Helix Autonomous QA
Helix is an autonomous AI‑driven QA platform that automatically creates, executes, and maintains browser‑based tests from user stories. It delivers self‑healing automation, real‑time insights, and seamless Jira/Azure DevOps integration to improve quality, accelerate releases, reduce manual effort, and ensure resilient, scalable testing across digital services.
Features
- AI‑driven test creation directly from Jira or Azure user stories.
- Self‑healing automation automatically updates tests when application interfaces change.
- Real‑time execution logs with full browser visibility and diagnostics.
- Parallel, scalable test execution across cloud or on‑prem environments.
- Seamless integration with Jira, XRAY, Azure DevOps, and CI/CD pipelines.
- Autonomous test maintenance reducing manual scripting and upkeep significantly.
- Secure deployment options on Azure, AWS, GCP, or on‑premises.
- Comprehensive reporting including coverage, risk indicators, and performance analytics.
- Visual browser inspection for accurate UI understanding and validation.
- API‑driven architecture enabling automated workflows and enterprise system integrations.
Benefits
- Accelerate release cycles by automating test creation and execution instantly.
- Reduce manual QA effort by removing the need for scripting.
- Improve service reliability through continuous, autonomous test maintenance.
- Identify defects earlier with real‑time visibility into outcomes.
- Increase test coverage by generating scenarios directly from user stories.
- Minimise downtime by rapidly detecting and self‑healing broken tests.
- Enhance collaboration by integrating seamlessly with Jira and Azure DevOps.
- Scale testing effortlessly across multiple cloud or on‑prem environments.
- Strengthen governance with audit‑ready logs and transparent test reasoning.
- Boost team productivity by freeing staff from repetitive QA tasks.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 6 7 4 7 5 6 2 4 1 9 0 5 2 1
Contact
Pi Digital Solutions
Vanessa Pieterse
Telephone: 07908882595
Email: vanessa.pieterse@pidigitalsolutions.com
About your service
- Service categories
-
Application Development and Deployment
Software quality and life cycle
- Automated software quality
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Helix QA integrates with common development and test management platforms such as Jira, XRAY, Azure DevOps and CI/CD tools. It does not depend on any other software service and can operate as a standalone SaaS platform.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- Helix QA is provided as a SaaS platform and requires access to supported cloud or private cloud environments. The service integrates with common development and test management tools and is limited to supported configurations as set out in the Service Definition. Planned maintenance may require temporary service unavailability, which is communicated in advance where possible. Support is provided during UK business hours in line with the selected licence tier.
- System requirements
-
- Linux‑based operating system supporting containerised workloads
- Container runtime such as Docker or compatible alternative
- Container hosting or orchestration platform (managed or self‑managed)
- Secure outbound network connectivity to Helix Planning API
- Access to supported large language model services via Helix platform
- Modern web browser for Helix QA user interface
- TLS‑enabled networking and standard enterprise firewall configuration
- Integration access to Jira or Azure DevOps (optional)
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours, tickets are triaged based on priority.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have conducted foundational accessibility testing using screen readers (NVDA and VoiceOver), keyboard‑only navigation, and colour‑contrast validation tools to ensure the webchat is usable without a mouse and readable by assistive technologies. While we have not yet run sessions with real assistive‑technology users, our approach follows WCAG 2.2 AA requirements
- Onsite support
- Yes, at extra cost
- Support levels
-
Helix QA Support Model
1. Lite Support (Included in Lite Licence Fee)
Price: Included in £1,500/month licence
Environments: 1 environment (e.g., Test)
Support Channels:
Email support only
Self‑service documentation
SLA: 24‑hour response
Phone Support: Not included
Assigned Roles: None (self‑service)
2. Standard Support (Included in Standard Licence Fee)
Price: Included in £2,500/month licence
Environments: Up to 4 environments (e.g., Dev, Test, UAT, Prod)
Support Channels:
Email support
Phone support included
Access to documentation
SLA: 24‑hour response
Assigned Roles:
Cloud Support Engineer (CSE) available for escalation
No dedicated Technical Account Manager
3. Premium / Enterprise Support (Included in Premium Licence Fee)
Price: Included in £4,000/month licence
Environments: Unlimited environments
Support Channels:
Priority email support
Phone support included
Option for extended‑hours support (POA)
SLA: 24‑hour response (priority queue)
Assigned Roles:
Dedicated Technical Account Manager (TAM)
Cloud Support Engineer for technical escalations
Optional enhanced support (POA)
4. Optional Add‑On Support (Any Tier)
Day‑Rate Specialist Support: £1,150/day
Includes:
Environment debugging
Complex integration fixes
Performance tuning
Release‑support hours
Customised workflows - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We support buyers with a structured onboarding and training programme designed to help teams begin using Helix quickly and confidently.
Getting started includes:
Kick‑off session and platform tour (remote or onsite): introducing the UI, workflows, and key concepts.
Workshops and guided exercises, such as writing first user stories, generating tests, and running executions. These are delivered through scheduled sessions during onboarding.
Technical onboarding, including installation/configuration in the buyer’s environment, integrations with Jira/Xray and Azure DevOps, and environment setup.
