Free trial
The homepage invites visitors to start testing and try Strix for free in the app, and offers an open-source version on GitHub. Limits are not stated.
Learn moreAutonomous pentesting that proves each flaw and opens the fix PR

Strix is an autonomous AI pentesting platform that tests code, APIs, cloud and infrastructure, validates each finding with proof of exploit, and opens merge-ready fix PRs. It fits CI/CD pipelines and offers self-hosted enterprise deployment.
Strix is an autonomous penetration testing platform that probes code, APIs, web apps, cloud accounts and internal infrastructure, then reports only the issues it has managed to exploit. Each finding arrives with a proof of concept, reproduction steps, a severity and CVSS score, a CWE reference and the file and line where the weakness lives. The aim is to replace the occasional manual pentest with testing that runs on every deploy. The workflow follows three stages. Discovery covers the attack surface continuously, including REST, GraphQL and gRPC endpoints, and checks cloud setups on AWS, Google Cloud, Azure and Kubernetes for misconfigurations such as open storage or overly broad IAM policies. Validation reproduces each issue against the live environment and ranks it by real impact, which cuts down the false positives that make scanner output tiresome to triage. Auto-fix then drafts a code change, retests to confirm the hole is closed and delivers a merge-ready pull request. A bot can also comment on pull requests with a suggested change that can be committed directly, and integrations with GitHub, GitLab and Bitbucket plus CI/CD hooks let it review every PR and block vulnerable deploys. The audience is application security teams and engineering groups that ship often and cannot wait for a yearly external audit. The vendor lists AWS, PayPal, Uber, Cisco and Pfizer among its users. Larger organisations get self-hosted deployment in a VPC, on-premise or air-gapped setups, internal network testing, zero data retention with model providers, a support SLA, and SOC 2 Type II and ISO 27001 compliance. Tests are described as context-aware, using knowledge of the stack and business logic, and as learning from earlier findings. Among alternatives, Strix sits between traditional static and dynamic scanners, which flag candidates without proving them, and consultancy-led pentests, which are thorough but periodic. An open-source edition on GitHub gives teams a way to evaluate the approach before adopting the hosted platform. The vendor also publishes research on vulnerabilities its system found, including an etcd authentication bypass.


The homepage invites visitors to start testing and try Strix for free in the app, and offers an open-source version on GitHub. Limits are not stated.
Learn moreThe homepage gives no price figures. It points to a separate pricing page and offers a free start, an open-source edition and enterprise options through a demo.
Learn moreEnterprise plans include dedicated support, custom SLAs, a priority Slack channel and hands-on onboarding. Demos can be booked on the site.
Learn moreShows GitHub, GitLab and Bitbucket for code, AWS, Google Cloud, Azure and Kubernetes for cloud, Swagger, GraphQL and gRPC for APIs, and a CI/CD pipeline hook.
Continuous pentesting of APIs, web apps, code, cloud and infrastructure; proof-of-exploit validation; CVSS and CWE-tagged findings; auto-fix PRs with retesting; PR review, deploy blocking, CVE monitoring, and self-hosted enterprise deployment.





