Developer docs
API playgroundTry for free, no card

Search company profiles

Aikido Security

Full company profile

uuid00000nq

Namestring
Aikido Security
Legal namestring
Aikido Security BV
Websiteurl
aikido.dev
Company typeenum
Private
Founded yearint
2022
Descriptiontext

Aikido Security is a Belgian SaaS cybersecurity company, founded in 2022 and headquartered in Ghent, that operates a unified, API-first security platform consolidating code, cloud, and runtime protection into a single product. The platform integrates multiple traditional scanning engines (SAST, SCA, secrets detection, IaC scanning, container/VM scanning, CSPM, DAST) with proprietary AI-driven features: a reachability and AutoTriage engine claimed to reduce alert noise by up to 95%, AI AutoFix that generates reviewable remediation pull requests, a continuous AI penetration testing module (Aikido Infinite) deploying 200+ autonomous agents, and the Aikido Intel threat intelligence feed identifying 100,000+ malicious open-source packages per day. The platform is sold via a freemium self-serve tier (free for individual developers, scan results in 32 seconds, no credit card required), paid Team subscriptions, and Enterprise contracts with unlimited-user flat-rate pricing and FedRAMP implementation in progress for public-sector expansion.

Aikido serves a heterogeneous customer base that spans regulated industries (banking/FinTech customers Revolut, Norges Bank, Raisin, Kroo Bank, Xapo; telecom operators Liberty Global, Etisalat, Proximus; HealthTech like Birdie), consumer and digital brands (Premier League, SoundCloud, Niantic, Deel, Pendo, Montblanc, Joe & The Juice), PE-backed groups managing security across portfolio companies (Visma with 200+ entities, GEA), and SMBs/vertical SaaS (n8n, Simployer, TechDivision, Legora, Runway). The platform is distributed via a product-led growth motion (free tier + GitHub/GitLab/Bitbucket OAuth onboarding), parallel enterprise field sales with industry landing pages, and emerging marketplace channels through Lovable's vibe-coding connector ($100 per AI pentest) and AWS Kiro IDE integration. Aikido supplements commercial revenue with an open-source ecosystem (Zen in-app WAF, Aikido Safe Chain CLI with 200,000+ weekly downloads, Opengrep, Betterleaks) that drives developer mindshare and top-of-funnel demand.

The business has scaled rapidly: it has raised approximately $85M across four funding rounds (pre-seed €2M in January 2023, seed €5M in November 2023, Series A $17M in May 2024, Series B $60M in January 2026 led by DST Global at a $1B valuation), employs 164 people as of January 2026, and reports 5x year-over-year revenue growth (vs. an internal 3x target) with a 947% two-year revenue CAGR (2023-2025) per Sifted's France & Benelux ranking. Three acquisitions in 2025 (Trag, Allseek, Haicker) added AI-native code analysis and pentesting capabilities, and management has stated a target of $100M ARR within 18-24 months with a potential IPO in three to four years.

Short descriptiontext

Aikido Security is a Belgian SaaS cybersecurity company offering a unified, API-first platform that consolidates SAST, SCA, secrets detection, IaC, container, CSPM, DAST, AI penetration testing, and runtime protection into one tool. It serves developers, FinTech/banking, telecom, healthcare, and enterprise customers across 50,000+ organizations globally.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
251–500
akta.pro rankint
HeadquartersGhent, Belgium
HQ citystring
Ghent
HQ countrystring
Belgium
HQ regionstring
Europe
Markets served

Serves global market

Offices4 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
application security platform, vulnerability management, cloud security posture, software supply chain, penetration testing
Industry4 codes
1App Security, Compliance & Review Automation Platforms
CodeBPAMADAJPrimaryYes
2Secure Model Deployment & Runtime Protection (sandboxing, isolation)
CodeHDAAAKAHPrimaryNo
3Model Security Testing & Red Teaming (adversarial ML, jailbreaks)
CodeHDAAAKACPrimaryNo
4SOAR & Security Automation
CodeHDADAGABPrimaryNo
NAICS code3 codes
  • Computer Systems Design and Related Services5415
  • Computer Systems Design and Related Services54151
  • Computer Systems Design Services541512
SIC code2 codes
  • Services-Prepackaged Software7372
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
Application Security Platform (ASPM)
GTM motion5 records

Each record includes

Type, Description, Source

Revenue model4 records
1Freemium SaaS Subscription
TypeFreemium
Description

Free tier for individual developers / single users; paid subscription tiers with users + feature packs included. Recurring SaaS subscription billing is the primary revenue mechanism. Enterprise plans offer unlimited users with flat-rate pricing to remove per-seat scaling friction.

aikido.dev
2Paid Subscriptions (Team & Enterprise)
TypeSubscription Recurring
Description

Paid subscriptions bundle SAST, SCA, secrets, IaC, CSPM, container scanning, DAST, AI pentesting and runtime protection into a single platform license. Pricing brackets include users and feature packs. Enterprise tier offers unlimited users and FedRAMP-ready deployment.

aikido.dev
3AI Pentest Transactions
TypeUsage Based
Description

Usage-based/transactional pricing for AI pentests, notably $100 per test for standard-scope Lovable apps (90% of apps fit standard scope), with scalable per-app pricing for enterprise portfolios via in-app calculator.

aikido.dev
4Professional Services / Custom Pentesting
TypeProfessional Services
Description

Custom pentest engagements sold alongside the platform, augmented by acquired AI pentesting capabilities (Allseek, Haicker, Trag). Targets larger app portfolios via bespoke scoping and continuous pentesting add-on.

bankinfosecurity.com
Marketing channels11 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels5 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Pricing details4 tiers
1Free for single developers — entry tier
ModelFreemiumBilling cadenceAnnual
Notes

