QualGent
QualGent is an autonomous mobile QA platform for iOS and Android teams. Its closed loop turns real-world bugs into reusable regression tests, then routes each check to an AI agent, a coding agent, or a human tester.
What is QualGent?
QualGent is an autonomous quality assurance platform for iOS and Android applications, published by QualGent, Inc. in San Francisco. It positions itself as closed-loop QA for AI-built software, or in its own words, the quality flywheel for AI-built software, where every bug, fix and test result makes the next release smarter. The premise it states is that AI accelerates code faster than teams can verify it: generative interfaces break scripted tests, functional checks miss how a release actually feels, and manual QA does not scale. Three products form one system. TrustLoop works shift-right: it captures bugs from real usage and turns a session into a structured report carrying video, device, OS, region, screen flow, reproduction steps, screenshots, notes and a candidate test case, pushed into Notion, Jira, Linear or Slack. DevLoop works shift-left: it exposes an MCP server of 28 tools and 3 skills that plugs into Claude Code, Cursor, Copilot Workspace or any MCP-capable agent, so a coding agent can verify what it just wrote. QualGent Enterprise fans work out, sending exploratory, ambiguous and high-risk flows to human testers while smoke tests and regressions go to agents, then consolidates everything in a release readiness dashboard whose dispatcher learns which test needs which kind of verification. The home page frames the cycle in five stages: Capture, Convert, Verify, Fan out, Learn. Execution is agentic. Test steps are written in plain English and the agent drives the application with taps, typing and scrolling, and can read one-time passwords by SMS. Two modes exist: agent, with full AI reasoning, and cached run, a deterministic replay. A REST API v1 at api.qualgent.ai exposes apps, test cases, jobs, devices and categories, authenticated with an X-Api-Key header and scoped per organization. The company describes its architecture as multi-agent orchestration, vision-language reasoning over the UI, deterministic execution engines, structured tool use and enterprise security controls. QualGent was founded in 2025, went through Y Combinator's Spring 2025 batch, and dates its milestones V1 to May 2025, V2 to June 2025 and V3 to December 2025.
What it does
- Capture a mobile bug during real usage and turn it into a structured report with reproduction steps
- Convert a captured bug into a reusable regression test case
- Let a coding agent tap, type, scroll, inspect and verify flows on real devices and simulators
- Route each test to the right verifier: AI agent, human tester, real device or simulator
- Consolidate human and AI results into a single release readiness view
- Trigger test runs from a CI/CD pipeline and fail the build when a test fails
- Check the available credit balance before queueing a batch of jobs
When to use QualGent / When not to
A quick filter to help you decide if QualGent is the right fit.
When to use QualGent
- Mobile teams shipping frequently on iOS and Android that need regression coverage able to keep up with the release pace
- Engineering teams working with coding agents such as Claude Code, Cursor or Copilot Workspace who want changes verified before code review
- Founders, product managers and UX leads who want bugs found by beta testers and real users turned into reusable regression tests
- QA managers who need to arbitrate between AI verification and human judgement on ambiguous or high-risk flows
- DevOps and platform engineers wiring real-device test runs into GitHub Actions, CircleCI or Jenkins pipelines
When not to use QualGent
- Teams whose priority is accessibility testing: the terms explicitly exclude WCAG, Section 508, screen reader and assistive technology coverage
- Products with non-English interfaces, since QualGent states its AI capabilities are optimized for English and may be inadequate for internationalization, localization, RTL languages and non-Latin character sets
- Security teams looking for penetration testing or vulnerability scanning, which the acceptable use policy forbids outright
- Anyone wanting to test an application they do not own or have no written authorization to test, or to run tests against live production data without internal guardrails and approvals
- Buyers who need self-service purchasing and a published price list, because every commercial path goes through a sales demo
How to use QualGent
A typical end-to-end flow, from setup to results.
