Triage tracking and AI validation

Last updated: June 18, 2026

Every vulnerability detected by Strike goes through a triage process: the review that determines whether a finding is real, how relevant it is, and how it should be reported. This process is now visible directly from each vulnerability, through the triage history.

This gives you full traceability: you can see how each finding was assessed, who reviewed it, and what decision was made — from detection to confirmation.


What the triage history is

Inside each vulnerability you'll find a triage history section that records every assessment made on that finding. Each entry includes:

  • Who performed the triage — Strike's AI Triager or the Strike team.

  • Triage status — where the finding is in the evaluation process.

  • Triage result — the conclusion, once the evaluation is complete.

👉 This way you have visibility into the entire evaluation process, not just the final result.


Triage statuses

Status

What it means

Pending

The finding is awaiting evaluation.

In progress

The evaluation is underway.

Completed

The evaluation has finished and has an associated result.


Triage results

Once the triage is Completed, the finding receives one of these results:

  • Valid — the bug was reproduced and its impact demonstrated. The finding is a real vulnerability.

  • False positive — not a real vulnerability (by-design behavior, misinterpretation, wrong agent context, etc.).

  • Not reproducible — the base behavior could not be reproduced.

  • Out of scope — the asset, host, or functionality is outside the engagement scope.

  • Duplicate — the finding is real and valid, but it was already reported previously.

  • Needs more context — the setup to reproduce it is missing (credentials, secondary user, prior endpoint, role context, complete steps, etc.).

  • Needs more evidence — the bug is reproduced or plausible, but its impact isn't sufficiently demonstrated (theoretical impact, unproven chain, incomplete PoC).

👉 Only findings with a Valid result become part of your active vulnerabilities. The rest are considered discarded and shown in a separate section. Learn more in the Discarded vulnerabilities article.


The AI Triager

Before the Strike team's review, each finding is evaluated by the AI Triager, our AI-based triage agent. Its assessment is recorded in the triage history, clearly identified as performed by the AI agent.

This gives you an immediate first read on the finding while the validation process continues.

💡 Combining artificial intelligence with human validation reduces noise and improves the accuracy of results, ensuring every confirmed vulnerability has real context and is actionable.


Why it's useful

Full traceability of how each finding was assessed

Transparency about the role of AI and the Strike team's validation

More context to prioritize and make decisions