← Founder Ops

QA & VAPT (autopilot)

Quality assurance + vulnerability checks before scale. Agent charter: .cursor/autopilot/qavapt.md · checklist: docs/QA_VAPT_CHECKLIST.md (repo).

Automated (CI / local)

  1. ./scripts/security-smoke.sh: client secret hygiene, IPN gate, admin RPC auth
  2. ./tests/e2e_smoke.sh: build + auth modules + worker compile
  3. ./scripts/verify-activation-path.sh: after P0 green
  4. ./scripts/check-plan-intent.sh · ./scripts/check-seo-content.sh: production funnel/SEO
  5. ./scripts/verify-activation-path.sh --partial: signup → deploy (no worker)
  6. ./scripts/guide-partial-e2e.sh: founder manual partial E2E steps
  7. ./scripts/check-parallel-growth.sh · ./scripts/check-sales-ready.sh
  8. ./scripts/check-qa-parallel.sh: security + XSS + partial activation + sales (worker blocked)
  9. ./scripts/check-xss-hygiene.sh: /app esc() patterns
  10. ./scripts/guide-qa-founder-standup.sh: combined parallel QA playbook
  11. ./scripts/guide-founder-growth-standup.sh: all role standups combined · quick: ZT_QUICK_GROWTH_STANDUP=1
  12. ./scripts/guide-founder-parallel.sh: all parallel playbooks

Probing production IPN gate…

While worker is blocked

Automated QA you can run now (no trades required):

Trust path before checkout: deploy → View evidence → /app#forward · Index: docs/FOUNDER_PARALLEL.md · ./scripts/check-growth-goal.sh

  1. E2E activation, signup → deploy → trades (partial steps 1–2 OK while worker down; View evidence → /app#forward)
  2. RLS isolation: second account must not see first user's trades (/app)
  3. Pro checkout, tier flip only via signed IPN
  4. Review docs/QA_VAPT_CHECKLIST.md: mark Q1–V3