New — Security Scan

Replay QA now does penetration testing.

Security Scan runs a full pentesting pass against your web app — injection flaws, broken access control, IDOR, cross-tenant data exposure — the vulnerabilities that AI-written code introduces at scale.

No credit card. Ownership verification required.

What you get

Bug reports that read like a real pen test finding

Each security finding comes with a full breakdown: what the vulnerability is, how it was discovered, what an attacker could do with it, and exactly what to fix.

The problem

AI coding agents write insecure code at scale.

AI coding tools can build a working web app in hours. What they can't do is apply the security intuition that takes years of pen testing experience to develop. The models optimize for functionality — they produce code that works, not code that resists attack.

The result is a new class of vulnerability pattern. IDOR flaws appear when agents generate API endpoints that fetch resources by ID without checking who's asking. Broken access control shows up when role logic is inconsistent across routes written in different sessions. Injection surfaces when inputs are assembled into queries without the sanitization a security-aware developer would add instinctively.

These aren't edge cases — they're systematic. And because AI-generated codebases ship fast, they reach production before anyone runs a security review.

How Replay QA works

An agentic testing harness that works like a swarm of QA testers

Most QA tooling starts with flows your team defines. Replay QA begins by exploring the application and identifying flows worth verifying.

  1. 1

    Explore

    Agents map the app, quickly discover user journeys, and work through them the way a new QA hire would in their first week.

  2. 2

    Test & Record

    Agents then write tests that they run while puppeting your app in our Chromium browser, capturing deterministic runtime recordings of every session.

  3. 3

    Investigate & Report

    Our QA agents look for bugs across a range of types: deep runtime bugs, UI glitches, accessibility issues, performance problems, and security vulnerabilities — including security scanning for injection, access control, and business logic gaps. They deliver robust bug reports with a root cause and a suggested fix.

Learn more about how it works.

How it fits your workflow

It runs where your team already works

Replay QA hooks into GitHub, comments on pull requests, and files into the tracker you already use. Nobody has to adopt a new tool to get the benefit.

Connect a repo, then forget it

Add your GitHub repo and authenticate. The Replay QA GitHub app installs itself and runs a new pass whenever your codebase changes: every push to main, every pull request, or both. No config file, no CI changes.

Set your testing schedule

Run Replay QA on every push, every PR, or on a fixed schedule. Daily or weekly runs let your team wake up to a fresh batch of issues — ready for coding agents to work through before the day starts.

Test across every environment

Point a project at dev, staging, production, or localhost. Switch environments in settings or manage them via the REST API. Consistent QA coverage no matter which environment you're looking at.

Every pull request gets checked

PR runs test against your preview deployment and post the root cause and suggested fix as a comment on the pull request, next to the diff that caused it.

Bugs land in your tracker

Not another dashboard nobody opens. GitHub Issues, Linear, Jira, or any endpoint that accepts a webhook. You control whether everything gets filed or only what Replay QA has confirmed.

Everyone on the team can read it

Invite as many collaborators to a project as you want. Designers, PMs, and contractors can read a report and watch the recording without a seat license or a debugging background.

Love the tooling! Our QA workflows and bug discovery has become 10X faster. The devs are able to cycle through loopholes much faster and delivery timelines have been enhanced
Harshil Tomar

Harshil Tomar

@Hartdrawss
Blown away by what Replay QA discovered for my solo startup, helped me identify and fix bugs that could potentially affect conversions.
Peter Mick

Peter Mick

@ThePeterMick
Connecting my GitHub repository took only a few seconds, and the first run uncovered issues across functionality, UX, and accessibility that would've been easy to miss manually.
Kaitee

Setup

Up and running in minutes

1

Connect the repo or drop in a URL

Add your GitHub repo URL and authenticate, or paste a URL directly. The Replay QA GitHub app installs itself. No config file, no test suite, no CI changes.

2

Verify you own the app

The first time you run a Security Scan on a web app, we'll walk you through a quick ownership verification. Security testing sends real attack traffic, so we only run it against apps you control.

3

Enable Security Scan

Turn on Security Scan in your project settings and choose when it runs — on every push, every PR, or on a schedule. Replay QA will run the full pentesting pass alongside your standard QA.

4

Findings land in your tracker

Each security finding arrives with the vulnerability description, reproduction steps, severity rating, and a suggested fix. When the run came from a pull request, Replay QA comments on that PR directly.

Not ready to connect a repo? Point it at a staging or production URL to see it in action.

Frequently asked questions

Security Scan sends real attack traffic — actual injection payloads, crafted requests designed to test access control, probes that look exactly like what an attacker would send. That's what makes it accurate. But it also means we need to be certain you're authorized to test the target. Ownership verification is how we confirm that.

Questions about how it works? See the full breakdown.

Find the vulnerabilities before your users do.

Run a Security Scan against your app. It takes minutes to set up and works on any live web app — no security expertise required.

No credit card. Ownership verification required.

Need to run this across many projects? Talk to us or see plans.