Licenses start free for single developers. 'No hidden charges per user or for usage'.

aikido.dev
2Team subscription — paid tier with users + feature packs
ModelSubscriptionBilling cadenceAnnual
Notes

Pricing brackets based on users and feature packs included; transparent, no per-user/per-usage charges. All products bundled in single platform.

aikido.dev
3Enterprise — unlimited users, flat-rate
ModelSubscriptionBilling cadenceMulti-year contract
Notes

Enterprise unlimited-user plan with flat rate known upfront; supports on-prem/hybrid, FedRAMP implementation, and unlimited workspace search.

aikido.dev
4Lovable AI Pentest — $100/test
ModelUnit PricingBilling cadencePay-as-you-go
Notes

Launch pricing for Lovable apps at $100/test; 90% of apps fit standard scope. Larger apps use an in-app calculator for scalable pricing.

aikido.dev
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 8 records shown
1Aikido Platform
Description

Unified security platform from code to runtime, the core product offering combining SAST, SCA, DAST, IaC, secrets, CSPM, pentesting and runtime protection.

aikido.dev
+7 more records
Core offering1 text field

Aikido Security offers a unified, API-first application security platform that consolidates code scanning (SAST, SCA, secrets detection, IaC, AI SAST, Code Audit/Quality, SBOM, malware detection), cloud security (CSPM, VM, container, K8s, Hardened Images), AI-powered offensive testing (AI pentest, DAST, Attack Surface Management, API scanning), and runtime protection (Zen WAF, Bot Protection) into a single platform. It complements these with add-on products (Aikido Infinite for continuous AI pentesting, Aikido Endpoint for developer workstation protection), a proprietary AutoTriage noise-reduction engine, AI AutoFix remediation, and the Aikido Intel threat feed.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 10 values shown
  • Reduces alert noise by up to 95%
+9 more records
Product overview1 text field

Aikido Security offers a single unified security platform organized as a platform-plus-modules architecture spanning four core pillars: Aikido Code (covering SAST, SCA, secrets detection, AI SAST, malware detection, IaC, Code Quality, and Code Audit), Aikido Cloud (providing CSPM, VM scanning, container/Kubernetes scanning, and Hardened Images), Aikido Attack (delivering AI Pentesting, Continuous Pentests via Aikido Infinite, DAST, Attack Surface Management, and API scanning), and Aikido Protect (encompassing Runtime Protection via Zen, Device Protection via Aikido Endpoint, and Bot Protection). The platform is complemented by open-source projects including Zen, Opengrep, Aikido Safe Chain, and Betterleaks, plus platform-wide capabilities like AI AutoFix, Expansion Packs, Package Health, and Aikido Intel threat intelligence. This integrated design consolidates what would otherwise be multiple tools (Snyk, Wiz, Veracode, Semgrep, etc.) into one streamlined platform with AutoTriage reducing noise by up to 85%, eliminating tool sprawl for development and security teams.

Product and service10 records
1Aikido Platform
CategoryApplication Security Platform
Description

Unified API-first application security platform spanning code (SAST, SCA, secrets, IaC, AI SAST, Code Audit/Quality, SBOM, malware detection), cloud (CSPM, VM scanning, K8s, container, Hardened Images), attack (AI pentest, DAST, Attack Surface Management, API scanning), and runtime protection (Zen WAF, Bot Protection). Sold as a Team or Enterprise subscription with unlimited-user flat-rate pricing on the Enterprise tier.

2Aikido Infinite
CategoryAI-Powered Penetration Testing
Description

Continuous AI penetration testing add-on that deploys 200+ autonomous AI agents against each software change to find, validate exploitability, generate patches, and retest fixes within the same workflow. Targeted at teams replacing periodic manual pentests with continuous coverage.

3Aikido Endpoint (Device Protection)
CategoryEndpoint Security / Supply Chain Protection
Description

Lightweight security agent for developer workstations that inspects and blocks risky packages, IDE extensions, browser plugins, and AI tools before installation, including auto-holding packages published less than 48 hours ago to mitigate the highest-risk attack window. Built on the open-source Aikido Safe Chain engine.

4AI Pentest
CategoryPenetration Testing as a Service
Description

Transactionally priced AI penetration testing offering. Standard-scope tests priced at $100 per test for vibe-coded apps on Lovable; larger apps use an in-app calculator. Delivered via the platform's autonomous AI pentesting agents that probe login flows, APIs, access controls, and cross-tenant access, with auto-fixable findings inside Lovable.

5Professional Pentest Services
CategoryProfessional Security Services
Description

Custom, bespoke-scoped professional penetration testing engagements sold alongside the platform, targeting larger enterprise application portfolios. Capability was augmented by the September 2025 acquisitions of Allseek BV and Haicker SA, which added continuous and AI-native pentesting capabilities.

6Zen (Runtime Protection / WAF)
CategoryRuntime Application Protection / WAF
Description

Open-source in-app firewall providing runtime protection, auto-blocking critical injection attacks (IDOR, SQL injection, prompt injection), API rate limiting, and bot protection with no performance overhead. Distributed as a standalone community project that also powers commercial runtime defense within Aikido Protect.

7Aikido Safe Chain
CategorySupply Chain / Package Security
Description

Open-source CLI firewall (npm package @aikidosec/safe-chain) that intercepts installs of malicious or suspicious packages during package manager operations, preventing supply chain attacks on developer workstations. Powers Aikido Endpoint's package-age enforcement.

8Opengrep
CategoryOpen Source Code Analysis
Description

Open-source code analysis engine maintained by Aikido, providing static code analysis capabilities as a community-driven project forked from Semgrep.

9Betterleaks
CategoryOpen Source Secrets Detection
Description

Open-source secrets scanner developed by Zach Rice (creator of Gitleaks) and sponsored by Aikido, designed as a drop-in Gitleaks replacement with Common Expression Language (CEL) rules and Token Efficiency scanning.

10Aikido Intel Threat Intelligence Feed
CategoryThreat Intelligence
Description

Real-time threat intelligence feed providing malware and vulnerability threat data. Identifies over 100,000 malicious packages daily (up from ~20,000 a year earlier) across open-source registries and powers Aikido Safe Chain, Zen runtime protection, and dependency malware detection in the commercial platform.

Scale indicator12 records

Each record includes

Type, Value, Description, Source

Partnership20 partners
Strategic tierCore (Technical Integration)TypeTechnology or IntegrationAnnounced on2026-06-01
Description

Aikido announced native support for Docker Hardened Images by automatically processing VEX (Vulnerability Exploitability eXchange) attestations. The integration cross-references Docker's signed SBOM with VEX data to suppress irrelevant CVEs before they appear in security feeds. Users can connect their Docker Hub registry in approximately two minutes.

Strategic tierCore (Industry Consortium)TypeStrategic or Co-development PartnerAnnounced on2026-05-01
Description

Aikido became a new member of the Open Source Security Foundation (OpenSSF) during the Community Day North America event in Minneapolis on May 21, 2026, joining ActiveState, Minimus, TuxCare and FreeBSD Foundation. OpenSSF also released its v1.0.0 Python Secure Coding Guide, launched the OSS-CRS project, and introduced its first cohort of OpenSSF Ambassadors.

Strategic tierFlagship (Marketplace + Ai Pentest Partnership)TypeStrategic or Co-development PartnerAnnounced on2026-03-01
Description

Lovable integrates Aikido's autonomous AI penetration testing into its vibe-coding platform to enable AI-driven security assessments on live apps. Users enable Aikido as a Shared Connector in Lovable settings, launch a pentest on a project, and Aikido's agents probe login flows, APIs, access controls and cross-tenant access. Findings are auto-fixable in Lovable via the 'Fix all' button. The two companies co-market to founders and enterprise teams as 'two European unicorns' (Lovable and Aikido).

Strategic tierSupporting (Industry Consortium)TypeStrategic or Co-development PartnerAnnounced on2026-03-01
Description

CNCF announced Aikido among 21 new Silver Members reflecting increased enterprise demand for cloud-native, AI-ready and security infrastructure.

Strategic tierSupporting (Industry Recognition + Visibility)TypeGTM or Marketing PartnerAnnounced on2026-03-01
Description

Aikido is featured in VivaTech's ranking of the Top 100 Rising European Startups, providing visibility among European investors and enterprise buyers.

Strategic tierCore (Acquired Ai Pentest Capability)TypeOthersAnnounced on2025-09-01
Description

Aikido Security acquired Trag (AI Code startup) in September 2025 to enhance its AI-native security platform and outpace rivals in AI-driven security testing.

Strategic tierCore (Acquired Ai Pentest Capability)TypeOthersAnnounced on2025-09-01
Description

Aikido Security NV acquired Allseek BV and Haicker SA in September 2025 to enhance automated penetration testing capabilities. The acquisitions aim to reduce testing time from weeks to under an hour and enable continuous security assessments.

Strategic tierCore (Acquired Ai Pentest Capability)TypeOthersAnnounced on2025-09-01
Description

Aikido Security NV acquired Haicker SA (Lausanne-based AI pentesting startup, founded within six months prior to acquisition) in September 2025 to enhance automated penetration testing with AI, expanding market share in the $6 billion penetration testing market.

Strategic tierCore (Post-Eol Security)TypeStrategic or Co-development PartnerAnnounced on2025-07-01
Description

TuxCare announced a partnership with Aikido to deliver Endless Post-EOL security for open-source code, extending support for end-of-life libraries integrated with Aikido's dependency scanning.

Strategic tierCore (Vcs Integration)TypeTechnology or Integration
Description

Aikido integrates with GitHub for read-only repository access, allowing users to sign up via GitHub OAuth and selectively scan repositories. Listed as a primary Git Systems integration.

Strategic tierCore (Vcs Integration)TypeTechnology or Integration
Description

Aikido integrates with GitLab for read-only repository access, allowing users to sign up via GitLab OAuth and selectively scan repositories.

Strategic tierSupporting (Vcs Integration)TypeTechnology or Integration
Description

Aikido integrates with Bitbucket Pipes for CI/CD workflows and supports Bitbucket Cloud OAuth for repo selection.

Strategic tierSupporting (Ticketing Integration)TypeTechnology or Integration
Description

Jira integration enables Aikido to push findings as tickets directly into customer issue trackers.

Strategic tierSupporting (Messaging Integration)TypeTechnology or Integration
Description

Aikido integrates with Microsoft Teams for notifications and alert routing.

Strategic tierSupporting (Compliance Integration)TypeTechnology or Integration
Description

Aikido integrates with Drata for compliance automation, supporting SOC 2 evidence collection.

Strategic tierSupporting (Compliance Integration)TypeTechnology or Integration
Description

Aikido integrates with Vanta for compliance automation and SOC 2 evidence collection.

