Panto AI
Panto AI is an agentic mobile QA platform from Singapore: describe test flows in plain English, run them on 150+ real Android and iOS devices with self-healing tests, then pair it with an AI code review and security agent.
What is Panto AI?
Panto AI is a software development lifecycle platform published by PANTO AI PTE. LTD., a Singapore company founded in 2024 and led by founder and CEO Pavan Kamat. The vendor positions it as a Wall of Defence bringing together two products: agentic mobile QA and AI code review.
The QA side, featured on the home page, promises autonomous testing for mobile apps across 150+ real devices, with a swarm of agents crawling workflows around the clock. You describe a feature in plain English, an AI agent executes the flow on the app, and the system generates a deterministic Appium or Maestro script that can be replayed on any device, any version, at any time through integrated device farms. Three named building blocks structure the work: Execute plays a natural-language test case step by step and asks clarifying questions when it needs them, Automate converts a successful run into an automated test on a proprietary framework, and Knowledge Base stores application context written in plain English so the agent's understanding improves over time.
Panto AI states explicitly that its automation layer does not rely on Playwright, Appium or Selenium, but on an in-house framework described as agnostic to language, operating system, device and LLM. Self-healing is central: when the interface changes, elements are identified by context, structure and visual cues instead of brittle selectors, the failing step is repaired on the fly, the final script is rewritten, and a full audit trail records what was healed. Tests run on real hardware rather than emulators: Pixel 9 on Android 14 and 15, Galaxy S23 Ultra, iPhone 16 Pro on iOS 18. Native Android and iOS, hybrid, WebView, React Native and Flutter apps are supported, as are Unity, Unreal Engine and Roblox games, which render to canvas with no DOM and no accessibility tree. Runs also collect app health data: memory, cold and warm start, CPU, FPS, frozen frames, battery, network, crashes and ANRs, tracked run after run.
The second product reviews code: automatic pull request summaries, chat on comments, custom rules and reinforcement learning across GitHub, GitLab, Bitbucket and Azure DevOps, with 30+ languages and 30,000+ security checks, and claimed figures of 500+ developers and 5M+ lines reviewed. Under the hood, LLMs are combined with fine-tuned small language models, AST and LSP analysis, SAST, static analysis and deterministic rules, plus visual screenshot analysis and XML hierarchy parsing for UI understanding.
What it does
- Describe a mobile user journey in plain English and have an agent execute it step by step on a real device
- Turn an executed flow into a reusable automated test without writing a line of code
- Run the same suite in parallel across 150+ real Android and iOS device and OS combinations
- Let the agent repair tests broken by a UI change on its own, with an audit trail of what was healed
- Export the tests as deterministic Appium or Maestro scripts
- Trigger runs from CI/CD, a pull request, a webhook, an API call or Slack, and get back logs, videos, screenshots and root-cause analysis
- Have every pull request reviewed by the code review agent and the code scanned for security issues (SAST, secrets, IaC)
When to use Panto AI / When not to
A quick filter to help you decide if Panto AI is the right fit.
When to use Panto AI
- Lean mobile QA teams with no dedicated time for maintaining automation scripts
- Fast-shipping product teams — FinTech, quick-commerce and consumer apps releasing weekly or daily — that need regression coverage inside a short release window
- Product managers, QA leads and other non-developer profiles who need to author tests themselves in plain English
- Mobile game studios building on Unity, Unreal Engine or Roblox, where there is no DOM and no element ID for classic selector-based tools to target
- Engineering organizations that also want AI pull request review and code security scanning on GitHub, GitLab, Bitbucket or Azure DevOps
When not to use Panto AI
- Teams looking for web or browser test automation: the QA documentation covers mobile applications only, and the vendor positions the product as built mobile-first
- Buyers whose procurement requires a published privacy policy, terms of service or data processing agreement before a pilot — none of these documents exists on the site
- Organizations that outgrow the free plan (15 test flow runs, five minutes per run) but cannot absorb the 999 USD per month QA Scale plan, since nothing is offered in between
- Individuals looking for a consumer mobile app: this is a platform for engineering teams, designed primarily for QA engineers and developers, and its advanced features (dynamic code review, security scans, test case customization) require basic technical understanding
- Teams that need Jira or Confluence synchronization on the QA side today — the documentation still describes those integrations as being developed
How to use Panto AI
A typical end-to-end flow, from setup to results.
