Aikido

Application security platform spanning code, cloud, container and runtime scanning with AI triage, autofix and automated pentesting.

$31.50/user/moLast verified 2026-08-18

Deployment

Cloud · Self-Hosted · Air-Gapped

Languages

17+

Pricing model

Per developer seat, Usage-based credits, Quote-based / Enterprise

Free tier

Yes

Workflow coverage

Where in the development lifecycle Aikido operates.

Real-Time IDE FeedbackYesPro

VS Code, JetBrains, Visual Studio, Eclipse, Vim/Neovim plugins give real-time findings

AI Agent Guardrail (MCP)No

Not offered in vendor documentation reviewed as of 2026-09-05.

Local CLI / Pre-CommitPartial

Offline local SAST scanning possible; no CLI or pre-commit hook documented

PR Inline ReviewYes

Pull request scanning and comments on GitHub, GitLab, Bitbucket, Azure DevOps

Merge Gate BlockingYes

Status checks and merge gate enforcement; GitLab merge request approval rules

Full Repo ScanYes

Six repo scanners: SCA, SAST, secrets, license, IaC, malware

Scheduled / Continuous RescanYesPro

Continuous monitoring of cloud infra, container registries and deployed front-ends

Runtime / Production MonitoringYesEnterprise

Zen Firewall runtime WAF (sidecar, reverse proxy, inline library); Advanced/Enterprise plan only

Analysis & detection

Every detection and code-analysis capability tracked for Aikido.

SASTYes

13 named languages; SQLi, XSS, CSRF, deserialization, crypto, command injection, path traversal, XXE

Taint / Data-Flow AnalysisYesPro

Data flow analysis inside AI Deep Review; credit-metered, Pro plan and above

Secrets DetectionYes

100+ secret patterns: API keys, SSH/PGP keys, AWS, DB creds, OAuth tokens

Secrets ValidationPartial

Contextual flagging separates actively used secrets from test values; no provider verification claimed

SCA (Dependencies)Yes

Lockfile and dependency-tree scanning across 20+ package managers with chain visualization

Reachability AnalysisPartialPro

AI CVE exploitability analysis prioritizes exploitable over theoretical; no call-path reachability claimed

Malicious Package DetectionYes

Malware in packages, typosquatting, supply chain compromise, suspicious behaviour patterns

License ComplianceYes

SPDX identification, permitted/restricted/forbidden policies, org-wide enforcement, compliance reports

SBOM GenerationYesBasic

Exports full SBOM (CycloneDX, SPDX, CSV) from Licenses & SBOM report

IaC ScanningYes

Terraform, CloudFormation, Kubernetes, Docker, Helm, Ansible, ARM, Bicep, Pulumi, CDK, Serverless

Container ScanningYesPro

15+ registries; base image vulns, layer secrets, malicious packages, misconfigurations

Cloud Posture (CSPM)YesPro

16+ providers; IAM, buckets, security groups, DNS, VPC, encryption, continuous monitoring

DAST / API ScanningYesPro

Front-end domain DAST plus REST, GraphQL, gRPC, WebSocket API scanning

Code Smells & MaintainabilityNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Complexity MetricsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Duplication DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Dead / Unused CodeNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Test Coverage TrackingNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Diff / New-Code CoverageNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Architecture GovernanceNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Technical Debt QuantificationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Behavioral Delivery AnalyticsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

AI Logic Bug DetectionYesPro

Deep Review finds business-logic vulnerabilities; security-scoped, 1 credit per pull request

PR Summaries & WalkthroughsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Custom Rule AuthoringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Autofix SuggestionsYesPro

AutoFix suggests dependency, SAST, IaC and secret-rotation fixes; compatibility tested

Autofix via Agentic PRsYesPro

AutoFix opens pull requests with proposed fixes; never auto-merged

AI Triage / False-Positive FilteringYesPro

AutoTriage ranks by exploitability, effort, false-positive probability; Secrets AutoTriage included

Monorepo SupportYesPro

Split monorepo per path (Pro+); GitLab/Azure DevOps only, no secrets scanning

AI capabilities

AI Review EngineYesPro

Deep Review performs AI contextual code review of business logic and attack paths

BYO Model / BYOKNo

Not offered in vendor documentation reviewed as of 2026-09-05.

MCP ServerYesBasic

Aikido MCP Plugin exposes its own MCP server (scan, list/ignore issues, login tools) for AI agents

AI Usage GovernanceNo

No AI-generated-code governance; Device Protection inventories AI tool, model and MCP usage per workstation instead.

Chat With ReviewerYes

Ask Aikido answers natural-language security questions about code; not a PR review thread

Learns From FeedbackNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Code Excluded From TrainingYesFree (all plans)

"Never use, store, or train on customer data"; AI ops are inference-only, not retained

Compliance & governance

Audit LogsYesEnterprise

Comprehensive audit trail of user actions; Advanced/Enterprise plan only

SSO / SAMLYesBasic

SAML SSO included from the Basic tier, not gated to Enterprise

Role-Based Access ControlYesEnterprise

Advanced RBAC with custom roles; Advanced/Enterprise plan only, no lower-tier roles described

Compliance Reporting ExportsYesPro

AI Custom Reports include compliance-ready documentation (Pro+); license compliance reports on all plans

Certifications

SOC 2 Type IIISO 27001GDPRCCPAHIPAA

Standards mapping

OWASP Top 10CWE (100+ mappings)PCI DSSGDPRCCPAHIPAASOC 2SPDX license identifiers

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterPartial
Azure DevOpsYes
REST APIYes
CLIYes
WebhooksYes

CI/CD systems

GitHub ActionsGitLab CI/CDJenkinsBambooTeamCityAWS CodePipelineAzure PipelinesTravis CICircleCIBitbucket Pipelines

