Strix
Strix is an autonomous security agent that runs continuous penetration tests across your code, APIs, web apps, cloud, and infrastructure. It reproduces findings with proof of exploit, prioritizes by real impact, and can open merge-ready pull requests after retesting a fix. The platform also reviews pull requests in CI and blocks vulnerable deploys before they reach production.
Where traditional scanners stop at alerts, Strix ties discovery to validation and remediation in one loop. It tests REST, GraphQL, and gRPC APIs alongside web apps, scans cloud misconfigurations on AWS, Google Cloud, and Azure, and ships an open source edition on GitHub with 51K stars. Enterprise teams can self-host in a VPC or air-gapped environment with zero data retention and bring-your-own-model routing.
Strix fits application security engineers, DevSecOps teams, and platform teams that want year-round external and internal testing without waiting on annual pentest cycles. Integrations cover GitHub, GitLab, Bitbucket, Jira, Linear, and Slack, with an API for automating pentests, schedules, and webhooks.
Pro plan is $29 per seat per month with pentests billed separately on a pay-per-test basis
Tests REST, GraphQL, and gRPC APIs plus web apps with proof-of-exploit validation for each finding
Reviews pull requests in GitHub, GitLab, and Bitbucket and can block vulnerable deploys in CI/CD
Generates merge-ready fix PRs after retesting that the vulnerability is gone
Enterprise supports VPC, on-prem, or air-gapped deployment with SSO, SCIM, and BYOK model routing
Open source edition on GitHub (usestrix/strix) with 51K stars alongside the hosted Strix platform
Validates findings with proof of exploit instead of surfacing unverified scanner alerts
Covers APIs, web apps, pull requests, and cloud infrastructure in one platform
Auto-fix workflow opens merge-ready PRs after retesting the patch
Open source core on GitHub with 51K stars for teams that want to self-run agents
Enterprise supports VPC, on-prem, air-gapped deployment, and bring-your-own-model routing
Pro plan charges per seat plus separate pay-per-test pentest fees beyond the subscription
Enterprise pricing is custom and requires a sales conversation for VPC and SSO features
API integrations require managing multiple org-scoped token scopes for least-privilege access
What does Strix test?
Strix pentests APIs, web apps, source code, pull requests, and cloud infrastructure. It covers REST, GraphQL, and gRPC endpoints, scans AWS, Google Cloud, and Azure environments, and can test internal networks on Enterprise plans.
How much does Strix Pro cost?
Strix Pro is $29 per seat per month on the pricing page. Pentests are billed separately on a pay-per-test basis, and new accounts get a 7-day free trial before committing.
Does Strix fix vulnerabilities automatically?
Strix can generate a code fix, retest to confirm the issue is resolved, and open a merge-ready pull request. The Auto-Fix workflow is included on the Pro plan alongside PR security reviews.
Is there a self-hosted Strix option?
Yes. Strix Enterprise supports self-hosted deployment in your own VPC, on-prem, or air-gapped environments. Enterprise also adds internal infrastructure pentesting, SSO, SCIM, and dedicated support with custom SLAs.
Does Strix have an API?
Yes. The Strix API at app.strix.ai/api/v1 lets you start and manage pentests, update vulnerabilities, create schedules, and configure webhooks. Tokens are org-scoped and created from Settings > API Access in the dashboard.
Is Strix open source?
Strix publishes an open source project at github.com/usestrix/strix with 51K GitHub stars. The hosted platform at app.strix.ai adds continuous coverage, autofix PRs, integrations, and enterprise controls on top of the OSS core.

