FAQS

Answers to common questions

Everything teams ask before and after connecting Strix — from how alerts are scored to how cases close, what each plan includes, and how your data is handled. Jump to a topic below.

Getting started

What Strix is and how to begin.

Strix is an alert triage and response platform. It takes the alerts your existing security tools already produce — Wazuh, Splunk, Microsoft Sentinel — scores them, groups them, and automatically opens cases for the critical ones, complete with a Jira ticket, an SLA clock, and AI-written remediation guidance. The goal is to turn a noisy firehose of alerts into a short list of things that genuinely need action.

Integrations & sources

Connecting your tools and data.

Three alert sources — Wazuh, Splunk, and Microsoft Sentinel — plus Jira for two-way case tracking and Slack for notifications. All alert sources connect the same way: a secure, tokenised webhook unique to your organization.

Alerts & scoring

How alerts are prioritised.

Every alert runs through a multi-stage risk engine that weighs base severity, frequency (bursts of the same detection), correlation (related detections on the same asset), timing (off-hours vs business-hours), and duplicate suppression. Those stages combine into a single score that decides whether an alert is actionable or filed as noise.

Cases, SLAs & workflows

What happens after a critical alert.

No. Scoring, inbox grouping, auto-cases, and the SLA clock all run out of the box on every connected source — there's nothing to configure. The only optional piece is Jira: connect it and two-way sync turns on automatically for new cases.

Jira & notifications

Keeping your other tools in step.

It's two-way. When a critical case opens, Strix creates a linked Jira ticket carrying the full analysis. From there, Jira status, assignee, comments, and attachments sync back onto the case — moving the ticket to Done pushes the case to awaiting-verification, and a Jira attachment marks it Verified. Your team can live in Jira and the case stays current.

Reports

Turning history into documents.

Four kinds, all AI-written from your real alert and case data and exported to PDF: an Admin Remediation Action Report (for security ops), an Auditor Remediation Evidence Report (evidence-forward, for compliance), a Device Owner Patch Advisory (short and plain-language), and a per-device Remediation Report with full technical detail and a closure section.

Security & data

How your data is handled.

Secrets you enter — like Jira credentials — are encrypted at rest with an AES-256 key, and each organization's data is isolated. Webhook tokens are per-organization and can be rotated or revoked at any time, which immediately invalidates the old value.

Plans & getting started

Choosing a plan and provisioning.

Starter is sized for a single team getting started: one alert source, one notification channel, one ticketing connection, up to 50 monitored endpoints, and about a month of retention. Growth scales that up: three alert sources, unlimited notification channels, two ticketing connections, up to 150 endpoints, around three months of retention, and compliance tagging.

Team & roles

Who can do what.

Two organization roles. Admin has full control — integrations, billing, team management, role changes, and assigning cases. Analyst is the default member role: triage the inbox, work and comment on cases, and generate reports, without org-level settings.

Still have a question?

Browse the setup guides, or reach our team — we're happy to help you connect.

Ready to see Strix on your own alerts?

Book Demo