Aikido Security
Aikido SecurityReviews from AWS customer
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
82 reviews
from
External reviews are not included in the AWS star rating for the product.
A developer-first security tool that delivers fast, actionable results
What do you like best about the product?
At HotDoc, we integrated Aikido to enhance our secure development practices, and it has quickly demonstrated its worth. The platform is very developer-friendly, offering a seamless onboarding experience, rapid scans, and results that are both clear and actionable, all without overwhelming our teams with unnecessary noise. In contrast to many traditional SAST tools, Aikido feels lightweight but remains effective, providing the right guardrails to support our developers without causing delays. It allows us to maintain security at a pace that aligns with modern software development. I strongly recommend Aikido to security teams who prioritise a secure-by-design philosophy.
What do you dislike about the product?
These aren't major drawbacks, as Aikido is a newer tool and still evolving, but there are areas where the platform is less mature. Its cloud and infrastructure security coverage is not yet as comprehensive as its application code scanning. While integrations with core platforms like Github, Slack, and Jira are strong, support for broader ecosystems is still limited - though this is expected to expand over time.
What problems is the product solving and how is that benefiting you?
Aikido's auto-ignore capability prioritises accuracy over noise by surfacing only vulnerabilities that truly matter. This significantly reduces alert fatigue common with older SAST tools and keeps our developers focused on fixes with real security impact.
The platform's fast, lightweight scans run in minutes and are non-disruptive to our development workflows. Unlike bulky enterprise SAST solutions, Aikido requires no heavy configuration or infrastructure overhead, making it easy to adopt.
With its developer-centric design, Aikido integrates natively with Github and Slack to deliver clear, actionable findings directly into existing workflows. Features like pull-request scans and inline comments minimise context switching for our developers.
The platform's fast, lightweight scans run in minutes and are non-disruptive to our development workflows. Unlike bulky enterprise SAST solutions, Aikido requires no heavy configuration or infrastructure overhead, making it easy to adopt.
With its developer-centric design, Aikido integrates natively with Github and Slack to deliver clear, actionable findings directly into existing workflows. Features like pull-request scans and inline comments minimise context switching for our developers.
Game changing tool for shift left security mindset
What do you like best about the product?
First off, I rarely write reviews, but Aikido absolutely deserves praise.
This tool has been really reliable for MoveInSync's code security pipeline. It's clear that a lot of thought, effort, and love has gone into creating a product that genuinely finds reliable security findings with clear instruction on fixing the issues making shift left mindset seemless.
What I love most about Aikido is its simplicity and false positive filter capability, where you don’t have to jump through hoops of irrelevant findings.
It seamlessly integrates into our DevSecOps pipeline.
The UI is intuitive, the performance is lightning-fast, and the slack support team? Absolutely top-notch.
They’re quick to respond, actively listen to feedback, and are constantly releasing thoughtful improvements.
Having All-in-one: SAST, SCA, Secret Scanning, DAST (still in early stage), CSPM, and api asset monitoring tool in a single tool is really helpful and now I can’t imagine working without it.
This is exactly the kind of innovative tool that reminds me why I love tech in the first place.
Highly recommend.
This tool has been really reliable for MoveInSync's code security pipeline. It's clear that a lot of thought, effort, and love has gone into creating a product that genuinely finds reliable security findings with clear instruction on fixing the issues making shift left mindset seemless.
What I love most about Aikido is its simplicity and false positive filter capability, where you don’t have to jump through hoops of irrelevant findings.
It seamlessly integrates into our DevSecOps pipeline.
The UI is intuitive, the performance is lightning-fast, and the slack support team? Absolutely top-notch.
They’re quick to respond, actively listen to feedback, and are constantly releasing thoughtful improvements.
Having All-in-one: SAST, SCA, Secret Scanning, DAST (still in early stage), CSPM, and api asset monitoring tool in a single tool is really helpful and now I can’t imagine working without it.
This is exactly the kind of innovative tool that reminds me why I love tech in the first place.
Highly recommend.
What do you dislike about the product?
Aikido does provide a local CLI scanner, which we prefer for our DevSecOps workflow, but the experience has been awkward for branch-based development.
We have to run scans locally and manually set the branch each time. In our usage, the CLI treated each branch scan as a separate “repo,” which quickly eats into the repo quota on our plan (e.g., 200 repos), whereas the cloud-connected scanner lets us switch branches on the same repository and re-run without consuming additional repo slots .
For teams with lots of short‑lived branches, that repo-counting behavior makes the local option a little hard to adopt.
Also the PR annotations are cloud-only. Inline PR comments/checks work via the cloud-integrated service (e.g., GitHub/GitLab/Bitbucket).
Local CLI scans do not post PR annotations.
We have to run scans locally and manually set the branch each time. In our usage, the CLI treated each branch scan as a separate “repo,” which quickly eats into the repo quota on our plan (e.g., 200 repos), whereas the cloud-connected scanner lets us switch branches on the same repository and re-run without consuming additional repo slots .
