AppCheck by Opsenium

Hands-on QA for software built quickly

An experienced software practitioner works through your app as your users will, drawing on hands-on experience building, testing and operating production software. AppCheck is a three-hour manual review, not an automated AI scan. You receive a clear, prioritised report and a focused recheck after you apply the fixes.

  • Three hours with an experienced reviewer
  • Report within two working days
  • 30-minute recheck included

£300 fixed price

Tell us about your app

No payment until we confirm your product is suitable. See an example report

AppCheck reportIllustrative example
Product
Ledgerly (fictional)
Environment
Staging, web
Testing
3 hours, exploratory
Roles
Owner, staff, client

Risk summary

  • High1 finding
  • Medium3 findings
  • Low4 findings

Prioritised findings

  1. HighRepeated submission creates duplicate records
  2. MediumUpdated permissions are not applied until a new session begins
  3. LowValidation errors are not announced to assistive technology
Opsenium Ltd · AppCheckSummary, page 1 of 11
Illustrative example. The product, findings and figures are fictional.

What an experienced reviewer looks for The review follows real journeys, including the awkward ones.

AI-assisted development tools, low-code platforms and small teams make it possible to ship a working product quickly. The normal paths soon become familiar to the person building it, which makes rough edges and missing safeguards harder to see.

A fresh reviewer arrives without that context. They work through the important journeys as a user would, then explore the careless, impatient and unexpected paths that expose defects.

  • Repeated actions

    A double click, a slow connection or a browser refresh creates a second order, invoice or account.

  • Roles and permissions

    A user sees or changes something that belongs to another role, or keeps access after it was removed.

  • The unhappy path

    Expired sessions, invalid input and failed payments end in a blank screen, a lost form or a misleading message.

  • Small screens

    The journey that works on a laptop cannot be completed on a phone.

  • Data that disagrees

    Totals, statuses and counts differ between screens, or change without explanation.

  • Signals of carelessness

    Personal data in page addresses, detailed error messages, or other people’s records one edit away.

Who AppCheck is for Founders and business owners who want a hands-on review before customers or employees rely on their product.

A good fit

  • Founders and business owners who built a product quickly, with AI-assisted development tools, a low-code or no-code platform, or conventional development
  • Small teams without a dedicated tester who want a hands-on review before customers rely on the product
  • Internal tools about to be rolled out to employees
  • Products approaching a launch, a pilot with a first customer, an investor demonstration or a funding round
  • Agencies and independent developers who want a second pair of eyes before handover

Probably not the right fit

  • Products that need specialist hardware, physical devices or on-site access
  • Work that requires a penetration test, a compliance audit or formal certification
  • Very large products where three hours would cover too little to be useful
  • Products that cannot be accessed safely without real customer data or permanent administrator credentials

Not sure? Submit the questionnaire. If AppCheck is not suitable we will say so before any payment, and release your date.

What the three hours cover. A risk-based review of the whole product. We cover as much of the following as is relevant, in the order that matters most for your users.

  • Core user journeys

    The three to five journeys that matter most, end to end.

  • Functional defects

    Things that do not do what they should.

  • Error handling and edge cases

    Invalid input, interruptions, retries and empty states.

  • Data consistency

    Records, totals and statuses that agree across screens.

  • Authentication and user roles

    Sign-in, sessions and what each role can see and change.

  • Confusing or risky usability

    Where users are likely to make mistakes or give up.

  • Mobile and responsive behaviour

    Layouts and journeys on representative screen sizes.

  • Accessibility basics

    Keyboard use, labels, contrast and announced errors.

  • Visible performance and reliability

    Slow screens, timeouts and intermittent failures.

  • Security and privacy observations

    Obvious warning signs visible from the product itself.

  • Customer trust

    Behaviour likely to make a customer doubt the product.

Security and privacy observations are warning signs visible from using the product as its users would. AppCheck does not attack your systems or attempt to bypass their controls.

What we check against. Six standards and guidelines. Each has its own section in your report, with its own findings.

  1. Accessibility

    WCAG 2.2 AA

    Keyboard use, focus, labels, error messages, contrast and zoom on your main journeys. Each finding references its success criterion.

  2. Privacy and cookies

    UK and EU GDPR, PECR and ePrivacy

    Whether tracking waits for consent, and whether privacy information is shown where personal data is collected.

  3. AI transparency

    EU AI Act, Article 50

    Whether people are told when they are interacting with an AI system, and whether AI-generated content is labelled where required.

  4. Search (SEO)

    Google Search Essentials

    Whether your pages can be found and indexed: titles, descriptions, headings, structured data, sitemap and robots.txt.

