
Strix
Open-source AI penetration-testing agents for apps and APIs, validating findings with PoCs plus an optional managed cloud.
1 upvote · 0 downvotes
- Pricing
- Freemium
- Platforms
- LinuxmacOSWindowsWeb
- Licence
- Open source
- Reviewed
- Last reviewed 29 September 2026
What it is
Strix is a freemium AI penetration-testing product, made by OmniSecure, Inc., that runs autonomous agents to find, validate and help remediate vulnerabilities in applications, APIs, code and infrastructure. It combines an open-source CLI under the Apache Licence 2.0 that runs security agents in a Docker sandbox with a managed cloud platform at app.strix.ai.
What it helps with
- Finding access-control flaws, injection issues, SSRF and related web vulnerabilities through dynamic testing
- Validating findings with proof-of-concept evidence rather than unverified alerts
- Reviewing pull requests and integrating checks into CI pipelines
- Checking cloud misconfigurations as described in the official documentation
- Proposing merge-ready remediation suggestions for confirmed issues
Who it's for
Application security engineers, developers embedding security into CI/CD, and security teams that want continuous or on-demand testing of systems they own or are authorised to assess. Organisations that need SSO, VPC or on-premises deployment can use the commercial enterprise tier.
Worth knowing
Local CLI use requires Docker and an LLM API key or a local model; cloud use removes that setup. Pricing is freemium: the open-source core is usable free of charge, while Pro and custom plans add managed scanning, integrations and enterprise controls. The licence is Apache Licence 2.0 (OSI-approved). Use only against systems you own or have explicit written authorisation to test. OmniSecure, Inc. (Delaware) operates the Strix brand and SaaS under published terms and privacy policy.