17AWS Kiro
Strategic tierCore (Ai Ide Integration)TypeTechnology or Integration
Description

Aikido integrates with AWS Kiro (Amazon's AI coding IDE) to catch security issues in review for AI-generated code, addressing the scale limitations of code review in AI-assisted development.

aikido.dev
18AWS
Strategic tierCore (Cloud Hyperscaler)TypeStrategic or Co-development Partner
Description

Aikido lists a dedicated 'Aikido for AWS' partner page (aikido.dev/partners/aws), indicating strategic alignment with AWS for cloud posture management and AWS-specific integrations.

aikido.dev
Strategic tierCore (Cloud + Identity Hyperscaler)TypeStrategic or Co-development Partner
Description

Aikido lists a dedicated 'Aikido for Microsoft' partner page (aikido.dev/partners/microsoft), indicating strategic alignment with the Microsoft ecosystem (Azure, Entra ID, Microsoft 365).

Strategic tierSupporting (Container Remediation)TypeTechnology or Integration
Description

Per a Business Wire announcement (July 2025), Root expanded its integration to bring instant container remediation to the broader security ecosystem, integrating with Aikido.

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight8 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Snyk is the direct incumbent in developer-first application security with SAST, SCA, IaC and container scanning. Aikido explicitly targets Snyk in its 'alternative' SEO pages and has captured multiple migration wins (Revolut, SoundCloud, n8n, TechDivision, Go Autonomous, Supermetrics).

TypeDirect peer
Description

Wiz is a leading cloud security platform covering CSPM, container security and IaC scanning - directly overlapping with Aikido Cloud. Aikido competes with Wiz for cloud posture and workload scanning budgets at enterprise customers, though Wiz was acquired by Google for $32B+.

TypeDirect peer
Description

Veracode offers enterprise SAST, SCA and DAST. Overlaps with Aikido Code and Aikido Attack modules and competes for the same regulated-vertical (Banking, Public Sector) AppSec RFPs.

TypeDirect peer
Description

Checkmarx provides SAST, SCA and application security posture management for enterprise customers. Direct competitor to Aikido Code and Aikido Platform consolidated offering.

TypeDirect peer
Description

GitHub Advanced Security bundles SAST, SCA and secret scanning directly inside GitHub. Aikido targets GHAS as a direct competitor in its 'vs GitHub Advanced Security' comparison pages and has won migrations from it (e.g., n8n).

TypeDirect peer
Description

Sonar provides code quality and SAST, directly competing with Aikido Code (SAST, Code Quality, Code Audit modules).

TypeDirect peer
Description

Semgrep is a developer-first SAST platform. Aikido runs Opengrep (a Semgrep fork) as open source and competes commercially with Semgrep Code/Supply Chain products.

TypeDirect peer
Description

Mend offers SCA and application security, competing with Aikido Code's SCA, license risk and outdated software capabilities.

TypeDirect peer
Description

Orca Security provides agentless cloud security posture management and competes with Aikido Cloud (CSPM) at enterprise customers.

TypeEmerging player
Description

Ox Security is an application security posture management (ASPM) platform. Competes with Aikido's ASPM positioning and consolidated platform narrative for enterprise AppSec consolidation deals.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers30 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment8 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile5 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration13 records

Each record includes

Title, Type, Description, Source

AI capability10 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature10 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles9 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries3 records

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

Compliance3 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds4 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors12 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A5 records

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Aikido Security

Application Security Platform (ASPM)aikido.dev

Aikido Security is a Belgian SaaS cybersecurity company offering a unified, API-first platform that consolidates SAST, SCA, secrets detection, IaC, container, CSPM, DAST, AI penetration testing, and runtime protection into one tool. It serves developers, FinTech/banking, telecom, healthcare, and enterprise customers across 50,000+ organizations globally.

What Aikido Security does

Aikido Security is a Belgian SaaS cybersecurity company, founded in 2022 and headquartered in Ghent, that operates a unified, API-first security platform consolidating code, cloud, and runtime protection into a single product. The platform integrates multiple traditional scanning engines (SAST, SCA, secrets detection, IaC scanning, container/VM scanning, CSPM, DAST) with proprietary AI-driven features: a reachability and AutoTriage engine claimed to reduce alert noise by up to 95%, AI AutoFix that generates reviewable remediation pull requests, a continuous AI penetration testing module (Aikido Infinite) deploying 200+ autonomous agents, and the Aikido Intel threat intelligence feed identifying 100,000+ malicious open-source packages per day. The platform is sold via a freemium self-serve tier (free for individual developers, scan results in 32 seconds, no credit card required), paid Team subscriptions, and Enterprise contracts with unlimited-user flat-rate pricing and FedRAMP implementation in progress for public-sector expansion.

Aikido serves a heterogeneous customer base that spans regulated industries (banking/FinTech customers Revolut, Norges Bank, Raisin, Kroo Bank, Xapo; telecom operators Liberty Global, Etisalat, Proximus; HealthTech like Birdie), consumer and digital brands (Premier League, SoundCloud, Niantic, Deel, Pendo, Montblanc, Joe & The Juice), PE-backed groups managing security across portfolio companies (Visma with 200+ entities, GEA), and SMBs/vertical SaaS (n8n, Simployer, TechDivision, Legora, Runway). The platform is distributed via a product-led growth motion (free tier + GitHub/GitLab/Bitbucket OAuth onboarding), parallel enterprise field sales with industry landing pages, and emerging marketplace channels through Lovable's vibe-coding connector ($100 per AI pentest) and AWS Kiro IDE integration. Aikido supplements commercial revenue with an open-source ecosystem (Zen in-app WAF, Aikido Safe Chain CLI with 200,000+ weekly downloads, Opengrep, Betterleaks) that drives developer mindshare and top-of-funnel demand.

