# QA and release assurance, backed by evidence

> AI-assisted test automation, independent validation, exploratory testing, AI-product evaluation and documented release assessments, including for software other teams built.

Source: https://npcoding.ca/services/qa-testing/

We test what your business depends on: critical workflows, integrations, permissions and edge cases. AI helps us build and extend automated coverage faster, experts investigate what scripts miss, and before each release you get a documented, risk-based view of whether it's ready.

Specialist services in this capability: [Application Security](https://npcoding.ca/services/application-security/).

## Overview

Faster development makes independent validation more important, not less. Code that compiles, passes its own tests and looks right in a demo can still apply the wrong discount, expose the wrong record or fail on the third step of a refund.

So we test against what the business requires, not just what the code was written to do. Acceptance criteria come from your requirements, written with product owners before development starts. AI helps us generate test cases, find gaps in coverage and triage defects quickly; experienced testers review what each test proves and investigate the product the way users, edge cases and integrations will stress it.

Before a release you get documented findings and a risk-based assessment: what was tested, what wasn't, what's still open and what that means for going live. QA is built into every NPCoding project, and it's available on its own, including for software built by other teams.

## Is this the right service?

Choose QA & Release Assurance when:

- You need to know whether a release does what the business requires before it goes live
- Regression, integration, device, accessibility or AI-feature coverage is missing or unreliable
- Software built by another team (or quickly with AI tools) needs an independent check

Consider instead:

- [Application Security](https://npcoding.ca/services/application-security/) when the question is whether the software can be attacked or misused, not whether it works
- [DevOps & Managed Operations](https://npcoding.ca/services/devops-managed-operations/) when releases themselves are the problem: pipelines, environments and rollback

## What's included in QA & release assurance

- **Acceptance criteria & test strategy:** Criteria grounded in business requirements, and a risk-based plan that focuses effort where failure would hurt most.
- **AI-assisted test automation:** Unit, API and end-to-end suites generated and extended faster with AI, reviewed by testers and run in your pipeline on every change.
- **Coverage analysis:** A map of which journeys, business rules and integrations are covered, and where the gaps carry real risk.
- **Exploratory & integration testing:** Experienced testers probe business logic, permissions, edge cases and third-party integrations with realistic data and failures.
- **Devices, accessibility & performance:** Coverage across the browsers and devices your users rely on, WCAG checks and load testing, as scoped for each release.
- **Defect triage & release assessments:** Reproducible, prioritized findings, regression tests for every fix, and a documented recommendation for each release.

**Built by another team?** We run independent QA assessments of software we didn't write, including AI-generated codebases. You receive test suites, findings and a release assessment, and we can keep the coverage growing or embed testers in your team's sprints.

## A release decision you can explain.

An illustrative example of the one-page assessment we prepare before a release. The format is real; the release and its findings are invented. (Illustrative example.)

**Release assessment · Checkout and returns update**: Ready, with one condition

Scope tested:

- Checkout with saved and new cards
- Returns and partial refunds
- Discount stacking rules
- Order sync to the ERP

Evidence:

- Automated regression on every critical journey: passing
- Exploratory sessions on refunds and permissions
- Keyboard and screen-reader checks on checkout

Open risks:

- Medium: refund email delayed when the ERP sync retries (workaround documented)
- Low: a long discount name truncates on small screens

Recommendation:

- Release, and watch ERP retry volume for 48 hours
- Fix the label in the next release; its regression test already exists

## How AI assists quality assurance.

Where AI helps:

- Generating test cases and test data from agreed acceptance criteria
- Finding untested journeys, business rules and integrations
- Grouping duplicate defects and suggesting likely causes
- Re-running evaluation suites whenever an AI feature changes

What our experts own:

- Acceptance criteria grounded in your requirements
- Reviewing what each generated test actually proves
- Exploratory investigation of the riskiest areas
- The release recommendation

## Testing AI features beyond the happy path.

AI features fail differently from ordinary code, so the test plan adds evaluation.

- **Output quality:** Evaluation sets built from real cases, scored for accuracy, grounding and tone before launch and after every change.
- **Tool permissions:** Checks that an agent can only read and do what it's allowed to, with the right credentials and limits.
- **Unsafe actions:** Adversarial tests for prompt injection, data leakage and actions that should require approval.
- **Failure handling:** Timeouts, tool errors and low-confidence answers fall back safely and reach a person.
- **Regression behaviour:** The evaluation suite is re-run when a model, prompt or tool changes, so quality doesn't drift unnoticed.