  5. AI search (GEO)

    AI search readiness

    Whether AI assistants such as ChatGPT, Perplexity and Google’s AI answers can read and cite your content: text without JavaScript, schema.org markup and crawler access.

  6. Performance

    Core Web Vitals

    Loading, responsiveness and layout stability on your key pages, measured against Google’s thresholds.

Findings are what we observe from using your product within the three hours. They are not a compliance audit, a certification or legal advice.

How AppCheck works. Seven steps, one date. You choose the review date in the questionnaire; payment confirms it.

There is no separate booking step.The date you select is held while we assess your request, and is yours once payment is received.
  1. Tell us about your app

    Complete the short AppCheck questionnaire. It takes a few minutes.

  2. Choose a provisional review date

    Select one of the currently available dates.

  3. We assess suitability

    Your date is held provisionally while we review your request, normally within one working day.

  4. Pay to confirm the date

    If your product is suitable, you receive a £300 Stripe-hosted payment link. Payment within 48 hours, and no later than 24 hours before the review, confirms the date you chose.

  5. We perform the review

    Once you have paid, you tell us the journeys and roles that matter most, and access is arranged separately and safely. You do not attend.

  6. Receive the report

    Your prioritised PDF report is delivered within two working days of the review date.

  7. Request the included recheck

    Reported fixes can be rechecked for up to 30 minutes, requested within 30 days.

What you receive. A prioritised report that shows what to fix first and why.

Deliverable
A branded, prioritised PDF report
Delivery
Within two working days of the confirmed review date
Recheck
One focused 30-minute recheck of the reported findings, requested within 30 days
Price
£300 fixed, paid through a Stripe-hosted payment page. Stripe sends the receipt.

Inside the report

  • Engagement and product details
  • Executive summary
  • Overall risk observations
  • Scope and limitations
  • Areas tested
  • Prioritised findings with severity
  • A section for each standard checked, with its own findings
  • Affected journey or area for each finding
  • Reproduction steps
  • Screenshots or other evidence where useful
  • User or business impact
  • Practical recommended action
  • Areas not tested
  • Recheck status

What a finding looks like. Every finding says where it happens, what should happen, what does, why it matters and what to do about it.

This page is an illustrative example for a fictional product. Real reports follow the same structure, with evidence such as screenshots where it helps.

AppCheck reportIllustrative example
Product
Ledgerly (fictional)
Environment
Staging, web
Testing
3 hours, exploratory
Roles
Owner, staff, client

Executive summary

The core invoicing journey works for a single careful user. The main risks appear under real conditions: repeated actions, changed permissions and slower connections. One high-severity finding should be fixed before paying customers are invited.

Risk summary

  • High1 finding
  • Medium3 findings
  • Low4 findings

Standards checked

  • WCAG 2.2 AA2 findings
  • UK and EU GDPR, PECR and ePrivacy1 finding
  • EU AI Act, Article 50Not applicable
  • Google Search Essentials1 finding
  • AI search readiness2 findings
  • Core Web VitalsWithin thresholds

Prioritised findings

  1. F-01High

    Repeated submission creates duplicate records

    Affected journey
    Create and send an invoice
    Expected
    Pressing Send once, or again while the first request is in progress, sends one invoice.
    Actual
    Pressing Send twice within about a second created two invoices with consecutive numbers, and the client received both.
    Impact
    Clients are asked to pay twice. Invoice numbering has gaps once one is voided, which complicates bookkeeping.
    Recommended action
    Disable the button while the request is in progress and make the create operation idempotent on the server.
  2. F-02Medium

    Updated permissions are not applied until a new session begins

    Affected journey
    Remove a staff member’s access
    Expected
    When an owner removes a staff member’s access to client records, the change applies immediately.
    Actual
    The staff member could still open and edit client records until they signed out, around 40 minutes later in testing.
    Impact
    Access that has been removed remains usable, which matters most when someone leaves the business.
    Recommended action
    Check permissions on each request rather than only at sign-in, or end active sessions when roles change.
  3. F-03Low

    Validation errors are not announced to assistive technology

    Affected journey
    Sign up and verify email
    Expected
    When a field is invalid, the error is linked to the field and announced by screen readers.
    Actual
    Errors appear visually in red text but are not associated with their fields, and nothing is announced.
    Impact
    People using screen readers cannot tell why sign-up fails.
    Recommended action
    Associate each message with its field using aria-describedby and move focus to an error summary.
Opsenium Ltd · AppCheckFindings, page 3 of 11
Illustrative example. The product, findings and figures are fictional.

