You built it with Lovable, Bolt, Cursor or Claude, and it works when you click through it yourself. Then a customer pays and the app still shows the free plan. A second user logs in and sees the first one's data, or waits for a sign-up or reset email that never comes. I'm a senior QA engineer: I use your live app behind the login, with two accounts, and tell you in plain words what breaks first.
Send me your URL - I'll reply within 24 hours with 3 things I found by hand and a fixed price. Free, no call.
No newsletter - I use your email only to answer you.
Or start with the free 20-second scan. It only checks what a visitor can see without logging in.
Async-first - no meetings required. You get a written report with a launch verdict, plus a screen recording of every critical and high issue.AI writes code fast, and often the first person to really test it is a paying customer. Latest full audit: 36 findings across 44 of 48 checks, 4 critical.
The AI wrote it. You're not sure what's solid and what's held together with tape.
What if someone sees another user's data, or gets charged twice? You can't tell.
One broken form in front of real users and they're gone.
Your live app or staging URL and your email, in the form at the top. Within 24 hours I reply with 3 things I found by hand and a fixed price.
It's short: a test account, a second one so I can see what one user sees of another, and test-mode payments if the app takes money. Repo access is optional.
Sign-up, payments, forms, one account against another, security basics, mobile. By hand, plus tooling. Every critical and high issue gets a screen recording.
I start when I get access. You get page 1 (the verdict) before paying. The invoice is a Payoneer link - card or bank transfer, no account needed. Full report the same day the payment lands.
A sample pre-launch pass on an AI-built study app (built with Lovable). Product anonymized.
Password-reset and sign-up emails never arrived - while the app displayed “Check your inbox - email sent.” Every user who forgot their password would be silently locked out on launch day.
Sample report: 22 of 48 checks, 9 findings (critical flows, forms, access control). Each finding says what it does to a user and how to fix it.
Only numbers I can show the source for.
The free scan only sees what is visible without an account. The gap between 3.3 and 36 is the part that takes a person: logging in, using the app with two accounts, and trying to break it.
Simple, fixed prices. No hourly billing.
Whichever package you pick, you get page 1 (the verdict) before paying. The invoice is a Payoneer link - card or bank transfer, no account needed.
For comparison: a QA agency retainer typically runs $2,500-3,500 a month, and an hourly freelancer is about 40 hours at $50 - roughly $2,000 with no fixed scope. Here the price, the scope and the delivery date are fixed before you pay. Re-testing your fixes is a separate $290 order limited to the findings of your report; on QA Partner re-tests are included.
The listing gives you revenue and screenshots, and nothing about what a paying customer runs into after sign-up. After the LOI, with the seller's consent and a test account they set up, I check the live product behind the login before you sign the purchase agreement: sign-up and password reset, the payment path, and whether one user can reach another user's data.
Say yes in writing and create a test account for me, plus a second one if users can share data. I don't need the code.
Same packages and prices as above. Quick Check ($290) covers those paths; Pre-Launch Audit ($790) runs all 48 checks. You get page 1 (the verdict) before paying.
Send me the app's URLFree guides, written from what I keep finding in AI-built apps.
What a pre-launch audit of a Lovable app covers behind the login, what Lovable's free scans already catch and what they can't see, price, turnaround and a sample report.
Manual QA for Lovable apps: the flows customers use, regressions after the next AI edit, a monthly option for teams that ship often, and what two-minute automated audits can't reach.
Keys, prices, webhooks, payment links and the customer portal all exist twice in Stripe. Six checks that catch the half-switched setup: the key in your live JavaScript, live price IDs, the live webhook secret, test links, one real purchase, and the 4242 test.
The anon key is public by design, so RLS does all the work. Six checks you can run in the Supabase dashboard and two browser windows: key type, RLS switch, over-broad policies, the two-account test, logged-out requests, storage buckets.
An outside-in scan of 190 live Lovable-built apps: 94% send no CSP, 79% return 200 for missing pages, 67% have no enforcing DMARC, 3 ship an API key. Method, limits, and a 2-minute self-check for every number.
Missing SPF/DKIM/DMARC, the shared Supabase dev sender, silent rate limits, a wrong Site URL, or content-level spam filtering - with exact steps to check each one.
I'm Novruz - a Senior QA engineer with 10+ years testing real products. I've seen a lot of ways software breaks in front of users. Now I test AI-built apps for solo founders and small teams who want to know what breaks before launch day.
Your URL and email are enough to start. You decide after you read my reply.
Get 3 findings and a price