Features
No Setup Required
No Docker, API keys, or local installation needed.
Full Reports
Detailed findings with remediation guidance.
Team Dashboards
Track vulnerabilities and fixes over time.
GitHub Integration
Automatic scans on pull requests.
What You Get
- Penetration test reports — Validated findings with PoCs
- Shareable dashboards — Collaborate with your team
- CI/CD integration — Block risky changes automatically
- Continuous monitoring — Catch new vulnerabilities quickly
Getting Started
- Sign up at app.strix.ai
- Connect your repository or enter a target URL
- Launch your first scan
Scan Local Source
Send a local working tree to the managed white-box scanner without connecting a source-control provider:.git, symlinks, dependencies and build output, secret-like filenames, and nested archives are excluded by default. Use .strixignore or repeat --exclude GLOB for project-specific exclusions. --include-hidden, --include-sensitive, and --include-archives are explicit opt-ins.
The CLI limits individual files, total expanded bytes, archive bytes, and file count. For an agent or CI handoff, repeat the same --source, --exclude, and --include-* flags with --approve-sha256; Strix refuses the upload if the rebuilt archive differs from the reviewed digest. --yes is a one-invocation approval for the snapshot built at that moment, not a digest-bound two-step approval.
The temporary local archive is always removed. After a definitive launch rejection, Strix also deletes the staged remote upload. If a network error, server error, or interruption makes the launch outcome ambiguous, it retains the upload and reports its ID; check strix cloud scans list before retrying, then delete an unlinked upload with strix cloud uploads delete UPLOAD_ID.
Try Strix Cloud
Run your first pentest in minutes.