- Try the browser Playground first if you want to watch the agent work with no device and no installation
- Upload your mobile build (.apk or .ipa) by drag and drop into the dashboard, or through the Upload Build File API
- Describe the journeys you want to protect in plain English — sign-up, login, search, onboarding, forms, navigation, payment — either step by step or in a single block
- Answer the agent's clarifying questions (credentials, input values) and interrupt the run whenever you need to add context
- Watch Panto Execute play the flow on a real device, then save the successful run and push it into automation with Panto Automate
- Enrich the Knowledge Base with plain-English context about your app so the agent navigates it more reliably
- Create API tools (REST calls with headers, JSON body and expected status code) or read-only SQL tools, then call them inside a prompt by typing @
- Run the suite in parallel across the real-device and emulator matrix, triggered from CI/CD, a pull request, Slack, a webhook, an API call or one-click scheduling
- Install the PantoAI QA Bridge desktop app (Windows, Linux .deb and .rpm, macOS Intel and Apple Silicon) to run the same tests on your own devices connected by USB or Wi-Fi
- Read the reports — crash traces, screenshots, videos, per-step logs and root-cause analysis — in the dashboard or in Slack
Pros & Cons
Pros
- No-code test creation that non-developers can genuinely use — the BukuWarung customer story credits the GUI with unblocking an automation backlog
- 150+ real devices available in one click, with no device lab to provision, and coverage of Unity, Unreal Engine and Roblox that the vendor's own comparison table presents as unmatched
- Self-healing is claimed to cut test maintenance by more than 70%
- Deterministic, exportable output (Appium, Maestro) avoids lock-in to an unreadable proprietary format
- Documented and audited security posture: ISO/IEC 27001:2022, CERT-IN code audit, AES-256, MFA, RBAC and per-tenant isolation, with an explicit commitment not to train models on customer data
- A permanent free plan and an install-free browser Playground make evaluation possible before any commitment, with no credit card required
- Public documented API plus CI/CD, pull request, webhook and Slack triggers, and dedicated, on-premise or private cloud deployment (Azure, AWS, GCP or custom) on the Enterprise plan
Cons
- No privacy policy and no terms of service are published: the usual URLs all return 404 and are absent from the sitemap, leaving the security page as the only quasi-legal document
- No postal address, no contact page and no contact form; the only channel shown is a support email hosted on a third-party domain (support@pantomax.co)
- No data processing agreement is offered or even mentioned anywhere on the site
- The third-party device farms that actually execute the tests are not named — the vendor states plainly that it does not name them publicly
- A wide gap between the free plan (15 test flow runs, five minutes per run) and the first paid QA plan at 999 USD per month, with no self-service tier in between
- No hosting country is named, only the Azure region selected by the customer, and code review pricing is not in the pricing page's HTML — it only appears once JavaScript has run
- A young company (domain registered in March 2025, pre-seed announced in July 2025) whose history is centred on code review, with mobile QA as the newer half, two separate documentation worlds coexisting, and Jira and Confluence integrations still described as being developed on the QA side
Pricing & Plans
Panto AI follows a freemium model, with a permanent free plan on each product and quotation-based Enterprise tiers. The lowest paid entry point on the platform is Panto Code Review at 20.00 USD per developer per month billed annually (23 USD billed monthly), rising to 24 USD per developer per month for Code Review with Code Security (28 USD monthly). Mobile QA starts considerably higher: the free Go plan costs 0 USD, and the first paid tier, Scale, begins at 999 USD per month billed annually (1,149 USD monthly) before device and run add-ons. Annual billing is advertised as saving up to 15%, and no credit card is required to start.
