Skip to main content

Help us improve the Digital Marketplace - send your feedback

Pi Digital Solutions

Helix Autonomous QA

Helix is an autonomous AI‑driven QA platform that automatically creates, executes, and maintains browser‑based tests from user stories. It delivers self‑healing automation, real‑time insights, and seamless Jira/Azure DevOps integration to improve quality, accelerate releases, reduce manual effort, and ensure resilient, scalable testing across digital services.

Features

  • AI‑driven test creation directly from Jira or Azure user stories.
  • Self‑healing automation automatically updates tests when application interfaces change.
  • Real‑time execution logs with full browser visibility and diagnostics.
  • Parallel, scalable test execution across cloud or on‑prem environments.
  • Seamless integration with Jira, XRAY, Azure DevOps, and CI/CD pipelines.
  • Autonomous test maintenance reducing manual scripting and upkeep significantly.
  • Secure deployment options on Azure, AWS, GCP, or on‑premises.
  • Comprehensive reporting including coverage, risk indicators, and performance analytics.
  • Visual browser inspection for accurate UI understanding and validation.
  • API‑driven architecture enabling automated workflows and enterprise system integrations.

Benefits

  • Accelerate release cycles by automating test creation and execution instantly.
  • Reduce manual QA effort by removing the need for scripting.
  • Improve service reliability through continuous, autonomous test maintenance.
  • Identify defects earlier with real‑time visibility into outcomes.
  • Increase test coverage by generating scenarios directly from user stories.
  • Minimise downtime by rapidly detecting and self‑healing broken tests.
  • Enhance collaboration by integrating seamlessly with Jira and Azure DevOps.
  • Scale testing effortlessly across multiple cloud or on‑prem environments.
  • Strengthen governance with audit‑ready logs and transparent test reasoning.
  • Boost team productivity by freeing staff from repetitive QA tasks.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at vanessa.pieterse@pidigitalsolutions.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 6 7 4 7 5 6 2 4 1 9 0 5 2 1

Contact

Pi Digital Solutions Vanessa Pieterse
Telephone: 07908882595
Email: vanessa.pieterse@pidigitalsolutions.com

About your service

Service categories

Application Development and Deployment

Software quality and life cycle

  • Automated software quality
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Helix QA integrates with common development and test management platforms such as Jira, XRAY, Azure DevOps and CI/CD tools. It does not depend on any other software service and can operate as a standalone SaaS platform.
Cloud deployment model
Hybrid cloud
Service constraints
Helix QA is provided as a SaaS platform and requires access to supported cloud or private cloud environments. The service integrates with common development and test management tools and is limited to supported configurations as set out in the Service Definition. Planned maintenance may require temporary service unavailability, which is communicated in advance where possible. Support is provided during UK business hours in line with the selected licence tier.
System requirements
  • Linux‑based operating system supporting containerised workloads
  • Container runtime such as Docker or compatible alternative
  • Container hosting or orchestration platform (managed or self‑managed)
  • Secure outbound network connectivity to Helix Planning API
  • Access to supported large language model services via Helix platform
  • Modern web browser for Helix QA user interface
  • TLS‑enabled networking and standard enterprise firewall configuration
  • Integration access to Jira or Azure DevOps (optional)

User support

Email or online ticketing support
Yes
Support response times
Within 24 hours, tickets are triaged based on priority.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes, at an extra cost
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We have conducted foundational accessibility testing using screen readers (NVDA and VoiceOver), keyboard‑only navigation, and colour‑contrast validation tools to ensure the webchat is usable without a mouse and readable by assistive technologies. While we have not yet run sessions with real assistive‑technology users, our approach follows WCAG 2.2 AA requirements
Onsite support
Yes, at extra cost
Support levels
Helix QA Support Model
1. Lite Support (Included in Lite Licence Fee)
Price: Included in £1,500/month licence
Environments: 1 environment (e.g., Test)
Support Channels:
Email support only
Self‑service documentation
SLA: 24‑hour response
Phone Support: Not included
Assigned Roles: None (self‑service)