Training & knowledge transfer for testers, developers, and product teams, supported by best‑practice documentation.
User documentation, including deployment guidance, runbooks, and troubleshooting materials supplied during implementation.
Support onboarding, where support channels, escalation routes, and (for enterprise buyers) the dedicated support engineer are introduced.
This structured programme ensures users can begin creating stories, generating tests, and operating Helix effectively from day one. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- At the end of the contract, all customer data remains fully under the buyer’s control because Helix stores test stories, generated plans, and test execution results in the customer’s own Azure tenant. Data extraction is therefore straightforward: users can export or retrieve all content directly from their storage accounts before access is removed. No proprietary formats or restrictions apply. Helix does not retain customer data long‑term; any user stories temporarily processed by the Planning API are deleted within 7 days, ensuring compliant and secure offboarding.
- End-of-contract process
-
At the end of the contract, the buyer retains full control of their data because all operational data (user stories, test plans, test execution results) is stored entirely within the buyer’s own tenant, not in Helix’s infrastructure. This means the customer can extract or export all data directly from their own storage accounts using their normal access controls, without any dependency on Helix. Helix only temporarily processes user stories for plan generation and automatically deletes them from its Planning API after 7 days, ensuring no long‑term retention.
After the contract ends, Helix access (licence key and UI/API access) is disabled, but no data is deleted from the customer’s systems. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Helix provides two service interfaces: a secure, TLS‑encrypted Planning API for automated test‑plan generation, and a web‑based user interface deployed in the customer’s Azure environment. The UI allows users to create stories, generate and execute tests, review logs, and manage automation workflows. The Planning API is authenticated via licence key and supports machine‑to‑machine integrations. Together, these interfaces enable both technical and non‑technical users to interact with Helix effectively.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have conducted accessibility-focused interface testing using keyboard-only navigation, colour‑contrast analysis, and screen‑reader tools such as NVDA and VoiceOver to confirm that core Helix UI journeys story creation, test generation, and results review are operable without a mouse and readable by assistive technologies. While we have not yet carried out usability sessions with real assistive‑technology users, our current approach aligns with WCAG 2.2 AA practices and informs our roadmap for full user‑based accessibility testing.
- API
- Yes
- What users can and can't do using the API
- Helix includes a secure, TLS‑encrypted Planning API that enables automated test‑plan generation and machine‑to‑machine integration. The API is hosted in the Helix tenant and accessed using an authenticated licence key. Client deployments use this API to submit user stories, generate plans, and verify system health. The API also underpins the Helix web interface, which communicates with the backend through the same service layer.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Buyers can customise the service. Helix offers configurable deployments tailored to a customer’s environment, including integration with Jira, XRAY, Azure DevOps and optional multi‑environment setups. Buyers may also request custom onboarding, which supports bespoke integrations, regulatory requirements, multi‑region deployments, or environment‑specific configurations. These customised elements are delivered on a POA (Price on Application) basis and form part of the “Custom Technical Onboarding Project'. Helix itself cannot be modified at source‑code level, but configuration, integrations, deployment architecture, and environment setup can be customised to meet buyer needs.
Scaling
- Independence of resources
-
Helix guarantees resource independence because each customer receives a fully isolated deployment within their own tenant. No compute, storage, network, or application components are shared between customers.
Each installation runs on dedicated customer‑owned resources (e.g., VM, Storage Account, and API components), ensuring that usage spikes or workloads from other organisations cannot affect performance, availability, or security. Helix’s Planning API is horizontally scalable and designed to handle concurrent requests while maintaining SLA‑level throughput.
This architecture provides complete segregation of data, workloads, and performance profiles across all customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Helix provides service usage metrics, including test execution volumes, plan‑generation activity, environment usage, and performance insights available through the platform dashboard and logs.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users export their data directly from their own tenant, where all Helix test stories, plans, and execution results are stored. Data can be downloaded through their Portal, CLI, or automated pipelines, with no proprietary formats or restrictions. Helix does not retain customer data beyond temporary processing. User stories sent to the Planning API are automatically deleted within seven days. Users may also retrieve data programmatically via the Helix API before contract end.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- TypeScript
- TXT
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee a monthly service availability target of 98% for the core service, calculated on a per calendar month basis.
Availability is defined as the percentage of time the service is available and operational during the month, excluding:
Planned maintenance (notified in advance);
Force majeure events outside our reasonable control;
Client‑side issues, including network or platform outages;
Issues caused by client configuration changes or modifications;
Availability is monitored and reviewed monthly.
Service level agreement (SLA)
We use best endeavours to meet or exceed the availability target. Where availability falls below the guaranteed level in any calendar month, customers may be eligible for service credits, subject to the terms of the applicable commercial agreement.
Service credits are applied as a credit against future charges and represent the customer’s sole and exclusive remedy for failure to meet the availability target. Cash refunds are not provided.
To be eligible for service credits, customers must notify us in writing within a reasonable period following the end of the affected month.
This availability commitment applies only to the core service and does not extend to third‑party services or components outside our direct control. - Approach to resilience
-
Service resilience- the service is designed using a cloud‑native architecture to maximise resilience, availability, and recoverability. It operates entirely within enterprise‑grade public cloud infrastructure and does not rely on on‑premise components.