- free
- 0 USD. 15 test flow runs
- five minutes maximum per run on a shared real device
- unlimited local runs
- dynamic variables
- AI root-cause analysis
- reporting
- Slack alerts
- from 999 USD per month billed annually
- 1
- 149 USD billed monthly
- for 250 test flow runs and one dedicated real device. Sliders raise it to 2
- 500 runs (+300 USD per additional 250 runs) and 10 parallel dedicated devices (+200 USD per device). Unlimited real-device minutes
- everything in Go plus CI/CD integration
- on quotation. Custom integrations
- dedicated or on-premise deployment on Azure
- AWS
- GCP or a custom cloud
- 24/7 priority support
- SSO and advanced security
- 20 USD per developer per month billed annually
- 23 USD billed monthly. Unlimited pull request reviews
- customizable rules
- per-repository and per-developer reports
- 24 USD per developer per month billed annually
- 28 USD billed monthly. Everything above plus 30+ languages
- 30
- 000+ checks
- custom security rules
- SAST
- secret detection
- IaC and static analysis
- on quotation. Self-deployment in a private cloud
- custom API and CI/CD integrations
- compliance audit reports
- SAML SSO
- audit logs
Data, GDPR & hosting
A consolidated view of how Panto AI handles your data.
GDPR overview
Panto AI displays a GDPR and CCPA compliance badge on its security page and states that it acts as a data processor while customers retain ownership of their data. It is ISO/IEC 27001:2022 certified, has undergone a CERT-IN code audit by an empanelled auditor, and describes a SOC 2 Type 2 attestation as still in progress. Listed technical measures include FIPS-compliant AES-256 encryption at rest including backups, TLS in transit, mandatory MFA for administrative access, Azure RBAC, SAML and OAuth SSO through Microsoft Entra ID, and an incident response plan aligned with NIST SP 800-61. Data localization requests are accepted. The claim rests entirely on that single page, however: no privacy policy, terms of service or data processing agreement is published, no data protection officer or Article 27 EU representative is named, and no postal address appears anywhere on the site.
Who owns the data?
The only document addressing data governance is the security page; no terms of service and no privacy policy are published. It states that customers retain ownership of their data and that Panto AI positions itself as a data processor acting on their behalf. Each customer sits in an isolated tenant — separate storage containers or databases, no shared database — and can consult its own audit logs from the dashboard, showing who accessed which report and when. Customers are responsible for uploading only authorized builds and for keeping secrets out of them. The publisher warns that any uploaded data or APK is also visible to its support team during troubleshooting.
Reuse rights
The security page lists what the platform ingests: application artefacts (customer APKs, build metadata such as version, name and package), test execution data (run identifiers, configurations, device details, steps and results), application, device, network, crash and session logs and metrics (CPU, memory, battery, temperature, frame rate), media captures (screenshots, screen recordings and video streams when enabled), workflow context (prompts, responses, environment variables, agent memory and state), integration and account metadata including secrets, configuration, team, workspace, identity and roles, and aggregated historical reports. The stated purpose is narrow: run tests on real devices, debug, and produce reports and analytics on demand. The publisher declares it never mines this material or uses it to train general AI models, and never shares it outside the scope of testing; AI assistants work on an ephemeral basis, with the input and output of each session or run isolated rather than aggregated for learning. External device farms receive the APK and the test instructions over encrypted channels as service providers under mutual confidentiality agreements, with no right to keep or reuse builds beyond execution — but they are not named publicly. No training opt-out is documented, which is consistent with a publisher that claims not to train at all.
Data retention & training
Hosting summary
Panto AI hosts its platform on Microsoft Azure. Data is stored in the Azure region selected by the customer, and the publisher states that it complies with data localization requests and can keep data within specified geographic boundaries when required. No country and no Azure region is named anywhere on the site, which is why the hosting country and region fields remain empty. Tenants are isolated through Azure Active Directory and separate subscriptions, with separate storage containers or databases and no shared database. Encryption is FIPS-compliant AES-256 at rest, backups included, and TLS/HTTPS in transit. A shared responsibility model is stated explicitly: Microsoft secures the infrastructure, Panto AI secures its own usage and software. Test execution partly leaves that perimeter, since unnamed external device farms receive the APK and the test instructions over encrypted channels. Enterprise customers can obtain a dedicated or on-premise deployment on Azure, AWS, GCP or a custom cloud. Note that the site's resolved IP address (76.76.21.21, Amazon AS16509, an anycast node) belongs to the marketing site's CDN and says nothing about where the platform itself runs.