2. Standard Support (Included in Standard Licence Fee)
Price: Included in £2,500/month licence
Environments: Up to 4 environments (e.g., Dev, Test, UAT, Prod)
Support Channels:
Email support
Phone support included
Access to documentation
SLA: 24‑hour response
Assigned Roles:
Cloud Support Engineer (CSE) available for escalation
No dedicated Technical Account Manager

3. Premium / Enterprise Support (Included in Premium Licence Fee)
Price: Included in £4,000/month licence
Environments: Unlimited environments
Support Channels:

Priority email support
Phone support included
Option for extended‑hours support (POA)

SLA: 24‑hour response (priority queue)
Assigned Roles:
Dedicated Technical Account Manager (TAM)
Cloud Support Engineer for technical escalations
Optional enhanced support (POA)

4. Optional Add‑On Support (Any Tier)
Day‑Rate Specialist Support: £1,150/day
Includes:
Environment debugging
Complex integration fixes
Performance tuning
Release‑support hours
Customised workflows
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We support buyers with a structured onboarding and training programme designed to help teams begin using Helix quickly and confidently.
Getting started includes:
Kick‑off session and platform tour (remote or onsite): introducing the UI, workflows, and key concepts.
Workshops and guided exercises, such as writing first user stories, generating tests, and running executions. These are delivered through scheduled sessions during onboarding.
Technical onboarding, including installation/configuration in the buyer’s environment, integrations with Jira/Xray and Azure DevOps, and environment setup.
Training & knowledge transfer for testers, developers, and product teams, supported by best‑practice documentation.
User documentation, including deployment guidance, runbooks, and troubleshooting materials supplied during implementation.
Support onboarding, where support channels, escalation routes, and (for enterprise buyers) the dedicated support engineer are introduced.
This structured programme ensures users can begin creating stories, generating tests, and operating Helix effectively from day one.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
At the end of the contract, all customer data remains fully under the buyer’s control because Helix stores test stories, generated plans, and test execution results in the customer’s own Azure tenant. Data extraction is therefore straightforward: users can export or retrieve all content directly from their storage accounts before access is removed. No proprietary formats or restrictions apply. Helix does not retain customer data long‑term; any user stories temporarily processed by the Planning API are deleted within 7 days, ensuring compliant and secure offboarding.
End-of-contract process
At the end of the contract, the buyer retains full control of their data because all operational data (user stories, test plans, test execution results) is stored entirely within the buyer’s own tenant, not in Helix’s infrastructure. This means the customer can extract or export all data directly from their own storage accounts using their normal access controls, without any dependency on Helix. Helix only temporarily processes user stories for plan generation and automatically deletes them from its Planning API after 7 days, ensuring no long‑term retention.
After the contract ends, Helix access (licence key and UI/API access) is disabled, but no data is deleted from the customer’s systems.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Helix provides two service interfaces: a secure, TLS‑encrypted Planning API for automated test‑plan generation, and a web‑based user interface deployed in the customer’s Azure environment. The UI allows users to create stories, generate and execute tests, review logs, and manage automation workflows. The Planning API is authenticated via licence key and supports machine‑to‑machine integrations. Together, these interfaces enable both technical and non‑technical users to interact with Helix effectively.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have conducted accessibility-focused interface testing using keyboard-only navigation, colour‑contrast analysis, and screen‑reader tools such as NVDA and VoiceOver to confirm that core Helix UI journeys story creation, test generation, and results review are operable without a mouse and readable by assistive technologies. While we have not yet carried out usability sessions with real assistive‑technology users, our current approach aligns with WCAG 2.2 AA practices and informs our roadmap for full user‑based accessibility testing.
API
Yes
What users can and can't do using the API
Helix includes a secure, TLS‑encrypted Planning API that enables automated test‑plan generation and machine‑to‑machine integration. The API is hosted in the Helix tenant and accessed using an authenticated licence key. Client deployments use this API to submit user stories, generate plans, and verify system health. The API also underpins the Helix web interface, which communicates with the backend through the same service layer.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise the service. Helix offers configurable deployments tailored to a customer’s environment, including integration with Jira, XRAY, Azure DevOps and optional multi‑environment setups. Buyers may also request custom onboarding, which supports bespoke integrations, regulatory requirements, multi‑region deployments, or environment‑specific configurations. These customised elements are delivered on a POA (Price on Application) basis and form part of the “Custom Technical Onboarding Project'. Helix itself cannot be modified at source‑code level, but configuration, integrations, deployment architecture, and environment setup can be customised to meet buyer needs.