- Create an account on app.qualgent.ai and sign in to the dashboard
- Generate an API key under Settings then Developer, and keep the qg_ token in an environment variable; revocation takes effect within 30 seconds
- Upload a build with POST /v1/apps/upload (APK, IPA or AAB) and keep the returned app_file_id; files of 32 MB and above are split server-side into 8 MB chunks, transparently for the caller
- Call GET /v1/devices just before submitting, since the pool only returns devices free at that moment, grouped into phones and tablets
- Check the balance with check_credits before queueing: a batch of 10 jobs consumes 10 credits and the API returns 402 before creating anything if the balance is insufficient
- Launch runs with POST /v1/test-cases/run, up to 10 jobs per request, targeting specific test case identifiers or a whole suite filtered by category; omit app_file_id and the API uses the latest uploaded build
- Follow progress from queued to running with 0 to 100 completion, then passed, failed or completed, polling every 15 seconds at most to respect the limit of 10 requests per second
- Open the run at app.qualgent.ai/test-runs/{id} to read the execution trace, step-by-step screenshots and the plain-language failure explanation
- For SMS or OTP flows, filter devices on sms_enabled and set use_sim on the job
- Connect the DevLoop MCP server to your coding agent so its 28 tools appear in the agent toolbox, or wire the same upload, run and wait sequence into CI using the documented GitHub Actions example, failing the job when a test fails
Pros & Cons
Pros
- The loop really closes: one bug becomes a report, a regression test and memory that feeds the next verification pass
- Verification runs on real devices and simulators, not on emulators alone
- A native MCP server lets coding agents test what they have just written without leaving their environment
- Explicit arbitration between AI and human verification instead of blanket automation on flows where judgement matters
- Documented API with firm operational guarantees (atomic batches, credit pre-checks, rollback, published rate limits) and readable traces: setup, act and verify plan, step-by-step execution, screenshots and plain-language failure explanations
- Native integrations with the ticketing, source and CI tools teams already run: Jira, Linear, Slack, Notion, GitHub, GitLab, ClickUp, GitHub Actions, CircleCI and Jenkins
- Documented security posture (TLS 1.2+ in transit, encryption at rest, RBAC with MFA and SSO, network segmentation, code review and dependency scanning), with the option to restrict testing to emulators and simulators for stricter requirements
Cons
- No public pricing whatsoever: no pricing page, no amount, no announced free plan, and a mandatory sales demo before any figure appears
- Credit model in which consumption rates and prices can change on 30 days' notice, with purchased credits expiring 12 months after purchase
- QualGent owns the Service Outputs and the Usage Data, and those outputs are not intended to be shared widely
- Models are trained on interactions with customer applications with no documented opt-out, and embeddings and vector representations are kept indefinitely
- Real-device runs are executed on third-party device fleets that QualGent neither owns nor controls, with a potentially different security level
- No GDPR section, no EU representative, no disclosed hosting country or region, and no certification displayed, neither SOC 2 nor ISO 27001
- AI capabilities are optimized for English with coverage declared possibly inadequate elsewhere, no accessibility testing, and a very young company: domain registered in March 2025, first Wayback capture on 17 March 2025, around ten people
Pricing & Plans
QualGent publishes no pricing. There is no pricing page, no amount anywhere on the site and no pricing entry in its sitemap, so neither a lowest price point nor a currency can be stated. No free plan and no free trial are announced, and the site does not state that none exists either. Commercial terms are set in a negotiated Order Form, the only commercial entry point being the Book Your Demo form. Consumption is metered in credits: a batch of ten jobs consumes ten credits, and the API returns 402 Payment Required before creating anything when the balance is insufficient. Purchased credits expire twelve months after purchase, on a first-in first-out basis, and QualGent may change consumption rates, credit prices and feature costs with thirty days' notice. Invoices are payable within thirty days unless stated otherwise, fees are non-refundable and non-creditable, late payments carry interest at the lower of 1.5% per month or the legal maximum, taxes other than QualGent's own income taxes are borne by the customer, and terms renew automatically for twelve-month periods unless notice of non-renewal is given thirty days before the term ends.
- the offer is structured as three products rather than as pricing tiers
- bug capture from real usage
- presented for founders
- product managers
- UX and QA
- MCP server and verification for engineers and coding agents
- AI and human fan-out with a consolidated release readiness view
- presented for engineering leaders and QA teams
- Commercial terms are agreed individually through a negotiated Order Form
- including a dedicated agency Order Form
- architecture diagrams
- penetration test summaries and vendor security questionnaire responses
- The default parallelism quota of 10 concurrent jobs per batch can be raised on request through support
Data, GDPR & hosting
A consolidated view of how QualGent handles your data.
GDPR overview
QualGent's privacy policy contains no GDPR section: no legal bases, no European data subject rights such as access, rectification, erasure or portability, no international transfer commitments and no standard contractual clauses. The rights it details are US state rights only: California (Civil Code 1798.83-1798.84), Nevada, Colorado, Connecticut, Montana, Oregon, Texas, Utah and Virginia. Under those laws QualGent describes itself as a processor or service provider when it handles data for a business customer, its obligations being governed by the Data Processing Agreement with that customer. No EU representative under Article 27 is designated, no data protection officer is named, and privacy@qualgent.ai is the sole contact. The only occurrence of the word GDPR on the site is in the acceptable use policy, about customer apps handling children's data. A DPA exists on request; the policy carries no effective date. European buyers must obtain GDPR commitments contractually.
Who owns the data?
QualGent's terms split ownership three ways. The customer keeps all rights, title and interest in the applications it submits for testing, and grants QualGent only a non-exclusive license to access, copy and create derivatives of those builds so they can run in its test simulators. QualGent owns the Service Outputs, meaning the evaluations and reports produced for the customer, and licenses them back perpetually and irrevocably for internal use only; they are not intended to be published or widely shared. QualGent also owns all Usage Data, including execution data, bug reports, screenshots, results, interactions, embeddings and derived data, with the customer's applications and code excluded, and retains every right in the Services themselves.
