Functional and regression
Flows that carry money and data, such as sign-up, login, cart, checkout and cancellation, are tested end to end.
SendTheCanary is an independent testing team that systematically stresses web, mobile and API products before they go live. Every finding is delivered with reproduction steps, a screen recording and a severity level.

SendTheCanary is an independent software testing service founded in 2021 by three test engineers. The core team defines the scope, the test plan and the report; testers living in their own geographies try the scenarios on their own devices. It does not write code, sell consulting or apply fixes: it finds, documents and reports. Because the party that finds the bug is not the party that fixes it, verification stays independent.
Hours 0–4. Which services, how many platforms, which devices; start from a ready-made package or build the scope by hand. Output: a scope summary. Sign-up is free.
Hours 4–12. Payment is taken only when the scope is approved. The core team writes the test plan; what will not be tested is also stated in writing.
Hours 12–72. The number of assigned testers, their devices and which scenario they are on right now are live in the panel. Every verified finding lands in the panel without waiting for the report; a daily summary is sent.
Hours 72–84. A prioritized inspection report and PDF, signed by a named person. Every finding includes reproduction steps, video and a console log.
Hours 84–120. When a fix is released, verification is requested from the panel; closed and unclosed items are updated in the same place. One round in Discovery, two in Release.
Flows that carry money and data, such as sign-up, login, cart, checkout and cancellation, are tested end to end.
On the device-browser matrix derived from your user analytics, on real devices and real browser versions.
Core Web Vitals measurements, slow-connection scenarios and staged load testing with k6.
Based on the OWASP Top 10: authorization bypass, horizontal and vertical privilege escalation, session management, insecure direct object references and input validation. It does not replace a penetration test.
Endpoints are validated against the schema; error codes, boundary values and concurrency are stressed.
Keyboard, focus order, screen reader and contrast are tested by hand against WCAG 2.2 AA criteria.
Let’s evaluate the user structure, integration needs and, if any, options to adapt it to your brand.
The inspection report is delivered at hour 72; in the Release and Fleet packages the first report arrives in 48 hours. The remaining time is the verification round for your fixes. If a critical finding comes up, we do not wait for the report; you are notified immediately.
Web, mobile and API products. There are ten service headings: functional, regression, compatibility matrix, performance and load, security audit, API, payment, accessibility, usability and localization. You choose which ones you want in the panel; the outputs are combined in a single report.
No. The audit focuses on authorization, session and input validation weaknesses based on the OWASP Top 10; it targets the common and costly mistakes at the application layer. A comprehensive penetration test is a separate engagement.
Every finding comes with reproduction steps, a screen recording, a console log, environment details and a severity level. Findings land in the panel before the report is finished; in the Release and Fleet packages they are pushed directly to Jira or Linear.
There are three standard packages: Discovery (one product, one test, 72 hours), Release (the whole product, three platforms, pre-launch) and Fleet (regression on every release, monthly, six-month commitment). For regulated industries, the Enterprise option comes with a custom SLA. Sign-up is free; payment is taken only when you approve the scope.