Scaling

Independence of resources
Helix guarantees resource independence because each customer receives a fully isolated deployment within their own tenant. No compute, storage, network, or application components are shared between customers.
Each installation runs on dedicated customer‑owned resources (e.g., VM, Storage Account, and API components), ensuring that usage spikes or workloads from other organisations cannot affect performance, availability, or security. Helix’s Planning API is horizontally scalable and designed to handle concurrent requests while maintaining SLA‑level throughput.
This architecture provides complete segregation of data, workloads, and performance profiles across all customers.

Analytics

Service usage metrics
Yes
Metrics types
Helix provides service usage metrics, including test execution volumes, plan‑generation activity, environment usage, and performance insights available through the platform dashboard and logs.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users export their data directly from their own tenant, where all Helix test stories, plans, and execution results are stored. Data can be downloaded through their Portal, CLI, or automated pipelines, with no proprietary formats or restrictions. Helix does not retain customer data beyond temporary processing. User stories sent to the Planning API are automatically deleted within seven days. Users may also retrieve data programmatically via the Helix API before contract end.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • TypeScript
  • TXT
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee a monthly service availability target of 98% for the core service, calculated on a per calendar month basis.
Availability is defined as the percentage of time the service is available and operational during the month, excluding:
Planned maintenance (notified in advance);
Force majeure events outside our reasonable control;
Client‑side issues, including network or platform outages;
Issues caused by client configuration changes or modifications;
Availability is monitored and reviewed monthly.
Service level agreement (SLA)
We use best endeavours to meet or exceed the availability target. Where availability falls below the guaranteed level in any calendar month, customers may be eligible for service credits, subject to the terms of the applicable commercial agreement.
Service credits are applied as a credit against future charges and represent the customer’s sole and exclusive remedy for failure to meet the availability target. Cash refunds are not provided.
To be eligible for service credits, customers must notify us in writing within a reasonable period following the end of the affected month.
This availability commitment applies only to the core service and does not extend to third‑party services or components outside our direct control.
Approach to resilience
Service resilience- the service is designed using a cloud‑native architecture to maximise resilience, availability, and recoverability. It operates entirely within enterprise‑grade public cloud infrastructure and does not rely on on‑premise components.
Core application components are deployed using stateless and managed services where possible, reducing single points of failure and enabling rapid recovery in the event of a component failure. Monitoring and alerting are in place to identify service issues promptly and support timely remediation.
Datacentre resilience- the service is hosted within UK‑based public cloud datacentres, using platforms designed to support high availability, physical security, and infrastructure redundancy. Datacentre resilience includes redundant power, networking, and storage, managed directly by the cloud service provider in line with government‑aligned security and resilience standards.
Data is stored using managed cloud data services that provide built‑in replication, backup, and recovery capabilities. Backups are performed automatically, supporting restoration in the event of data loss or service disruption.
The architecture is designed to support scalability and failover, ensuring continued service operation during infrastructure incidents.
Further details of the technical architecture and resilience controls are available on request and can be shared under appropriate confidentiality arrangements.
Outage reporting
Service availability is monitored continuously to detect and respond to incidents or outages.
In the event of a service outage or significant degradation, customers are notified through direct communication channels. Notifications are issued via email to nominated customer contacts, providing a description of the issue, its impact, and progress updates until resolution.
At present, the service does not provide a public status dashboard or a dedicated outage reporting API. This approach avoids publishing sensitive operational information publicly while ensuring customers receive timely and relevant updates.
Where appropriate, customers may also receive updates through agreed support or service management channels, in line with the applicable support arrangements.
Post‑incident communication can be provided on request, including a summary of the issue and corrective actions taken.
Further details on outage reporting mechanisms and escalation processes are available on request and can be shared under appropriate confidentiality arrangements.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to authorised personnel only and controlled using role‑based access controls. Permissions are granted on a least‑privilege basis and reviewed periodically.
