Work

Representative engagements.

Three patterns for how a report card comes together: what the client arrives with, how scope and consent are set, who grades, the shape of what comes back, and what they leave with. These are engagement patterns, not client case studies — no named clients, no borrowed numbers.

Illustrative pattern — not a client result.

ENG.01e-commerce

Checkout under test

  • Security
  • Usability & Performance
  • Conversion

Brief

A checkout flow is losing customers somewhere between cart and confirmation, and it has never had a security test.

Scope

Written consent first. Testing runs against staging, with read-only access to production for timing and device checks only.

Graders

  • AI agents walk the auth and session abuse paths and the OWASP Top 10, inside the agreed scope and under human review.
  • Real devices on throttled networks time every step of the checkout.
  • Human testers, matched to the audience, are given one task: buy something.

Findings shape

  • A session token exposed where it should not be — graded critical, with evidence and a fix plan.
  • A 4-second largest contentful paint on a mid-range Android phone.
  • Two points in the form where testers hesitate, retry, or leave.

Deliverable

One report card across the three subjects, a fix plan per finding, and a retest after the fixes land.

ENG.02fintech-style app

API and auth abuse test

  • Security

Brief

An app that moves money or holds sensitive accounts needs a deeper, third-party security test than a screening pass — and help fixing what it finds.

Scope

The Retest Cybersecurity contract: scoped in writing, run only with written consent and approval. Nothing is touched that has not been signed off.

Graders

  • Senior reviewers lead the test and confirm every finding by hand.
  • Controlled agents extend coverage across endpoints, tokens and sessions — always inside the approved scope.

Findings shape

  • An insecure direct object reference on account endpoints.
  • A permissive CORS policy that lets other origins read responses.
  • Secrets left in a publicly readable storage bucket.

Deliverable

Each finding with evidence, impact and priority, a fix plan, hands-on help with the fixes, and a retest to confirm they hold.

ENG.03SaaS

Onboarding, graded by real people

  • UI & UX
  • Usability & Performance
  • Conversion

Brief

Sign-ups arrive but too few reach the first moment of value. The team suspects the onboarding, not the product.

Scope

Written consent, a staging build of the current release and the previous one, and a clear definition of what counts as activated.

Graders

  • Human testers matched to the real audience run the onboarding cold and think aloud.
  • Real devices check the same journey on the screens users actually hold.
  • AI agents add coverage across every path the humans did not take.

Findings shape

  • The moments that trigger confusion, and the words on screen when they do.
  • Where the journey drops people, step by step.
  • Responsive breakage on specific screen sizes.

Deliverable

A report card compared across two releases, so the team sees what moved, what did not, and what to fix next.

Book a test

Bring a URL. Leave with a report card.

Tell us what to test and how hard. We agree the scope in writing, test with your consent, and send the findings back in plain language.

Agreed scopeWritten consentSenior review on every report