Aikido Security
Aikido Security is a Belgian SaaS cybersecurity company offering a unified, API-first platform that consolidates SAST, SCA, secrets detection, IaC, container, CSPM, DAST, AI penetration testing, and runtime protection into one tool. It serves developers, FinTech/banking, telecom, healthcare, and enterprise customers across 50,000+ organizations globally.
- Company typePrivate
- Founded2022
- HeadquartersGhent, Belgium
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What Aikido Security does
Aikido Security is a Belgian SaaS cybersecurity company, founded in 2022 and headquartered in Ghent, that operates a unified, API-first security platform consolidating code, cloud, and runtime protection into a single product. The platform integrates multiple traditional scanning engines (SAST, SCA, secrets detection, IaC scanning, container/VM scanning, CSPM, DAST) with proprietary AI-driven features: a reachability and AutoTriage engine claimed to reduce alert noise by up to 95%, AI AutoFix that generates reviewable remediation pull requests, a continuous AI penetration testing module (Aikido Infinite) deploying 200+ autonomous agents, and the Aikido Intel threat intelligence feed identifying 100,000+ malicious open-source packages per day. The platform is sold via a freemium self-serve tier (free for individual developers, scan results in 32 seconds, no credit card required), paid Team subscriptions, and Enterprise contracts with unlimited-user flat-rate pricing and FedRAMP implementation in progress for public-sector expansion.
Aikido serves a heterogeneous customer base that spans regulated industries (banking/FinTech customers Revolut, Norges Bank, Raisin, Kroo Bank, Xapo; telecom operators Liberty Global, Etisalat, Proximus; HealthTech like Birdie), consumer and digital brands (Premier League, SoundCloud, Niantic, Deel, Pendo, Montblanc, Joe & The Juice), PE-backed groups managing security across portfolio companies (Visma with 200+ entities, GEA), and SMBs/vertical SaaS (n8n, Simployer, TechDivision, Legora, Runway). The platform is distributed via a product-led growth motion (free tier + GitHub/GitLab/Bitbucket OAuth onboarding), parallel enterprise field sales with industry landing pages, and emerging marketplace channels through Lovable's vibe-coding connector ($100 per AI pentest) and AWS Kiro IDE integration. Aikido supplements commercial revenue with an open-source ecosystem (Zen in-app WAF, Aikido Safe Chain CLI with 200,000+ weekly downloads, Opengrep, Betterleaks) that drives developer mindshare and top-of-funnel demand.
The business has scaled rapidly: it has raised approximately $85M across four funding rounds (pre-seed €2M in January 2023, seed €5M in November 2023, Series A $17M in May 2024, Series B $60M in January 2026 led by DST Global at a $1B valuation), employs 164 people as of January 2026, and reports 5x year-over-year revenue growth (vs. an internal 3x target) with a 947% two-year revenue CAGR (2023-2025) per Sifted's France & Benelux ranking. Three acquisitions in 2025 (Trag, Allseek, Haicker) added AI-native code analysis and pentesting capabilities, and management has stated a target of $100M ARR within 18-24 months with a potential IPO in three to four years.
Aikido Security firmographics
Firmographics- Name
- Aikido Security
- Legal name
- Aikido Security BV
- Website
- https://aikido.dev
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Aikido Security is a Belgian SaaS cybersecurity company offering a unified, API-first platform that consolidates SAST, SCA, secrets detection, IaC, container, CSPM, DAST, AI penetration testing, and runtime protection into one tool. It serves developers, FinTech/banking, telecom, healthcare, and enterprise customers across 50,000+ organizations globally.
- Ownership category
- akta.pro rank
Aikido Security industry classification
Industry- Product category
- Application Security Platform (ASPM)
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design and Related Services (54151), Computer Systems Design Services (541512)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- App Security, Compliance & Review Automation Platforms (BPAMADAJ)
- akta.pro secondary industries
- Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH), Model Security Testing & Red Teaming (adversarial ML, jailbreaks) (HDAAAKAC), SOAR & Security Automation (HDADAGAB)
Keywords
Where Aikido Security is headquartered
LocationHeadquarters
- HQ city
- Ghent
- HQ country
- Belgium
- HQ region
- Europe
Offices4 records
Markets served
Aikido Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Freemium SaaS Subscription: Free tier for individual developers / single users; paid subscription tiers with users + feature packs included. Recurring SaaS subscription billing is the primary revenue mechanism. Enterprise plans offer unlimited users with flat-rate pricing to remove per-seat scaling friction.
