Skip to content
BugLight

Find the bugs nobody wrote a test for.

Point BugLight at an OpenAPI spec or a running app. It decides what to test, runs it, reports findings.

A BugLight inspection of the sample API orders-api, showing each discovered endpoint, the number of scenarios generated for it, and whether the run produced a finding.
orders-apiv2.4.1openapi.jsonSample data
  • GET/v2/orders
  • POST/v2/orders
  • GET/v2/orders/{id}
  • PATCH/v2/orders/{id}/status
  • DELETE/v2/orders/{id}
  • GET/v2/customers/{id}/orders
6 of 6 endpoints inspected85 of 86 scenarios held1 finding

Code generation got faster.Verification did not.

AI assistance changed how quickly a team can produce working code. It did not change the work of deciding what to test, writing those tests, and keeping them current as the software moves underneath them. That work is still done by hand, by the same people, at the same speed.

So the distance between what a team ships and what a team has actually verified grows with every release. BugLight is built on a plain reading of that: when software is produced faster than it can be checked, the checking has to become autonomous too.

Three methods, one platform.

BugLight inspects software the way a lab inspects a part it cannot take apart. Each method enters from a different side of the same application, and all three report into the same place.

GET
POST
PATCH

API testing

From a specification

Give BugLight an OpenAPI or Swagger specification and a target URL. It discovers the endpoints, generates scenarios for them, executes those scenarios, validates the responses, and reports what did not hold.

How it works

Exploratory interface testing

From a running application

An AI-driven browser agent explores a running web application on its own: navigating it, discovering the flows a user could take, interacting with the interface, and collecting evidence when something behaves unexpectedly.

How it works

Security testing

From the outside in

The same autonomous approach turned on the security surface, so interface, API, and security testing report into one platform instead of three separate tools and three separate backlogs.

How it works

What a run actually involves

  1. You supply the target

    For API testing, an OpenAPI or Swagger specification and the URL it runs at. For interface testing, a reachable web application and a test account if it needs one.

    openapi.json

    https://api.example.com

  2. BugLight decides what to test

    It reads the specification or explores the running application, works out the endpoints and flows that exist, and generates the scenarios itself. Nobody writes them by hand.

    86 scenarios from 6 endpoints

    none written by hand

  3. You get findings, not a log

    Each finding states what was expected, what actually happened, the steps that reproduce it, and the evidence collected along the way.

    expected against actual

    steps, evidence, analysis

BugLight reduces the amount of test code a team writes and maintains by hand. It does not remove the need for a team that understands its own software, and it is not a claim that manual testing disappears.

What BugLight hands back

A finding is meant to be actionable without a second investigation. This one came out of an exploratory run against a sample storefront.

BL-4471HighStorefront checkoutExploratory browser agentSample data

Checkout accepts an order containing a zero-quantity line item

Expected

Setting a line item quantity to 0 removes the item. With no purchasable items, checkout is blocked.

Actual

The line item stays in the cart at quantity 0, the subtotal recalculates to 0, and the checkout button stays enabled. The order is accepted.

Evidence collected

cart.subtotal
0.00

The cart priced itself correctly, so nothing downstream looked wrong.

checkout.enabled
true

The guard reads cart length, and a zero-quantity line still counts as one.

order.status
confirmed

The order reached the backend and was accepted with nothing in it.

Steps to reproduce

  1. 1Sign in and add any two items to the cart
  2. 2Set the quantity of the first line item to 0
  3. 3Set the quantity of the second line item to 0
  4. 4Continue to checkout and confirm

Analysis

Quantity is validated on the line item input but not again when the cart is submitted. The checkout guard tests for an empty cart array, and a zero-quantity item keeps the array non-empty.

The AI layer can run on hardware you control.

BugLight’s AI layer can work with local models. An organization can run AI-assisted testing without sending its application data, internal information, workflows, or company documents to a third-party cloud AI provider.

Where privacy requirements, security restrictions, regulated data, confidential intellectual property, or on-premise rules apply, that is often the difference between AI-assisted testing being usable and being off the table. Finance, defense, healthcare, government, telecommunications, and enterprise software all live with some version of it.

How the private deployment works

Shipped, being built, and where it is headed

These three are kept apart on purpose. Nothing in the second or third column is something BugLight does for you today.

Available today

  • API testing from an OpenAPI or Swagger specification and a target URL
  • Endpoint discovery, scenario generation, execution, and response validation
  • Status codes, response schemas, error handling, boundary and edge cases, rate limiting, and timeout behavior
  • An AI-driven browser agent that explores a running web application and reports what it finds
  • Security testing, working the same application from the outside and reporting into the same place
  • An AI layer that can work with local models

In development

  • Deeper analysis of why a run failed rather than only that it failed
  • Running all three methods against one application as a single coordinated pass

Where this is going

  • BugLight learning a company's own context: requirements, acceptance criteria, architecture documentation, past results, past bugs, and past fixes
  • Moving from whether software technically works toward whether it behaves the way this company defines correct
  • A quality layer that gets more specific to a company the longer it runs there

The founding team

BugLight is early, and it is being built by four people who would rather show you the product than talk about it.

  • Alper Solmaz
  • Bengü Özbek
  • İrem Cengiz Solmaz
  • İzzet Ahmet

Straight answers

What do I have to give BugLight before it can start?

For API testing, an OpenAPI or Swagger specification and the URL the API runs at. For interface testing, a web application it can reach and a test account if the flows you care about sit behind a login. You are not writing test scenarios first.

Does this replace the test suite we already have?

No. BugLight is aimed at the tests nobody had time to write: the scenarios, edge cases, and flows that sit outside your existing coverage. Your own suite keeps encoding the behavior you have deliberately decided to pin down.

Which AI models does it run on?

The AI layer can work with local models, which is what allows a run to stay inside infrastructure you control. Hosted models remain available for teams with no restriction on them.

Can I use it for security testing?

Yes. Security testing is one of the three methods, and it reports into the same place as the other two, so security findings do not end up in a separate tool and a separate backlog. Bring the surface you care about to the demo and we will show you what it does with it.

How mature is each part of the product?

API testing is the most mature. Exploratory interface testing works and is earlier in its life. Security testing is the newest of the three. Company-specific quality intelligence is a long-term direction and not something you can use yet.

What does BugLight not do?

It does not remove the need for a team that understands its own software, and it does not promise the end of manual testing. It also has no knowledge of your company yet: today it evaluates whether software works, not whether it behaves the way your organization defines correct.

Bring us something you have not had time to test.

An API with a specification, or a web application we can reach. We will run BugLight against it and walk you through whatever it finds, including the runs where it finds nothing.