Triage tracking and AI validation
Last updated: June 18, 2026
Every vulnerability detected by Strike goes through a triage process: the review that determines whether a finding is real, how relevant it is, and how it should be reported. This process is now visible directly from each vulnerability, through the triage history.
This gives you full traceability: you can see how each finding was assessed, who reviewed it, and what decision was made — from detection to confirmation.
What the triage history is
Inside each vulnerability you'll find a triage history section that records every assessment made on that finding. Each entry includes:
Who performed the triage — Strike's AI Triager or the Strike team.
Triage status — where the finding is in the evaluation process.
Triage result — the conclusion, once the evaluation is complete.
👉 This way you have visibility into the entire evaluation process, not just the final result.

Triage statuses
Triage results
Once the triage is Completed, the finding receives one of these results:
Valid — the bug was reproduced and its impact demonstrated. The finding is a real vulnerability.
False positive — not a real vulnerability (by-design behavior, misinterpretation, wrong agent context, etc.).
Not reproducible — the base behavior could not be reproduced.
Out of scope — the asset, host, or functionality is outside the engagement scope.
Duplicate — the finding is real and valid, but it was already reported previously.
Needs more context — the setup to reproduce it is missing (credentials, secondary user, prior endpoint, role context, complete steps, etc.).
Needs more evidence — the bug is reproduced or plausible, but its impact isn't sufficiently demonstrated (theoretical impact, unproven chain, incomplete PoC).
👉 Only findings with a Valid result become part of your active vulnerabilities. The rest are considered discarded and shown in a separate section. Learn more in the Discarded vulnerabilities article.
The AI Triager
Before the Strike team's review, each finding is evaluated by the AI Triager, our AI-based triage agent. Its assessment is recorded in the triage history, clearly identified as performed by the AI agent.
This gives you an immediate first read on the finding while the validation process continues.
💡 Combining artificial intelligence with human validation reduces noise and improves the accuracy of results, ensuring every confirmed vulnerability has real context and is actionable.
Why it's useful
✔ Full traceability of how each finding was assessed
✔ Transparency about the role of AI and the Strike team's validation
✔ More context to prioritize and make decisions