Aikido

Free Use Aikido to triage, fix, and gate security issues across dev to production.
5 
Rating
23 votes
Your vote:
Latest version:
unknown See all
License type:
Freemium
Visit Website
aikido.dev
Loading
Freemium
Info updated on:

Teams typically start by linking Aikido to existing GitHub, GitLab, or Bitbucket repos and letting it run baseline checks across projects. Findings are then routed into a daily workflow: developers review the prioritized queue, ignore low-value noise, and focus on the items most likely to affect production. When a fix is straightforward, Aikido can propose a ready-to-merge pull request so remediation happens in the same place code changes already go through review. For release safety, checks can be enforced in CI/CD so new secrets, risky dependency updates, or misconfigured infrastructure changes are caught before merge or deploy. In parallel, engineers can use IDE feedback while coding to address issues early instead of waiting for a pipeline run.

Operationally, the platform is used to keep coverage continuous across code, containers, IaC, and cloud settings, with results tracked in the tools teams already manage work in, such as Jira or Linear. Security teams use the consolidated view to monitor trends, verify that runtime protections like the in-app WAF are active where needed, and validate exposure using active testing such as DAST or API scans. For audits, the same evidence and control signals can be synchronized into systems like Drata or Vanta, making it easier to show progress toward SOC 2 or ISO 27001 without manual screenshots and spreadsheets. If you want to trial the workflow before connecting private code, you can explore outputs through the public demo project to understand what the triage and fix loop looks like end to end.

Screenshot (1)

Review Summary

Features

  • Read-only repo connection
  • automated scanning for vulnerabilities and misconfigurations
  • AI-based prioritization and noise reduction
  • one-click fix via pull-request generation
  • IDE feedback
  • CI/CD gating checks
  • consolidated coverage for dependencies, secrets, app code, containers, IaC, and cloud posture
  • DAST and API scanning
  • runtime protection with in-app WAF
  • issue syncing to Jira/Linear
  • compliance evidence support via Drata/Vanta
  • public demo project access

How It’s Used

  • Pre-merge security checks for pull requests
  • preventing secret leaks during commits
  • prioritizing and triaging vulnerability backlogs
  • automated remediation PRs for common fixes
  • validating cloud and IaC changes before deployment
  • container and dependency risk monitoring during releases
  • ongoing posture monitoring across environments
  • runtime shielding for exposed apps/APIs
  • security verification with DAST/API scans before go-live
  • audit preparation and evidence collection for SOC 2/ISO 27001

Plans & Pricing

Developer

$0 / free forever

Incl. 2 users. For devs and curious minds. All scanners (Dependencies, Cloud, Secrets, SAST, DAST, IaC, Licenses, Outdated Software), IDE plugins (JS & Python), Rescans every 3 days. Includes: 10 repos, 2 container images, 1 domain, 1 cloud account, 2 AI AutoFixes/mo, 250k protected requests/mo.

Basic

$350 / month

Custom, incl. 10 users. For small teams to cover the basics. All Free features, plus: PR security review, IDE plugins, Sync issues to Jira, Linear & more, Sync to Drata, Vanta & more, Reports & analytics, Code quality, AI & Bot protection, Attack surface monitoring. Includes: 100 repos, 25 container images, 3 domains, 3 cloud accounts, 50 AI AutoFixes/mo, 10M protected requests/mo.

Pro

$700 / month

Custom, incl. 10 users. For growing teams to scale security. All Basic features, plus: Custom SAST rules, On-prem scanning, API Scanning for REST/GraphQL, Virtual machine scanning, Malware detection, Custom cloud alerts. Includes: 200 repos, 50 container images, 10 domains, 10 cloud accounts & 5 VMs, 200 AI AutoFixes/mo, 20M protected requests/mo.

Advanced

$1,050 / month

Custom, incl. 10 users. For orgs with advanced needs. All Pro features, plus: Hardened container images, Extended life for popular libraries, EPSS Prioritization, ∞ Cloud rules. Includes: 500 repos, 100 container images, 20 domains, 20 cloud accounts & 10 VMs, 500 AI AutoFixes/mo, 50M protected requests/mo.

Startup

Get up to 30% off

Eligibility: <1.5M in funding and <10 team members. All non-profits are eligible.

Enterprise

Contact us

Custom amount of: Users, Repos, Container images, AI AutoFixes. All advanced features, plus: Multi tenant portal, Training & onboarding, Enterprise support, SLA for support.

Comments

5
Rating
23 votes
5 stars
0
4 stars
0
3 stars
0
2 stars
0
1 stars
0
User

Your vote: