Your first users should not be your first testers

A BetterQA tester's hands typing on a white keyboard beside an open laptop
AI agents build exactly what the requirement says, bad requirements included. How we test AI-generated code, and free security audits for 10 companies shipping it.

We paid for a press release on 17 September. The news in it is that we are giving ten security audits away. The argument underneath it is the part worth reading, so here it is in our own words rather than the wire’s.

Code is arriving faster than anyone can check it. That much is uncontroversial. What people get wrong is where the bottleneck sits now, because it is not the writing. An agent will build what you ask for, quickly and faithfully. Ask for the wrong thing and you get the wrong thing, built correctly, at speed, sitting in the product from the first commit.

Code review does not catch that. There is too much of it to read properly, and once a codebase outgrows what one person can hold in their head it breaks where nobody thought to look. Two scheduled jobs that have never met each other, colliding at 3am.

“Everybody’s vibe coding now, but nobody’s testing everything that vibe coding produces. You no longer need developers as much, but you need people to test what AI agents are outputting before you send that to real humans. The human is the bottleneck, because the AI will implement the requirement if the requirement is good. Most of the time the requirements are not good. We ensure that the client’s first users are not also their first testers.”

Tudor Brad, founder

What we check it with

Five tools, all built in-house, because the off-the-shelf ones were not keeping up:

  • BugBoard turns a screenshot into a bug report and test cases.
  • Flows is test automation that repairs its own tests when the interface changes.
  • The security toolkit runs and correlates around 20 open-source security scanners in one pass, including the OWASP LLM Top 10.
  • Auditi checks pages against WCAG.
  • BetterFlow tracks where the hours went, per task.

The security one matters more than it used to. Code written by a model needs checks a functional suite was never designed for: prompt injection, and data exfiltration through a model that will cheerfully tell an attacker what it knows. A green regression suite says nothing about either. We run those checks inside the engagement instead of selling security separately.

Tudor puts a shelf life on the whole category: relevant “for roughly the next two to three years, until AI systems become reliable enough to verify their own output.” It is the gap between what a model can build and what a model can check, and the gap is wide right now.

How engagements start

Two weeks, free, before we invoice anything. You get the team and the tools against your own codebase, and you decide from there.

Ten free security audits

We are running the security toolkit over ten companies shipping AI-generated code, at no cost: SAST, DAST, SCA and the OWASP LLM Top 10.

The terms do not move:

  • Mutual NDA signed before any work starts.
  • You own the systems being audited, or you hold documented authorisation to have them audited. No authorisation, no audit.
  • We need code access or access to a running environment, arranged under that NDA.

What it is not: a penetration test, a certification, or an attestation. There is no badge at the end. You get findings describing what the toolkit found on the systems you gave us, which is not a guarantee that your systems are secure and not a claim that there is nothing else to find.

Ten is a capacity figure rather than a deadline. Details and how to apply are on the free security audit page, or email [email protected] directly.

Where the release ran

The announcement went out as a paid press release on AB Newswire on 17 September 2026. Wire syndication carried it to FinancialContent, openPR and other outlets.

About BetterQA

BetterQA is an independent software testing company, founded in 2018 by Tudor Brad and Ana Brad and based in Cluj-Napoca, Romania. We hold ISO 9001, ISO 27001:2022, ISO 14001 and ISO 13485 certification, and we are members of the Avetta Consortium. We work with clients across 24+ countries and hold 64 Clutch reviews averaging 4.9 out of 5.

Need help with software testing?

BetterQA provides independent QA services across manual testing, automation, security audits, and performance testing. ISO 27001, 9001, 14001 and 13485 certified.

Share the Post: