Virtuoso QA

Best viewed on a larger screen

This interactive demo mirrors the full Virtuoso QA desktop interface, so it needs a wider screen to be readable.

Open it on a laptop or desktop for the full walkthrough, or continue here and pinch to zoom.

Virtuoso QA

See how Virtuoso QA works

Walk through a guided demo for a D2C retailer: load your Knowledge Base and see how an AI Analyst and an AI Architect turn PCI-DSS 4.0.1, the Consumer Rights Act, and DMCC pricing transparency guidance into requirements and human-approved test journeys covering add-to-cart, checkout, payment, and order processing.

The AI Autopilot then writes a deterministic Virtuoso NLP test, which runs with self-healing selectors - so every release has its checkout proven secure and compliant, not just delivered.

?
Project dashboard
Overview
Tags
Webhooks
Share
Tickets

Project dashboard

From the project dashboard you can create shiny new goals - a testing scope within a project.

?
Knowledge Base beta
🔍 Search for a source
Tags
Search tags
File type
Search file types
All (0)
Project (0)
🗂️

You have no active sources

The Knowledge Base is a centralised repository of sources that our agents can use to build your requirements from.

?
Knowledge Base beta
🔍 Search for a source
Tags
Search tags
File type
Search file types
All (6)
Project (6)
SourcesTagsLast change
Add-to-Cart, Checkout & Payment BRDNEW
ProjectBRD_Checkout_Payment.docx
008/09/2026, 09:14 PM
PCI-DSS 4.0.1 - Payment Page Script Control & Tamper Detection (Req 6.4.3 / 11.6.1)NEW
ProjectPCI-DSS-4.0.1-Req-6.4.3-11.6.1.pdf
008/09/2026, 09:14 PM
Digital Markets, Competition and Consumers Act (DMCC) - Pricing TransparencyNEW
ProjectDMCC-Pricing-Transparency.pdf
008/09/2026, 09:14 PM
Consumer Rights Act 2015 / Consumer Contracts RegulationsNEW
ProjectConsumer-Rights-Act-CCR.pdf
008/09/2026, 09:14 PM
European Accessibility Act (EAA)NEW
ProjectEuropean-Accessibility-Act.pdf
008/09/2026, 09:14 PM
UK GDPR / EU GDPRNEW
ProjectUK-EU-GDPR.pdf
008/09/2026, 09:14 PM
?
Requirements
Requirements
Requirement directives
RequirementsRiskCoverage
Checkout Negative ScenariosHIGH100%
Successful Discount and Cart CalculationCRITICAL-
Successful Order Placement and Evidence CaptureCRITICAL100%

PCI-DSS 4.0 - Payment-Page Integrity (6.4.3 / 11.6.1)

Organization-level directiveChanges apply to every project in the organisation unless overridden at the project level.
Content
Core instruction: apply PCI-DSS 4.0.1 payment-page script-control (Req 6.4.3) and tamper-detection (Req 11.6.1) requirements, alongside the Consumer Rights Act / Consumer Contracts Regulations, the European Accessibility Act, and DMCC pricing transparency guidance, when generating test requirements, test conditions, journeys, or test cases for any change to the checkout or payment page - using the uploaded regulatory documentation as a primary reference. For every requirement, user story, or business rule provided, the Analyst must: 1. Analyse the source material as a professional aligned to PCI-DSS 4.0.1, Consumer Rights Act, EAA, and DMCC obligations. 2. Derive clear, testable requirements confirming the payment page only executes authorised scripts and that any tampering is detected before payment submission. 3. For any change to the checkout or payment page, require evidence that the script inventory was checked against the authorised list and any deviation flagged - sufficient to satisfy PCI-DSS 4.0.1 Req 6.4.3 and 11.6.1 audit obligations. 4. Structure journeys and test cases around observable customer and auditor-facing outcomes, with clear objectives, preconditions, inputs, and expected results - including that pricing and discounts are presented transparently and the checkout remains accessible. 5. Justify key decisions with citations from the regulatory knowledge base - never inventing a citation. If none applies, the Analyst must say so explicitly. The Analyst must apply this guidance rather than merely quoting it, must analyse the underlying test basis rather than surface-level acceptance criteria, and must flag any gaps in the source documentation rather than silently filling them in.
Every release - checkout proven secure & compliant.
?
✨ New Requirements
💬 Chat history

Sources selected:

📄 Checkout & Payment BRD 📄 PCI-DSS 4.0.1 (Req 6.4.3 / 11.6.1) 📄 DMCC Pricing Transparency
AI can make mistakes!
?
✨ New Requirements
💬 Chat history

The existing requirements provide good coverage for the primary success paths. However, I identified three gaps not explicitly covered by the BRD:

  1. Add-to-Cart and Discount Calculation Validation (BR-002, BR-003) - not covered by the existing checkout-focused negative scenario.
  2. Payment-Page Script Integrity (PCI-DSS 4.0.1, Req 6.4.3 / 11.6.1) - the payment page must run only authorised scripts and detect tampering; not currently tested.
  3. Checkout Compliance and Order Processing Evidence - pricing transparency, accessibility, and order evidence must be addressed together; not addressed by existing functional tests.

