Our products · AI testing platform

NexGen QA

NexGen QA is our AI-powered quality assurance platform for web applications, APIs, LLMs, and AI agents. It brings more than 35 testing and QA modules into one multi-tenant product, and lets enterprise and government customers run AI tests with their own keys inside their own GitHub Actions.

Homepage of qa-automation.com with the headline Enterprise QA Reimagined with AI and a preview of the NexGen QA dashboard
Screenshot of the public homepage, captured by Techtonic Innovations on September 21, 2026.

The product and the goal

Teams testing modern software juggle separate tools for test management, security scanning, accessibility, performance, API testing, and — increasingly — evaluating LLMs and AI agents. NexGen QA's goal is one platform for all of it, built for organizations with real compliance requirements.

The challenge

Enterprise and government buyers often can't send their AI provider keys, or their test traffic, through a vendor. The platform needed a way to run AI-powered tests without ever holding a customer's keys — and a public website audit tool that fetches arbitrary URLs without becoming a server-side request forgery hole.

What we built

A multi-tenant web application with organization-scoped data, and a separate prerendered marketing site.

  • Modules spanning test management, an AI walkthrough recorder, scheduled tests with alerts and public status badges, security scanning, Section 508 / WCAG accessibility with VPAT/ACR export, performance and load testing, REST/GraphQL/WebSocket testing, and AI model evaluation.
  • Omni-Scan, a browser engine that combines Playwright, deterministic checks, and AI analysis to score a site.
  • Autonomous testing with a director agent that plans work for specialized worker agents.
  • Continuous testing on push and pull request via a GitHub App, shareable reports with PDF export, organization API keys with scopes, RBAC, and audit logging.

Architecture: a BYOK GitHub Actions runner

With Bring Your Own Key, the platform stores only the names of a customer's GitHub Secrets — never the values. Using a fine-grained token the customer provides, it commits a workflow and a sample test into their repository. When a run is dispatched, it executes in the customer's own GitHub Actions, calls the AI provider with the key from their secrets, and posts results back authenticated with a per-run HMAC-SHA256 callback token.

Behind the app, a Prisma schema of 60 models backs the multi-tenant data layer, with Redis for rate limiting and agent coordination, OpenTelemetry instrumentation, and field-level AES-256-GCM encryption for sensitive values.

Security, SEO, and performance

The free website audit tool on the marketing site fetches user-supplied URLs, so every request goes through an SSRF guard: HTTP(S) on ports 80 and 443 only, no embedded credentials, DNS resolved by the server with any non-public address rejected, the connection pinned to the validated IP to defeat DNS rebinding, and every redirect re-validated. It's also rate-limited to 10 audits per 10 minutes per IP, capped on concurrency, and limited to 4 KB request bodies.

The marketing site is server-rendered and prerendered for crawlers, with SEO landing pages, a pricing page, compression, immutable caching for hashed assets, a lazily loaded 3D hero, and a permanent redirect from www to the apex domain. NexGen QA reflects our AI development, AI security audit, and managed AI work.

Results

  • Live at qa-automation.com, with the application at app.qa-automation.com.
  • Scores 95/100 on its own website audit tool (measured September 21, 2026); the live sitemap lists 23 URLs.
  • 140 backend test files (Vitest) in the platform repository, and 582 commits between January 25 and September 16, 2026.
  • BYOK runs keep AI provider keys inside the customer's GitHub Secrets.

Facts verified against the project's repository and live site. Past results don't guarantee future results; every project is different.

More case studies

All case studies