End-to-End SaaS QA Audit
Budget: $250 – $750 USD
I’m ready to give you full access to our live, multi-tenant transportation SaaS, and I need a complete quality audit finished as soon as possible—no later than 20 business days after the NDA is signed.
What I expect you to cover
• Functional depth first: 13 individual modules (booking, dispatch, driver tracking, pricing, invoicing, SMS/email marketing, and the rest) must be exercised in real-world workflows for all six user roles.
• Security with special focus on tenant-to-tenant isolation. Authentication, authorization, injection vectors, and PCI areas still need attention, but isolation is the non-negotiable baseline.
• Load and performance baselines under realistic concurrency.
• Usability feedback from the perspective of each role.
• Cross-browser verification (latest Chrome, Firefox, Safari, Edge) and true mobile coverage on real devices—not emulators.
• RESTful API verification for both happy-path and negative scenarios.
• Compliance spot-checks against GDPR, CAN-SPAM, TCPA, and WCAG 2.1 AA.
Deliverables
1. Test strategy document for all seven categories, including the tools you will employ (e.g., Postman, JMeter, Burp Suite, BrowserStack, real-device farm, etc.).
2. Daily progress log in a shared dashboard or Slack channel.
3. Defect tracker export with severity, repro steps, evidence (screenshots, HAR files, video where helpful).
4. Consolidated final report with executive summary, detailed findings, and clear remediation recommendations.
5. Fixed-price milestone breakdown you propose at kick-off.
Acceptance criteria
• No critical or high-severity issue left unresolved or without a mutually agreed mitigation plan.
• All mandatory compliance checkpoints evidenced.
• Performance targets documented with reproducible scripts.
Minimum profile I’ll accept
– 3+ years dedicated to SaaS QA.
– Current OSCP, CEH, or CREST certification (attach proof).
– Access to a range of real iOS and Android devices.
– Demonstrable GDPR experience.
When you respond
Send two recent project examples of comparable scope, mention the exact stack of tools you plan to use for each test category, attach a sample report, and outline your fixed-price schedule. A signed NDA will follow before credentials are shared.
What I expect you to cover
• Functional depth first: 13 individual modules (booking, dispatch, driver tracking, pricing, invoicing, SMS/email marketing, and the rest) must be exercised in real-world workflows for all six user roles.
• Security with special focus on tenant-to-tenant isolation. Authentication, authorization, injection vectors, and PCI areas still need attention, but isolation is the non-negotiable baseline.
• Load and performance baselines under realistic concurrency.
• Usability feedback from the perspective of each role.
• Cross-browser verification (latest Chrome, Firefox, Safari, Edge) and true mobile coverage on real devices—not emulators.
• RESTful API verification for both happy-path and negative scenarios.
• Compliance spot-checks against GDPR, CAN-SPAM, TCPA, and WCAG 2.1 AA.
Deliverables
1. Test strategy document for all seven categories, including the tools you will employ (e.g., Postman, JMeter, Burp Suite, BrowserStack, real-device farm, etc.).
2. Daily progress log in a shared dashboard or Slack channel.
3. Defect tracker export with severity, repro steps, evidence (screenshots, HAR files, video where helpful).
4. Consolidated final report with executive summary, detailed findings, and clear remediation recommendations.
5. Fixed-price milestone breakdown you propose at kick-off.
Acceptance criteria
• No critical or high-severity issue left unresolved or without a mutually agreed mitigation plan.
• All mandatory compliance checkpoints evidenced.
• Performance targets documented with reproducible scripts.
Minimum profile I’ll accept
– 3+ years dedicated to SaaS QA.
– Current OSCP, CEH, or CREST certification (attach proof).
– Access to a range of real iOS and Android devices.
– Demonstrable GDPR experience.
When you respond
Send two recent project examples of comparable scope, mention the exact stack of tools you plan to use for each test category, attach a sample report, and outline your fixed-price schedule. A signed NDA will follow before credentials are shared.