STRIGOI.AI

COMING SOON

ADVERSARIAL AI

Agentic AI
red teaming.

Security testing with independent confirmation and visible limits.

Authorized targets. Reproducible evidence. Transparent coverage.

THE DATA BOUNDARY

Storage. Processing. AI inference.

Europe, throughout.

Evidence storage
EU ONLY
Assessment processing
EU ONLY
AI inference
EU ONLY

Your data stays in the EU, including AI inference.

See Strigoi in action.

From verified ownership to evidence and coverage.
The assessment, in 75 seconds.

One authorized assessment. Real activity. Visible limits.
Starts muted. Turn on sound in the player.
1080p 75 seconds

Your data stays in Europe.

Full EU data residency, including AI inference.

BUILT FOR EUROPEAN ORGANIZATIONS

Technical evidence does not establish compliance or certification.

EXTERNAL THREAT CONTEXT

Attacks don’t wait.
Get ahead of them.

Aggregate activity from Cloudflare Radar.
Context for the work ahead.

OBSERVED FLOWS

GLOBAL SHARE

Waiting for recent observations.

The geographic view remains available.

European destinations among the top global flows.

EUROPEAN THREAT ACTIVITY

European threat activityCountry-level aggregate flows into Europe. Select a flow in the adjacent list for its source, destination, and share. Paths illustrate direction, not network routes.ICELANDISUNITED KINGDOMGBFRANCEFRSPAINESGERMANYDEITALYITROMANIAROPOLANDPLNORWAYNOSWEDENSEFINLANDFIUKRAINEUAGREECEGRRUSSIARU

COUNTRY-LEVEL ACTIVITY / GLOBAL ORIGINS

Methodology & coverage

This map visualizes mitigated HTTP traffic observed by Cloudflare over the returned 24-hour window. We request the top 100 global country pairs, select destinations in geographic Europe, and display up to 30. Shares retain Cloudflare’s global denominator; the list is incomplete coverage.

Source countries derive from IP geography. Destination countries derive from customer billing locations. Markers are illustrative country anchors. Arcs indicate direction, not network routes; animation does not represent individual attacks. This is external context, not Strigoi assessment evidence or a count of confirmed incidents.

The geographic selection includes the UK, Norway, Switzerland, Russia and Kosovo; it is not an EU-membership filter. Cyprus and Türkiye fall outside this geographic selection. The visible page refreshes every five minutes; the provider’s timestamp reports the actual data age.

Attack categories and industries are separate global Radar summaries over the preceding day. Categories are Cloudflare managed-rule classifications; industry labels describe the distribution of mitigated HTTP traffic by customer industry. We preserve the provider’s percentages without renormalizing them. Neither summary is attributed to an individual country pair, and selecting a tab does not filter the map. Each summary refreshes independently while its tab is visible and retains its last successful snapshot if updates fail.

Country outlines use Natural Earth’s detailed 1:10 million vector geography (version 5.1.1, Germany boundary convention), including Crimea within Ukraine. They are country boundaries, not current military control lines. Kosovo is displayed separately; its recognition is disputed.

Cloudflare methodology ↗Data source & licensing ↗Natural Earth geography ↗

Evidence you can
stand behind.

Strigoi brings agentic AI red teaming to authorized web assessments. Specialist AI agents choose focused checks, investigate security hypotheses, and challenge each other’s conclusions. Every validated finding must stand up to evidence.

  1. Discover.

    AI agents map exposed routes, APIs, headers, and scripts, then pursue security hypotheses. Every target-facing action stays within fixed authorization limits.

  2. Confirm.

    Independent confirmation rechecks potential issues. An optional adversarial AI review challenges assumptions, weak evidence, and overstated coverage.

  3. Review.

    A final adjudicator weighs the evidence and contradictions. Validated findings include impact, reproducible steps, remediation, and explicit limitations.

Challenge the conclusion.

The assessment itself gets challenged. The optional adversarial review examines alternative explanations, false-positive risks, and claims that overstate what was tested.

This reasoning role works from collected evidence and has no direct target access. Independent adjudication then decides which signals qualify as validated findings.

Permission before action.

Defined targets. Bounded requests. Non-destructive checks. Every assessment follows an explicit authorization policy that the agents cannot expand themselves.

Sensitive evidence is redacted. Coverage and limitations stay visible. An assessment with no findings is never a guarantee of safety.