Strix - AI Penetration Testing & Autonomous Security
Continuous Security On Every Deploy.
Secure your entire stack with autonomous pentesting.
Find and fix vulnerabilities 24/7.
Your full-stack security platform
One platform to secure your code, APIs, web apps, infrastructure, and cloud.
| Pentest | Status | Issues | Date |
|---|---|---|---|
| api.example.com | Completed | 3 | 2h ago |
| staging.app.io | Running | 1 | Now |
| auth-service | Completed | 2 | 1d ago |
| payments-api | Completed | 1 | 3d ago |
| dashboard.app.io | Completed | 1 | 5d ago |
APIs & Web Apps
Full-coverage pentesting across REST, GraphQL, and web apps - with proof-of-exploit for every finding.
🔴 IDOR in invoice download endpoint
Severity: HIGH · CWE-639
The GET /api/invoices/:id/pdf handler fetches the invoice by id from the global scope without scoping it to req.org. Any authenticated user can download invoices belonging to other organizations.
Suggested change
| Line | Code |
|---|---|
| 47 | const inv = await Invoice.findById(id); |
| 47 | const inv = await Invoice.findOne({ |
| 48 | _id: id, org: req.org._id}); |
Code & Pull Requests
Analyze code and pull requests for security issues in your CI pipeline. Catch vulnerabilities at the source.
| Issue | Severity | CVSS | Tested |
|---|---|---|---|
| S3 bucket public access | Critical | 9.8 | 9.81h ago |
| IAM wildcard policy | Critical | 9.1 | 9.13h ago |
| SSH open to 0.0.0.0/0 | High | 8.1 | 8.11d ago |
| RDS unencrypted at rest | Medium | - | 5.32d ago |
| CloudTrail logging disabled | Medium | - | 4.73d ago |
Infrastructure & Cloud
Find misconfigurations and exposures across cloud environments and infrastructure before attackers do.
From issue to fix in seconds
Find critical issues, auto-validate, and auto-fix with merge-ready PRs.
←Issues/STR-00847
SSRF via URL Parameter in /api/proxy
Open High · 8.6 CWE-918
TL;DR
The /api/proxy endpoint accepts a user-supplied URL without validation. An attacker can access internal services, read cloud metadata, and exfiltrate credentials.
Impact
Access to cloud metadata at 169.254.169.254, potential credential theft, and internal network scanning.
Location
acme/api · proxy-handler.ts:23
GET/api/proxy?url=
Severity: High
CVSS: 8.6
Fix Effort: Low
Discovered: 2h ago
Discover & Validate
Pentests your entire attack surface continuously. Reproduces each finding, confirms exploitability with proof, and prioritizes by real impact.
| How to fix it? | ||
|---|---|---|
| Validate and restrict the target URL using an allowlist of permitted hostnames. Reject private/internal IP ranges and enforce HTTPS-only. |
proxy-handler.ts:23-29
| Line | Code |
|---|---|
| 23 | const targetUrl = req.query.url; |
| 24 | const resp = await fetch(targetUrl); |
| 24 | const parsed = new URL(targetUrl); |
| 25 | if (!ALLOWED_HOSTS.has(parsed.hostname)) { |
| 26 | throw new ForbiddenError("blocked"); |
| 27 | } |
| 28 | const resp = await fetch(parsed.href); |
| 29 | return res.json(await resp.json()); |
✓Fix verified — vulnerability no longer exploitable
→PR #247 fix/ssrf-proxy-handler ready to merge
Auto-Fix
Generates a fix, retests to confirm the vulnerability is gone, and delivers a merge-ready PR. Review, merge, done.
Deploy with confidence
Ensure nothing vulnerable reaches production. Every vulnerability discovered, validated, and resolved before it reaches production.
Every PR reviewed
Catches vulnerabilities at the source. Every pull request is reviewed before it can be merged.
Blocks vulnerable deploys
Plugs into your CI/CD pipeline. Vulnerable code never reaches production.
Monitors your attack surface
New CVEs tested against your systems. Latest threats flagged instantly.
Runtime validation
Each finding ships with a PoC and reproduction steps. Proven against your live environment.
Context-aware pentesting
Knows your stack, architecture, and business logic. Tests tailored to your environment.
Continuous learning
Learns from past findings and how you fixed them. Every pentest builds on the last.
Ship fast without compromising security
Everything you need to track your security posture, validate findings, and ship fixes — without slowing your team down.
Real-time security posture
Validated findings with proof
Auto-fix with merge-ready PRs
Enterprise-grade security
Built for teams that need full control over deployment, data privacy, and compliance.
Self-Hosted Deployment
Deploy in your own VPC, on-premise, or air-gapped environment with complete control over your infrastructure.
Internal Infrastructure Pentesting
Go beyond external attack surfaces. Test internal networks, services, and infrastructure from inside your environment.
Zero Data Retention
Your source code is never stored or used for model training. All model providers operate under zero data retention agreements.
Dedicated Support & SLA
Dedicated support, custom SLAs, priority Slack channel, and hands-on onboarding. SOC 2 Type II and ISO 27001 compliant.