Core application components are deployed using stateless and managed services where possible, reducing single points of failure and enabling rapid recovery in the event of a component failure. Monitoring and alerting are in place to identify service issues promptly and support timely remediation.
Datacentre resilience- the service is hosted within UK‑based public cloud datacentres, using platforms designed to support high availability, physical security, and infrastructure redundancy. Datacentre resilience includes redundant power, networking, and storage, managed directly by the cloud service provider in line with government‑aligned security and resilience standards.
Data is stored using managed cloud data services that provide built‑in replication, backup, and recovery capabilities. Backups are performed automatically, supporting restoration in the event of data loss or service disruption.
The architecture is designed to support scalability and failover, ensuring continued service operation during infrastructure incidents.
Further details of the technical architecture and resilience controls are available on request and can be shared under appropriate confidentiality arrangements. - Outage reporting
-
Service availability is monitored continuously to detect and respond to incidents or outages.
In the event of a service outage or significant degradation, customers are notified through direct communication channels. Notifications are issued via email to nominated customer contacts, providing a description of the issue, its impact, and progress updates until resolution.
At present, the service does not provide a public status dashboard or a dedicated outage reporting API. This approach avoids publishing sensitive operational information publicly while ensuring customers receive timely and relevant updates.
Where appropriate, customers may also receive updates through agreed support or service management channels, in line with the applicable support arrangements.
Post‑incident communication can be provided on request, including a summary of the issue and corrective actions taken.
Further details on outage reporting mechanisms and escalation processes are available on request and can be shared under appropriate confidentiality arrangements.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted to authorised personnel only and controlled using role‑based access controls. Permissions are granted on a least‑privilege basis and reviewed periodically.
Administrative access requires authenticated user accounts and is limited to staff with an operational need. Access to production environments is further restricted to reduce risk.
Support channels are protected to ensure that only verified users can raise or manage support requests. User identity is confirmed before providing access to service information or making changes.
All access to management interfaces and support systems is logged and monitored to support oversight and incident investigation. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
We operate security governance arrangements aligned to recognised best‑practice frameworks. Our controls are designed to support the principles of ISO/IEC 27001 and the UK Government Cloud Security Principles.
Hosted on Microsoft Azure, which maintains industry certifications including ISO/IEC 27001 and provides physical and environmental security controls at the datacentre level. - Information security policies and processes
-
We maintain information security policies and procedures aligned to recognised good practice, including the principles of ISO/IEC 27001 and the UK Government Cloud Security Principles.
These policies cover access control, data protection, incident management, and change control, and are reviewed periodically.
Governance and reporting
Overall responsibility for information security sits with senior management. Security incidents and material risks are reported through established internal management channels and, where required, communicated to customers in line with contractual obligations.
Policy compliance
Policies are enforced through documented processes, technical controls, and role‑based access restrictions. Personnel are required to follow these policies as part of their responsibilities, with compliance supported through operational oversight and management review. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We follow supplier‑defined configuration and change management processes aligned to recognised good practice and the UK Government Cloud Security Principle on Operational Security.
Changes to the service are controlled through documented change processes, including assessment of risk, approval prior to implementation, and validation after change. Configuration settings are managed centrally and access is restricted on a least‑privilege basis.
Changes are tracked and reviewed to minimise service disruption and maintain security and stability.
Where the service relies on cloud infrastructure, underlying configuration and change controls are provided by the cloud service provider in line with their certified operational standards. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We operate supplier‑defined vulnerability management processes aligned to recognised good practice and the UK Government Cloud Security Principle on Operational Security.
Vulnerabilities are identified through platform‑provided security tooling, vendor security updates, and operational monitoring. Identified issues are assessed for risk and prioritised based on potential impact.
Remediation actions are tracked and managed through established operational processes. Where vulnerabilities present a material risk, they are handled in line with our incident management processes, including escalation and mitigation where appropriate.
For underlying cloud infrastructure, vulnerability scanning and patching are managed by the cloud service provider in line with their certified operational standards. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We operate supplier‑defined protective monitoring processes aligned to recognised good practice and the UK Government Cloud Security Principle on Operational Security.
The service uses platform‑provided monitoring and logging to detect security events and anomalous activity. Alerts are reviewed and assessed as part of normal operations.
Potential security incidents identified through monitoring are handled in line with our incident management processes, including investigation, escalation, and mitigation where appropriate.
Where the service relies on public cloud infrastructure, protective monitoring of the underlying platform is provided by the cloud service provider in line with their operational security standards. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We operate defined incident management processes to identify, assess, and respond to service and security incidents.
Documented procedures are in place for common incident types, including service disruption and security events. These cover assessment, prioritisation, escalation, mitigation, and recovery.
Users can report incidents through agreed support channels, including email. Incidents may also be identified through operational monitoring.
Where incidents have a material impact, customers are informed in line with contractual obligations. Incident summaries and details of corrective actions can be provided on request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D37fa2bd-1f0d-413c-886f-4ad2bf9abe2c
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-