Frequently asked questions (FAQs)
Last updated: April 13, 2026
This section brings together the most common questions about how the platform works, what it can do, and how it's used across different contexts.
The goal is to clear up common doubts and make it easier to adopt continuous testing, giving you clarity on how Strike operates and what to expect from the platform.
About the platform
What exactly does Strike do?
Strike continuously discovers, tests, and validates the security of digital assets, combining artificial intelligence with expert validation.
👉 It works like an always-on pentester, running non-stop across your attack surface.
Do I have to run tests manually?
No. Once an asset is set up, the platform runs testing automatically and continuously.
Detects changes
Runs new tests
Revalidates vulnerabilities
👉 All of this happens without any manual intervention.
What kind of assets can it test?
The platform mainly evaluates:
Web applications
APIs
Backend services
It can also operate in private environments via VPN or custom access setups.
About testing
How are new assets detected?
The platform uses mechanisms like External Radar and Cloud Radar to continuously discover assets and changes across the attack surface.
👉 This keeps the inventory up to date without manual work.
What if my systems are protected (VPN, authentication, etc.)?
Strike adapts to different access levels:
Limited testing (public surface)
Controlled access via VPN
Use of credentials or tokens
👉 Coverage depends on the level of access configured.
How are false positives handled?
Findings are validated by the Hacking Governance team before being reported.
👉 This cuts down noise significantly and makes sure results are actionable.
Can AI detect complex vulnerabilities?
Yes. The platform doesn't just run automated scans — it also:
Reasons about how the system behaves
Runs tests like a real attacker would
Can detect business logic flaws
👉 The hybrid model (AI + experts) reaches coverage on par with — or beyond — a traditional pentest.
About operations
Can it affect how my systems run?
No. The platform is built to operate safely:
No destructive actions
Respects defined limits
Includes preventive controls
It also comes with:
Real-time monitoring
Automatic stop if anomalies are detected
Immediate pause button (kill switch)
Can I stop tests?
Yes. You can pause all executions at any time.
Can it be used to validate new releases?
Yes. In fact, it's a recommended practice to use the platform to test new features before shipping them.
About security and data
Is my data protected?
Yes. The platform applies security controls, encryption, and isolation to protect customer data.
👉 On top of that, customer data is never used to train models.
This section is updated regularly to reflect new capabilities, features, and best practices.