Autonomous penetration testing with proof attached
Agents recon the target, hunt for vulnerabilities, and prove each one with a working exploit before it is ever reported. CVSS-scored, CWE-tagged, mapped to the compliance frameworks your customers ask about, with a full audit trail.
A scanner reports what might be wrong. Strike refuses to file a finding it cannot back up with a working proof of concept.
A finding without a working exploit is rejected, not filed.
create_finding hard-rejects anything missing a real, working proof-of-concept script, along with the rest of its required fields. This is not a policy an agent can talk its way around: it is the same code path every finding on this site, real or illustrative, has to pass through.
The one real, filed finding this site shows in full, its PoC and its audit trail, is on the proof page.
Recon, then hunting, then exploitation.
CVSS-scored, CWE-tagged, exported however you need it.
Every finding carries a deterministic CVSS 3.1 score, not an LLM's self-reported severity, and a CWE id. Findings surface in the local dashboard and export as:
A real finding, in full
An admin-session SQL injection against a deliberately vulnerable training app, filed by an agent, shown with its exact PoC script and the target's exact response.
See the finding →A scored benchmark run
One full, untruncated run scored 8 of 8 on OWASP Juice Shop's own scoreboard, graded by the target rather than by our report, with the run count and the exclusions stated, and the earlier numbers we withdrew explained.
See the numbers →Three strengths. Deep is what a pentest is built for.
A reduced turn budget. Fastest, and the least thorough.
More turns than quick, less than deep. A middle ground.
The strength full-pentest is designed for. Quick mode's turn budget defers exactly the vulnerability classes that need multiple requests to confirm (blind/time-based SQLi, stored XSS, file upload, race conditions), so deep is what a real pentest needs to catch them.
Credits are Ryvx Strike's own currency: no subscription required, and none grants them: buy credits as needed and they never expire. Ryvx Agent spends this exact same balance, on this exact same strength ladder, rather than having a currency of its own. Currency prices vary by region, so they live on the pricing page rather than here.
See plans and pricing →The parts a sceptical engineer would poke at, stated first.
One run, not a rate
One 8-of-8 scored run is one run, not a rate. Stated as such, with the run count and exclusions on the benchmarks page.
Human approval on production
Exploitation against a production-tagged target requires human approval before it runs, and auto-denies rather than hanging when run non-interactively. Never silently skipped.
No free hosted Strike scan
A hosted account starts with zero credits. There is no free hosted Strike scan; the free path is the desktop app and the CLI. The only free hosted thing is a read-only health check of a website you own, and it is not a pentest.