Administrative access requires authenticated user accounts and is limited to staff with an operational need. Access to production environments is further restricted to reduce risk.
Support channels are protected to ensure that only verified users can raise or manage support requests. User identity is confirmed before providing access to service information or making changes.
All access to management interfaces and support systems is logged and monitored to support oversight and incident investigation.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
We operate security governance arrangements aligned to recognised best‑practice frameworks. Our controls are designed to support the principles of ISO/IEC 27001 and the UK Government Cloud Security Principles.
Hosted on Microsoft Azure, which maintains industry certifications including ISO/IEC 27001 and provides physical and environmental security controls at the datacentre level.
Information security policies and processes
We maintain information security policies and procedures aligned to recognised good practice, including the principles of ISO/IEC 27001 and the UK Government Cloud Security Principles.
These policies cover access control, data protection, incident management, and change control, and are reviewed periodically.
Governance and reporting
Overall responsibility for information security sits with senior management. Security incidents and material risks are reported through established internal management channels and, where required, communicated to customers in line with contractual obligations.
Policy compliance
Policies are enforced through documented processes, technical controls, and role‑based access restrictions. Personnel are required to follow these policies as part of their responsibilities, with compliance supported through operational oversight and management review.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We follow supplier‑defined configuration and change management processes aligned to recognised good practice and the UK Government Cloud Security Principle on Operational Security.
Changes to the service are controlled through documented change processes, including assessment of risk, approval prior to implementation, and validation after change. Configuration settings are managed centrally and access is restricted on a least‑privilege basis.
Changes are tracked and reviewed to minimise service disruption and maintain security and stability.
Where the service relies on cloud infrastructure, underlying configuration and change controls are provided by the cloud service provider in line with their certified operational standards.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate supplier‑defined vulnerability management processes aligned to recognised good practice and the UK Government Cloud Security Principle on Operational Security.
Vulnerabilities are identified through platform‑provided security tooling, vendor security updates, and operational monitoring. Identified issues are assessed for risk and prioritised based on potential impact.
Remediation actions are tracked and managed through established operational processes. Where vulnerabilities present a material risk, they are handled in line with our incident management processes, including escalation and mitigation where appropriate.
For underlying cloud infrastructure, vulnerability scanning and patching are managed by the cloud service provider in line with their certified operational standards.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We operate supplier‑defined protective monitoring processes aligned to recognised good practice and the UK Government Cloud Security Principle on Operational Security.
The service uses platform‑provided monitoring and logging to detect security events and anomalous activity. Alerts are reviewed and assessed as part of normal operations.
Potential security incidents identified through monitoring are handled in line with our incident management processes, including investigation, escalation, and mitigation where appropriate.
Where the service relies on public cloud infrastructure, protective monitoring of the underlying platform is provided by the cloud service provider in line with their operational security standards.
Incident management type
Supplier-defined controls
Incident management approach
We operate defined incident management processes to identify, assess, and respond to service and security incidents.
Documented procedures are in place for common incident types, including service disruption and security events. These cover assessment, prioritisation, escalation, mitigation, and recovery.
Users can report incidents through agreed support channels, including email. Incidents may also be identified through operational monitoring.
Where incidents have a material impact, customers are informed in line with contractual obligations. Incident summaries and details of corrective actions can be provided on request.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
D37fa2bd-1f0d-413c-886f-4ad2bf9abe2c
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at vanessa.pieterse@pidigitalsolutions.com. Tell them what format you need. It will help if you say what assistive technology you use.