Ask Cat › AI Tool Summary › Strix
[Review] Strix's Free Tier Is Real, But It Comes With Two Costs the Vendor Page Skips
- Free tier: None
- Cheapest paid plan: US$29/mo and up
- Free quota: The cloud platform has no ongoing free plan; Pro has a 7-day free …
- Last checked: 2026-10-05
Article last updated: 2026-10-07
Strix bills itself as an autonomous AI penetration-testing tool — a set of AI agents that work together to probe a system, find and confirm security holes, and write pull requests (PRs, the file “please merge this change” requests developers use on GitHub) to fix them. The headline most people repeat is “it’s open source, so it’s free.” That’s true for the software itself. What gets left out is that running it still costs money, just not to Strix. We checked the free tier claim against the official pricing page and the CLI (command-line interface, the no-GUI version you run from a terminal) documentation, and found two thresholds that change whether “free” actually means free for you.
What Strix actually does
Strix runs multiple AI agents that explore a target, try to exploit what they find, and verify the exploit actually works before reporting it — rather than just flagging a suspicious pattern. It can point at your own source code, a GitHub repository, or a live website, and it can generate a fix as a PR instead of just a report. That’s the pitch across both the open-source CLI and the paid cloud platform.

Figure: strix.ai official pricing page, captured 2026-10-07.
The cloud platform has no standing free tier
If you go to strix.ai expecting a free account like you’d get from a SaaS tool, there isn’t one. The Pro plan is a 7-day free trial, nothing longer, and after that it’s US$29 per seat (per user) per month. Pentests on Pro are billed separately — pay per test — so the US$29 doesn’t include the actual scans, only continuous features: API and web pentesting, PR security review, one-click autofix, attack-surface monitoring, scheduled pentests, and integrations with Jira, Linear, and Slack.
Beyond Pro, Strix sells standalone engagements. A “Rightsized Pentest” is listed at US$60–300 per test, depending on target size — a self-serve test of an app, API, or repo with white-box access (testers get internal visibility, not just an outside view) and authorized testing, verified vulnerabilities with proof-of-exploit, autofix, and OWASP Top 10 coverage (a standard list of the ten most common web vulnerability categories). It includes one free retest once you’ve applied the fix. A “Full Audit” starts from US$2,000 per audit and adds business-logic and attack-chain testing, formal SOC 2 or ISO 27001 compliance reports, custom scope and test accounts, review by a CREST-certified pentester (an independently accredited human tester, not just the AI agents), and same-day results. Enterprise is quote-only, for recurring audits across an organization’s full environment.
There’s also a discount worth knowing about: early-stage startups get 50% off Pro for the first six months.
The open-source route: free software, not a free ride
The actual free option is the open-source CLI, installable with curl or pipx (a Python package installer). There’s no scan limit and no watermark — Strix doesn’t cap how many times you run it or badge your results. But two things have to be true before you can use it at all: Docker needs to be running on your machine, and you need your own API key from a supported LLM provider — OpenAI, Anthropic, Google, or similar. The software costs nothing. The inference — the actual work the AI agents do — bills straight to whichever model provider you picked, at that provider’s rates, not Strix’s.

Illustration: While the open tool asks for no ticket, behind the gate automated agents endlessly consume tokens, quietly spinning a separate mountain of bills.

Figure: compiled by AMPM from its verified data (last verified 2026-10-05).
🔍 AMPM exclusive check
The vendor’s pricing page is upfront about the 7-day trial and the per-seat Pro price, but it doesn’t put the open-source CLI’s two prerequisites — Docker and a paid LLM API key — anywhere near the word “free.” You have to go into the documentation to learn that “free” means “free software, bring your own compute and your own model bill.” That’s the gap: the pricing page frames the free option as a clean alternative to paying Strix, when it’s really a different bill, sent by someone else, with no ceiling Strix controls.
The second thing we flagged: the official site lists the Rightsized Pentest at US$60–300 per test, but a third-party roundup, intruder.io, describes a standalone Strix pentest starting at US$1,000. That’s a big gap for the same product category. We’re treating the official pricing page as authoritative since it’s Strix’s own current listing, but a reader comparing sources elsewhere should know the two don’t match.
☀️ AMO, the budget-minded cat