Reuse rights
Reuse is asymmetric. Reports and evaluations can be used freely inside the customer's own organization under a perpetual, irrevocable, non-exclusive license, but they are not intended for publication or wide distribution, so sharing them outward is not a permission the terms grant. On QualGent's side, permission is granted up front: identity and profile data, mobile test data (APK, AAB and IPA builds, screenshots, screen recordings, logs, flows, bug reports), test credentials and API tokens, repository and CI/CD data, marketing and web analytics, device and IP data and cookies are collected to deliver and improve the service, meter credit consumption, personalize, secure the platform, market it, meet legal obligations and train QualGent's AI models. Interactions with customer applications, UI structures, user flows, application behavior patterns, bug patterns, screenshots and testing outcomes explicitly feed model training; application binaries explicitly do not. Data is de-identified before entering training sets, and aggregated or anonymized data can be reused and shared onward without further notice. Sharing also covers hosting, AI/ML, security, support and payment vendors, third-party real-device fleets, marketing, advertising and analytics partners, platforms the customer connects such as GitHub, legal obligations and any business transfer. Cookies used are essential, functional and performance or analytics cookies, and Do Not Track signals are not honored. For enterprise customers, the Data Processing Agreement prevails over the privacy policy.
Data retention & training
Hosting summary
QualGent names no hosting country and no hosting region anywhere on its site. The privacy policy refers to Cloud Infrastructure Providers for hosting and processing without naming them, and no nominative sub-processor list is published. What the documentation does distinguish is where tests run: emulators and simulators run on QualGent's own cloud servers, while real-device runs are executed on third-party device fleets that QualGent neither owns nor operates. Customers with stricter security requirements can ask for testing to be restricted to emulators and simulators. The stated protections are TLS 1.2 or above in transit, standard encryption at rest, role-based access control with MFA and SSO, firewalls, intrusion detection and prevention, network segmentation and DDoS protection. On the infrastructure side, the domain resolves to 216.239.32.21, a Google LLC anycast node in the United States, but that describes the marketing site, not where customer data lives. The publisher is QualGent, Inc., a Delaware corporation based in San Francisco, so US jurisdiction applies by default. Any data residency requirement will have to be answered contractually, through the Data Processing Agreement.
Things to keep in mind
Risks and trade-offs to weigh before adopting QualGent.
- The Service Outputs and the Usage Data belong to QualGent, not to you: reports about your own product come back as an internal-use license, not as property
- Your application interactions feed model training with no documented opt-out, and derived embeddings are kept indefinitely, so what is distinctive about your interface and flows can outlive your contract
- Real-device runs pass through third-party device fleets that QualGent neither owns nor operates, and builds, test data and credentials travel there too
- Never point the agents at production data or production credentials: the acceptable use policy requires it and QualGent disclaims liability for misconfiguration
- Credits expire after 12 months, consumption rates and prices can change with 30 days' notice, and terms renew automatically for 12-month periods unless you give notice 30 days before the term ends
- No GDPR section, no Article 27 representative and no disclosed hosting country, while disputes go to binding AAA arbitration in San Francisco, conducted in English
- Delegating verification can quietly erode a team's own testing judgement: a plain-language pass or fail from an agent is easy to trust and hard to audit, and the privacy policy shows no effective date, so you cannot tell since when the current rules apply
Setup & Integrations
Technical difficulty
Two different levels. TrustLoop needs no technical skill: start a recording, reproduce the problem, and the report is generated. The API and CI path is light but real engineering: create an account, generate an X-Api-Key under Settings then Developer, then upload, run and poll over HTTP, with cURL, Python and Node.js examples and a complete GitHub Actions workflow. Connecting the DevLoop MCP server takes one connection before its 28 tools appear in the agent toolbox. Rigor matters on key rotation, 15-second polling, credit checks and back-off on 429. Nothing is installed locally: devices and simulators come from the platform.
Deployment
Integrations
Supported languages
Behind QualGent
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Which platforms does QualGent test?
Does QualGent offer an API?
How much does QualGent cost?
Does QualGent train its models on my data?
Can I opt out of model training?
How long are my files kept?
Is a Data Processing Agreement available?
Is QualGent GDPR compliant?
How do coding agents use QualGent?
How do I plug QualGent into my CI pipeline?
Should you pick QualGent?
QualGent is young, and it shows in both directions. The domain was registered in March 2025, yet the product already has a clear shape: three coordinated offers, a documented REST API, an MCP server of 28 tools and a stated architecture of multi-agent orchestration running on real devices. The idea carrying it is simple and unusually coherent, namely that a bug should not merely be closed but become a regression test and, beyond that, memory the next verification pass can use. That makes it a strong fit for mobile teams that ship often, already work with coding agents, and want to capitalize on the defects their users and beta testers find. Elsewhere the reservations are concrete. There is no public pricing, so evaluation cannot begin without a sales conversation. QualGent owns the Service Outputs and the Usage Data. Models are trained on interactions with customer applications with no documented opt-out, and derived embeddings are kept indefinitely. The privacy policy addresses US state law only and never mentions the GDPR, which leaves a European buyer to negotiate that ground alone. Credibility is real: co-founders who came from Google, Y Combinator's Spring 2025 batch, several funds behind the company. But credibility is not a contract. Before buying, ask in writing for the credit terms, the Data Processing Agreement and the hosting countries, none of which the site publishes. Read those answers next to the ambition and the tool becomes much easier to judge.
- Choosing a selection results in a full page refresh.
- Opens in a new window.