FAQS
Answers to common questions
Everything teams ask before and after connecting Strix — from how alerts are scored to how cases close, what each plan includes, and how your data is handled. Jump to a topic below.
Getting started
What Strix is and how to begin.
Strix is an alert triage and response platform. It takes the alerts your existing security tools already produce — Wazuh, Splunk, Microsoft Sentinel — scores them, groups them, and automatically opens cases for the critical ones, complete with a Jira ticket, an SLA clock, and AI-written remediation guidance. The goal is to turn a noisy firehose of alerts into a short list of things that genuinely need action.
Integrations & sources
Connecting your tools and data.
Three alert sources — Wazuh, Splunk, and Microsoft Sentinel — plus Jira for two-way case tracking and Slack for notifications. All alert sources connect the same way: a secure, tokenised webhook unique to your organization.
Alerts & scoring
How alerts are prioritised.
Every alert runs through a multi-stage risk engine that weighs base severity, frequency (bursts of the same detection), correlation (related detections on the same asset), timing (off-hours vs business-hours), and duplicate suppression. Those stages combine into a single score that decides whether an alert is actionable or filed as noise.
Cases, SLAs & workflows
What happens after a critical alert.
No. Scoring, inbox grouping, auto-cases, and the SLA clock all run out of the box on every connected source — there's nothing to configure. The only optional piece is Jira: connect it and two-way sync turns on automatically for new cases.
Jira & notifications
Keeping your other tools in step.
It's two-way. When a critical case opens, Strix creates a linked Jira ticket carrying the full analysis. From there, Jira status, assignee, comments, and attachments sync back onto the case — moving the ticket to Done pushes the case to awaiting-verification, and a Jira attachment marks it Verified. Your team can live in Jira and the case stays current.
Reports
Turning history into documents.
Four kinds, all AI-written from your real alert and case data and exported to PDF: an Admin Remediation Action Report (for security ops), an Auditor Remediation Evidence Report (evidence-forward, for compliance), a Device Owner Patch Advisory (short and plain-language), and a per-device Remediation Report with full technical detail and a closure section.
Security & data
How your data is handled.
Secrets you enter — like Jira credentials — are encrypted at rest with an AES-256 key, and each organization's data is isolated. Webhook tokens are per-organization and can be rotated or revoked at any time, which immediately invalidates the old value.
Plans & getting started
Choosing a plan and provisioning.
Starter is sized for a single team getting started: one alert source, one notification channel, one ticketing connection, up to 50 monitored endpoints, and about a month of retention. Growth scales that up: three alert sources, unlimited notification channels, two ticketing connections, up to 150 endpoints, around three months of retention, and compliance tagging.
Team & roles
Who can do what.
Two organization roles. Admin has full control — integrations, billing, team management, role changes, and assigning cases. Analyst is the default member role: triage the inbox, work and comment on cases, and generate reports, without org-level settings.
Still have a question?
Browse the setup guides, or reach our team — we're happy to help you connect.