Contract QA services

Hands-on QA that runs alongside your scans

QA Audit automates the crawl. When you need engineers in the loop — test design, triage, regression maintenance, and Security Pro depth — Wolf (Staff SDET) and a small senior team pick up the work. Same plain-language standards as the product; contact-only engagements.

Contract offerings

Dedicated QA engineer

One Staff-level QA engineer embedded on your release rhythm.

Availability: accepting dedicated engineer engagements

  • Single point of contact — Wolf (Staff SDET) or a senior engineer he assigns
  • Hands-on test design, execution, and triage alongside your automated QA Audit scans
  • Works in your stack (Playwright, Cypress, manual checklists) with plain-language status updates
  • Ideal when you need steady QA capacity without hiring full-time yet
Contact for pricing

QA team (up to 4)

A small QA squad for parallel coverage across web, API, and release checks.

Availability: team engagements — contact to confirm capacity

  • Up to four QA engineers on one contract — coordinated by Wolf (Staff SDET)
  • Split coverage: functional regression, accessibility, performance triage, and scan interpretation
  • Same peer voice as the product — no offshore ticket queue or sales handoffs
  • Best for launches, migrations, or when Engineering-depth scans surface more than one lane of work
Contact for pricing

Monthly retainer

We operate your scans and do the hands-on work the reports imply.

Availability: monthly retainer slots — onboarding weekly

  • We run and interpret your QA Audit scans on the cadence you need — same categories as Launch through Engineering (links, SEO, HTTPS, accessibility, performance, mobile, social previews).
  • We set up and maintain automated checks for functional flows, accessibility (including axe where your package includes it), performance signals, and passive security configuration — matching what the scan engine evaluates.
  • Application Map upkeep, Test Coverage Review with CLI bundle workflows, and behavioral QA (forms, dialogs, keyboard, same-origin CTAs) when you are on Team or Engineering depth.
  • Full operational support behind Security Pro monthly for recurring external-surface programs, or Monthly re-audit for recurring website crawl and regression alerts — we manage scope, DNS gates, and report review alongside your team.
  • You keep the reports and artifacts; we keep the automation honest as the product ships.
Contact for pricing

Security expert add-on

Additional Security Pro depth — human experts on the same scope as the product.

Availability: Security Pro add-on — DNS verification required before external work

  • Includes Team-depth website QA first — Application Map, Test Coverage Review, Jira-ready findings
  • External port and service discovery (nmap-class) after DNS ownership proof
  • Attack-surface findings in plain language plus API inventory from observed crawl traffic
  • Optional OpenAPI contract upload — merge declared paths and flag contract-vs-observed gaps
  • Encrypted QA credential vault and authenticated session probe for logged-in routes
  • Broader subdomain and declared staging scope on recurring Security Pro monthly programs
  • Assessment framing — not credential stuffing, injection verification, or a scoped penetration test
Contact for pricing

What we maintain hands-on (matches the scan engine)

Monthly retainer work covers the same categories your QA Audit reports score — not a separate checklist. We keep automated tests and manual spot-checks aligned with Application Discovery, functional and behavioral QA, accessibility, performance, security configuration, and test-intelligence slices from the product catalog.

  • Search & page titles
  • HTTPS & site security basics
  • Broken links
  • Mobile-friendly basics
  • Accessibility basics
  • Page speed signals
  • Social sharing previews
  • Application Map
  • Test Coverage Review
  • Behavioral QA
  • Application Discovery — routes, forms, controls, and link hygiene
  • Responsive layout checks and report screenshots on Engineering-depth runs
  • Recurring scan ops coordinated with Security Pro monthly or Monthly re-audit when you want a fixed cadence
  • Hands-on test maintenance in your repo or staging — not a dump of generated files into Engineering reports alone

Recurring programs use the same monitoring product names as self-serve when you want a fixed cadence: Security Pro monthly for external surface scope, and Monthly re-audit for recurring website crawl and regression alerts. We operate the scans; you get the interpretation and test maintenance.

Not sure which shape fits?

Start with a one-time audit on the pricing page, then add contract QA when the report backlog needs owners. Every engagement starts with a short scope call — no Stripe checkout on this page.