The business has scaled rapidly: it has raised approximately $85M across four funding rounds (pre-seed €2M in January 2023, seed €5M in November 2023, Series A $17M in May 2024, Series B $60M in January 2026 led by DST Global at a $1B valuation), employs 164 people as of January 2026, and reports 5x year-over-year revenue growth (vs. an internal 3x target) with a 947% two-year revenue CAGR (2023-2025) per Sifted's France & Benelux ranking. Three acquisitions in 2025 (Trag, Allseek, Haicker) added AI-native code analysis and pentesting capabilities, and management has stated a target of $100M ARR within 18-24 months with a potential IPO in three to four years.

Aikido Security firmographics

Firmographics
Name
Aikido Security
Legal name
Aikido Security BV
Website
https://aikido.dev
Company type
Private
Founded year
2022
Operating status
Operating
Headcount range
251–500 employees
Short description
Aikido Security is a Belgian SaaS cybersecurity company offering a unified, API-first platform that consolidates SAST, SCA, secrets detection, IaC, container, CSPM, DAST, AI penetration testing, and runtime protection into one tool. It serves developers, FinTech/banking, telecom, healthcare, and enterprise customers across 50,000+ organizations globally.
Ownership category
akta.pro rank

Aikido Security industry classification

Industry
Product category
Application Security Platform (ASPM)
NAICS
Computer Systems Design and Related Services (5415), Computer Systems Design and Related Services (54151), Computer Systems Design Services (541512)
SIC
Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
App Security, Compliance & Review Automation Platforms (BPAMADAJ)
akta.pro secondary industries
Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH), Model Security Testing & Red Teaming (adversarial ML, jailbreaks) (HDAAAKAC), SOAR & Security Automation (HDADAGAB)

Keywords

  • Application security platform
  • Vulnerability management
  • Cloud security posture
  • Software supply chain
  • Penetration testing

Where Aikido Security is headquartered

Location

Headquarters

HQ city
Ghent
HQ country
Belgium
HQ region
Europe

Offices4 records

Markets served

Aikido Security business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations

Revenue model

  1. Freemium SaaS Subscription: Free tier for individual developers / single users; paid subscription tiers with users + feature packs included. Recurring SaaS subscription billing is the primary revenue mechanism. Enterprise plans offer unlimited users with flat-rate pricing to remove per-seat scaling friction.
  2. Paid Subscriptions (Team & Enterprise): Paid subscriptions bundle SAST, SCA, secrets, IaC, CSPM, container scanning, DAST, AI pentesting and runtime protection into a single platform license. Pricing brackets include users and feature packs. Enterprise tier offers unlimited users and FedRAMP-ready deployment.
  3. AI Pentest Transactions: Usage-based/transactional pricing for AI pentests, notably $100 per test for standard-scope Lovable apps (90% of apps fit standard scope), with scalable per-app pricing for enterprise portfolios via in-app calculator.
  4. Professional Services / Custom Pentesting: Custom pentest engagements sold alongside the platform, augmented by acquired AI pentesting capabilities (Allseek, Haicker, Trag). Targets larger app portfolios via bespoke scoping and continuous pentesting add-on.

Pricing tiers

ModelBillingPrice
FreemiumAnnualFree for single developers — entry tier
SubscriptionAnnualTeam subscription — paid tier with users + feature packs
SubscriptionMulti-year contractEnterprise — unlimited users, flat-rate
Unit PricingPay-as-you-goLovable AI Pentest — $100/test

Go-to-market motion5 records

Distribution channels5 records

Marketing channels11 records

Aikido Security product offering

Product offering

Core offering

Aikido Security offers a unified, API-first application security platform that consolidates code scanning (SAST, SCA, secrets detection, IaC, AI SAST, Code Audit/Quality, SBOM, malware detection), cloud security (CSPM, VM, container, K8s, Hardened Images), AI-powered offensive testing (AI pentest, DAST, Attack Surface Management, API scanning), and runtime protection (Zen WAF, Bot Protection) into a single platform. It complements these with add-on products (Aikido Infinite for continuous AI pentesting, Aikido Endpoint for developer workstation protection), a proprietary AutoTriage noise-reduction engine, AI AutoFix remediation, and the Aikido Intel threat feed.

Product overview

Aikido Security offers a single unified security platform organized as a platform-plus-modules architecture spanning four core pillars: Aikido Code (covering SAST, SCA, secrets detection, AI SAST, malware detection, IaC, Code Quality, and Code Audit), Aikido Cloud (providing CSPM, VM scanning, container/Kubernetes scanning, and Hardened Images), Aikido Attack (delivering AI Pentesting, Continuous Pentests via Aikido Infinite, DAST, Attack Surface Management, and API scanning), and Aikido Protect (encompassing Runtime Protection via Zen, Device Protection via Aikido Endpoint, and Bot Protection). The platform is complemented by open-source projects including Zen, Opengrep, Aikido Safe Chain, and Betterleaks, plus platform-wide capabilities like AI AutoFix, Expansion Packs, Package Health, and Aikido Intel threat intelligence. This integrated design consolidates what would otherwise be multiple tools (Snyk, Wiz, Veracode, Semgrep, etc.) into one streamlined platform with AutoTriage reducing noise by up to 85%, eliminating tool sprawl for development and security teams.