For teams with lots of short‑lived branches, that repo-counting behavior makes the local option a little hard to adopt.
Also the PR annotations are cloud-only. Inline PR comments/checks work via the cloud-integrated service (e.g., GitHub/GitLab/Bitbucket).
Local CLI scans do not post PR annotations.
What problems is the product solving and how is that benefiting you?
Aikido has been really reliable for MoveInSync's code security pipeline.
Having All-in-one: SAST, SCA, Secret Scanning, DAST (still in early stage), CSPM, and api asset monitoring tool in a single tool is really helpful and now I can’t imagine working without it.
Having All-in-one: SAST, SCA, Secret Scanning, DAST (still in early stage), CSPM, and api asset monitoring tool in a single tool is really helpful and now I can’t imagine working without it.
Excellent platform for security and vulnerability management
What do you like best about the product?
We came to Aikido after a frustrating experience with another popular SAST platform. Aikido has be incredibly easy to get started with, and has quickly become an integral part of our security and compliance process. Within an hour of signing up, I was certain that this was the right platform for us. The team has been incredibly responsive to our needs, and we have yet to run into any major issues. The reports are simple and easy to understand, and we get clear and actionable insights from the scans. The workflow in Aikido is quite simple, so everyone on our team has been able to jump in with ease. I highly recommend having a look at them if you want a solid platform for managing your application security.
What do you dislike about the product?
Each issue is assigned a severity. Some issues are lacking context to justify their severity level, but even in these instances, we can easily modify the level and leave justifications where necessary for our compliance process.
What problems is the product solving and how is that benefiting you?
Our organization takes security seriously and maintains compliance certifications to give our users confidence. Aikido makes it easy for us to uphold these strict security standards, simplifying what would otherwise be a complex and time-consuming process.
Finally, a Security Tool That Cuts Through the Noise
What do you like best about the product?
Aikido has been a great fit for our needs, with broad coverage across use cases and excellent support whenever we’ve needed it. Compared to other tools we’ve tried, it does a much better job at reducing noise and surfacing what actually matters, which saves our team a lot of time.
What do you dislike about the product?
Enterprise ready, broad set of features and amazing support team!
What problems is the product solving and how is that benefiting you?
Aikido helps us manage security across a wide range of codebases and dependencies without drowning in false positives. The platform consolidates what we need into one place, reduces noise compared to other tools, and gives our team clear, actionable insights. This saves time, improves focus, and helps us address real risks faster.
Rapid setup (minutes), human support (no bots) and a fantastic solution.
What do you like best about the product?
The combination of SAST/DAST/CSPM/SBOM/RASP (and other capabilities) is astoundingly useful. All-in-one security scanning and configuration validation may seem mythical and impossible, but it demonstrably is not. It's just that nobody was doing it well.
What do you dislike about the product?
For a young company, you can forgive the fact that there are not as many enterprise capabilities in the platform just yet, but that is definitely something they are aware of and working on as evidenced by the ability to enroll the entire AWS Organization instead of having to enroll each tenant account separately for the cloud security posture management scanning.
What problems is the product solving and how is that benefiting you?
Because the solution provides code and cloud modules, it is possible to link a repo scan (inside risk) with an API or web application scan (outside risk) for an integrated view of real exposure of vulnerabilities. But one of the features that is most valuable in my experience is taking on legacy code risk using the Zen Firewall as a RASP capability. This "in-app" firewall brings swift mitigation of common failings for inherited APIs and other apps whose authors have usually left the company and who never implemented rate limiting or blocking rules/logic.
An all-round vulnerability management system that is affordable for small to mid-sized businesses
What do you like best about the product?
In the 9 months we have been using Aikido, we have been very impressed with the offering. They have a significant number of tools available (SAST, SCA, attack surface scanning, etc.) and they are adding something new every month or two that makes me go "ooh, that's nice". The user interface is a bit of a learning curve, but ultimately it is servicable.
The scans themselves are fast and don't impact the performance of our systems in any noticeable way. They run automatically once a day and update the list of known issues. It doesn't do anything that any of the big competitors (Tenable, Qualys, etc.) don't, but a big difference is the pricing. It is a fraction of the price those other products ask, and the limits on the paid plans are very reasonable (we've only had to upgrade a limit once, and that costed a few euro's a month extra).
The products doesn't allow as much customizability as for instance Tenable allows, but as a tradeoff, setting up was extremely easy; configure your integrations (Gitlab, Github, AWS, etc.) with standards tokens, wait a few minutes and everything begins populating with your projects.
We've had to reach out to product support a few times, and every time they were very quick, friendly and helpful.
The scans themselves are fast and don't impact the performance of our systems in any noticeable way. They run automatically once a day and update the list of known issues. It doesn't do anything that any of the big competitors (Tenable, Qualys, etc.) don't, but a big difference is the pricing. It is a fraction of the price those other products ask, and the limits on the paid plans are very reasonable (we've only had to upgrade a limit once, and that costed a few euro's a month extra).
