Skip to main content
Skip the setup. Run Strix in the cloud at app.strix.ai.

Features

No Setup Required

No Docker, API keys, or local installation needed.

Full Reports

Detailed findings with remediation guidance.

Team Dashboards

Track vulnerabilities and fixes over time.

GitHub Integration

Automatic scans on pull requests.

What You Get

  • Penetration test reports — Validated findings with PoCs
  • Shareable dashboards — Collaborate with your team
  • CI/CD integration — Block risky changes automatically
  • Continuous monitoring — Catch new vulnerabilities quickly

Getting Started

  1. Sign up at app.strix.ai
  2. Connect your repository or enter a target URL
  3. Launch your first scan

Scan Local Source

Send a local working tree to the managed white-box scanner without connecting a source-control provider:
In a Git repository, Strix includes tracked files and untracked files that are not ignored. Hidden files, .git, symlinks, dependencies and build output, secret-like filenames, and nested archives are excluded by default. Use .strixignore or repeat --exclude GLOB for project-specific exclusions. --include-hidden, --include-sensitive, and --include-archives are explicit opt-ins. The CLI limits individual files, total expanded bytes, archive bytes, and file count. For an agent or CI handoff, repeat the same --source, --exclude, and --include-* flags with --approve-sha256; Strix refuses the upload if the rebuilt archive differs from the reviewed digest. --yes is a one-invocation approval for the snapshot built at that moment, not a digest-bound two-step approval. The temporary local archive is always removed. After a definitive launch rejection, Strix also deletes the staged remote upload. If a network error, server error, or interruption makes the launch outcome ambiguous, it retains the upload and reports its ID; check strix cloud scans list before retrying, then delete an unlinked upload with strix cloud uploads delete UPLOAD_ID.

Try Strix Cloud

Run your first pentest in minutes.