Next-Gen Test Automation

TestForge

AI-Powered Audit Platform. Zero Code Access Required.

One URL. One Click. Complete CERT-In / STQC / VAPT Report.

The Problem

Every application needs security testing. But traditional approaches are broken:

💸

Expensive

CERT-In auditors charge ₹2-20L per audit. Small companies can't afford compliance.

Slow

Manual VAPT takes 2-6 weeks. Development cycles wait for audit reports.

🔑

Invasive

Auditors need source code, git access, server credentials. Clients hesitate.

🔄

One-Time

Audits are point-in-time. No continuous monitoring. Vulnerabilities emerge between cycles.

TestForge solves all four: Affordable. 15-second audits. Zero source code access. Continuous.

How It Works — The 15-Second Audit

🔗

Paste URL

Give us any URL. No SDK. No git. No source code.

🕵️

Auto-Crawl

Stealth browser discovers all pages, forms, flows, APIs automatically.

🧠

AI Analysis

Claude AI generates test cases + security checks specific to the app.

📊

Report Ready

Complete report: bugs, PII leaks, compliance score. Ready to share.

$ curl -X POST https://testing-bice-sigma.vercel.app/api/run-all \
-d '{"url":"https://your-app.com","name":"Client App"}'

# Returns in 15 seconds:
8 pages discovered 3 bugs found 42 AI test cases
162 compliance checks 6 PII leaks detected Report ready

Complete Feature Set

🛡️

Cloudflare Bypass

Stealth Playwright engine bypasses Cloudflare, WAF, bot detection. Test any protected site.

🔐

Multi-Step Auth

Handles login → OTP → admin password → dashboard. Any auth flow supported.

📝

CRUD Testing

Automatically fills forms, submits, verifies persistence. Tests data isolation between sessions.

🔍

PII Detection

Scans for Aadhar, PAN, mobile, email in HTML. Flags data exposure in plain text.

💳

Payment Gateway VAPT

Amount tampering, callback manipulation, checksum validation. Modeled after CyRAACS/HDFC audits.

🔒

Security Headers Audit

CSP, HSTS, XFO, nosniff, CORS, cookie flags. All 12 headers checked automatically.

🧠

AI Test Generation

Claude (OpenRouter) analyzes app and generates 7-42 test cases with detailed steps.

📊

5 Compliance Suites

STQC (39), VAPT (39), DPDP (27), CERT-In Localization (18), Payment Gateway VAPT (39) = 162 checks.

📧

Email Reports

Auto-delivers audit reports to client email. Reads email replies for additional credentials.

👥

Team Collaboration

Owner/Admin/Editor/Viewer roles. Invite by email. Multi-user project access.

🖥️

Admin Panel

Full CRUD: users, projects, reports, settings. Password-protected with ACL.

🚀

CI/CD Ready

GitHub Actions, Jenkins, GitLab CI templates. One-file setup, no SDK.

What Makes TestForge Unique

Features no other platform offers:

#1 Zero-Code-Access Testing

Every competitor requires SDK install, git access, or source code. TestForge needs only a URL. This is our core USP — no client ever shares their source code.

#2 Cloudflare & WAF Bypass

Stealth browser (playwright-extra) bypasses Cloudflare, Akamai, Imperva. No other testing platform can test Cloudflare-protected government portals automatically.

#3 Payment Gateway VAPT (CERT-In Standard)

39 test cases modeled after CyRAACS/HDFC Bank audits. Amount tampering, callback manipulation, checksum validation. No competitor offers this.

#4 5 Indian Compliance Suites in One Platform

STQC (e-Governance), VAPT (RBI/CERT-In), DPDP Act 2023, CERT-In Localization, Payment Gateway VAPT. 162 checks. Single click. No competitor covers Indian compliance.

#5 Automated PII Detection

Scans rendered HTML for Aadhar, PAN, mobile, email. Flags data exposure that even human auditors miss. Found 3 exposed Aadhar numbers on PSEB portal.