The products doesn't allow as much customizability as for instance Tenable allows, but as a tradeoff, setting up was extremely easy; configure your integrations (Gitlab, Github, AWS, etc.) with standards tokens, wait a few minutes and everything begins populating with your projects.
We've had to reach out to product support a few times, and every time they were very quick, friendly and helpful.
What do you dislike about the product?
There aren't any major issues with Aikido, but there a few things that I feel Aikido could do different, namely:
- The UI and scans themselves aren't very configurable. Don't expect a system that allows you to tweak every minor details of every minor scan
- The findings are divided into a number of categories (VMs, Code, Cloud Scanner). You cannot group items together to get one easy overview. For instance, if you want to group the code of a specific repository, the sBOM of the built code and the scan of the VM the code is running on, you can't. You have to navigate back and forth to match findings from different categories.
- The UI could use a bit of care to improve UX. For instance, we had issues where we couldn't delete an old asset that we used for testing purposes.
- The UI and scans themselves aren't very configurable. Don't expect a system that allows you to tweak every minor details of every minor scan
- The findings are divided into a number of categories (VMs, Code, Cloud Scanner). You cannot group items together to get one easy overview. For instance, if you want to group the code of a specific repository, the sBOM of the built code and the scan of the VM the code is running on, you can't. You have to navigate back and forth to match findings from different categories.
- The UI could use a bit of care to improve UX. For instance, we had issues where we couldn't delete an old asset that we used for testing purposes.
What problems is the product solving and how is that benefiting you?
We use Aikido as our first line of vulnerability detection. It's various scans cover the broad strokes of what we want to do to detect any security issues, all from the same dashboard.
So now Aikido scans all our source code, any built artefacts, container images, software packages once every day. We use it to get a clean dashboard of all our (potential) security issues and can prioritize which issue should be resolved first. We also allow our developers access to the findings, so they can give feedback on items they feel were scored too high, or too low so the communication regarding these issues is also improved. Furthermore, it is a great motivator to see that from one release to the next, the number of relevant security issues went down, so it has helped us motivate the developers to fix these issues.
So now Aikido scans all our source code, any built artefacts, container images, software packages once every day. We use it to get a clean dashboard of all our (potential) security issues and can prioritize which issue should be resolved first. We also allow our developers access to the findings, so they can give feedback on items they feel were scored too high, or too low so the communication regarding these issues is also improved. Furthermore, it is a great motivator to see that from one release to the next, the number of relevant security issues went down, so it has helped us motivate the developers to fix these issues.
Great all-in-one security product
What do you like best about the product?
Aikido is a great all-in-one security product that makes my life easier as an early stage startup founder. The UI/UX is simple and the coverage is broad. Customer support was also good.
What do you dislike about the product?
Issues and suggested remediations are at times ambiguous.
What problems is the product solving and how is that benefiting you?
Aikido helps me fulfill my SOC 2 and gives me security piece of mind that our infrastructure is hardened.
Great experience
What do you like best about the product?
Unlike some security tools that overwhelm with false positives, Aikido emphasizes actionable alerts. It filters out the noise and highlights only what truly matters, saving time and reducing alert fatigue.
What do you dislike about the product?
Power users may find that Aikido lacks deep customization for advanced scanning rules or configurations compared to tools like Snyk or SonarQube.
What problems is the product solving and how is that benefiting you?
Teams often juggle multiple tools for code scanning, dependency scanning, cloud misconfigurations, etc., leading to disjointed insights and confusion.
Fantastic application that gives me peace of mind, very quick onboarding process
What do you like best about the product?
I get a weekly rundown of any issues for my application using their code analysis tools. Very easy to use application - just connect to github and you're set. The team are super responsive when you reach out to them too.
What do you dislike about the product?
When manually ignored, I'd like to see the name of the user in the table - but it's a nitpick - it's fastastic
What problems is the product solving and how is that benefiting you?
It's keeping us up to date with the most recent vulnerabilities.
Security Posture Review: Aikido Security Platform
What do you like best about the product?
Aikido consolidates multiple scanners into one platform, including SAST (source code), SCA (dependencies), Container Scanning, and IaC (Infrastructure as Code) scanning. This accurately reflects its "all-in-one" approach. Its ease of use and integration is top notch. Customer support is exceptional in case you need help.
What do you dislike about the product?
Aikido lacks ability to build and enforce complex, multi-layered security policies across the entire orginzation.
What problems is the product solving and how is that benefiting you?
It solves the security in development lifecycle. By automatically triaging alerts and showing only the "reachable" vulnerabilities that matter and eliminates noise. Integrates directly into their existing tools like GitHub/GitLab. Empower team to context they need to fix security issues themselves, quickly and confidently, without needing to wait for a security expert.
showing 1 - 10