suite/ai-generated-app-testing

AI-generated app testing that finds the bugs before your users do

We test apps built withLovable, Bolt, Cursor, Claude, Gemini, Replit, v0, Windsurf, Copilot and ChatGPT

Free launch check in 48 hours. Full 5-day audit with a go or no-go report. No code access needed to start.

works-with/

  • Lovable
  • Bolt
  • Cursor
  • Claude
  • Gemini
  • Replit
  • v0
  • Windsurf
  • Copilot
  • ChatGPT

Logos belong to their respective owners; QACraft is not affiliated.

Senior-led QA team testing software since 2017, with clients in the US, UK, Canada, Australia, New Zealand, France and India.

“Since partnering with QACraft, our software quality has improved dramatically — defect rates dropped and our release cycles are faster than ever.”
Jason Peter, Toronto, Canada

Why AI-generated apps need independent testing

AI coding tools and vibe coding ship features fast. They do not promise those features are safe, complete or ready for strangers.

Edge cases nobody tried

Empty fields, double clicks, slow networks and refreshes quietly break flows that looked finished in the demo.

Access checks left out

Pages look protected, but the data behind them can be reached by anyone who knows where to look.

Secrets and settings exposed

Keys in browser code and open database rules are common in apps built quickly with AI tools.

What our AI-generated app testing includes

One fixed scope, one report and one senior engineer accountable for the sign-off.

Functional testing

Your most important user journeys, tested by a person, including the unhappy paths.

Security testing

Access control, exposed secrets, input handling and backend configuration. An engineer confirms every finding.

API testing

Authorization, validation, error handling and webhooks on the routes your app depends on.

Performance testing

A basic load test of key pages and APIs, so you know what breaks first.

Browser and mobile checks

The main flows on current browsers and common phone sizes.

Launch readiness report

A go or no-go verdict, findings ranked by severity, evidence, and a suggested fix for each. Free retest included.

Issues we often find in apps built with Cursor, Claude, Lovable and Bolt

Missing authorization checks

A signed-in user can open another user's records by changing an ID.

Exposed API keys

Admin or third-party keys bundled into public JavaScript.

Open database rules

Supabase or Firebase rules that allow far more reads and writes than intended.

Weak input validation

Forms and APIs that accept data they should reject.

Broken payment and webhook flows

Duplicate charges, unverified webhooks and coupons that apply twice.

Edge-case failures

Flows that work once but fail on refresh, retry or slow connections.

From first call to launch verdict in five days

  1. day 1

    Scope

    A short call and test access to your staging app.

  2. days 2-3

    Test

    Functional, security and performance checks.

  3. day 4

    Report

    Findings, evidence and the verdict.

  4. day 5

    Walkthrough

    We review the report with your team.

  5. after fixes

    Retest

    Free check and an updated verdict.

We only test systems you own or have authorised us to test, under a signed scope and NDA.

Choose how to start

Every engagement is scoped to your app. Tell us what you are shipping and we will recommend the right package.

Launch Audit

  • Functional, security and performance testing
  • Readiness report with verdict
  • Walkthrough call and free retest
  • Main flows checked on current browsers and common phone sizes
  • Every finding ranked by severity, with evidence and a suggested fix
  • No code access needed to start
Talk to us

Launch Audit with Security Report

  • Everything in Launch Audit
  • Deeper manual security testing
  • Findings mapped to SOC 2 and OWASP controls
  • A report you can share with customers or auditors
  • Access-control, exposed-secret and database-rule review
  • API authorization, input validation and webhook checks
Talk to us

Monthly QA Retainer

  • Release checks every week or sprint
  • Regression testing of key flows
  • One-page quality report each month
  • Security spot-checks on new and AI-generated features
  • A named QA engineer who learns your app
  • Bugs logged straight into your tracker
Talk to us

Get a free launch check for your AI-generated app

Send us your app link. Within 48 hours you get a short report with the top issues we can spot from the outside, plus a readiness score. No sales pitch required.

We only look at what is publicly visible, and never test anything deeper without your written approval. Built for founders, freelancers and agencies handing over AI-generated apps, and teams preparing for a customer security review.

AI-generated app testing: common questions

What is AI-generated app testing?

It is independent QA and security testing for apps written mostly with AI coding tools (often called vibe coding) such as Cursor, Claude Code, Lovable, Bolt or Copilot. We check that the app works for real users, that data is protected and that it holds up under load.

How long does a pre-launch audit take?

A standard audit takes five working days from the scoping call to the report walkthrough. Retesting after your fixes is included.

Do you need our source code?

Not for the free check or the standard audit. Code access makes the security review deeper, and we only take it under a signed NDA.

Will testing break our live app?

We test a staging copy wherever possible. If production testing is needed, we agree timing and limits with you in writing first.

Is this the same as a SOC 2 penetration test?

No. The Launch Audit is a quality and security check before release. The version with the security report adds deeper manual testing and maps findings to SOC 2 and OWASP controls, which you can share with customers or auditors.

Can't I just ask my AI tool to review the code?

AI review helps and we use it too. But the tool that wrote the code tends to share its blind spots, and nobody is accountable for the verdict. We give you tested evidence and a human sign-off.

How much does an AI-generated app audit cost?

Every audit is quoted at a fixed price for your app after a short scoping call, so you know the full cost before any testing starts. The free launch check costs nothing.

Get a free launch check