Frequently asked questions (FAQs)

Last updated: April 13, 2026

This section brings together the most common questions about how the platform works, what it can do, and how it's used across different contexts.

The goal is to clear up common doubts and make it easier to adopt continuous testing, giving you clarity on how Strike operates and what to expect from the platform.


About the platform

What exactly does Strike do?

Strike continuously discovers, tests, and validates the security of digital assets, combining artificial intelligence with expert validation.

👉 It works like an always-on pentester, running non-stop across your attack surface.

Do I have to run tests manually?

No. Once an asset is set up, the platform runs testing automatically and continuously.

  • Detects changes

  • Runs new tests

  • Revalidates vulnerabilities

👉 All of this happens without any manual intervention.

What kind of assets can it test?

The platform mainly evaluates:

  • Web applications

  • APIs

  • Backend services

It can also operate in private environments via VPN or custom access setups.


About testing

How are new assets detected?

The platform uses mechanisms like External Radar and Cloud Radar to continuously discover assets and changes across the attack surface.

👉 This keeps the inventory up to date without manual work.

What if my systems are protected (VPN, authentication, etc.)?

Strike adapts to different access levels:

  • Limited testing (public surface)

  • Controlled access via VPN

  • Use of credentials or tokens

👉 Coverage depends on the level of access configured.

How are false positives handled?

Findings are validated by the Hacking Governance team before being reported.

👉 This cuts down noise significantly and makes sure results are actionable.

Can AI detect complex vulnerabilities?

Yes. The platform doesn't just run automated scans — it also:

  • Reasons about how the system behaves

  • Runs tests like a real attacker would

  • Can detect business logic flaws

👉 The hybrid model (AI + experts) reaches coverage on par with — or beyond — a traditional pentest.


About operations

Can it affect how my systems run?

No. The platform is built to operate safely:

  • No destructive actions

  • Respects defined limits

  • Includes preventive controls

It also comes with:

  • Real-time monitoring

  • Automatic stop if anomalies are detected

  • Immediate pause button (kill switch)

Can I stop tests?

Yes. You can pause all executions at any time.

Can it be used to validate new releases?

Yes. In fact, it's a recommended practice to use the platform to test new features before shipping them.


About security and data

Is my data protected?

Yes. The platform applies security controls, encryption, and isolation to protect customer data.

👉 On top of that, customer data is never used to train models.

This section is updated regularly to reflect new capabilities, features, and best practices.