About Strix

Built by Security Engineers Who Ran the Old Playbook

Founded in 2023. Bootstrapped. Focused entirely on the problem of continuous penetration testing for teams that ship fast.

Mission

The Security Model Has Not Kept Pace With How Software Ships

In 2023, Ahmed Allam was running the security program at a fintech company that shipped multiple production deployments per day. Their annual penetration test produced 140 findings. By the time the remediation cycle was complete, the codebase had changed enough that three of the critical findings were already fixed by unrelated engineering work, and two new equivalent issues had been introduced.

The core problem was not the quality of the pentest. It was the fundamental mismatch between a point-in-time assessment and a continuously changing attack surface. Every team experiencing this mismatch was spending money on security coverage that expired the moment the report was delivered.

Strix was built to close that gap. Not by making humans run faster, but by running the analysis continuously and automatically, in the environment where the code actually lives.

Team

The People Building Strix

Ahmed Allam, CEO and Co-Founder
Ahmed Allam
CEO and Co-Founder

Previously led security engineering at a fintech company managing PCI DSS compliance for a high-volume payments platform. Ran penetration test programs across multiple product teams before founding Strix.

Priya Nair, CTO
Priya Nair
CTO

Researched AI-assisted vulnerability discovery at a university security lab before joining a cloud infrastructure company to build automated security analysis tooling. Leads the core reasoning engine at Strix.

Marcus Webb, Head of Research
Marcus Webb
Head of Research

Specialized in exploit chain research and adversarial technique analysis at an enterprise security vendor. Published research on supply chain attack patterns and API authorization bypass techniques.

How We Build

Building something worth breaking

We do not sell false confidence. If Strix does not find a chain, we tell you what it checked and why. If something is outside scope, we say so clearly.

We are not trying to replace the security engineer. We are trying to give them 90 days of coverage between engagements instead of a 200-page report that is already outdated.

Strix is bootstrapped. We grow by being correct, not by being loud.

Get Early Access