Aikido Security
All-in-one AppSec platform: SAST, SCA, IaC, secrets, DAST, and runtime protection — zero CI config required.
Overview
Aikido Security is a unified application security posture management (ASPM) platform that consolidates over 15 security scanners — including SAST, SCA (open-source dependencies), IaC, secrets detection, DAST, container scanning, CSPM, and runtime protection — into a single developer-friendly interface. Founded in Ghent, Belgium in October 2022, it connects directly to your code repositories and cloud accounts with no CI pipeline reconfiguration required, then uses AI AutoTriage to cut alert noise by up to 95% and AI AutoFix to generate remediation pull requests automatically.
By January 2026, Aikido had reached unicorn status ($1B valuation) on the back of a $60M Series B led by DST Global, with more than 100,000 teams globally using the platform daily — including Revolut, Niantic, Premier League, SoundCloud, and Deel. The company has an active open-source presence through projects such as Opengrep (a vendor-neutral Semgrep fork), the Zen in-app firewall (Node, Python, PHP, Java, .NET, Ruby), and SafeChain (supply-chain malware blocker for npm/pip). An APAC office is established in Singapore, with focus markets spanning Singapore, Hong Kong, South Korea, and Japan.
Pricing
Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.
- 10 repos
- 2 users
- SCA + SAST + secrets
- 10 AI AutoFixes/mo
- 100 repos
- PR security review
- Jira/Linear sync
- Unlimited AutoFixes
- On-prem scanning
- API fuzzing
- Attack surface monitoring
- Malware detection
- Broker for internal apps
- Private registry proxy
- FIPS base images
- Priority support
- Custom SLA
- Multi-tenant portal
- On-prem deployment
- Dedicated support
Use cases
What you can produce with Aikido Security
- Consolidated vulnerability dashboard spanning code, containers, cloud, and runtime in one interface
- AI-generated remediation pull requests (AutoFix) for detected SAST, SCA, IaC, and secrets findings
- Reduced alert noise — AI AutoTriage cuts findings by up to 95% through reachability analysis and deduplication
- Continuous AI penetration testing (Aikido Infinite) surfacing exploitable attack paths without manual pen-test scheduling
- Open-source Zen firewall blocking zero-day injection attacks in-process for Node, Python, PHP, Java, .NET, and Ruby
- Supply-chain malware prevention via SafeChain, wrapping npm, pip, yarn, and pnpm package managers
- Compliance-ready reporting supporting SOC 2 Type II and ISO 27001:2022 audit evidence collection
ASEAN Perspective
Aikido Security in Southeast Asia
Aikido Security has established a physical APAC presence in Singapore (109 North Bridge Rd) with a dedicated Revenue Lead APAC role and stated focus markets of Singapore, Hong Kong, South Korea, and Japan. The flat-rate unlimited-user pricing is well-suited to the lean engineering teams common in ASEAN startups. However, APAC-specific compliance guidance (MAS TRM, PDPA, OJK) is not yet prominently documented on the platform, and the regional partner ecosystem is still in early build-out as of mid-2026 — teams in regulated sectors should engage the Singapore office directly to assess fit.
Aikido remains one of the strongest all-in-one AppSec plays for startups and mid-market teams. The January 2026 Series B -- $60M led by DST Global at a $1B valuation, the fastest unicorn run of any European cybersecurity company -- is real validation. The free tier is genuinely usable (10 repos, 2 users, core SCA/SAST/secrets scanning), AI AutoTriage cuts real noise, and -- contrary to earlier reports -- pricing above free is now fully published: Basic $350/month, Pro (most popular) $700/month, Advanced $1,050/month, with Enterprise the only custom-quote tier.
The tradeoffs: teams with heavy Snyk, Checkmarx, or Veracode investment may find Aikido trades depth for breadth in specialized areas, and free-to-$350 is a real cliff for solo developers. APAC go-to-market is still early -- a Singapore office exists and Singapore/Hong Kong/South Korea/Japan are named focus markets, but PDPA- or MAS TRM-specific documentation isn't prominent yet.
What people say
Aikido's biggest selling point isn't a feature, it's a number: $700/month gets a 10-user team the full Pro tier (on-prem scanning, API fuzzing, attack surface monitoring), and Basic starts at $350/month -- contrary to some older write-ups, Aikido now publishes this pricing openly rather than gating it behind a sales call. Only the top Enterprise tier requires contacting sales. Startups under $1.5M in funding and fewer than 10 people get up to 30% off either way.
G2 reviewers put the product between 4.6 and 4.7 out of 5 across just over 100 reviews, with the recurring theme being fast setup (several reviewers cite results in under 30 minutes) and meaningfully less alert noise than running Snyk or Checkmarx separately -- one enterprise customer, Visma, cites a flat-rate model that replaced six separate AppSec tools and their six separate alert streams. The free tier draws specific praise as functionally real rather than a lead-gen gate, covering SCA, SAST, secrets detection, and IDE plugins for up to 2 users and 10 repos.
The January 2026 Series B -- $60M led by DST Global at a $1B valuation -- makes Aikido the fastest European cybersecurity company to reach unicorn status, which should reassure buyers worried about vendor longevity. Weaknesses are more about depth than breadth: reviewers with heavy compliance-reporting needs or large existing Snyk/Checkmarx deployments say Aikido's all-in-one model doesn't yet match specialist tools feature-for-feature. APAC coverage is early-stage -- a Singapore office and a stated focus on Singapore, Hong Kong, South Korea, and Japan -- but regional compliance documentation (PDPA, MAS TRM) isn't well fleshed out yet.
Summary of public user & expert reviews, compiled by RECATOOLS.
Notable facts
- Aikido reached unicorn status ($1B valuation) in just over three years from founding — the fastest European cybersecurity company to do so.
- The company is named after the Japanese martial art aikido, reflecting a philosophy of redirecting attacker energy rather than brute-force blocking.
- Aikido co-founded Opengrep in January 2025, uniting 10 rival security companies to fork Semgrep and keep a core SAST engine truly open source.
- Revolut founder Nik Storonsky personally invested in Aikido's Series B — while Revolut itself is also a paying customer.
Frequently asked questions
About this listing
This entry was compiled from publicly available data including Aikido Security's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Aikido Security unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to Aikido Security directly →
Spotted something out of date? Suggest an update →
Aikido Security in the news
Cybersecurity
Miasma Returns With 'Phantom Gyp': npm Worm Sidesteps the Install-Script Defences Teams Ju...
Developer Tools
Miasma: How a Hijacked CI Pipeline Shipped Malicious npm Packages With Valid Provenance
Developer Tools
GitLab 19.0 drops Redis for Valkey by default and brings Gitaly to Kubernetes
Alternatives to Aikido Security
More in Security & Safety