Code Security Platform
Aikido
Application security platform spanning code, cloud, container and runtime scanning with AI triage, autofix and automated pentesting.
Deployment
Cloud · Self-Hosted · Air-Gapped
Languages
17+
Pricing model
Per developer seat, Usage-based credits, Quote-based / Enterprise
Free tier
Yes
Workflow coverage
Where in the development lifecycle Aikido operates.
VS Code, JetBrains, Visual Studio, Eclipse, Vim/Neovim plugins give real-time findings
Not offered in vendor documentation reviewed as of 2026-09-05.
Offline local SAST scanning possible; no CLI or pre-commit hook documented
Pull request scanning and comments on GitHub, GitLab, Bitbucket, Azure DevOps
Status checks and merge gate enforcement; GitLab merge request approval rules
Six repo scanners: SCA, SAST, secrets, license, IaC, malware
Continuous monitoring of cloud infra, container registries and deployed front-ends
Zen Firewall runtime WAF (sidecar, reverse proxy, inline library); Advanced/Enterprise plan only
Analysis & detection
Every detection and code-analysis capability tracked for Aikido.
13 named languages; SQLi, XSS, CSRF, deserialization, crypto, command injection, path traversal, XXE
Data flow analysis inside AI Deep Review; credit-metered, Pro plan and above
100+ secret patterns: API keys, SSH/PGP keys, AWS, DB creds, OAuth tokens
Contextual flagging separates actively used secrets from test values; no provider verification claimed
Lockfile and dependency-tree scanning across 20+ package managers with chain visualization
AI CVE exploitability analysis prioritizes exploitable over theoretical; no call-path reachability claimed
Malware in packages, typosquatting, supply chain compromise, suspicious behaviour patterns
SPDX identification, permitted/restricted/forbidden policies, org-wide enforcement, compliance reports
Exports full SBOM (CycloneDX, SPDX, CSV) from Licenses & SBOM report
Terraform, CloudFormation, Kubernetes, Docker, Helm, Ansible, ARM, Bicep, Pulumi, CDK, Serverless
15+ registries; base image vulns, layer secrets, malicious packages, misconfigurations
16+ providers; IAM, buckets, security groups, DNS, VPC, encryption, continuous monitoring
Front-end domain DAST plus REST, GraphQL, gRPC, WebSocket API scanning
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Deep Review finds business-logic vulnerabilities; security-scoped, 1 credit per pull request
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
AutoFix suggests dependency, SAST, IaC and secret-rotation fixes; compatibility tested
AutoFix opens pull requests with proposed fixes; never auto-merged
AutoTriage ranks by exploitability, effort, false-positive probability; Secrets AutoTriage included
Split monorepo per path (Pro+); GitLab/Azure DevOps only, no secrets scanning
AI capabilities
Deep Review performs AI contextual code review of business logic and attack paths
Not offered in vendor documentation reviewed as of 2026-09-05.
Aikido MCP Plugin exposes its own MCP server (scan, list/ignore issues, login tools) for AI agents
No AI-generated-code governance; Device Protection inventories AI tool, model and MCP usage per workstation instead.
Ask Aikido answers natural-language security questions about code; not a PR review thread
Not offered in vendor documentation reviewed as of 2026-09-05.