- Paid Subscriptions (Team & Enterprise): Paid subscriptions bundle SAST, SCA, secrets, IaC, CSPM, container scanning, DAST, AI pentesting and runtime protection into a single platform license. Pricing brackets include users and feature packs. Enterprise tier offers unlimited users and FedRAMP-ready deployment.
- AI Pentest Transactions: Usage-based/transactional pricing for AI pentests, notably $100 per test for standard-scope Lovable apps (90% of apps fit standard scope), with scalable per-app pricing for enterprise portfolios via in-app calculator.
- Professional Services / Custom Pentesting: Custom pentest engagements sold alongside the platform, augmented by acquired AI pentesting capabilities (Allseek, Haicker, Trag). Targets larger app portfolios via bespoke scoping and continuous pentesting add-on.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Annual | Free for single developers — entry tier |
| Subscription | Annual | Team subscription — paid tier with users + feature packs |
| Subscription | Multi-year contract | Enterprise — unlimited users, flat-rate |
| Unit Pricing | Pay-as-you-go | Lovable AI Pentest — $100/test |
Go-to-market motion5 records
Distribution channels5 records
Marketing channels11 records
Aikido Security product offering
Product offeringCore offering
Aikido Security offers a unified, API-first application security platform that consolidates code scanning (SAST, SCA, secrets detection, IaC, AI SAST, Code Audit/Quality, SBOM, malware detection), cloud security (CSPM, VM, container, K8s, Hardened Images), AI-powered offensive testing (AI pentest, DAST, Attack Surface Management, API scanning), and runtime protection (Zen WAF, Bot Protection) into a single platform. It complements these with add-on products (Aikido Infinite for continuous AI pentesting, Aikido Endpoint for developer workstation protection), a proprietary AutoTriage noise-reduction engine, AI AutoFix remediation, and the Aikido Intel threat feed.
Product overview
Aikido Security offers a single unified security platform organized as a platform-plus-modules architecture spanning four core pillars: Aikido Code (covering SAST, SCA, secrets detection, AI SAST, malware detection, IaC, Code Quality, and Code Audit), Aikido Cloud (providing CSPM, VM scanning, container/Kubernetes scanning, and Hardened Images), Aikido Attack (delivering AI Pentesting, Continuous Pentests via Aikido Infinite, DAST, Attack Surface Management, and API scanning), and Aikido Protect (encompassing Runtime Protection via Zen, Device Protection via Aikido Endpoint, and Bot Protection). The platform is complemented by open-source projects including Zen, Opengrep, Aikido Safe Chain, and Betterleaks, plus platform-wide capabilities like AI AutoFix, Expansion Packs, Package Health, and Aikido Intel threat intelligence. This integrated design consolidates what would otherwise be multiple tools (Snyk, Wiz, Veracode, Semgrep, etc.) into one streamlined platform with AutoTriage reducing noise by up to 85%, eliminating tool sprawl for development and security teams.
Differentiator
Problem solved
Functional benefit
Brands
- Aikido Platform: Unified security platform from code to runtime, the core product offering combining SAST, SCA, DAST, IaC, secrets, CSPM, pentesting and runtime protection.
- Aikido Zen
- Aikido Safe Chain
- Opengrep
- Betterleaks
- Aikido Infinite
- Aikido Endpoint
- Aikido Intel
Products and services
- Aikido Platform Unified API-first application security platform spanning code (SAST, SCA, secrets, IaC, AI SAST, Code Audit/Quality, SBOM, malware detection), cloud (CSPM, VM scanning, K8s, container, Hardened Images), attack (AI pentest, DAST, Attack Surface Management, API scanning), and runtime protection (Zen WAF, Bot Protection). Sold as a Team or Enterprise subscription with unlimited-user flat-rate pricing on the Enterprise tier.
