The ranking scores every vendor on eight dimensions. The weights were fixed before any vendor data was collected and have not changed since. Each dimension is scored from 0 to 100 against the published scale below, using only public evidence: the vendor's own pages, Clutch, G2 and GoodFirms profiles, certification statements and public case studies. Material a vendor shares privately is not used.
Dimensions and weights
| Dimension | Weight | What is measured |
|---|---|---|
| Healthcare domain evidence | 20% | Public cases, named clients or product types in EHR, telehealth, medical devices, payers, pharma |
| Regulatory and standards coverage | 18% | Documented practice for HIPAA, HITRUST, FDA 21 CFR Part 11, IEC 62304, HL7 FHIR, with named deliverables |
| Security and data handling | 14% | Verified certifications (ISO 27001, SOC 2, HITRUST), BAA availability, PHI handling policy |
| Client review quality and volume | 12% | Verified reviews on Clutch, G2, GoodFirms weighted to healthcare engagements |
| Automation and integration testing depth | 12% | Documented automation and interface testing practice for HL7, FHIR, DICOM, APIs |
| Validation documentation practice | 9% | Documented IQ/OQ/PQ, traceability, validation reports as deliverables |
| Engagement flexibility and onboarding | 8% | Models offered, documented time to start, minimum contract |
| Pricing transparency | 7% | Published rates or ranges and minimum project size |
How a candidate gets into the ranking
- Scope gate. A candidate must show documented healthcare or life-sciences testing work: a healthcare services page plus at least one public case, named client or certification tied to healthcare. Candidates that fail are not scored.
- Completeness. A candidate with more than two dimensions that have no public evidence at all is not ranked, regardless of size or reputation.
- Selection. Of the candidates that pass both checks, the twelve with the most complete public record are ranked. The full screening table, including the candidates that were excluded and why, is published with the sources.
Scales
A score is either one of the anchor values below or the anchor value plus 10 when every condition of the next anchor except one is met. No other values are used.
Healthcare domain evidence (20%)
Public cases, named clients or product types in EHR, telehealth, medical devices, payers, pharma.
| Score | What it means |
|---|---|
| 0 | No healthcare page, case or client found in public sources. |
| 25 | A healthcare services page exists, but no public case study or named healthcare client. |
| 50 | One or two public healthcare case studies, mostly anonymised, covering one product type. |
| 75 | Three or more public healthcare cases across at least two product types (for example EHR and telehealth), or at least one named healthcare client. |
| 100 | Five or more public healthcare cases across three or more product types, with at least two named healthcare or life-sciences clients and stated outcomes. |
Regulatory and standards coverage (18%)
Documented practice for HIPAA, HITRUST, FDA 21 CFR Part 11, IEC 62304, HL7 FHIR, with named deliverables.
| Score | What it means |
|---|---|
| 0 | No healthcare regulation or standard mentioned in public sources. |
| 25 | One or two regulations named in marketing copy, with no described testing practice or deliverable. |
| 50 | Three or more regulations or standards named, with a described testing approach for at least one. |
| 75 | Documented testing practice for at least three of HIPAA, HITRUST, 21 CFR Part 11, IEC 62304, HL7 FHIR, with at least one named deliverable (for example a compliance test report or traceability matrix). |
| 100 | Documented practice for four or more of those standards, named deliverables for at least three, and at least one public case where the standard was in scope. |
Security and data handling (14%)
Verified certifications (ISO 27001, SOC 2, HITRUST), BAA availability, PHI handling policy.
| Score | What it means |
|---|---|
| 0 | No security certification, BAA statement or data-handling policy found. |
| 25 | A general security or privacy statement only; no certification or BAA statement. |
| 50 | One relevant certification claimed on the vendor site (ISO 27001, SOC 2 or HITRUST) or a public statement that the vendor signs BAAs. |
| 75 | ISO 27001 or SOC 2 confirmed with a certificate number, registry entry or audit-firm statement, plus a public BAA or PHI-handling statement. |
| 100 | Two or more of ISO 27001, SOC 2 Type II, HITRUST confirmed through a registry or auditor, plus a public BAA and PHI-handling policy. |
Client review quality and volume (12%)
Verified reviews on Clutch, G2, GoodFirms weighted to healthcare engagements.
| Score | What it means |
|---|---|
| 0 | No profile with reviews on Clutch, G2 or GoodFirms. |
| 25 | Fewer than 10 verified reviews in total across platforms, or an average below 4.5. |
| 50 | 10-29 verified reviews in total with an average of 4.5 or higher. |
| 75 | 30-59 verified reviews in total with an average of 4.7 or higher, including at least one healthcare engagement visible in review titles or sectors. |
| 100 | 60 or more verified reviews in total with an average of 4.8 or higher, including three or more healthcare engagements. |
Automation and integration testing depth (12%)
Documented automation and interface testing practice for HL7, FHIR, DICOM, APIs.
| Score | What it means |
|---|---|
| 0 | No automation or integration testing service described. |
| 25 | Test automation offered as a general service; no healthcare interface standard mentioned. |
| 50 | Automation and API testing described with a named tool stack; one healthcare interface standard (HL7, FHIR or DICOM) mentioned. |
| 75 | Documented interface testing for at least two of HL7 v2, FHIR, DICOM, with a named automation stack and at least one public case covering integration testing. |
| 100 | Documented HL7, FHIR and DICOM or device-interface testing, a named automation stack or accelerator, and public cases with stated automation outcomes (coverage, cycle time) in healthcare. |
Validation documentation practice (9%)
Documented IQ/OQ/PQ, traceability, validation reports as deliverables.
