Procure is a procurement and inventory management platform built for non-profit organizations, including schools, universities, hospitals, and religious and service organizations. It gives them enterprise-grade tools to organize, track, and manage assets, inventory, order requests, work orders, vendors, warehousing, and purchasing at a fraction of the cost of typical enterprise software.
A platform handling purchasing workflows and financial data for organizations that answer to boards and donors leaves no room for instability. Procure partnered with Testscenario from requirements planning in April 2017 through post-launch monitoring ending in June 2022, covering the platform’s launch push and five years of continuous QA as the product grew.
Across that engagement, our team identified and resolved more than 2,000 issues, improved load capacity by 30%, and validated the platform against every OWASP Top 10 security category before it carried live purchasing data.
Procure’s Testing Challenges
A procurement platform serving many organization types stacks several hard testing problems on top of each other. The key challenges were:
- Tight go-live commitments: The launch date was fixed by client commitments, compressing the window for full test cycles during the pre-launch phase.
- Complex third-party integrations: The platform connected to ERP systems, CRM platforms, and payment gateways, and every integration point was a potential failure surface under real transaction conditions.
- Role-based permissions across organization types: Schools, hospitals, and service organizations each run different approval chains, and every user role from requesters to approvers to administrators needed its access boundaries verified, because a permission error in a purchasing system means unauthorized spending.
- Security and compliance stakes: Financial and transactional data flowing through the platform made security testing a core requirement rather than a final checkpoint.
Goals
The engagement was structured around what a procurement platform must guarantee its users.
Key objectives included:
- Deliver a stable, bug-free experience for every user across all workflows.
- Verify every integration with third-party ERPs, CRMs, and payment gateways under realistic conditions.
- Confirm the platform performed reliably under high traffic loads without degradation.
- Validate data security and authentication against industry standards.
- Verify the role-based permission structure behaved correctly for every organization and user type.
The Solution by Testscenario
Our team ran an Agile testing strategy embedded in the development process, scaling from launch-focused intensity to long-term continuous QA.
Solutions implemented included:
- Sprint-based testing with continuous integration, so issues surfaced early in development rather than accumulating toward release.
- Automated regression and functional testing built on Selenium and JUnit, keeping repetitive coverage fast and consistent across the tight pre-launch schedule.
- Detailed integration test cases simulating real-time API interactions with ERP, CRM, and payment gateway systems, backed by mock environments for edge-case validation.
- Load and performance testing with JMeter to find bottlenecks under traffic, followed by database query and API call optimization.
- Security testing with OWASP ZAP, covering data protection, encryption, and user authentication protocols across the platform.
- Role-by-role functional verification of permission structures across requester, approver, and administrator workflows.
- QA Summary at a Glance
Types of Testing
- Functional testing across all user workflows.
- Integration testing against ERP, CRM, and payment gateway APIs.
- Automated regression testing on every release cycle.
- Load and performance testing under simulated peak traffic.
- Security and penetration testing against OWASP standards.
Tools Used
- Selenium and JUnit for test automation.
- JMeter for load and performance testing.
- OWASP ZAP for security validation.
- Mock API environments for integration edge cases.
Platforms Tested On
- Web platform across major desktop browsers.
- Third-party integration endpoints under real and mocked conditions.
- Production environment during post-launch monitoring.
Results
| Metric | Outcome |
|---|---|
| Issues resolved | 2,000+ bugs identified and resolved across the engagement |
| Load capacity | Improved by 30% through performance optimization of database queries and API calls |
| Downtime risk | Reduced by 20% through proactive bottleneck identification and automated regression coverage |
| Security validation | Platform validated against all OWASP Top 10 security categories |
| Engagement span | 5 years, from pre-launch QA through post-launch monitoring |
Lessons Learned
- Integration points fail first: The majority of high-severity issues clustered around third-party API boundaries, confirming that mock-environment edge-case testing earns its cost.
- Permission testing needs role-by-role rigor: Approval-chain access structures can’t be spot-checked. Systematic verification per role caught boundary errors that sampling would have missed.
- Performance work compounds: Bottlenecks found and fixed during load testing kept paying off across five years of traffic growth.
- Security is a cycle, not a milestone: Continuous validation against OWASP standards kept the platform compliant as new features changed the attack surface.
Client Testimonial
“The testing team at Testscenario played a crucial role in the successful launch of the Procure platform. Their expertise in handling complex integrations and security testing provided us with confidence going into the market. Their thoroughness and commitment exceeded our expectations.” — Scott Bundgaard, CEO, Procure