## How NPCoding delivers it

1. **Understand the risk:** Learn the product, users, integrations and release rhythm, and agree what quality means for this release.
2. **Define acceptance:** Turn business requirements into testable acceptance criteria before development starts.
3. **Automate the critical paths:** Generate, review and extend fast, reliable suites for the journeys that must never break.
4. **Explore:** Investigate business logic, permissions, integrations and edge cases by hand.
5. **Report & assess:** Documented findings, regression evidence and a risk-based release recommendation.

## Connected capabilities

- [Software & App Development](https://npcoding.ca/services/ai-software-engineering/): Tests are written alongside each change, so engineers get feedback before review rather than after release.
- [DevOps & Managed Operations](https://npcoding.ca/services/devops-managed-operations/): Suites run in the delivery pipeline and gate releases; production incidents come back as regression tests.
- [Product Design & UI/UX](https://npcoding.ca/services/product-design-ux/): Design acceptance criteria and accessibility requirements become explicit checks, so the built product matches what was agreed.

## How we build with AI

Independent QA doesn't need a development package. When we also build or change the software, both packages carry exactly the same QA standards.

- [Private / Local AI Engineering](https://npcoding.ca/services/private-ai-engineering/): AI-powered software delivery in a controlled processing environment.
- [Claude Code & Codex Engineering](https://npcoding.ca/services/claude-code-codex-engineering/): AI-accelerated delivery with Claude Code and OpenAI Codex, directed by experienced engineers.

## Why NPCoding

- **Releases you can explain:** Know what was tested, what's still open and why a release is or isn't ready.
- **Validation kept separate:** Tests are designed from requirements, not worked backwards from the code they check.
- **Coverage that grows:** Every fixed defect gets a regression test, so the same problem doesn't return.

## Tools and technologies

Playwright, Cypress, Jest / Vitest, Appium, Postman, k6, axe DevTools, BrowserStack, LLM evaluation suites

## Industries

- [eCommerce](https://npcoding.ca/industries/e-commerce/)
- [Healthcare](https://npcoding.ca/industries/healthcare/)
- [Finance](https://npcoding.ca/industries/finance/)
- [Education](https://npcoding.ca/industries/education/)

## Related work

- [Yifat: three mobile apps for a media-intelligence group](https://npcoding.ca/case-studies/yifat/): Native iOS and Android apps for the Yifat group: Vigo for managing communication crises, Info Buzzer for real-time media alerts, and Tenders Mobi for tracking public tenders.
- [Dfus3D: rebuilding a top-ranking 3D-printing store — without throwing away its SEO](https://npcoding.ca/case-studies/dfus3d/): A new online store and Android app for a leading 3D print house. The brief: highlight the brand's values in a fresh site while preserving the Google rankings it had already earned.

## Frequently asked questions

### What do we receive from a QA engagement?

Test suites in your repository, a coverage map, documented and prioritized findings, a regression test for every fixed defect, and a release assessment you can share with stakeholders.

### Can AI write our tests?

AI helps us draft tests and extend coverage faster, and we use it. But a test generated from the code it checks can share that code's mistakes. So acceptance criteria come from the requirements, a person reviews what each test proves, and exploratory testing covers what scripts don't.

### Manual or automated testing: which do we need?

Both. Automation protects the critical paths on every change and makes regression cheap. Manual exploratory testing finds usability problems and unexpected behaviour that scripts miss. We balance the two based on your release frequency and risk.

### Can you test software another team built?

Yes. We run independent QA assessments of existing products, including codebases built quickly with AI tools. We can also set up automation or embed testers in your team's sprints. You don't need to choose a development package for QA-only work.

### How do you test AI features?

With evaluation sets built from real cases, checks on tool permissions and unsafe actions, and failure-handling tests. The same suite is re-run whenever a model, prompt or tool changes.

### Do you test for accessibility and AODA?

Yes. We audit against WCAG using automated tools plus manual screen-reader and keyboard testing, and provide a prioritized remediation list. Ontario's AODA requires WCAG 2.0 Level AA for organizations with 50+ employees and the public sector.

Request a QA assessment: https://npcoding.ca/contact/?topic=assess&service=qa#enquiry

---

NPCoding · AI-powered software & app development · Toronto, Canada · support@npcoding.com · https://npcoding.ca/contact/
