Prior to sign-off
Your agency declares the application finished. Defects found before you sign are usually covered by the order; afterwards fixing them often turns into a discussion about money.
Every service here settles a different doubt. Is the delivered software faithful to the spec? Will it hold when a campaign sends traffic through the roof? Could the Friday ritual of clicking through the same screens be handed to a script? Do real people find their way around? Might one user peek at another’s data? Not sure which doubt is yours? Write to us about the symptom and we will point you to the right one.
Features measured against the agreed requirements, fed with the data Austrian businesses really handle: UID numbers, umlauts in surnames, EU cross-border VAT rates, eps transfers, purchase on account. What remains afterwards is a reusable catalogue of cases for future releases.
Simulated rushes, such as Black Friday, a concert ticket release or winter-season bookings at a Tyrolean hotel, fired at a clone of your system. You learn the concurrent-user ceiling and which component buckles first.
Recurring checks turned into scripts, built with Playwright, Cypress or Appium, that run by themselves in your CI pipeline. We calculate the return beforehand and will be honest if automation would not earn its cost.
A handful of participants drawn from your actual target group attempt a set task at their own desks. Over a video link we note every pause, wrong turn and abandoned attempt. Accessibility checks come as standard.
An authorised break-in attempt: signed consent from whoever operates the system, targets and dates fixed contractually. We concentrate on privilege boundaries between accounts, the login process and how user input is processed.
Hardly anyone books testing out of curiosity. Certain moments make a defect unusually costly, and a short external review at exactly those points tends to save a great deal of pain.
Your agency declares the application finished. Defects found before you sign are usually covered by the order; afterwards fixing them often turns into a discussion about money.
A Shopware upgrade, a switch of accounting package, a move to another host. Logic that ran flawlessly for ages may fail silently, with tax and shipping rules the usual victims.
Sales, Black Friday, the opening of the ski season. Peak traffic is a terrible moment to find out how much the server can take.
Hand-testing has fallen behind the release rhythm. Automate the routine checks, or accept that some build will eventually go out unchecked.
A large client or the cyber insurer wants to see security testing. A dated pen test report with a defined scope settles the matter.
Late testing is better than none, yet testing alongside development costs a fraction. When a flaw surfaces while the developer is still inside that code, the fix takes minutes. Let the same flaw reach live users and it turns into an emergency patch, irritated customers and, should invoices be wrong, a tricky call with your tax adviser. That is why we prefer to accompany a project in short loops instead of arriving the evening before launch.
Instead of a one-line verdict like “quality fine”, you get numbered findings ranked by severity, each with a reproduction recipe. We connect to your staging system via secured access or through test accounts created specifically for us.
You demo the software and tell us who relies on it and what it exchanges data with. Between us we mark the areas where a failure would hurt revenue or reputation.
The test types, browser and device matrix, exclusions and an hour budget. Nothing starts until you have approved both the concept and the price.
Findings are filed straight into Jira, GitLab, GitHub or Azure DevOps, whichever you use, complete with steps, data, screenshot and severity, so no developer has to come back with questions.
Each correction is checked individually, and so is the code around it, since one repair occasionally breaks the next module. A summary report and an explicit go or no-go recommendation close the job.
Developer testing matters, yet it has a blind spot: authors know the intended path through their code and naturally follow it. Someone from outside lacks that habit, tries the odd combinations nobody planned for and gains nothing from a rosy report. It also frees your developers to spend their hours building features.
Frequently, or they at least expect to be told in advance. Numerous hosting and cloud firms address security testing in their terms, and some ask for registration with a time slot and the testers’ IP addresses. We clarify this with you up front and only touch systems whose operator has consented in writing. Components run by third parties, a payment gateway for instance, remain excluded.
Functional checks on a modest application need a lead time of one or two weeks. Load tests ahead of a promotion deserve at least a month, because the first measurement is usually followed by tuning and a second round. For pen tests, the schedule depends chiefly on obtaining consent and coordinating with the host.
Individual jobs run on hours actually worked at €110 per hour plus VAT, up to the limit you approved in our quote. Should every release need testing, it can become part of a monthly Start, Business or Premium plan. We send e-invoices, due within 30 days.
Preferably not: we recommend synthetic records or an anonymised extract. Where live data cannot be avoided, a GDPR data processing agreement is signed first, access is kept to the bare minimum and logged, and it is withdrawn when testing ends.
Let us know what should be tested and your intended launch date. We reply with a test concept and an estimate of the hours involved.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.