- Aikido Infinite Continuous AI penetration testing add-on that deploys 200+ autonomous AI agents against each software change to find, validate exploitability, generate patches, and retest fixes within the same workflow. Targeted at teams replacing periodic manual pentests with continuous coverage.
- Aikido Endpoint (Device Protection) Lightweight security agent for developer workstations that inspects and blocks risky packages, IDE extensions, browser plugins, and AI tools before installation, including auto-holding packages published less than 48 hours ago to mitigate the highest-risk attack window. Built on the open-source Aikido Safe Chain engine.
- AI Pentest Transactionally priced AI penetration testing offering. Standard-scope tests priced at $100 per test for vibe-coded apps on Lovable; larger apps use an in-app calculator. Delivered via the platform's autonomous AI pentesting agents that probe login flows, APIs, access controls, and cross-tenant access, with auto-fixable findings inside Lovable.
- Professional Pentest Services Custom, bespoke-scoped professional penetration testing engagements sold alongside the platform, targeting larger enterprise application portfolios. Capability was augmented by the September 2025 acquisitions of Allseek BV and Haicker SA, which added continuous and AI-native pentesting capabilities.
- Zen (Runtime Protection / WAF) Open-source in-app firewall providing runtime protection, auto-blocking critical injection attacks (IDOR, SQL injection, prompt injection), API rate limiting, and bot protection with no performance overhead. Distributed as a standalone community project that also powers commercial runtime defense within Aikido Protect.
- Aikido Safe Chain Open-source CLI firewall (npm package @aikidosec/safe-chain) that intercepts installs of malicious or suspicious packages during package manager operations, preventing supply chain attacks on developer workstations. Powers Aikido Endpoint's package-age enforcement.
- Opengrep Open-source code analysis engine maintained by Aikido, providing static code analysis capabilities as a community-driven project forked from Semgrep.
- Betterleaks Open-source secrets scanner developed by Zach Rice (creator of Gitleaks) and sponsored by Aikido, designed as a drop-in Gitleaks replacement with Common Expression Language (CEL) rules and Token Efficiency scanning.
- Aikido Intel Threat Intelligence Feed Real-time threat intelligence feed providing malware and vulnerability threat data. Identifies over 100,000 malicious packages daily (up from ~20,000 a year earlier) across open-source registries and powers Aikido Safe Chain, Zen runtime protection, and dependency malware detection in the commercial platform.
Quantifiable outcome
- Reduces alert noise by up to 95%
- +9 more outcomes
Companies that use Aikido Security
Customer profileNamed customers30 records
Segments8 records
Ideal customer profiles5 records
Aikido Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability10 records
Feature10 records
Aikido Security partnerships and signals
Strategic signalPartnerships
20 partnerships are on record, tiered core (technical integration), core (industry consortium), flagship (marketplace + ai pentest partnership), supporting (industry consortium), supporting (industry recognition + visibility), core (acquired ai pentest capability), core (post-eol security), core (vcs integration), supporting (vcs integration), supporting (ticketing integration), supporting (messaging integration), supporting (compliance integration), core (ai ide integration), core (cloud hyperscaler), core (cloud + identity hyperscaler) and supporting (container remediation).
- Dockercore (technical integration)Aikido announced native support for Docker Hardened Images by automatically processing VEX (Vulnerability Exploitability eXchange) attestations. The integration cross-references Docker's signed SBOM with VEX data to suppress irrelevant CVEs before they appear in security feeds. Users can connect their Docker Hub registry in approximately two minutes.
- OpenSSF (Open Source Security Foundation)core (industry consortium)Aikido became a new member of the Open Source Security Foundation (OpenSSF) during the Community Day North America event in Minneapolis on May 21, 2026, joining ActiveState, Minimus, TuxCare and FreeBSD Foundation. OpenSSF also released its v1.0.0 Python Secure Coding Guide, launched the OSS-CRS project, and introduced its first cohort of OpenSSF Ambassadors.