Competitive Comparison

FeatureTestForgemablTestimSauce LabsBrowserStackCypressGhost Inspector
Cloudflare Bypass✅ UniqueNoNoNoNoNoNo
Zero Code Access✅ URL onlySDK reqSDK reqSDK reqSDK reqCode reqPartial
AI Test Generation✅ Claude✅ ML✅ AINoNoNoNo
Payment Gateway VAPT✅ 39 testsNoNoNoNoNoNo
Indian Compliance (STQC/VAPT/DPDP)✅ 162 checksNoNoNoNoNoNo
PII Detection (Aadhar/PAN)✅ Auto scanNoNoNoNoNoNo
Multi-Step Auth✅ OTP+adminBasicBasicBasicBasicBasicNo
Cross-Browser✅ Chrome+FF+Safari✅ All✅ All
Visual Regression✅ AI-powered✅ PercyPlugin
Analytics Dashboard✅ Trends+Flaky+MTTRBasic
Price PointFree/self$250/mo$450/mo$39/mo$29/moFree OSS$89/mo
6 unique features No competitor offers in combination

Features Competitors Have (We Don't — Yet)

Honest gap analysis:

Tier 2 — Important (Q3 2026)

Test Recording

Browser extension: record user actions → auto-generate test steps. Playwright Codegen integration.

CI/CD Deep Integration

Native GitHub App. Auto-comment on PRs with test results. Status checks on commits.

Mobile Device Testing

Real device profiles via Playwright emulation. Already partially built.

Tier 3 — Nice to Have (Q4 2026)

Accessibility (axe-core)

Automated WCAG 2.1 AA compliance checking.

Performance/Lighthouse

Automated Lighthouse scores per page.

Load Testing

Concurrent user simulation with k6 integration.

✅ Recently Added (Now at Parity)

Cross-Browser (Chrome + Firefox + Safari), Visual Regression (AI-powered pixel diff), Analytics Dashboard (trends + flaky detection + MTTR)

Tier 2 — Important (Q4 2026)

Test Recording

Browser extension: record user actions → auto-generate test steps. Playwright Codegen integration.

CI/CD Deep Integration

Native GitHub App (not just templates). Auto-comment on PRs with test results. Status checks.

Mobile Device Testing

Real device profiles (iPhone, Pixel, Galaxy) via Playwright device emulation. Already partially built.

API Testing Engine

REST/GraphQL test steps. Assertion on status codes, response bodies, headers. Schema validation.

Tier 3 — Nice to Have (2027)

Accessibility (axe-core)

Automated WCAG 2.1 AA compliance checking.

Performance/Lighthouse

Automated Lighthouse scores per page.

Load Testing

Concurrent user simulation with k6 integration.

Infrastructure & Go-To-Market

Technology Stack

FrontendVanilla JS SPA, Inter font, CSS Grid/Flexbox
BackendExpress.js + PostgreSQL (Neon)
AI EngineOpenRouter (Claude) via kavachbrowser.com
Browser EnginePlaywright + Stealth on AWS EC2 (Mumbai)
HostingVercel (app) + AWS EC2 t3.medium (engine)
AuthJWT httpOnly cookies + 2FA TOTP
SecurityHelmet CSP, rate limiting, HSTS, XFO
EmailGmail SMTP/IMAP for reports + OTP

Target Market

Government

STQC mandatory for e-Governance. 162 compliance checks. PSEB already tested.

Banking/Fintech

RBI mandates VAPT via CERT-In auditors. Payment gateway VAPT built-in.

SaaS Companies

Continuous security monitoring. Weekly automated audits. Zero setup.

Audit Firms

White-label reports. Multiply auditor productivity 10x. Resell as managed service.

TestForge — The only platform that can audit any application with just a URL.

https://testing-bice-sigma.vercel.app | sumit.gilhotra@gmail.com