"Never use, store, or train on customer data"; AI ops are inference-only, not retained
Compliance & governance
Comprehensive audit trail of user actions; Advanced/Enterprise plan only
SAML SSO included from the Basic tier, not gated to Enterprise
Advanced RBAC with custom roles; Advanced/Enterprise plan only, no lower-tier roles described
AI Custom Reports include compliance-ready documentation (Pro+); license compliance reports on all plans
Certifications
Standards mapping
Integrations
CI/CD systems
IDEs
Issue trackers
Chat & notifications
Pricing & plans
$31.50/user/month billed annually (10-user minimum on Basic); $35/user/month if billed monthly ($315/mo or $350/mo total for 10 users)
Minimum seats: 10 (Basic plan minimum; Free plan includes 2 users)
- SCA dependency scanning, SAST & AI SAST, secrets detection
- Cloud (CSPM-lite), license risk, outdated software & IaC scanning
- IDE plugins, rescans every 3 days
- 10 repos, 2 container images, 1 domain, 1 cloud account, 10 AI AutoFixes/mo, 250k protected requests/mo
- No PR security review, no Jira/Linear/Drata/Vanta sync
- No AI & Bot Protection or Device Protection
- No on-prem, cloud/container/API scanning beyond the basics
- Community support only
- All Free features, plus: PR Security Review
- Sync issues to Jira, Linear & more; sync to Drata, Vanta & more
- Reports & analytics, PR code quality checks
- AI & Bot Protection, Device Protection (AI tools & models detection)
- Aikido Libraries (CVE-free), SSO (SAML), SBOM generation, MCP server, audit log
- 100 repos, 50 container images, 3 domains, 3 cloud accounts, unlimited AI AutoFixes/mo, 10M protected requests/mo
- Full-repository AI analysis is credit-based, not unlimited
- No on-prem scanning, VM scanning, attack surface monitoring or malware detection (Pro+)
- No monorepo splitting (Pro+)
- No broker for internal apps, FIPS images or FedRAMP ATO (Advanced+)
- All Basic features, plus: on-prem scanning, virtual machine scanning
- Attack surface monitoring, malware detection
- Same-day support, Aikido Images (CVE-free)
- Monorepo splitting (GitLab/Azure DevOps only, SCA/SAST/IaC only)
- 100 credits/month included for AI Pentesting, Deep PR Reviews, AI Code Analysis
- 200 repos, 100 container images, 10 domains, 10 cloud accounts, 20M protected requests/mo
- No broker for internal apps, private registry proxy, FIPS base images or FedRAMP ATO (Advanced+)
- No multi-tenant portal (Advanced+)
- Credits are metered, not unlimited, for advanced AI features
- All Pro features, plus: broker for internal apps, private registry proxy
- Higher API rate limits, FIPS base images, FedRAMP ATO
- Priority support in Slack or MS Teams
- Multi-tenant portal, air-gapped/fully isolated deployments via broker
- 200 credits/month included
- 500 repos, 200 container images, 20 domains, 20 cloud accounts, 50M protected requests/mo
- Highest published tier — anything beyond (custom volume, bespoke SLAs) requires Enterprise
- Credits still metered for advanced AI features
- Everything in Advanced, with custom limits, contracts and support terms
- Quote-only pricing — no published numbers
Who it's for
Notable strengths
- Six scanners (SCA, SAST, secrets, license, IaC, malware) available on the free plan
- Runtime protection via Zen Firewall as sidecar, reverse proxy or inline library
- Cloud posture scanning across 16+ providers and container scanning across 15+ registries
- AI AutoFix opens fix pull requests; AutoTriage and CVE exploitability analysis cut noise
- Wide integration surface: 10 CI systems, 11 issue trackers, 13 private registries, 9 IDEs
Notable limitations
- No published prices; both Pro and Enterprise require contacting sales
- Zen Firewall runtime protection and Device Protection are Advanced/Enterprise only
- Cloud, container and API scanning plus IDE plugins are excluded from the free plan
- SSO, advanced RBAC, audit logging, data residency and on-premise are Enterprise only
- No code quality, maintainability, complexity, duplication or test coverage capability documented
Similar tools
Other Code Security Platform tools in the directory.
FAQ
When should you choose Aikido?
Aikido best fits Indie developers, Startups, Mid-market teams, Enterprise, Regulated industries. Six scanners (SCA, SAST, secrets, license, IaC, malware) available on the free plan
What languages does Aikido support?
Aikido supports 17+ languages and frameworks, including JavaScript, TypeScript, Java, C#, PHP, Python, Ruby, Go, Elixir, Rust, and 7 more.
What does Aikido integrate with?
Aikido integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center (partial), Azure DevOps for source control, CI systems including GitHub Actions, GitLab CI/CD, Jenkins, Bamboo, TeamCity, and 5 more, and IDEs including VS Code, IntelliJ IDEA, WebStorm, PyCharm, GoLand, and 4 more.
What tools are similar to Aikido?
Similar Code Security Platform tools tracked here include Checkmarx One, Corgea, GitHub Advanced Security, Semgrep.
What are Aikido's plans and pricing?
Aikido offers a free tier, with paid plans starting around $31.50/user/mo.
Opens www.aikido.dev in a new tab. Review Radar is not affiliated with Aikido.