| Score | What it means |
|---|---|
| 0 | No validation or traceability practice mentioned. |
| 25 | Validation or computer system validation (CSV) mentioned in passing, with no deliverables listed. |
| 50 | Requirements traceability or validation reports listed as deliverables. |
| 75 | Documented CSV or GxP validation practice with IQ/OQ/PQ or equivalent protocols and a traceability matrix listed as deliverables. |
| 100 | All of 75, plus a public case where validation documentation was delivered for a regulated system (FDA 21 CFR Part 11, IEC 62304 or GAMP 5). |
Engagement flexibility and onboarding (8%)
Models offered, documented time to start, minimum contract.
| Score | What it means |
|---|---|
| 0 | No engagement model described. |
| 25 | One engagement model described; no start time or minimum stated. |
| 50 | Two or more models (for example project-based and dedicated team), with no stated start time. |
| 75 | Two or more models plus a published start time or a free pilot / trial offer. |
| 100 | Three or more models (project, dedicated team, managed QA or on-demand), a published start time of 10 business days or less, and a published minimum engagement or pilot terms. |
Pricing transparency (7%)
Published rates or ranges and minimum project size.
| Score | What it means |
|---|---|
| 0 | No rate or minimum project information in any public source. |
| 25 | Only a third-party rate band (for example a Clutch hourly range) or minimum project size, not both. |
| 50 | A third-party hourly band and minimum project size are both public. |
| 75 | Rates or a pricing page published on the vendor site, or a public cost calculator, plus a minimum project size from any source. |
| 100 | Published rate card or package prices on the vendor site with a stated minimum project size. |
Interpretation rules
These rules say how the anchor text is read. They were written after a first scoring pass showed that the same facts could be read in different ways, and before any total score was computed. They did not change any weight or anchor.
- Named client. A client counts as named only when the name is tied to an engagement: a case study, testimonial, press release or third-party review. Names that appear only in a logo wall or client list do not count.
- Healthcare case. Any public case with a healthcare or life-sciences client counts toward healthcare domain evidence. It counts toward testing dimensions only when testing or QA was in scope.
- Intermediate values. Anchor value, or anchor value plus 10 when exactly one condition of the next anchor is missing.
- Published terms. A start time, minimum engagement or pilot term counts as published when it appears on the vendor's site or on a third-party profile. "10 days" or less counts as ten business days or less; "two weeks" does not.
- Live pages. A claim counts only when its source page was reachable at collection. Claims found only on dead pages or legacy PDFs count at most as a general statement.
- Confirmed certification. A certificate number or a named certifying body, auditor or appraiser counts as confirmed. A badge or list without either counts as stated by the vendor.
- Standards. A combined mention such as "HL7/FHIR" counts as both. A documented testing practice for a standard needs at least one sentence saying what is tested or how; a name in a list is not enough.
- Interface testing. Documented interface testing needs a service-page sentence about testing that interface. The top score also needs a public healthcare case with a stated automation outcome.
- Reviews. Only Clutch, G2 and GoodFirms count, each with a profile URL. Averages are weighted by review count.
- Validation deliverables. Deliverables must be named: traceability matrix, validation report, IQ/OQ/PQ protocol or CSV plan.
Total and tie-break
The total is the weighted sum of the eight scores divided by 100, rounded to one decimal. It is computed at build time from the stored dimension scores; no total is entered by hand. Equal totals are separated by the score on the highest-weighted dimension, then the next. The current table:
| # | Company | Healthcare domain evidence (20%) | Regulatory and standards coverage (18%) | Security and data handling (14%) | Client review quality and volume (12%) | Automation and integration testing depth (12%) | Validation documentation practice (9%) | Engagement flexibility and onboarding (8%) | Pricing transparency (7%) | Total |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | ScienceSoft | 100 | 100 | 60 | 75 | 85 | 85 | 100 | 85 | 87.2 |
| 2 | DeviQA | 100 | 60 | 60 | 85 | 60 | 25 | 100 | 60 | 71.1 |
| 3 | BetterQA | 75 | 60 | 60 | 85 | 60 | 50 | 85 | 85 | 68.9 |
| 4 | Citrusbug Technolabs | 85 | 60 | 60 | 85 | 60 | 25 | 60 | 60 | 64.9 |
| 5 | a1qa | 85 | 60 | 50 | 50 | 60 | 50 | 60 | 60 | 61.5 |
| 6 | TestDevLab | 85 | 35 | 50 | 75 | 35 | 0 | 60 | 60 | 52.5 |
| 7 | TestFort | 75 | 25 | 50 | 60 | 50 | 0 | 100 | 60 | 51.9 |
| 8 | Empeek | 75 | 50 | 60 | 50 | 35 | 0 | 60 | 60 | 51.6 |
| 9 | QualityLogic | 75 | 25 | 50 | 75 | 35 | 0 | 85 | 60 | 50.7 |
| 10 | XBOSoft | 85 | 25 | 50 | 50 | 35 | 0 | 60 | 60 | 47.7 |
| 11 | ImpactQA | 75 | 35 | 0 | 50 | 50 | 25 | 60 | 60 | 44.6 |
| 12 | Mindfire Solutions | 75 | 35 | 25 | 50 | 50 | 0 | 60 | 35 | 44.1 |
What the scores do not measure
The scores measure how much a buyer can verify before the first call. They do not measure delivery quality on a specific project, team seniority on the day you sign, or anything a vendor shares only under NDA. Every vendor can be scored again after it publishes new evidence; corrections follow the editorial policy.