Strix
Product Use Cases Security Pricing Blog Company
Sign In Get Early Access
Product Use Cases Security Pricing Blog Company Get Early Access Sign In

Privacy Policy

Last updated: February 18, 2026

1. Introduction

Strix, Inc. ("the Company," "we," "us," or "our") operates getstrix.org and the Strix autonomous penetration testing platform (collectively, the "Service"). The Strix platform connects to your code repositories, API endpoints, and cloud accounts to run continuous, automated security testing and produce exploit-chain findings for your security team.

This Privacy Policy explains what information the Company collects from visitors to getstrix.org and from customers and users of the Strix platform, how we process it, and the choices available to you. It applies to information collected through the Service and through direct communications with us.

The Company is located at 2325 3rd Street, Suite 400, San Francisco, CA 94110 and can be reached at [email protected].

2. Information We Collect

2.1 Information You Provide

We collect information you submit directly, including:

  • Contact details (name, work email, phone) when you request early access, submit a contact form, or communicate with us;
  • Professional context you choose to share (company name, team size, primary security use case);
  • The content of messages you send us.

2.2 Security Testing Data

When you connect systems to the Strix platform, the Company accesses and processes the following in order to deliver the penetration testing service:

  • Source code: cloned from your connected repositories under read-only OAuth scopes into isolated ephemeral scan environments. Source code is never persisted beyond the scan lifecycle; each environment is destroyed at the end of its run.
  • Cloud account credentials and API authentication tokens: stored in an encrypted secrets vault solely for executing authorized security scans. No Company employee has direct read access to stored credentials. These are authentication credentials allowing access to accounts and are treated as sensitive personal information under applicable California law.
  • Scan findings: exploit chain paths, severity assessments, affected components, and reproduction steps generated by the Strix platform. Findings are stored encrypted at rest and scoped to your workspace.

2.3 Information Collected Automatically

When you visit getstrix.org, we automatically collect limited technical information:

  • IP address and approximate location (city/region level);
  • Browser type, operating system, device class;
  • Pages visited, referring URLs, time on page;
  • Cookie and similar identifiers (see Section 5 and our Cookie Policy).

2.4 We Do Not Knowingly Collect Children's Data

getstrix.org is a professional security platform not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.

3. How We Use Information

We use the information we collect to:

  • Operate, deliver, and improve the Strix platform, including running automated penetration tests and generating exploit-chain reports for your connected systems;
  • Communicate with you about your access request, service status, and security findings relevant to your workspace;
  • Send service updates and, where required by applicable law, marketing communications with your consent;
  • Analyze aggregate, anonymized usage patterns to improve test coverage and detection quality;
  • Detect, investigate, and prevent unauthorized access, fraud, or abuse of the Service;
  • Comply with legal obligations.

We do not use your source code, scan findings, or cloud credentials to train machine-learning models. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.

4. Sharing of Information

We share personal information only with:

  • Infrastructure and security sub-processors acting on our behalf (for example, cloud hosting providers, encrypted storage services, email delivery providers) under contractual confidentiality and data-processing terms;
  • Legal authorities, when required by applicable law, valid legal process, or to protect the rights, safety, or property of the Company or others;
  • A successor entity in the event of a merger, acquisition, or asset sale, subject to the commitments in this Policy.

We do not sell personal information to third parties. Scan findings, source code access data, and cloud credentials are never disclosed to parties outside your authorized workspace.

5. Cookies and Tracking

We use cookies and similar technologies to operate the site, remember preferences, and measure usage. For details and choices, see our Cookie Policy.

6. Data Retention

We retain personal information only as long as needed for the purposes described, to comply with legal or accounting obligations, and to resolve disputes:

  • Scan findings are retained for the duration of your active workspace subscription and deleted within 30 days of workspace closure, or sooner upon request;
  • Cloud credentials and API tokens are stored in an encrypted secrets vault tied to your workspace and purged on workspace deletion;
  • Source code cloned for scanning is destroyed at the end of each scan run and is never retained beyond the scan lifecycle;
  • Contact and early-access inquiry data is retained for 24 months from last interaction, then deleted;
  • Server access logs are retained for 90 days, then aggregated and anonymized.

7. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption for all data in transit, encryption at rest for scan findings and workspace data, an encrypted secrets vault with restricted access for stored credentials, isolated ephemeral scan environments destroyed after each run, and least-privilege access controls for internal systems. The Company has implemented access controls, audit logging, and incident response procedures aligned with SOC 2 Type II requirements; formal certification is on our roadmap as we scale. No system is perfectly secure, and we cannot guarantee absolute security.

8. Your General Rights

Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.

9. California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), California residents have specific rights regarding personal information collected about them. This section supplements the rest of the Policy.

9.1 Categories We Collect

In the past 12 months, we have collected the following categories of personal information defined under Cal. Civ. Code §1798.140: identifiers (name, work email, IP address); professional information (company name, role, team size); commercial information (service inquiries, early-access requests); internet activity (browsing on getstrix.org); inferences drawn from the above for service-improvement purposes; and sensitive personal information as defined under §1798.140(ae)(1)(B): cloud account credentials and API authentication tokens provided by platform customers to enable authorized security scanning of connected systems. Customers who use only the marketing website without connecting systems for scanning do not have sensitive personal information collected beyond the standard categories above.

9.2 Sources, Purposes, Disclosure

We obtain this information from you directly and through automatic site instrumentation. We use it to operate and improve the Service, communicate with you, and meet legal obligations. We disclose it only to service providers under written contract and to legal authorities where required.

9.3 Your CCPA / CPRA Rights

Cloud account credentials and API tokens held in the Strix secrets vault are used solely to execute authorized security scans as directed by your workspace configuration. The Company does not use them for any purpose beyond delivering the Service.

  • Right to Know: request the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete: request deletion of personal information we collected from you, subject to legal exceptions.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: we do not sell personal information; we do not "share" it for cross-context behavioral advertising as defined under CPRA.
  • Right to Limit Use of Sensitive PI: we do not use sensitive personal information for purposes beyond those permitted without authorization.
  • Right to Non-Discrimination: we will not deny services, charge different prices, or provide a different level of service because you exercised a right.

9.4 How to Exercise

Submit a verifiable request by emailing [email protected] with the subject line "California Privacy Request." Include enough detail for us to verify you are the person whose information is the subject of the request. We respond within 45 days, with a possible 45-day extension for which we will notify you.

9.5 Authorized Agents

You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization; we may also require you to verify your identity directly.

9.6 "Shine the Light"

California Civil Code §1798.83 entitles California residents to request information regarding our disclosure of personal information to third parties for direct marketing. We do not disclose personal information for third-party direct marketing.

9.7 Do Not Track and Global Privacy Control

Under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code §22575), we disclose how we respond to "Do Not Track" (DNT) browser signals. Because there is no common industry standard for interpreting DNT signals, we do not currently respond differently to them. We do not authorize third parties to collect personally identifiable information about your activity across different websites when you use the Service. We honor an opt-out preference signal sent by a platform or browser that complies with the CPRA, such as the Global Privacy Control (GPC); when we detect a GPC signal, we treat it as a valid request to opt out of the sale or sharing of personal information for that browser or device.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.

11. Contact

Questions, requests, or complaints can be sent to:

Strix, Inc.
2325 3rd Street, Suite 400, San Francisco, CA 94110
Email: [email protected]
Phone: +1 (415) 553-8041
Strix

AI-driven autonomous penetration testing for code, API, and cloud security.

2325 3rd Street, Suite 400
San Francisco, CA 94110
[email protected]
+1 (415) 553-8041

Product

  • Platform Overview
  • Use Cases
  • Security
  • Pricing

Company

  • About
  • Blog
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Strix, Inc.

Cookie preferences