If yours isn't here, it's a fair question to just ask directly — send it over.
No. Read access to your repo or a staging link is enough to get started — we don't need production credentials upfront, and we scope exactly what we need before touching anything.
Lovable, Bolt, Claude Code, Codex, Cursor, v0, and similar app-building tools, plus AI product patterns on OpenAI, Anthropic, and Gemini. For testing, we use Playwright, LangSmith, Promptfoo, Braintrust, k6, Sentry, and 40+ more — see the full tool comparison. Try free tools on our Resources page.
Yes — open the Resources hub for dedicated tools: coverage gap finder, launch risk score, 24-point checklist, severity classifier, first-test scope builder, adversarial prompt pack, go/no-go helper, and pre-triage prep. Tool stack and eval method are linked from there too. Everything interactive runs in your browser with no signup.
Most focused validation sprints kick off within 48 hours of a scoping call. If you're launching this week, tell us that on the call and we'll adjust.
Both. We test wherever your users actually are — responsive web, native mobile, and the AI-built apps that blur the line between the two.
Yes. We are a remote team working across US, European, and Asia-Pacific hours, with async reporting and calls scheduled around your time zone, not around one headquarters.
A severity-ranked report — critical, high, medium — with a plain-language description of each issue, where it lives in your app, and what a fix looks like. No jargon padding, no findings without a location.
You do, fully. It's your codebase and your data — the report is yours to keep, share internally, or hand to another developer.
Tell us. We'll walk through exactly how we reproduced it, and if it turns out to be a false positive, it comes off the report — no charge to confirm that.
No — we test, we don't build. That's deliberate: it means we have no reason to inflate a report to sell you more development work. We're happy to walk your developer or AI tool through the fix, though.
Yes, before any code or data access changes hands — we'll sign yours or offer ours. More on how we handle access and data is on the About page.
Any credentials or access we're given are revoked or rotated at the end of the engagement. We use synthetic test data wherever possible, and don't retain real user data beyond what's needed to write the report.
Send it over — a real person reads and answers, usually within a day.