Replay QA now does penetration testing.
Security Scan runs a full pentesting pass against your web app — injection flaws, broken access control, IDOR, cross-tenant data exposure — the vulnerabilities that AI-written code introduces at scale.
No credit card. Ownership verification required.
What you get
Bug reports that read like a real pen test finding
Each security finding comes with a full breakdown: what the vulnerability is, how it was discovered, what an attacker could do with it, and exactly what to fix.
The problem
AI coding agents write insecure code at scale.
AI coding tools can build a working web app in hours. What they can't do is apply the security intuition that takes years of pen testing experience to develop. The models optimize for functionality — they produce code that works, not code that resists attack.
The result is a new class of vulnerability pattern. IDOR flaws appear when agents generate API endpoints that fetch resources by ID without checking who's asking. Broken access control shows up when role logic is inconsistent across routes written in different sessions. Injection surfaces when inputs are assembled into queries without the sanitization a security-aware developer would add instinctively.
These aren't edge cases — they're systematic. And because AI-generated codebases ship fast, they reach production before anyone runs a security review.
How Replay QA works
An agentic testing harness that works like a swarm of QA testers
Most QA tooling starts with flows your team defines. Replay QA begins by exploring the application and identifying flows worth verifying.
- 1
Explore
Agents map the app, quickly discover user journeys, and work through them the way a new QA hire would in their first week.
- 2
Test & Record
Agents then write tests that they run while puppeting your app in our Chromium browser, capturing deterministic runtime recordings of every session.
- 3
Investigate & Report
Our QA agents look for bugs across a range of types: deep runtime bugs, UI glitches, accessibility issues, performance problems, and security vulnerabilities — including security scanning for injection, access control, and business logic gaps. They deliver robust bug reports with a root cause and a suggested fix.
Learn more about how it works.
How it fits your workflow
It runs where your team already works
Replay QA hooks into GitHub, comments on pull requests, and files into the tracker you already use. Nobody has to adopt a new tool to get the benefit.
Connect a repo, then forget it
Add your GitHub repo and authenticate. The Replay QA GitHub app installs itself and runs a new pass whenever your codebase changes: every push to main, every pull request, or both. No config file, no CI changes.
Set your testing schedule
Run Replay QA on every push, every PR, or on a fixed schedule. Daily or weekly runs let your team wake up to a fresh batch of issues — ready for coding agents to work through before the day starts.
Test across every environment
Point a project at dev, staging, production, or localhost. Switch environments in settings or manage them via the REST API. Consistent QA coverage no matter which environment you're looking at.
Every pull request gets checked
PR runs test against your preview deployment and post the root cause and suggested fix as a comment on the pull request, next to the diff that caused it.
Bugs land in your tracker
Not another dashboard nobody opens. GitHub Issues, Linear, Jira, or any endpoint that accepts a webhook. You control whether everything gets filed or only what Replay QA has confirmed.
Everyone on the team can read it
Invite as many collaborators to a project as you want. Designers, PMs, and contractors can read a report and watch the recording without a seat license or a debugging background.
“Love the tooling! Our QA workflows and bug discovery has become 10X faster. The devs are able to cycle through loopholes much faster and delivery timelines have been enhanced”

Harshil Tomar
@Hartdrawss“Blown away by what Replay QA discovered for my solo startup, helped me identify and fix bugs that could potentially affect conversions.”

Peter Mick
@ThePeterMick“Connecting my GitHub repository took only a few seconds, and the first run uncovered issues across functionality, UX, and accessibility that would've been easy to miss manually.”

Kaitee
@KaiteeShiksSetup
Up and running in minutes
Connect the repo or drop in a URL
Add your GitHub repo URL and authenticate, or paste a URL directly. The Replay QA GitHub app installs itself. No config file, no test suite, no CI changes.
Verify you own the app
The first time you run a Security Scan on a web app, we'll walk you through a quick ownership verification. Security testing sends real attack traffic, so we only run it against apps you control.
Enable Security Scan
Turn on Security Scan in your project settings and choose when it runs — on every push, every PR, or on a schedule. Replay QA will run the full pentesting pass alongside your standard QA.
Findings land in your tracker
Each security finding arrives with the vulnerability description, reproduction steps, severity rating, and a suggested fix. When the run came from a pull request, Replay QA comments on that PR directly.
Not ready to connect a repo? Point it at a staging or production URL to see it in action.
Frequently asked questions
Questions about how it works? See the full breakdown.
Find the vulnerabilities before your users do.
Run a Security Scan against your app. It takes minutes to set up and works on any live web app — no security expertise required.
No credit card. Ownership verification required.
Need to run this across many projects? Talk to us or see plans.