If you just want to try Strix without opening your wallet, the open-source CLI is the honest free option — no scan cap, no watermark, run it as much as you want. But “free” only covers the Strix part. You still need Docker running and an API key from OpenAI, Anthropic, Google, or another supported provider, and every scan burns that provider’s tokens on your account, not Strix’s. For a solo dev poking at one repo occasionally, that might be a few dollars. For anything resembling regular use, budget for it like any other API bill — Strix just won’t be the line item.
On the hosted side, there’s no free tier to fall back on, only a 7-day Pro trial. After that it’s US$29 per seat per month, and pentests are billed on top of that per test — so a single-person team doing one scan a month is paying US$29 plus a separate per-test fee, not just US$29. The Rightsized Pentest at US$60–300 per test is the cheaper one-off if you don’t want a monthly seat at all, and it includes a free retest after you fix what it finds, which is a real saving if your first pass turns up a lot. The 50% startup discount on Pro’s first six months is the best deal on this page if you qualify — half of US$29 for six months is a meaningfully lower entry point for a small team testing the waters.
🌙 PIMI, the performance-minded cat

The feature that actually matters for whether this tool does its job: verified vulnerabilities with proof-of-exploit. Strix’s agents don’t just flag a pattern that looks risky — they try to exploit it and confirm it worked before telling you about it, which cuts down on the noisy false positives that make most scanners exhausting to triage. OWASP Top 10 coverage on even the cheapest paid tier (US$60–300 per Rightsized Pentest) means you’re not missing the standard categories attackers actually use.
For teams that need this running continuously rather than as a one-off, Pro’s scheduled pentests and attack-surface monitoring at US$29/seat/month plus per-test billing means new code gets checked automatically, not just when someone remembers to run a scan. PR security review and one-click autofix are the pieces that turn a finding into a merged fix instead of a ticket nobody gets to — paired with Jira, Linear, and Slack integrations so the alert lands where the team already works.
If the bar is a report you can hand to an auditor, the Full Audit at US$2,000 per audit is where this stops being just an AI tool: a CREST-certified human pentester reviews the AI’s findings and the report comes formatted for SOC 2 or ISO 27001 compliance, with same-day turnaround. The open-source CLI, whatever model you point it at, skips all of that — no human review, no compliance-formatted report. It’s a different tier of tool for a different job.
Verdict: who should use it, who should skip it
Use the open-source CLI if you’re comfortable running Docker and already pay for an LLM API key for other work — the marginal cost of pointing it at your own repo is low and there’s no Strix-imposed cap. Use Pro if you want continuous, scheduled testing wired into your existing dev tools and can absorb US$29/seat/month plus per-test fees, especially if you qualify for the 50% startup discount. Use a Rightsized Pentest (US$60–300) if you want one credible pass at an app or API without a subscription. Use Full Audit (US$2,000) only if you specifically need a CREST-reviewed, compliance-formatted report — anyone who just wants vulnerabilities found doesn’t need to pay for the human sign-off.
Skip the cloud platform if you were expecting an actual free tier — there isn’t one, only a 7-day Pro trial. And skip the open-source CLI if you don’t already have Docker set up or don’t want to carry a separate, uncapped LLM API bill — “free” here means free of charge from Strix, not free of charge, period.
Written: 2026-10-07 Price last verified: 2026-10-05 Tool last health-checked: 2026-10-07
🔗 Related on AMPM
📎 Sources
All prices and quotas in this article come from AMPM’s verified dataset for Strix (last verified 2026-10-05); primary sources:
🐾 Meet the cats: AMO and PIMI
AMPM is a Taiwan-based AI-tool pricing watchdog. Our motto: ask before you subscribe. Two cats argue every tool from two sides:
- ☀️ AMO — the budget-minded cat. Always asks: is the free tier enough, and is paying actually worth it?
- 🌙 PIMI — the performance-minded cat. Cares about whether it works well, fast, and gets your job done.
When they are done arguing, you know whether to pay. Every number is checked by us, with the verification date at the end.
🐾 Our sister sites also checked
Let's take a look at these
- Strix Comprehensive Introduction: Pricing, Features, and Actual Limitations
- Strix Is the free quota enough?
- Strix Alternatives
- Comprehensive Free Quota List for All Tools
