Our products · AI testing platform
NexGen QA
NexGen QA is our AI-powered quality assurance platform for web applications, APIs, LLMs, and AI agents. It brings more than 35 testing and QA modules into one multi-tenant product, and lets enterprise and government customers run AI tests with their own keys inside their own GitHub Actions.

The product and the goal
Teams testing modern software juggle separate tools for test management, security scanning, accessibility, performance, API testing, and — increasingly — evaluating LLMs and AI agents. NexGen QA's goal is one platform for all of it, built for organizations with real compliance requirements.
The challenge
Enterprise and government buyers often can't send their AI provider keys, or their test traffic, through a vendor. The platform needed a way to run AI-powered tests without ever holding a customer's keys — and a public website audit tool that fetches arbitrary URLs without becoming a server-side request forgery hole.
What we built
A multi-tenant web application with organization-scoped data, and a separate prerendered marketing site.
- Modules spanning test management, an AI walkthrough recorder, scheduled tests with alerts and public status badges, security scanning, Section 508 / WCAG accessibility with VPAT/ACR export, performance and load testing, REST/GraphQL/WebSocket testing, and AI model evaluation.
- Omni-Scan, a browser engine that combines Playwright, deterministic checks, and AI analysis to score a site.
- Autonomous testing with a director agent that plans work for specialized worker agents.
- Continuous testing on push and pull request via a GitHub App, shareable reports with PDF export, organization API keys with scopes, RBAC, and audit logging.
Architecture: a BYOK GitHub Actions runner
With Bring Your Own Key, the platform stores only the names of a customer's GitHub Secrets — never the values. Using a fine-grained token the customer provides, it commits a workflow and a sample test into their repository. When a run is dispatched, it executes in the customer's own GitHub Actions, calls the AI provider with the key from their secrets, and posts results back authenticated with a per-run HMAC-SHA256 callback token.
Behind the app, a Prisma schema of 60 models backs the multi-tenant data layer, with Redis for rate limiting and agent coordination, OpenTelemetry instrumentation, and field-level AES-256-GCM encryption for sensitive values.
Security, SEO, and performance
The free website audit tool on the marketing site fetches user-supplied URLs, so every request goes through an SSRF guard: HTTP(S) on ports 80 and 443 only, no embedded credentials, DNS resolved by the server with any non-public address rejected, the connection pinned to the validated IP to defeat DNS rebinding, and every redirect re-validated. It's also rate-limited to 10 audits per 10 minutes per IP, capped on concurrency, and limited to 4 KB request bodies.
The marketing site is server-rendered and prerendered for crawlers, with SEO landing pages, a pricing page, compression, immutable caching for hashed assets, a lazily loaded 3D hero, and a permanent redirect from www to the apex domain. NexGen QA reflects our AI development, AI security audit, and managed AI work.
Results
- Live at qa-automation.com, with the application at app.qa-automation.com.
- Scores 95/100 on its own website audit tool (measured September 21, 2026); the live sitemap lists 23 URLs.
- 140 backend test files (Vitest) in the platform repository, and 582 commits between January 25 and September 16, 2026.
- BYOK runs keep AI provider keys inside the customer's GitHub Secrets.
Facts verified against the project's repository and live site. Past results don't guarantee future results; every project is different.
More case studies
All case studies
Our products · AI desktop app
Co-Help
Shipping v5.11.1 for Windows and macOS, backed by a managed API that races AI providers in parallel.
- Electron
- Multi-LLM
- Cloud Run
- Stripe

Our products · Legal AI (RAG)
Justice Genie
Live at justicegenie.help; audit score raised from 77 to 94 after one day of security and SEO hardening.
- FastAPI
- RAG
- PostgreSQL
- Multi-LLM

Client project · Community events
Bagram Events
Live at bagram.us: event listings, ticket links, and a Resend-powered contact form.
- Next.js
- React 19
- Three.js
- Resend