usestrix (Strix AI)
The company behind strix, the spoke’s first commercial vendor rather than an individual
researcher or a hobby project. It runs the open-core split this corpus hasn’t seen before: the
Apache-2.0 CLI is the whole agent, and the money is in the hosted platform at app.strix.ai —
continuous scanning, DevSecOps integrations (GitHub, GitLab, Bitbucket, Slack, Jira, Linear),
one-click AI-generated fix PRs, and findings that accumulate across runs.
The enterprise tier names its actual buyer: SSO (SAML/OIDC), compliance-ready pentest reports for SOC 2, ISO 27001 and PCI DSS, VPC or self-hosted deployment, BYOK models, and an SLA. Which is to say the product being sold is not the exploitation, it’s the audit artifact — the report a compliance regime requires, produced in hours instead of by a consulting engagement.
That framing is worth holding beside the tool’s capability. A pentest report is a governance
deliverable; automating its production changes what an attestation costs and therefore what it
attests to (cross-spoke: ../ai-governance-wiki, ../defensive-security-wiki).