QA DNA makes security testing part of every release

QA DNA builds, runs and maintains release-grade test coverage inside its customers' development cycles, so fast-moving software teams can ship often without hiring an in-house automation team. Customers own the test code; QA DNA provides the platform, the engineers and the upkeep.

By Petru Kovaci Every release

Quality across every release is their business, and they wanted security held to the same standard: not an annual exercise, but a check that runs alongside each release.

The practical obstacle was cadence. Traditional penetration testing is scoped and scheduled weeks in advance, which does not line up with teams shipping every sprint.

Testing that fits inside the release window

A full baseline test established the reference point. After that, each release candidate triggers a test, with release notes shared so effort concentrates on what changed while the core surface is still re-checked.

Results come back within four hours, validated and prioritised, which is fast enough for the release decision to be made with security data in hand rather than delayed until it arrives.

A gate, not a report nobody reads

Any follow-up work is re-tested before the release ships, and Intrudify issues a sign-off that QA DNA attaches to its release record. Every quarter, a broader test covers the full surface and reviews accumulated changes together.

Results arrive with reproduction steps and fix guidance in the format QA DNA's engineers already use for defects, so they slot into the existing workflow instead of needing a translation step.

Our clients ship constantly. We needed pentesting that could keep up, and this actually does.

Liana Stoian, CEO, QA DNA

The outcome

Security sign-off is now a line in QA DNA's release checklist alongside functional and performance results. The schedule has held since March 2026, which means the team can show customers that security is held to the same bar as every other quality check.

Join the Future of
AI-Driven Pentesting