I've generated three new requirements to close these gaps, applying the organisation's PCI-DSS 4.0 - Payment-Page Integrity (6.4.3 / 11.6.1) directive throughout.

Requirements preview (3)

?
Requirements
Requirements
Requirement directives
All 6
RequirementsRiskCoverage
Checkout Compliance and Order Processing EvidenceHIGH-
Payment-Page Script Integrity and Tamper DetectionCRITICAL-
Add-to-Cart and Discount Calculation ValidationMEDIUM-
Checkout Negative ScenariosHIGH100%
Successful Discount and Cart CalculationCRITICAL-
Successful Order Placement and Evidence CaptureCRITICAL100%

Checkout Compliance and Order Processing Evidence

Overview
Journeys 0
Summary

The purpose of this requirement is to ensure pricing and discounts are presented transparently per DMCC guidance, and that the checkout calculation itself completes within the 3-second threshold. It also confirms the checkout page remains accessible, and that order processing evidence includes a reference to the payment-page integrity check.

Description

Checkout Compliance and Order Processing Evidence Validation

This requirement validates that the checkout flow presents pricing transparently per DMCC guidance, remains accessible per the European Accessibility Act, and that order processing evidence is captured in a GDPR-compliant way.

?
🧭 New structured journeys
💬 Chat history

Requirement: Checkout Compliance and Order Processing Evidence

AI can make mistakes!
?
🧭 New structured journeys
💬 Chat history

I have designed five test journeys to validate the checkout compliance and order processing evidence requirement, as specified in this requirement.

These journeys cover:

  1. Response time for checkout calculation.
  2. The full add-to-cart, checkout, and payment flow end to end.
  3. Existence of an audit trail confirming the payment page's script inventory was checked before the order was processed.

I've created corresponding data tables to drive these tests and a new environment for the base URL. Please review the proposed journeys.

Journey structures preview (5)

PCI-DSS 4.0.1DMCCAccessibility
Goal
Checkout Compliance and Order Processing Evidence
Data table
Cart, Checkout & Payment Data
Environment
Retail & Direct-to-Consumer Storefront (UAT)
Journey
Add to Cart to Order: Checkout & Payment Page
Journey summary
This journey adds a product to the cart, applies a discount, completes checkout and payment, and asserts the payment page runs only authorised scripts and the resulting order is accurately evidenced, within the 3-second checkout-calculation threshold.
Checkpoints

Checkpoint 1: Add Product to Cart

Assuming the user is already logged in, go to the base URL, open the Products section, and click "Add to cart" to add an item to the basket.

    Checkpoint 2: Checkout, Pay, and Verify Payment Page

    Enter a discount code, then start timing. Click Checkout, wait for the total to recalculate, and stop timing once it's finished. Assert that checkout calculation completed in under 3 seconds, then proceed to payment and assert no unauthorised script is present on the payment page.

    ✓ 1 journey created successfully
    Goal: Checkout Compliance and Order Processing Evidence
    Retail & Direct-to-Consumer
    ← Back to journey list
    Journey 1 (Draft) : Add to Cart to Order: Checkout & Payment Page
    PCI-DSS 4.0.1DMCCAccessibility

    ✨ Autopilot · created

    ✨ How can I help with this journey?

    Describe what it should do and I'll write the checkpoints and steps for you to review.

    This journey already has 2 checkpoints. Want to change those instead? Describe changes you wish to make.

    Summary
    Timeline
    Tickets
    Journey summary

    This journey adds a product to the cart, applies a discount, completes checkout and payment, and asserts the payment page runs only authorised scripts and the resulting order is accurately evidenced, within the 3-second checkout-calculation threshold.

    NOT EXECUTED
    Assigned to:
    2 checkpoints
    17 steps
    0 extensions
    1 data table
    Journey plans

    There are no plans associated with this journey.

    Execution - Checkout Compliance and Order Processing Evidence
    08 September 2026, 11:58 PM
    Journey 1: Add to Cart to Order: Checkout & Payment Page running…
    Wait 30 seconds for "Products"
    Click on "Products"
    Wait 18 seconds for button "Add to cart"
    Click on button "Add to cart"
    Write $discountCode in field "Discount code"
    Summary
    Healed
    Journey side effects
    Tickets
    Execution in progress
    Execution is in progress…
    Execution - Checkout Compliance and Order Processing Evidence
    08 September 2026, 11:58 PM
    Journey 1: Add to Cart to Order: Checkout & Payment Page 00:01:05
    Wait 30 seconds for "Products"
    Click on "Products"
    Wait 18 seconds for button "Add to cart" 🩹 healed
    Click on button "Add to cart" 🩹 healed
    Write $discountCode in field "Discount code"
    Click on "Checkout"
    Assert performance measuring "Checkout Calculation" is less than 3000
    Summary
    Healed
    Journey side effects
    Tickets
    Summary report
    1 of 1 executions in 00:01:05
    1 passed
    Launched by:
    AT
    ⌘ Environment: UAT
    Congratulations! All your
    journeys are doing great!