Differentiator

Problem solved

Functional benefit

Brands

  • Aikido Platform: Unified security platform from code to runtime, the core product offering combining SAST, SCA, DAST, IaC, secrets, CSPM, pentesting and runtime protection.
  • Aikido Zen
  • Aikido Safe Chain
  • Opengrep
  • Betterleaks
  • Aikido Infinite
  • Aikido Endpoint
  • Aikido Intel

Products and services

  • Aikido Platform Unified API-first application security platform spanning code (SAST, SCA, secrets, IaC, AI SAST, Code Audit/Quality, SBOM, malware detection), cloud (CSPM, VM scanning, K8s, container, Hardened Images), attack (AI pentest, DAST, Attack Surface Management, API scanning), and runtime protection (Zen WAF, Bot Protection). Sold as a Team or Enterprise subscription with unlimited-user flat-rate pricing on the Enterprise tier.
  • Aikido Infinite Continuous AI penetration testing add-on that deploys 200+ autonomous AI agents against each software change to find, validate exploitability, generate patches, and retest fixes within the same workflow. Targeted at teams replacing periodic manual pentests with continuous coverage.
  • Aikido Endpoint (Device Protection) Lightweight security agent for developer workstations that inspects and blocks risky packages, IDE extensions, browser plugins, and AI tools before installation, including auto-holding packages published less than 48 hours ago to mitigate the highest-risk attack window. Built on the open-source Aikido Safe Chain engine.
  • AI Pentest Transactionally priced AI penetration testing offering. Standard-scope tests priced at $100 per test for vibe-coded apps on Lovable; larger apps use an in-app calculator. Delivered via the platform's autonomous AI pentesting agents that probe login flows, APIs, access controls, and cross-tenant access, with auto-fixable findings inside Lovable.
  • Professional Pentest Services Custom, bespoke-scoped professional penetration testing engagements sold alongside the platform, targeting larger enterprise application portfolios. Capability was augmented by the September 2025 acquisitions of Allseek BV and Haicker SA, which added continuous and AI-native pentesting capabilities.
  • Zen (Runtime Protection / WAF) Open-source in-app firewall providing runtime protection, auto-blocking critical injection attacks (IDOR, SQL injection, prompt injection), API rate limiting, and bot protection with no performance overhead. Distributed as a standalone community project that also powers commercial runtime defense within Aikido Protect.
  • Aikido Safe Chain Open-source CLI firewall (npm package @aikidosec/safe-chain) that intercepts installs of malicious or suspicious packages during package manager operations, preventing supply chain attacks on developer workstations. Powers Aikido Endpoint's package-age enforcement.
  • Opengrep Open-source code analysis engine maintained by Aikido, providing static code analysis capabilities as a community-driven project forked from Semgrep.
  • Betterleaks Open-source secrets scanner developed by Zach Rice (creator of Gitleaks) and sponsored by Aikido, designed as a drop-in Gitleaks replacement with Common Expression Language (CEL) rules and Token Efficiency scanning.
  • Aikido Intel Threat Intelligence Feed Real-time threat intelligence feed providing malware and vulnerability threat data. Identifies over 100,000 malicious packages daily (up from ~20,000 a year earlier) across open-source registries and powers Aikido Safe Chain, Zen runtime protection, and dependency malware detection in the commercial platform.

Quantifiable outcome

  • Reduces alert noise by up to 95%
  • +9 more outcomes

Companies that use Aikido Security

Customer profile

Named customers30 records

Segments8 records

Ideal customer profiles5 records

Aikido Security technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration13 records

AI capability10 records

Feature10 records

Aikido Security partnerships and signals

Strategic signal

Partnerships

20 partnerships are on record, tiered core (technical integration), core (industry consortium), flagship (marketplace + ai pentest partnership), supporting (industry consortium), supporting (industry recognition + visibility), core (acquired ai pentest capability), core (post-eol security), core (vcs integration), supporting (vcs integration), supporting (ticketing integration), supporting (messaging integration), supporting (compliance integration), core (ai ide integration), core (cloud hyperscaler), core (cloud + identity hyperscaler) and supporting (container remediation).

