March 15th, 2026

Partnering with Caido to Bring Precision & Control to Agentic Pentesting

Security teams shouldn't have to choose between speed and control.

That's why we're announcing our partnership with Caido. Strix is the first autonomous offensive security platform to bring a Caido proxy natively into its engine - giving AI agents a purpose-built interface to execute, replay, and chain requests with precision, while giving security teams complete visibility and control over everything happening under the hood.

Strix is a fully autonomous engine - built to scale offensive security testing across thousands of assets. Our team has used it to earn over $100k in bounties this year alone, so we know what it takes to get results. And the one thing that makes the difference every time is full visibility into what the AI is actually doing, not just more automation.

By integrating Caido, we're opening up a distinct Human-in-the-Loop (HITL) workflow - allowing security professionals to inspect, intercept, and modify traffic on the fly, without sacrificing the coverage of the automated engine underneath.

Eliminating False Positives

One of the biggest pain points in automated testing is noise. But not with Strix. Strix agents running through Caido have full structured access to everything happening in the sandbox - complete request and response history, a live sitemap built from every crawled endpoint, and HTTPQL to filter and query traffic with precision. Rather than operating blind, agents can inspect the full picture, cross-reference findings against real traffic patterns, and surface only what's genuinely exploitable. The result: vulnerability detection accuracy jumps from 82% to 96% on our benchmarks.

Why Caido?

Strix runs a multi-agent system - multiple specialized agents operating in parallel across a target, each handling different attack surfaces simultaneously. Caido is uniquely positioned to support this: it's the only proxy with a true client-server separation, meaning every agent can route traffic headlessly through the same Caido instance without any UI dependency. All agents feed into a single unified project - shared request history, one sitemap, one set of findings. No fragmentation, no lost context across agents.

On top of that, Caido's powerful GraphQL API and SDK give Strix's agents a clean, precise interface to interact with everything programmatically - pulling auth tokens, querying traffic with HTTPQL, creating replay sessions, and chaining requests across agents without bloating context or writing fragile custom scripts. Security teams can then connect their local Caido client at any point and see the full picture of what every agent has touched, in real time.

The real win is human-in-the-loop without any extra effort. Your agent runs, finds stuff, creates replay sessions with descriptive names. You open Caido and it's all right there. Same interface you already know. You can verify, edit the replay tabs as well, dig deeper, etc. There's no extra context switching between your agent's output and your tool that you're used to.

Joseph Thacker Joseph Thacker (@rez0)

For CISOs and Security Leaders

More than just speed, deploying autonomous AI agents in a security context demands accountability. Caido gives Strix's agents a fully auditable sandbox: every request sent, every response received, every finding generated is captured, logged, and inspectable in real time. Nothing is a black box. Security leaders get complete visibility into exactly what the AI is doing at every step, with the ability to monitor, review, and intervene at any point through the Caido interface.

Strix observability dashboard - full visibility into every request, endpoint, and agent activity in real time.
Strix observability dashboard - full visibility into every request, endpoint, and agent activity in real time.

This level of observability is what makes AI-driven pentesting reliable enough to trust at enterprise scale. Combine that with Strix's built-in AI guardrails - strict scope enforcement and tailored agent boundaries - and you have a system that moves fast without ever operating outside the lines.


AI in offensive security is only as good as what you can verify. That's exactly why we're partnering with Caido - to bring autonomous coverage at scale, with the visibility and control to back every finding with confidence.

Book a demo →