IDEs

VS CodeIntelliJ IDEAWebStormPyCharmGoLandVisual StudioEclipseVimNeovim

Issue trackers

Jira (Cloud and Server)ServiceNowLinearClickUpAzure BoardsGitHub IssuesGitLab IssuesYouTrackAsanaMonday.comShortcut

Chat & notifications

SlackMicrosoft TeamsEmail

Pricing & plans

$31.50/user/month billed annually (10-user minimum on Basic); $35/user/month if billed monthly ($315/mo or $350/mo total for 10 users)

Minimum seats: 10 (Basic plan minimum; Free plan includes 2 users)

Free$0Individual developers, open-source projects, small teams evaluating
  • SCA dependency scanning, SAST & AI SAST, secrets detection
  • Cloud (CSPM-lite), license risk, outdated software & IaC scanning
  • IDE plugins, rescans every 3 days
  • 10 repos, 2 container images, 1 domain, 1 cloud account, 10 AI AutoFixes/mo, 250k protected requests/mo
  • No PR security review, no Jira/Linear/Drata/Vanta sync
  • No AI & Bot Protection or Device Protection
  • No on-prem, cloud/container/API scanning beyond the basics
  • Community support only
Basic$350/month for 10 users ($3,780/year billed annually, 10% off)Small teams to cover the basics
  • All Free features, plus: PR Security Review
  • Sync issues to Jira, Linear & more; sync to Drata, Vanta & more
  • Reports & analytics, PR code quality checks
  • AI & Bot Protection, Device Protection (AI tools & models detection)
  • Aikido Libraries (CVE-free), SSO (SAML), SBOM generation, MCP server, audit log
  • 100 repos, 50 container images, 3 domains, 3 cloud accounts, unlimited AI AutoFixes/mo, 10M protected requests/mo
  • Full-repository AI analysis is credit-based, not unlimited
  • No on-prem scanning, VM scanning, attack surface monitoring or malware detection (Pro+)
  • No monorepo splitting (Pro+)
  • No broker for internal apps, FIPS images or FedRAMP ATO (Advanced+)
Pro$700/month for 10 users ($7,560/year billed annually, 10% off) — most popularGrowing teams to scale security
  • All Basic features, plus: on-prem scanning, virtual machine scanning
  • Attack surface monitoring, malware detection
  • Same-day support, Aikido Images (CVE-free)
  • Monorepo splitting (GitLab/Azure DevOps only, SCA/SAST/IaC only)
  • 100 credits/month included for AI Pentesting, Deep PR Reviews, AI Code Analysis
  • 200 repos, 100 container images, 10 domains, 10 cloud accounts, 20M protected requests/mo
  • No broker for internal apps, private registry proxy, FIPS base images or FedRAMP ATO (Advanced+)
  • No multi-tenant portal (Advanced+)
  • Credits are metered, not unlimited, for advanced AI features
Advanced$1,050/month for 10 users ($11,340/year billed annually, 10% off)Orgs with advanced needs
  • All Pro features, plus: broker for internal apps, private registry proxy
  • Higher API rate limits, FIPS base images, FedRAMP ATO
  • Priority support in Slack or MS Teams
  • Multi-tenant portal, air-gapped/fully isolated deployments via broker
  • 200 credits/month included
  • 500 repos, 200 container images, 20 domains, 20 cloud accounts, 50M protected requests/mo
  • Highest published tier — anything beyond (custom volume, bespoke SLAs) requires Enterprise
  • Credits still metered for advanced AI features
EnterpriseCustom (contact sales)Large enterprises and organizations needing bespoke terms beyond Advanced
  • Everything in Advanced, with custom limits, contracts and support terms
  • Quote-only pricing — no published numbers

Who it's for

Notable strengths

  • Six scanners (SCA, SAST, secrets, license, IaC, malware) available on the free plan
  • Runtime protection via Zen Firewall as sidecar, reverse proxy or inline library
  • Cloud posture scanning across 16+ providers and container scanning across 15+ registries
  • AI AutoFix opens fix pull requests; AutoTriage and CVE exploitability analysis cut noise
  • Wide integration surface: 10 CI systems, 11 issue trackers, 13 private registries, 9 IDEs

Notable limitations

  • No published prices; both Pro and Enterprise require contacting sales
  • Zen Firewall runtime protection and Device Protection are Advanced/Enterprise only
  • Cloud, container and API scanning plus IDE plugins are excluded from the free plan
  • SSO, advanced RBAC, audit logging, data residency and on-premise are Enterprise only
  • No code quality, maintainability, complexity, duplication or test coverage capability documented

Similar tools

Other Code Security Platform tools in the directory.

FAQ

When should you choose Aikido?

Aikido best fits Indie developers, Startups, Mid-market teams, Enterprise, Regulated industries. Six scanners (SCA, SAST, secrets, license, IaC, malware) available on the free plan

What languages does Aikido support?

Aikido supports 17+ languages and frameworks, including JavaScript, TypeScript, Java, C#, PHP, Python, Ruby, Go, Elixir, Rust, and 7 more.

What does Aikido integrate with?

Aikido integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center (partial), Azure DevOps for source control, CI systems including GitHub Actions, GitLab CI/CD, Jenkins, Bamboo, TeamCity, and 5 more, and IDEs including VS Code, IntelliJ IDEA, WebStorm, PyCharm, GoLand, and 4 more.

What tools are similar to Aikido?

Similar Code Security Platform tools tracked here include Checkmarx One, Corgea, GitHub Advanced Security, Semgrep.

What are Aikido's plans and pricing?

Aikido offers a free tier, with paid plans starting around $31.50/user/mo.