LaunchedEditorial Listing

Strix

Strix (OmniSecure, Inc.) · Strix: Open-Source AI Pentesting Agents for Authorized App Security Testing

Open Strix

Strix is an open-source (Apache-2.0) AI security testing tool that runs automated penetration tests against applications you own or are authorized to test, and reports findings only when it can validate them. It suits developers and security teams who want pentesting in the CLI or CI, with a paid cloud platform that adds continuous testing, PR security reviews, and autofix pull requests.

PricingFreemium
Setupmedium
Runs onSelf-hosted · Web · API
APIYes
Open sourceYes
DocsYes
CategorySecurity
Penetration TestingApplication SecurityOpen SourceCI/CDDevSecOpsAutofixMulti-Agent

Best for

Engineering and AppSec teams that want open-source, AI-driven pentesting of their own apps and APIs in the CLI or CI, with an option to move to a managed platform

Not ideal for

Teams without permission to test the target, organizations that cannot run Docker or send code context to an LLM provider, and anyone who needs a formally certified human pentest report without the paid Full Audit tier

Who it's for

Developers, AppSec engineers, and security teams testing applications and APIs they own or are authorized to test

Capabilities

  • Coordinated AI agents that test web apps, APIs, and code in an isolated Docker sandbox
  • Findings are validated before reporting to reduce false positives
  • Targets include local code, repositories, staging URLs, and OpenAPI or Postman API specs, with combined code-plus-app (white-box) testing
  • Quick, standard, and deep scan modes, with diff-scoped runs for pull requests
  • Headless CLI mode with SARIF 2.1.0 output and exit codes for CI gating in GitHub Actions, GitLab CI, and other pipelines
  • Model-agnostic through LiteLLM, with ChatGPT subscription sign-in and local model support
  • Budget caps on LLM spend per run
  • Strix Cloud: continuous and scheduled pentests, PR security reviews, one-click autofix PRs with retesting, dashboards, and a REST API
  • Integrations with GitHub, GitLab, Bitbucket, Jira, Linear, and Slack on the cloud platform

Limitations

  • Only for systems you own or have explicit written permission to test; it is an active testing tool, not a passive scanner
  • The open-source CLI requires Docker and your own LLM access, and you pay the model provider per token
  • Deep mode is the default and takes one to four hours per run
  • Local directory targets are mounted writable, so the docs advise committing or stashing changes first
  • The docs warn that smaller local models struggle with the agent workflow
  • Telemetry is on by default in the open-source tool
  • Pentests on the cloud platform are billed separately from Pro seats

Use cases

  • Running an authorized security test of a staging web app before a release
  • Adding a quick, diff-scoped security scan to pull requests as a CI gate
  • Testing an API from its OpenAPI spec in a pre-production environment
  • Scheduling recurring pentests of production-like environments on Strix Cloud
  • Turning validated findings into autofix pull requests and retesting after the fix

Our take

Strix is the most visible open-source project in AI-driven pentesting, and its main strength is flexibility: free Apache-2.0 code, any model, CI-friendly output, and a managed platform for teams that outgrow the CLI. Its validate-before-report approach addresses the biggest complaint about automated scanners. Budget for model costs and long deep scans, and treat it as a supplement to human review and formal pentests rather than a replacement. As with any active testing tool, keep it pointed at staging systems you are authorized to test.

Who should use it

Developers and AppSec teams who want to add AI-driven security testing of their own apps and APIs to local workflows or CI, and teams that want a managed option with PR reviews and autofix.

Who should skip it

Anyone without authorization to test the target, teams that cannot run Docker or use an external or local LLM, and organizations that need only a certified human-led pentest.

Strengths

  • Free and open source under Apache-2.0 with a very active release cadence
  • Validated findings reduce the noise of traditional scanners
  • Works in CI with SARIF output, diff-scoped PR scans, and exit codes
  • Model-agnostic, including local models and ChatGPT subscription sign-in
  • Clear path from local CLI to a managed cloud platform and self-hosted enterprise

Weaknesses

  • Requires Docker and pay-per-token model usage for the open-source tool
  • Default deep scans take hours
  • Cloud pentests are priced per test on top of seats
  • Active testing means it must be scoped carefully to authorized, non-production targets

Strix pricing

Open source

Free

  • Apache-2.0 CLI
  • Runs locally with Docker
  • Bring your own LLM key or local model

Pro

$29/seat

Billed monthly

  • PR security reviews and one-click autofix
  • Scheduled pentesting and attack surface monitoring
  • Jira, Linear, and Slack integrations
  • Pentests billed separately

Rightsized Pentest

$60–$300 per pentest

  • White-box and authenticated testing
  • Validated findings with autofix
  • Free re-test after fixes

Full Audit

From $2,000 per audit

  • PDF report for SOC 2 and ISO 27001
  • Reviewed by CREST-certified pentesters
  • Custom scope

Enterprise

Custom

  • VPC, on-prem, or air-gapped deployment
  • Bring your own model
  • SSO and SCIM
  • Internal infrastructure testing

Free tier limits: The open-source CLI has no plan limits; you pay your model provider. Pro includes 50 PR reviews per developer per month, then $1 per review.