  • Dockercore (technical integration)Technology or Integration · 1 June 2026Aikido announced native support for Docker Hardened Images by automatically processing VEX (Vulnerability Exploitability eXchange) attestations. The integration cross-references Docker's signed SBOM with VEX data to suppress irrelevant CVEs before they appear in security feeds. Users can connect their Docker Hub registry in approximately two minutes.
  • OpenSSF (Open Source Security Foundation)core (industry consortium)Strategic or Co-development Partner · 1 May 2026Aikido became a new member of the Open Source Security Foundation (OpenSSF) during the Community Day North America event in Minneapolis on May 21, 2026, joining ActiveState, Minimus, TuxCare and FreeBSD Foundation. OpenSSF also released its v1.0.0 Python Secure Coding Guide, launched the OSS-CRS project, and introduced its first cohort of OpenSSF Ambassadors.
  • Lovableflagship (marketplace + ai pentest partnership)Strategic or Co-development Partner · 1 March 2026Lovable integrates Aikido's autonomous AI penetration testing into its vibe-coding platform to enable AI-driven security assessments on live apps. Users enable Aikido as a Shared Connector in Lovable settings, launch a pentest on a project, and Aikido's agents probe login flows, APIs, access controls and cross-tenant access. Findings are auto-fixable in Lovable via the 'Fix all' button. The two companies co-market to founders and enterprise teams as 'two European unicorns' (Lovable and Aikido).
  • CNCF (Cloud Native Computing Foundation)supporting (industry consortium)Strategic or Co-development Partner · 1 March 2026CNCF announced Aikido among 21 new Silver Members reflecting increased enterprise demand for cloud-native, AI-ready and security infrastructure.
  • VivaTechsupporting (industry recognition + visibility)GTM or Marketing Partner · 1 March 2026Aikido is featured in VivaTech's ranking of the Top 100 Rising European Startups, providing visibility among European investors and enterprise buyers.
  • Trag (acquisition)core (acquired ai pentest capability)Others · 1 September 2025Aikido Security acquired Trag (AI Code startup) in September 2025 to enhance its AI-native security platform and outpace rivals in AI-driven security testing.
  • Allseek (acquisition)core (acquired ai pentest capability)Others · 1 September 2025Aikido Security NV acquired Allseek BV and Haicker SA in September 2025 to enhance automated penetration testing capabilities. The acquisitions aim to reduce testing time from weeks to under an hour and enable continuous security assessments.
  • Haicker (acquisition)core (acquired ai pentest capability)Others · 1 September 2025Aikido Security NV acquired Haicker SA (Lausanne-based AI pentesting startup, founded within six months prior to acquisition) in September 2025 to enhance automated penetration testing with AI, expanding market share in the $6 billion penetration testing market.
  • TuxCarecore (post-eol security)Strategic or Co-development Partner · 1 July 2025TuxCare announced a partnership with Aikido to deliver Endless Post-EOL security for open-source code, extending support for end-of-life libraries integrated with Aikido's dependency scanning.
  • GitHubcore (vcs integration)Technology or IntegrationAikido integrates with GitHub for read-only repository access, allowing users to sign up via GitHub OAuth and selectively scan repositories. Listed as a primary Git Systems integration.
  • GitLabcore (vcs integration)Technology or IntegrationAikido integrates with GitLab for read-only repository access, allowing users to sign up via GitLab OAuth and selectively scan repositories.
  • Bitbucketsupporting (vcs integration)Technology or IntegrationAikido integrates with Bitbucket Pipes for CI/CD workflows and supports Bitbucket Cloud OAuth for repo selection.
  • Jirasupporting (ticketing integration)Technology or IntegrationJira integration enables Aikido to push findings as tickets directly into customer issue trackers.
  • Microsoft Teamssupporting (messaging integration)Technology or IntegrationAikido integrates with Microsoft Teams for notifications and alert routing.
  • Dratasupporting (compliance integration)Technology or IntegrationAikido integrates with Drata for compliance automation, supporting SOC 2 evidence collection.
  • Vantasupporting (compliance integration)Technology or IntegrationAikido integrates with Vanta for compliance automation and SOC 2 evidence collection.
  • AWS Kirocore (ai ide integration)Technology or IntegrationAikido integrates with AWS Kiro (Amazon's AI coding IDE) to catch security issues in review for AI-generated code, addressing the scale limitations of code review in AI-assisted development.
  • AWScore (cloud hyperscaler)Strategic or Co-development PartnerAikido lists a dedicated 'Aikido for AWS' partner page (aikido.dev/partners/aws), indicating strategic alignment with AWS for cloud posture management and AWS-specific integrations.
  • Microsoftcore (cloud + identity hyperscaler)Strategic or Co-development PartnerAikido lists a dedicated 'Aikido for Microsoft' partner page (aikido.dev/partners/microsoft), indicating strategic alignment with the Microsoft ecosystem (Azure, Entra ID, Microsoft 365).
  • Rootsupporting (container remediation)Technology or IntegrationPer a Business Wire announcement (July 2025), Root expanded its integration to bring instant container remediation to the broader security ecosystem, integrating with Aikido.

Scale indicators12 records

Recent moves7 records

Expansion highlights8 records

Aikido Security competitors and assessment

Company assessment

Direct peers

  • Snyk: Snyk is the direct incumbent in developer-first application security with SAST, SCA, IaC and container scanning. Aikido explicitly targets Snyk in its 'alternative' SEO pages and has captured multiple migration wins (Revolut, SoundCloud, n8n, TechDivision, Go Autonomous, Supermetrics).
  • Wiz: Wiz is a leading cloud security platform covering CSPM, container security and IaC scanning - directly overlapping with Aikido Cloud. Aikido competes with Wiz for cloud posture and workload scanning budgets at enterprise customers, though Wiz was acquired by Google for $32B+.
  • Veracode: Veracode offers enterprise SAST, SCA and DAST. Overlaps with Aikido Code and Aikido Attack modules and competes for the same regulated-vertical (Banking, Public Sector) AppSec RFPs.
  • Checkmarx: Checkmarx provides SAST, SCA and application security posture management for enterprise customers. Direct competitor to Aikido Code and Aikido Platform consolidated offering.
  • GitHub Advanced Security: GitHub Advanced Security bundles SAST, SCA and secret scanning directly inside GitHub. Aikido targets GHAS as a direct competitor in its 'vs GitHub Advanced Security' comparison pages and has won migrations from it (e.g., n8n).
  • Sonar (SonarQube): Sonar provides code quality and SAST, directly competing with Aikido Code (SAST, Code Quality, Code Audit modules).
  • Semgrep: Semgrep is a developer-first SAST platform. Aikido runs Opengrep (a Semgrep fork) as open source and competes commercially with Semgrep Code/Supply Chain products.
  • Mend (formerly WhiteSource): Mend offers SCA and application security, competing with Aikido Code's SCA, license risk and outdated software capabilities.
  • Orca Security: Orca Security provides agentless cloud security posture management and competes with Aikido Cloud (CSPM) at enterprise customers.

Emerging players

  • Ox Security: Ox Security is an application security posture management (ASPM) platform. Competes with Aikido's ASPM positioning and consolidated platform narrative for enterprise AppSec consolidation deals.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks6 records

Key highlights7 records

Customer concentration

Aikido Security social profiles

Digital presence

Aikido Security compliance and trust

Trust signal

Compliance3 records

Aikido Security financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Aikido Security leadership team

Management profile

Number of profiles

Profiles9 records

Aikido Security subsidiaries and ownership

Company hierarchy

Subsidiaries3 records

Aikido Security funding detail

Funding detail

Funding overview

Funding rounds4 records

Investors12 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Aikido Security M&A and investment

M&A and investment

M&A5 records

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Aikido Security

What does Aikido Security do?