- Lovableflagship (marketplace + ai pentest partnership)Lovable integrates Aikido's autonomous AI penetration testing into its vibe-coding platform to enable AI-driven security assessments on live apps. Users enable Aikido as a Shared Connector in Lovable settings, launch a pentest on a project, and Aikido's agents probe login flows, APIs, access controls and cross-tenant access. Findings are auto-fixable in Lovable via the 'Fix all' button. The two companies co-market to founders and enterprise teams as 'two European unicorns' (Lovable and Aikido).
- CNCF (Cloud Native Computing Foundation)supporting (industry consortium)CNCF announced Aikido among 21 new Silver Members reflecting increased enterprise demand for cloud-native, AI-ready and security infrastructure.
- VivaTechsupporting (industry recognition + visibility)Aikido is featured in VivaTech's ranking of the Top 100 Rising European Startups, providing visibility among European investors and enterprise buyers.
- Trag (acquisition)core (acquired ai pentest capability)Aikido Security acquired Trag (AI Code startup) in September 2025 to enhance its AI-native security platform and outpace rivals in AI-driven security testing.
- Allseek (acquisition)core (acquired ai pentest capability)Aikido Security NV acquired Allseek BV and Haicker SA in September 2025 to enhance automated penetration testing capabilities. The acquisitions aim to reduce testing time from weeks to under an hour and enable continuous security assessments.
- Haicker (acquisition)core (acquired ai pentest capability)Aikido Security NV acquired Haicker SA (Lausanne-based AI pentesting startup, founded within six months prior to acquisition) in September 2025 to enhance automated penetration testing with AI, expanding market share in the $6 billion penetration testing market.
- TuxCarecore (post-eol security)TuxCare announced a partnership with Aikido to deliver Endless Post-EOL security for open-source code, extending support for end-of-life libraries integrated with Aikido's dependency scanning.
- GitHubcore (vcs integration)Aikido integrates with GitHub for read-only repository access, allowing users to sign up via GitHub OAuth and selectively scan repositories. Listed as a primary Git Systems integration.
- GitLabcore (vcs integration)Aikido integrates with GitLab for read-only repository access, allowing users to sign up via GitLab OAuth and selectively scan repositories.
- Bitbucketsupporting (vcs integration)Aikido integrates with Bitbucket Pipes for CI/CD workflows and supports Bitbucket Cloud OAuth for repo selection.
- Jirasupporting (ticketing integration)Jira integration enables Aikido to push findings as tickets directly into customer issue trackers.
- Microsoft Teamssupporting (messaging integration)Aikido integrates with Microsoft Teams for notifications and alert routing.
- Dratasupporting (compliance integration)Aikido integrates with Drata for compliance automation, supporting SOC 2 evidence collection.
- Vantasupporting (compliance integration)Aikido integrates with Vanta for compliance automation and SOC 2 evidence collection.
- AWS Kirocore (ai ide integration)Aikido integrates with AWS Kiro (Amazon's AI coding IDE) to catch security issues in review for AI-generated code, addressing the scale limitations of code review in AI-assisted development.
- AWScore (cloud hyperscaler)Aikido lists a dedicated 'Aikido for AWS' partner page (aikido.dev/partners/aws), indicating strategic alignment with AWS for cloud posture management and AWS-specific integrations.
- Microsoftcore (cloud + identity hyperscaler)Aikido lists a dedicated 'Aikido for Microsoft' partner page (aikido.dev/partners/microsoft), indicating strategic alignment with the Microsoft ecosystem (Azure, Entra ID, Microsoft 365).
- Rootsupporting (container remediation)Per a Business Wire announcement (July 2025), Root expanded its integration to bring instant container remediation to the broader security ecosystem, integrating with Aikido.
Scale indicators12 records
Recent moves7 records
Expansion highlights8 records
Aikido Security competitors and assessment
Company assessmentDirect peers
- Snyk: Snyk is the direct incumbent in developer-first application security with SAST, SCA, IaC and container scanning. Aikido explicitly targets Snyk in its 'alternative' SEO pages and has captured multiple migration wins (Revolut, SoundCloud, n8n, TechDivision, Go Autonomous, Supermetrics).