Scope and exclusions. A clear, fixed scope keeps the price fixed.

What AppCheck includes

  • One product and one supplied build or environment.
  • An agreed set of priority journeys and user roles.
  • Three hours of risk-based exploratory testing.
  • A prioritised PDF report within two working days of the review date.
  • One 30-minute recheck, requested within 30 days of the report, covering the original findings only.
  • No payment is requested until suitability is confirmed, and the date is provisional until payment.
  • Payment within 48 hours of acceptance, and no later than 24 hours before the review.
  • One free reschedule with at least 48 hours’ notice.

AppCheck is not

  • A penetration test
  • A formal security audit
  • A compliance certification
  • A complete accessibility audit
  • A source-code audit
  • Exhaustive testing of every screen, role, device or permutation
  • A guarantee that no defects remain

Products that need specialist hardware, prohibited access or substantially different expertise may be declined. Changes with less than 48 hours’ notice, or access that is not working on the review date, may result in the loss of the slot.

Never send credentials with your request.Do not submit passwords, API keys, permanent administrator credentials or customer data. Once your date is confirmed we agree a safe access method with you, normally temporary test accounts on a staging or test environment.

Read the AppCheck service terms

Questions. If yours is not answered here, email hello@opsenium.com.

What kinds of products can AppCheck review?

Web applications, mobile apps and desktop applications that we can access remotely: customer-facing products, internal tools, portals, marketplaces and software-as-a-service products. The product and our communication need to be in English.

Is AppCheck only for AI-built or “vibe-coded” apps?

No. AppCheck suits any product built quickly or by a small team, whether with AI-assisted development tools, a low-code or no-code platform, or conventional development. What matters is that an experienced reviewer has worked through it manually, rather than relying on an automated AI scan.

What happens after I submit the questionnaire?

Your selected date is held provisionally and you receive a confirmation email with your reference. We assess your request, normally within one working day. We then accept it and send a payment link, ask you a clarifying question, or explain why it is not a good fit.

Is my selected date confirmed immediately?

No. The date is held for you while we assess the request, and nobody else can select it. It becomes a confirmed booking when payment is received.

When do I pay?

Only after we confirm that your product is suitable. You receive a Stripe-hosted payment link for £300, and payment within 48 hours, and no later than 24 hours before the review, confirms your date. Stripe sends the receipt. No payment is taken through this website.

What if my product is unsuitable?

We tell you, explain why where we can, and release your provisional date. You will not have paid anything.

Do I attend the testing session?

No. The review is carried out asynchronously by someone with hands-on experience building, testing and operating production software. You need to be reachable by email in case something blocks testing, but you do not need to attend.

What access does Opsenium require?

Usually a staging or test environment and a temporary test account for each role in scope. We agree a safe method with you after payment. Please never send passwords, API keys, permanent administrator credentials or customer data through the questionnaire or by ordinary email.

Does AppCheck confirm that we comply with WCAG, GDPR or the EU AI Act?

No. The report has a section for each standard we check against, with the findings for that standard, so you can see where you stand and what to fix. It is an observation from using your product, not a compliance audit, a certification or legal advice. For a formal accessibility audit or a legal view, use a specialist.

Is this a penetration test?

No. AppCheck includes security and privacy observations: obvious warning signs visible from using the product. It is not a penetration test, a security audit or a compliance certification, and it does not involve attacking your systems.

Will AppCheck find every defect?

No. Three hours of risk-based exploratory testing focuses on the journeys and risks most likely to affect your users and your business. The report states what was tested and what was not, so you can decide what needs more attention.

What happens if the product is too large for three hours?

We focus on the priority journeys and roles you give us, and the report lists the areas not tested. If the product is clearly too large for three hours to be useful, we will say so during assessment, before any payment.

When will the report arrive?

Within two working days of the confirmed review date, as a branded PDF.

What does the recheck include?

Up to 30 minutes rechecking the findings in your report after you have applied fixes. Request it within 30 days of receiving the report. The recheck covers the original findings only, not new exploratory testing.

Can I reschedule?

Yes, once and free of charge with at least 48 hours’ notice, subject to another date being available. Changes with less notice, or access that is not working on the day, may mean losing the slot.

Can customers outside the UK buy?

Yes. AppCheck is available worldwide where the product and our communication can be in English. The price is £300 in pounds sterling, paid through Stripe.

Put your app in front of an experienced reviewer.

Tell us about your product and choose a provisional review date. It takes a few minutes, and no payment is taken until we confirm that AppCheck is suitable.

Example report

See how findings are prioritised and explained.

View the example

Privacy

How we handle the information in your request.

Read the privacy notice