Things to keep in mind
Risks and trade-offs to weigh before adopting Panto AI.
- Neither a privacy policy nor terms of service are published, so nothing contractually fixes retention periods, data subject rights or the liability regime — everything rests on a single security page the publisher can rewrite at any time
- No postal address appears anywhere on the site and the legal identity is visible only in the footer copyright (PANTO AI PTE. LTD.), which makes formal notice or a claim harder to serve
- The support address shown in the footer sits on a third-party domain (support@pantomax.co) rather than on getpanto.ai, and one home-page FAQ answer points to hello@getopanto.ai, a visibly misspelled domain that should not be used; the security address security@getpanto.ai is on the right domain
- The security page warns that any uploaded data or APK is fully visible to the vendor's support team during troubleshooting, so builds carrying real personal data, production credentials or hard-coded secrets should be kept out of the platform
- No data processing agreement is offered: ask for one before running tests on apps that process real personal data, bearing in mind that the device farms executing those tests are not named
- SOC 2 Type 2 is described as ongoing, not obtained — it should not be recorded as an existing attestation in a vendor questionnaire, and code review pricing only becomes visible after the pricing page's JavaScript has run
- The QA Bridge desktop app is not signed with an Apple certificate: macOS reports the app as damaged, and the documented workaround is to strip the quarantine attribute with xattr -c, a step your security team should approve first
Setup & Integrations
Technical difficulty
Low to start, moderate at team scale. Anyone can open the browser Playground with no device and no installation, and a first real run only requires dragging an .apk or .ipa into the dashboard; tests are written in plain English, so non-developers can author them. Two things raise the bar: installing the QA Bridge desktop app for local devices, which is unsigned on macOS and needs a documented xattr -c workaround, and wiring the platform into CI/CD, webhooks, the REST API, database connections or SAML SSO, which calls for an engineer.
Deployment
Integrations
Supported languages
Behind Panto AI
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Panto AI.
Frequently asked questions
Do I need to know how to code to create a test with Panto AI?
What do the tests actually run on?
What happens when the app's interface changes?
Does Panto AI run on Playwright, Appium or Selenium?
Is there an API, and can tests be triggered from CI?
Is customer data used to train AI models?
Where is the data hosted?
What certifications does Panto AI hold?
Is there a free plan?
How do I get my data deleted?
Should you pick Panto AI?
Panto AI is a technically dense product with unusually detailed functional documentation for a company this young. Its mobile QA half combines three things that rarely come together: a large pool of real Android and iOS devices rather than emulators, self-healing tests that survive interface changes, and deterministic output exportable as Appium or Maestro scripts, so the work done inside the platform is not locked into an unreadable proprietary format. Coverage extends to Unity, Unreal Engine and Roblox, which conventional selector-based tools cannot address. The second half of the product, AI pull request review and code security scanning, is the older of the two and speaks to the same engineering audience.
The structural weakness is legal rather than technical. No privacy policy, no terms of service and no data processing agreement are published; the security page alone carries the entire compliance discourse, and no postal address appears anywhere on the site. For a buyer whose procurement requires those documents before a pilot, that gap has to be closed by direct request. Two further reservations matter: the third-party device farms that actually execute the tests are not named, and SOC 2 Type 2 is presented as in progress rather than obtained.
Pricing is uneven as well. The free Go plan and the browser Playground make evaluation genuinely easy, and code review starts at 20 USD per developer per month, but the first paid QA tier jumps to 999 USD per month with nothing in between.
The natural fit is a mobile team that ships frequently, has no spare capacity for script maintenance, and can accept a young vendor. Evaluate on the free plan, then obtain the missing legal documents before sending any real user data through the platform.
- Choosing a selection results in a full page refresh.
- Opens in a new window.