About

The QA bench behind
the audit.

Russell SPC LLC is an independent QA, UX and AI auditing practice in Hobe Sound, Florida. Most websites and apps go live because someone decided they were probably fine. We get hired to check.

Who is doing the testing

Since 2022 I have worked as a QA engineer and project manager for a transportation software company. I test the systems that take payments, move an order through fulfillment, and turn a customer inquiry into a priced job.

That is a good place to learn what severity means. If a quote form rounds a number the wrong way, someone has underbid a job and will not find out for two weeks. If a shipping status fails to update, a driver is sitting outside a warehouse that thinks the load already left. Neither one looks like much on the screen. Both cost real money. You learn to rate a bug by what it does, not by how bad it looks.

The main thing I would point at is not a certificate. It is a fully automated regression suite I built from scratch for that company and have kept running for several years while the product changed underneath it. Anyone can run a scanner and paste the output into a document. The hard part is building something that catches a bug the week before release, keeping it reliable while the app it tests keeps changing, and knowing which of its failures are real. That is what the Verify work is built on.

I also do UX advisory and AI integration work, and I build and maintain websites with AI features for a Florida-based SEO company. Russell SPC LLC was incorporated in 2026.

Five principles

Each of these exists because the opposite happened first, either in our own tools or in something we were asked to look at. Each one is now enforced in code somewhere, not left to memory.

  • Evidence over opinion. Every finding comes with the steps to reproduce it and the proof: a screenshot, a log line, a request and its response, a transcript. You should be able to follow the steps and watch it happen yourself. If we cannot show you, we do not claim it.
  • What we could not test, we tell you. A check that failed to run gets reported as untested, by name, with the reason. It never becomes a pass and it never drops out of the total to make a number look better. A short report that hides its own gaps looks exactly like a clean one.
  • Severity is defined, not felt. Five levels with published definitions, written before your report was. So you can argue with a rating instead of just receiving it. If you think we called something High that is really Medium, tell us. That is a better outcome than you quietly deciding the whole report is overblown.
  • We audit ourselves first. This site gets tested with the same tools we would point at yours, against the same standards. When that finds something we have not fixed, it goes on the Proof page with a severity rating on it.
  • Independence is the whole point. We did not pick your stack, we were not in the room when the deadline moved, and we have nothing riding on the decisions we are testing. An auditor who needs you happy with the findings is not much use to you.

Standards we test against

Four, and they cover different ground. WCAG 2.2 AA is the accessibility standard that procurement teams and courts actually reference. Core Web Vitals measures whether a page is usable while it is still loading, which is a different question from whether it feels fast on your laptop. The OWASP Top 10 frames the security pass. And the testing itself follows an ISTQB-aligned process, which sets how the work gets planned, run and written up, so two audits of two different systems come out comparable.

One caveat, and it matters. We test against those standards using axe-core in a real browser, Lighthouse and our own test harness. We are not a certification body. Nothing we hand you is an accreditation and it should not be presented as one. What you get is a written conformance position: which criteria pass, which fail, which could not be checked automatically, and where the gaps are. For most purposes, including most procurement questionnaires, that is what is actually being asked for.

How we work

You talk to the person doing the testing. No sales team, no account manager.

Every job starts with a call and a written scope naming the pages, journeys and systems that are in bounds, and the ones that are not. You get that document before anything starts. Without it you end up with a list of technical defects and no way to tell which ones cost you money, and we end up testing things nobody asked us to touch. The report and recommendations land within 10 business days of the scope being agreed.

We do not publish prices. Any number quoted before we have seen the system is a guess, and a guess quoted early tends to become the number everyone argues over no matter what the work turns out to be. The figure goes in your scope, in writing, and that is what you pay unless the scope changes.

If your problem is outside what we can test honestly, we will say so and turn the work down. Some questions need a lawyer. Some need a penetration test with signed authorization behind it. Some just need a meeting with your own team. Selling you a report that does not answer your question is a bad trade for both of us.

Where we are

Registered in Florida and based in Hobe Sound, on the Treasure Coast, close enough to Jupiter, Stuart and Palm Beach to meet in person. The testing is remote, so your location does not matter to the work. We take clients across the United States and internationally when the time zones line up. If you are local and would rather meet face to face, say so and we will make the time.

Now go and find out what is wrong with yours.

Send us a URL, or run the free check on it first and see what comes back. Either way you get a written scope before any work starts, and we will say plainly if an audit is not the thing you actually need.