Note: Pentest pricing is credit-based (1 credit = $1) and shown before launch. Annual billing saves 20%. Strix says the platform is free for public open-source repositories and offers startups 50% off Pro for six months.

Technical specs

Available models

Any LiteLLM-supported providerOpenRouter modelsOpenAIAnthropic ClaudeGoogle GeminiLocal models via Ollama, LM Studio, or vLLM

Where Strix excels

Security checks on every pull request

Diff-scoped quick scans, SARIF upload, and exit codes let a pipeline flag validated issues before merge.

Pre-release testing of a staging app

Combining source code with a staging URL lets the agents validate findings against the running app instead of reporting theoretical issues.

Continuous testing for a small security team

Strix Cloud schedules pentests, opens autofix PRs, and retests, which reduces manual triage work.

Strix vs. competitors

Strix vs. Shannon

Shannon is an AGPL-3.0 white-box pentester that needs both source code and a running app and focuses on a defined set of web vulnerability classes; Strix is Apache-2.0, accepts a wider range of targets including URLs and API specs, and offers its own cloud platform with PR reviews and autofix.

Strix vs. CodeMender

CodeMender is Google Cloud's managed agent that finds and patches vulnerabilities in source code; Strix focuses on testing running applications and APIs and is available as free open-source software.

Frequently asked questions

What is Strix?

Strix is an open-source AI penetration testing tool. Its agents test applications, APIs, and code that you are authorized to test, validate findings before reporting them, and can suggest fixes. A paid cloud platform adds continuous testing, PR security reviews, and autofix pull requests.

Is Strix free?

The open-source CLI is free under Apache-2.0; you pay your LLM provider for model usage. Strix also says its cloud platform is free for public open-source repositories.

How much does Strix Cloud cost?

Pro costs $29 per seat per month with a 7-day free trial, and pentests are billed separately: rightsized pentests are listed at $60 to $300 each and Full Audits from $2,000. Enterprise is custom-priced. Pentest credits are priced at 1 credit = $1.

Which LLMs does Strix support?

Strix uses LiteLLM, so it works with OpenAI, Anthropic, Google, OpenRouter, Bedrock, Azure, and many other providers, plus local models through Ollama, LM Studio, or vLLM. You can also sign in with a ChatGPT subscription.

Can Strix run in CI?

Yes. Headless mode, a quick scan mode, diff-scoped runs, SARIF output, and exit codes let it run in GitHub Actions, GitLab CI, and other pipelines, as long as the runner has Docker access.

Integrations & fit

GitHubGitHub ActionsGitLabBitbucketJiraLinearSlackDockerLiteLLMOpenRouterOllama
Good fit forSolo / individual, Startup / small team, Enterprise
Pricing modelFreemium· Free tier available
See pricing on Strix →

Alternatives to consider

About Strix

Strix gives development and security teams an AI-driven way to test their own web apps, APIs, and code before release. You point it at a target you have permission to test, such as a local code directory, a repository, or a staging URL, and a team of coordinated agents investigates it inside an isolated Docker sandbox. Findings are validated before they are reported, which is meant to cut the false positives common with traditional scanners. The open-source CLI is free and runs with your own LLM key through LiteLLM, a ChatGPT subscription login, or a local model; quick, standard, and deep scan modes trade speed for coverage, and headless mode, SARIF output, and exit codes make it usable as a CI gate. Strix Cloud removes the local setup and adds team dashboards, scheduled and continuous pentests, pull request security reviews, one-click autofix PRs, a REST API, and Jira, Linear, and Slack integrations. Enterprise adds VPC, on-prem, or air-gapped deployment, bring-your-own-model options, and SSO. The tradeoffs: the open-source tool needs Docker and pays-per-token model usage, deep scans (the default) take hours, local directory targets are mounted writable, and like any active testing tool it must only be run against systems you are explicitly authorized to test.

Updates from Strix

New FeatureStrix v1.6 adds MCP support and a cloud CLI

v1.6.0 added MCP server support, a `strix cloud` CLI for running scans on the managed platform without Docker or an LLM key, new testing skills including OWASP LLM Top 10 2026 coverage, and hardened PDF reports. v1.6.1 and v1.6.2 followed with updated recommended models and Exa web search.

LaunchStrix Launch Week: new platform, PR pentesting, and REST API

Strix's first launch week introduced the new Strix Platform, pentesting on every pull request, a REST API, context-aware testing, and internal infrastructure testing.

Are you the founder? Claim this listing →