SERVICES

Ten services, one report.

Take these on their own or bundled into a package. Whatever the mix, the output arrives in one format: a ranked, reproducible list of findings.

SERVICES
10 areas
CHECKS
318 items
OUTPUT
One report

Functional testing

We verify the product actually does what it promises by running the critical flows end to end.

We run every flow that moves money or data — sign-up, login, search, basket, checkout, cancellation — from end to end. We work with written scenarios and exploratory sessions in parallel: scenarios catch the known risks, exploratory testing catches what nobody thought of.

Critical flow scenariosExploratory sessionsBoundary and error casesData integrity checks

check items62

Typical finding mix

Details

Regression testing

We check whether the new release broke something that used to work, using the same suite every time.

On the first test we build a regression suite for your product; every release after that repeats it exactly. So instead of guessing what changed between two versions, you measure it. The suite is reviewed each quarter and dead scenarios are retired.

Product-specific regression suiteRelease-to-release diff reportCritical flow smoke testsSuite maintenance

check items48

Typical finding mix

Details

Compatibility matrix

We test on real devices and real browser versions; an emulator on its own isn't enough.

We build a device and browser matrix from your own analytics and run the tests across it — including older iOS versions, low-memory Android handsets and the dated browsers still alive inside enterprises.

Real device labBrowser version matrixScreen size and orientationDark theme and text scaling

check items44

Typical finding mix

Details

Performance & load

We measure how fast the page opens and how many concurrent users it takes before things break.

Core Web Vitals measurements, slow-connection scenarios and staged load tests with k6. The output isn't just a score: we point at the query, the request or the asset creating the bottleneck.

Core Web Vitals (LCP, INP, CLS)Staged load and soak tests3G / high-latency scenariosBottleneck analysis

check items31

Typical finding mix

Details

Security review

We hunt for authorisation, session and input-validation weaknesses on the OWASP Top 10 baseline.

This does not replace a penetration test; it targets the common and expensive mistakes in the application layer. Authorisation bypass, horizontal and vertical privilege escalation, session handling, insecure direct object references and input validation are the main focus.

Authorisation and role checksSession and token lifecycleInput validation and injectionSensitive data exposure

check items38

Typical finding mix

Details

API testing

We test the contract behind the interface: the right response, the right error, the right limit.

We validate endpoints against the schema, check whether error codes actually mean something, and push boundary values and concurrency cases. We can work from your Postman collection or build our own.

Schema and contract validationError code consistencyRate limits and concurrencyAuthentication flows

check items35

Typical finding mix

Details

Payment testing

We run payment, refund and subscription flows end to end with real cards.

A sandbox makes everything look right; what surfaces once money actually moves is a different set of problems. 3-D Secure, bank declines, timeouts, double submits, partial refunds and subscription renewals are exercised with real cards and real bank responses.

Successful payment and order integrityDeclines and interrupted paymentsRefunds, cancellations and partial refundsSubscriptions and recurring charges

check items41

Typical finding mix

Details

Accessibility

We audit against WCAG 2.2 AA with automated scans and real screen reader sessions.

Automated tools catch roughly a third of the problems; the rest are found by hand. Full keyboard navigation, focus order, screen reader announcements, contrast and motion preferences are all tested manually.

Full keyboard navigationNVDA / VoiceOver sessionsContrast and text scalingForm labels and error announcements

check items33

Typical finding mix

Details

Usability review

We flag the flows that work but wear people down. Not a bug list — a friction list.

Using heuristic evaluation we surface the redundant steps, the ambiguous labels and the points of no return in your flows. Every item arrives with a suggestion attached, so it isn't just a list of complaints.

Heuristic evaluationFlow step countsCopy and label clarityError recovery paths

check items27

Typical finding mix

Details

Localization testing

We run the product in the target country, with a native speaker and that country’s formats.

A translation can be correct and the product still wrong. A clipped heading, an interface running the wrong way, a decimal comma, an address form that does not fit the country, a payment method nobody there recognises — none of it shows up until a native speaker looks at the screen.

Text and layoutFormats and unitsLanguage and toneLocal context

check items36

Typical finding mix

Details

It all lands in one output

Whichever services you choose, the result arrives in the same shape: a single list of findings ranked by severity, each backed by reproduction steps and evidence. Your team never has to merge two different reports.

Read a sample report

Don't test the next release alongside your users.

Sign up in the panel, pick what you want tested, pay. The first findings start landing in the same panel within hours.

SendTheCanary provides independent software testing for web, mobile and API products. Ten separate services from functional testing to payments and localization, run by a network of 4,700 testers and delivered as one report ranked by severity.