Skip to main content
RYVX STRIKE

Autonomous penetration testing with proof attached

Agents recon the target, hunt for vulnerabilities, and prove each one with a working exploit before it is ever reported. CVSS-scored, CWE-tagged, mapped to the compliance frameworks your customers ask about, with a full audit trail.

A scanner reports what might be wrong. Strike refuses to file a finding it cannot back up with a working proof of concept.

THE EVIDENCE BAR

A finding without a working exploit is rejected, not filed.

create_finding hard-rejects anything missing a real, working proof-of-concept script, along with the rest of its required fields. This is not a policy an agent can talk its way around: it is the same code path every finding on this site, real or illustrative, has to pass through.

The one real, filed finding this site shows in full, its PoC and its audit trail, is on the proof page.

HOW IT RUNS

Recon, then hunting, then exploitation.

Recon & OSINT
Maps the attack surface: subdomains, technology fingerprints, exposed cloud assets, leaked credentials.
Hunt & exploit
Every applicable OWASP Top 10 / CWE category is investigated, and every finding is verified with a working exploit before it's reported.
Report
One sandboxed tool loop, start to finish, steered by root agents spawning recon and vuln-hunter/exploiter subagents.
WHAT YOU GET

CVSS-scored, CWE-tagged, exported however you need it.

Every finding carries a deterministic CVSS 3.1 score, not an LLM's self-reported severity, and a CWE id. Findings surface in the local dashboard and export as:

SARIFfor CIPDFfor a client or an auditorMarkdownreport.md, for a repo

A real finding, in full

An admin-session SQL injection against a deliberately vulnerable training app, filed by an agent, shown with its exact PoC script and the target's exact response.

See the finding →

A scored benchmark run

One full, untruncated run scored 8 of 8 on OWASP Juice Shop's own scoreboard, graded by the target rather than by our report, with the run count and the exclusions stated, and the earlier numbers we withdrew explained.

See the numbers →
HOW HARD TO GO

Three strengths. Deep is what a pentest is built for.

Quick20 credits

A reduced turn budget. Fastest, and the least thorough.

Standard50 credits

More turns than quick, less than deep. A middle ground.

Deep100 credits

The strength full-pentest is designed for. Quick mode's turn budget defers exactly the vulnerability classes that need multiple requests to confirm (blind/time-based SQLi, stored XSS, file upload, race conditions), so deep is what a real pentest needs to catch them.

Credits are Ryvx Strike's own currency: no subscription required, and none grants them: buy credits as needed and they never expire. Ryvx Agent spends this exact same balance, on this exact same strength ladder, rather than having a currency of its own. Currency prices vary by region, so they live on the pricing page rather than here.

See plans and pricing →
WHAT WE ARE NOT GOING TO CLAIM

The parts a sceptical engineer would poke at, stated first.

One run, not a rate

One 8-of-8 scored run is one run, not a rate. Stated as such, with the run count and exclusions on the benchmarks page.

Human approval on production

Exploitation against a production-tagged target requires human approval before it runs, and auto-denies rather than hanging when run non-interactively. Never silently skipped.

No free hosted Strike scan

A hosted account starts with zero credits. There is no free hosted Strike scan; the free path is the desktop app and the CLI. The only free hosted thing is a read-only health check of a website you own, and it is not a pentest.

STAY IN THE LOOP

Release notes and product updates, by email.

We'll send a confirmation email; you're not on the list until you click the link in it. See our privacy policy.