- Wiz: Wiz is a leading cloud security platform covering CSPM, container security and IaC scanning - directly overlapping with Aikido Cloud. Aikido competes with Wiz for cloud posture and workload scanning budgets at enterprise customers, though Wiz was acquired by Google for $32B+.
- Veracode: Veracode offers enterprise SAST, SCA and DAST. Overlaps with Aikido Code and Aikido Attack modules and competes for the same regulated-vertical (Banking, Public Sector) AppSec RFPs.
- Checkmarx: Checkmarx provides SAST, SCA and application security posture management for enterprise customers. Direct competitor to Aikido Code and Aikido Platform consolidated offering.
- GitHub Advanced Security: GitHub Advanced Security bundles SAST, SCA and secret scanning directly inside GitHub. Aikido targets GHAS as a direct competitor in its 'vs GitHub Advanced Security' comparison pages and has won migrations from it (e.g., n8n).
- Sonar (SonarQube): Sonar provides code quality and SAST, directly competing with Aikido Code (SAST, Code Quality, Code Audit modules).
- Semgrep: Semgrep is a developer-first SAST platform. Aikido runs Opengrep (a Semgrep fork) as open source and competes commercially with Semgrep Code/Supply Chain products.
- Mend (formerly WhiteSource): Mend offers SCA and application security, competing with Aikido Code's SCA, license risk and outdated software capabilities.
- Orca Security: Orca Security provides agentless cloud security posture management and competes with Aikido Cloud (CSPM) at enterprise customers.
Emerging players
- Ox Security: Ox Security is an application security posture management (ASPM) platform. Competes with Aikido's ASPM positioning and consolidated platform narrative for enterprise AppSec consolidation deals.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Aikido Security social profiles
Digital presenceAikido Security compliance and trust
Trust signalCompliance3 records
Aikido Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Aikido Security leadership team
Management profileNumber of profiles
Profiles9 records
Aikido Security subsidiaries and ownership
Company hierarchySubsidiaries3 records
Aikido Security funding detail
Funding detailFunding overview
Funding rounds4 records
Investors12 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Aikido Security M&A and investment
M&A and investmentM&A5 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Aikido Security
What does Aikido Security do?
Aikido Security offers a unified, API-first application security platform that consolidates code scanning (SAST, SCA, secrets detection, IaC, AI SAST, Code Audit/Quality, SBOM, malware detection), cloud security (CSPM, VM, container, K8s, Hardened Images), AI-powered offensive testing (AI pentest, DAST, Attack Surface Management, API scanning), and runtime protection (Zen WAF, Bot Protection) into a single platform. It complements these with add-on products (Aikido Infinite for continuous AI pentesting, Aikido Endpoint for developer workstation protection), a proprietary AutoTriage noise-reduction engine, AI AutoFix remediation, and the Aikido Intel threat feed.
Is Aikido Security a public or private company?
Aikido Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Aikido Security founded?
Aikido Security was founded in 2022. It employs 251 to 500 people.
Where is Aikido Security based?
Aikido Security is headquartered in Ghent, Belgium, in the Europe region.
How does Aikido Security make money?
Four revenue lines are on record. Freemium SaaS Subscription is the primary driver. The others are paid Subscriptions (Team & Enterprise), AI Pentest Transactions and professional Services / Custom Pentesting.
Who are Aikido Security's main competitors?
Direct peers on record are Snyk, Wiz, Veracode, Checkmarx, GitHub Advanced Security, Sonar (SonarQube), Semgrep, Mend (formerly WhiteSource) and Orca Security. Ox Security is listed as an emerging player.
Does Aikido Security have an API?
Yes. Aikido offers a public API and developer hub enabling programmatic access to the platform. Developers can use the API to integrate Aikido's security scanning capabilities into their workflows. The platform documentation is available at apidocs.aikido.dev. Developer documentation is at apidocs.aikido.dev.
What industry is Aikido Security in?
Aikido Security's product category is Application Security Platform (ASPM). Its primary akta.pro industry code is BPAMADAJ, App Security, Compliance & Review Automation Platforms, with a secondary code of HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation). Its NAICS code is 5415 and its SIC code is 7372.