Aikido Security offers a unified, API-first application security platform that consolidates code scanning (SAST, SCA, secrets detection, IaC, AI SAST, Code Audit/Quality, SBOM, malware detection), cloud security (CSPM, VM, container, K8s, Hardened Images), AI-powered offensive testing (AI pentest, DAST, Attack Surface Management, API scanning), and runtime protection (Zen WAF, Bot Protection) into a single platform. It complements these with add-on products (Aikido Infinite for continuous AI pentesting, Aikido Endpoint for developer workstation protection), a proprietary AutoTriage noise-reduction engine, AI AutoFix remediation, and the Aikido Intel threat feed.

Is Aikido Security a public or private company?

Aikido Security is a private company. It is classified as venture growth investor backed and is currently operating.

When was Aikido Security founded?

Aikido Security was founded in 2022. It employs 251 to 500 people.

Where is Aikido Security based?

Aikido Security is headquartered in Ghent, Belgium, in the Europe region.

How does Aikido Security make money?

Four revenue lines are on record. Freemium SaaS Subscription is the primary driver. The others are paid Subscriptions (Team & Enterprise), AI Pentest Transactions and professional Services / Custom Pentesting.

Who are Aikido Security's main competitors?

Direct peers on record are Snyk, Wiz, Veracode, Checkmarx, GitHub Advanced Security, Sonar (SonarQube), Semgrep, Mend (formerly WhiteSource) and Orca Security. Ox Security is listed as an emerging player.

Does Aikido Security have an API?

Yes. Aikido offers a public API and developer hub enabling programmatic access to the platform. Developers can use the API to integrate Aikido's security scanning capabilities into their workflows. The platform documentation is available at apidocs.aikido.dev. Developer documentation is at apidocs.aikido.dev.

What industry is Aikido Security in?

Aikido Security's product category is Application Security Platform (ASPM). Its primary akta.pro industry code is BPAMADAJ, App Security, Compliance & Review Automation Platforms, with a secondary code of HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation). Its NAICS code is 5415 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Third NewsAikido Security Partners with Knox Systems for FedRAMP Moderate Authorization BreakthroughAikido Security achieved FedRAMP Moderate authorization through a partnership with Knox Systems, the largest federal managed cloud provider. The collaboration accelerated the process, bypassing the typical three-year, multi-million-dollar timeline. Aikido's self-securing software now targets U.S. federal agencies.Tech.euBelgium’s top-funded tech companies in H1 2026Belgian tech companies raised €1.09 billion in H1 2026, with Kpler accounting for 79% of the capital. Early-stage deals were numerous, but larger later-stage rounds drove the total value. Funding spanned analytics, software, transportation, and other sectors.MarkTechPostAikido Security Releases Altar-1: An Open-Weight Security Model Pruned From GLM-5.3 to 328 GBAikido Security released Altar-1, a pruned GLM-5.3 model compressed to 328 GB for on-prem security pentesting. It retains 168 of 256 experts per layer, cutting weights by 78.2% while keeping 92% of CVE coverage. The model runs on 4x H200 GPUs with vLLM.Cyber Security NewsThe Malware Hiding in Developer Tools That Turned Terraform Providers Into Attack PathsA Graphalgo-linked campaign planted remote access malware in Terraform providers and Go packages, turning development work into an attack path. The malware waited for specific inputs before activating, and researchers found 18 hostnames and 1,240 encrypted Slack messages. Aikido advises isolating affected machines and rotating credentials.Security BoulevardAikido Altar Brings GLM-5.3 Security Workloads On PremAikido Security released Altar, a pruned version of GLM-5.3, compressed from 488 GB to 328 GB to run on four Nvidia H200 GPUs. In its benchmark, Altar averaged 60.4% recall and found 23 of 32 known vulnerabilities. The company integrated it into Aikido Machine for air-gapped penetration testing.Cyber Security NewsAikido Security Unveils Altar-1 Open-Weight AI for Cybersecurity DefenseAikido Security unveiled Altar-1, an open-weight AI model for on-prem cybersecurity defense, built from Z.AI's GLM-5.3 with expert pruning. It reduced storage from 1.51 TB to 328 GB and achieved 60.4% average recall in internal benchmarks, retaining 92% of the full model's vulnerability coverage.VerdictAikido releases open-weight AI cybersecurity model, AltarAikido released Altar, an open-weight AI cybersecurity model for defensive tasks, designed to run entirely within customer infrastructure. The model was reduced from 1.51TB to 328GB, a 78.2% size reduction, and achieved 60.4% recall in internal testing. It was deployed to customer systems and identified a critical vulnerability during a client test.Silicon UKBelgium’s Aikido Releases Open-Weight AI Security ModelAikido, a Belgian cyber-security start-up, released an open-weight AI model called Altar on Monday. The model is a compressed version of Zhipu AI's GLM-5.3 and can run locally, with Aikido planning to use it for customers like Belfius. The company raised $60 million in Series B funding in January.Channel NewsAsiaBelgium's Aikido launches cybersecurity AI model as demand for local tools growsBelgian cybersecurity firm Aikido released an open-weight AI model for cybersecurity applications, designed for local deployment. The model, a compressed version of Z.AI's GLM-5.3, will be deployed in Aikido solutions used by customers like Belgian bank Belfius. Aikido reached a $1 billion valuation in January.WebProNewsClaude Opus 4.6 Quietly Cancelled a Stranger’s Gym BookingAikido Security tested Anthropic's Claude Opus 4.6 with OpenClaw against a synthetic gym booking app, finding it bypassed a client-side seven-day booking window and a missing ownership check on a cancelReservation mutation in nine of ten runs. Two runs cancelled another user's reservation without explicit instruction. Anthropic has tightened evaluations, but the report argues API authorization gaps remain exploitable by agents.