Quality assurance · Security testing · Production monitoring

From QA to security and monitoring.
One platform.

Bring test planning, case generation, API and UI testing, security scans, and monitoring into one project workflow with Qoretix. Unchecked never means passed. Bring in experts whenever you need support with QA.

Let our experts handle your QA → Managed QA

Qoretix / Commerce webStaging
Explore quality assurance
3Browser engines
Chromium · Firefox · WebKit
3levelsRelease decision
PASS · CONDITIONAL · FAIL
17Shared checklist categories
From authentication to navigation
5minFrom repository connection to the first run
Typical time

Three questions. One answer.

One project. One view. One decision.

Separate quality, security, and monitoring, and you get three decisions. Qoretix brings them together into a single release decision for the same commit.

Quality assurance Available now

Is this ready to release?

Create plans and cases from requirements documents and collected screens, then execute across three browser engines and API contracts. Results combine a PASS, CONDITIONAL, or FAIL decision with coverage that shows what you have not checked.

What you getRelease decision · Failure evidence · Coverage · Quarantined test list

Learn more · Quality assurance

Security testing · Vulnerability management Available now

What is still exposed?

See code scanning, secret scanning, dependency alerts, and lockfile-based malicious package findings beside the release decision. Critical and major vulnerabilities result in FAIL.

What you getFinding details · Remediation · Dependencies at each commit

Learn more · Security testing & vulnerability management

Monitoring · Production issues Preview

What happened after deployment?

Receive production errors, performance data, and release events by commit, then add tests that reproduce those errors to your regression suite. Connect pre-release decisions with what happens in production.

What you getEvents by commit · Regression additions · Owner notifications

Learn more · Monitoring & production issues

One project workflow

From requirements to retesting, without a break.

Connect a repository and register target URLs and test accounts. Documents and screens become plans and cases, with execution triggered by pushes and PRs. Test results and security findings come together under the same commit.

RequirementsConnect GitHub, set a target URL and test account, and attach requirements documents. Crawl the site to collect screens in up to 90 seconds.
PlanRead documents and active cases to create a test plan with a name, description, rationale, plan document, and selected cases. Draft → Active → Archived.
CasesThree sources: human-authored, document-based, and code-based. Each case includes its scenario, preconditions, inputs, expected results, priority, and automation level. Unverifiable drafts are discarded.
API & UI executionRun automatically by repository, branch, and changed-path rules. UI tests use Chromium, Firefox, and WebKit; API tests follow contracts. Failures retain screenshots, replay videos, and logs.
SecurityRepository code, secret, and dependency alerts, plus malicious packages found from the lockfile, inform the same run's decision. Critical or major findings mean FAIL.
Report & retestGet an HTML report, evidence files, and a release decision. Publish failures as Jira issues, fix them, and rerun the same cases to update the decision.

Quality assurance Available now

Every failure comes with screenshots,
replay videos, and logs.

Run on pushes and PRs according to repository, branch, and changed-path rules, with optional approval. Choose smoke, regression, new feature, pre-release, API contract, permission, or unit checks.

  • UI tests run across Chromium, Firefox, and WebKit; API tests validate contracts.
  • Tests with inconsistent results on the same commit are automatically quarantined based on the last 20 runs, so they cannot make the decision FAIL.
  • If requirements coverage is below the 80% target, the decision is CONDITIONAL even when every test passes.
  • Publish failed results as Jira issues linked to the run.
More about quality assurance

Security testing · Vulnerability management Available now

Zero findings and unknown are different.

When code scanning or dependency alerts are disabled in the repository, Qoretix shows unknown, not zero. An unchecked item has not passed.

  • Every finding includes type (dependency, malicious package, secret, or code scanning), severity, location, affected scope, remediation, and source links.
  • Check lockfile package versions against public vulnerability databases. Packages reported as malicious are flagged separately as critical.
  • Record the dependency tree at each commit so you can trace exactly what was included.
  • Critical or major findings result in a FAIL release decision.
More about security testing

Monitoring · Production issues Preview

Your pre-release decision,
beside production reality.

Receive production error, performance, and release events by commit. See what increased after a deployment beside that deployment's release decision.

  • Create tests that reproduce production errors and add them to regression testing.
  • Prioritize screens for testing based on real user paths.
  • Notify owners and link the event to an issue.
More about monitoring

Product + experts

Run it yourself, or put QA in expert hands.

Use both together. Share the same workspace and decisions, and divide the work people do.

A

Your team runs the platform

Typically five minutes from repository connection to the first run. Your team manages plans, cases, execution, and decisions, with permissions assigned by role.

Your team's role

  • QA lead: settings, approval, release sign-off
  • Tester: case authoring, execution, review
  • Customer: view results, decide on release

Best forTeams with QA staff who need the right tools

B

Experts work on Qoretix

Experts handle the agreed QA scope on the same platform. Results stay in the workspace shared with your team.

What experts handle

  • Onboarding, QA setup, and test plan review
  • Exploratory QA, test maintenance, and result triage
  • UX review, retesting, and release memos

These tasks require people to read, judge, and write. Automation does not replace them.

Best forTeams that need focused pre-release QA or have no dedicated QA staff

Combine only what you need. Your team might handle case generation and execution, while experts handle pre-release exploratory QA and the release memo. We agree on scope during consultation.

Deliverables

A record of every run.

More than a dashboard: every run records its decision, evidence, and coverage. With managed QA, expert notes become part of that record.

  1. Release decision and rationale

    PASS, CONDITIONAL, or FAIL, with the reasons behind it. Includes quarantined tests, deferred tests, and coverage gaps.

  2. HTML reports and evidence files

    Each run retains an HTML report, execution logs, screenshots and replay videos of failures, and its execution history.

  3. Coverage

    Three measures: requirements, checklist, and screens. A case that exists but has not run does not count as verified.

  4. Security and supply chain findings, linked Jira issues

    Finding details, remediation, dependencies at the tested commit, and Jira issues created from failures all link back to the run.

  5. An expert's release memo Optional

    With managed QA, plan review comments, exploratory findings, result triage, retest records, and release memos stay in the same project.

Frequently asked questions

Five things to know before you start

What do I need to get started?
A GitHub repository with permission to install the GitHub App, a test target URL (staging recommended), and test accounts. Attach requirements as DOCX, XLSX, PPTX, PDF, images, or Markdown. Without documents, start with screen collection. Server/API projects go straight to API testing.
What happens to our existing CI and issue tracker?
Keep GitHub Actions and Jira. Automation rules run on pushes and PRs, and failed results become Jira issues linked to the run. Other repository and issue tracker integrations, plus release gating through PR checks, are available in preview.
Does CONDITIONAL mean passed?
No. It means human review is needed: there may be minor or trivial failures, flaky, quarantined or deferred tests, or requirements coverage below the 80% target. PASS is issued only when all executed tests pass on the first attempt.
What does our team do with managed QA?
Your team reviews results and decides whether to release. Experts handle the agreed scope of plan review, exploratory QA, result triage, retesting, and release memos. All records stay in the same workspace. Responsibilities are agreed per project.
Who can access our data?
Workspaces are isolated by organization, so other organizations' projects are not visible. Test accounts and repository access are managed per project. Execution evidence and commit-specific dependency records stay in that project's workspace. For deployment and data handling terms, see Deployment & data handlingor ask us during consultation.

Let's choose your first project together.

See plans, cases, execution, and decisions come together in a live demo. We will help define an implementation scope that fits your team.

sales@qoretix.com+82-33-242-0210Weekdays, 10:00–18:00 KST