suite/ai-generated-app-testing
AI-generated app testing that finds the bugs before your users do
We test apps built withLovable, Bolt, Cursor, Claude, Gemini, Replit, v0, Windsurf, Copilot and ChatGPT
Free launch check in 48 hours. Full 5-day audit with a go or no-go report. No code access needed to start.
works-with/
- Lovable
- Bolt
- Cursor
- Claude
- Gemini
- Replit
- v0
- Windsurf
- Copilot
- ChatGPT
Logos belong to their respective owners; QACraft is not affiliated.
your ai-generated app
qacraft testing
result
launch
Free retest included
Senior-led QA team testing software since 2017, with clients in the US, UK, Canada, Australia, New Zealand, France and India.
“Since partnering with QACraft, our software quality has improved dramatically — defect rates dropped and our release cycles are faster than ever.”
Why AI-generated apps need independent testing
AI coding tools and vibe coding ship features fast. They do not promise those features are safe, complete or ready for strangers.
Edge cases nobody tried
Empty fields, double clicks, slow networks and refreshes quietly break flows that looked finished in the demo.
Access checks left out
Pages look protected, but the data behind them can be reached by anyone who knows where to look.
Secrets and settings exposed
Keys in browser code and open database rules are common in apps built quickly with AI tools.
What our AI-generated app testing includes
One fixed scope, one report and one senior engineer accountable for the sign-off.
Functional testing
Your most important user journeys, tested by a person, including the unhappy paths.
Security testing
Access control, exposed secrets, input handling and backend configuration. An engineer confirms every finding.
API testing
Authorization, validation, error handling and webhooks on the routes your app depends on.
Performance testing
A basic load test of key pages and APIs, so you know what breaks first.
Browser and mobile checks
The main flows on current browsers and common phone sizes.
Launch readiness report
A go or no-go verdict, findings ranked by severity, evidence, and a suggested fix for each. Free retest included.
Issues we often find in apps built with Cursor, Claude, Lovable and Bolt
Missing authorization checks
A signed-in user can open another user's records by changing an ID.
Exposed API keys
Admin or third-party keys bundled into public JavaScript.
Open database rules
Supabase or Firebase rules that allow far more reads and writes than intended.
Weak input validation
Forms and APIs that accept data they should reject.
Broken payment and webhook flows
Duplicate charges, unverified webhooks and coupons that apply twice.
Edge-case failures
Flows that work once but fail on refresh, retry or slow connections.
From first call to launch verdict in five days
- day 1
Scope
A short call and test access to your staging app.
- days 2-3
Test
Functional, security and performance checks.
- day 4
Report
Findings, evidence and the verdict.
- day 5
Walkthrough
We review the report with your team.
- after fixes
Retest
Free check and an updated verdict.
We only test systems you own or have authorised us to test, under a signed scope and NDA.
Choose how to start
Every engagement is scoped to your app. Tell us what you are shipping and we will recommend the right package.
Launch Audit
- Functional, security and performance testing
- Readiness report with verdict
- Walkthrough call and free retest
- Main flows checked on current browsers and common phone sizes
- Every finding ranked by severity, with evidence and a suggested fix
- No code access needed to start
Launch Audit with Security Report
- Everything in Launch Audit
- Deeper manual security testing
- Findings mapped to SOC 2 and OWASP controls
- A report you can share with customers or auditors
- Access-control, exposed-secret and database-rule review
- API authorization, input validation and webhook checks
Monthly QA Retainer
- Release checks every week or sprint
- Regression testing of key flows
- One-page quality report each month
- Security spot-checks on new and AI-generated features
- A named QA engineer who learns your app
- Bugs logged straight into your tracker
Get a free launch check for your AI-generated app
Send us your app link. Within 48 hours you get a short report with the top issues we can spot from the outside, plus a readiness score. No sales pitch required.
We only look at what is publicly visible, and never test anything deeper without your written approval. Built for founders, freelancers and agencies handing over AI-generated apps, and teams preparing for a customer security review.
Request received
We will email your launch check to within 48 hours.
AI-generated app testing: common questions
What is AI-generated app testing?
It is independent QA and security testing for apps written mostly with AI coding tools (often called vibe coding) such as Cursor, Claude Code, Lovable, Bolt or Copilot. We check that the app works for real users, that data is protected and that it holds up under load.
How long does a pre-launch audit take?
A standard audit takes five working days from the scoping call to the report walkthrough. Retesting after your fixes is included.
Do you need our source code?
Not for the free check or the standard audit. Code access makes the security review deeper, and we only take it under a signed NDA.
Will testing break our live app?
We test a staging copy wherever possible. If production testing is needed, we agree timing and limits with you in writing first.
Is this the same as a SOC 2 penetration test?
No. The Launch Audit is a quality and security check before release. The version with the security report adds deeper manual testing and maps findings to SOC 2 and OWASP controls, which you can share with customers or auditors.
Can't I just ask my AI tool to review the code?
AI review helps and we use it too. But the tool that wrote the code tends to share its blind spots, and nobody is accountable for the verdict. We give you tested evidence and a human sign-off.
How much does an AI-generated app audit cost?
Every audit is quoted at a fixed price for your app after a short scoping call, so you know the full cost before any testing starts. The free launch check costs nothing.
