professionals