Review Summary
Users appreciate Aikido Security for its clean, focused interface, comprehensive all-in-one security platform, and r ...
Users appreciate Aikido Security for its clean, focused interface, comprehensive all-in-one security platform, and r ...



Aikido is a developer-centric security platform that gives developers and security teams an instant overview of all code-to-cloud security issues and guides teams to fix vulnerabilities fast. Aikido supports security teams execute by aggressively reducing false-positives, automatic triage and risk bundling, and translating Common Vulnerabilities and Exposures (CVEs) into easy step-by-step explanations to resolve. Described as an "all-in-one" application security platform, Aikido's covers the entire Software Development Lifecycle (SDLC), including: static application security testing (SAST), dynamic application security testing (DAST), infrastructure-as-code (IaC), container scanning, secrets detection, open source lisence scanning, cloud posture management (CSPM), runtime protection, and more.
Do You Manage Peer Insights at Aikido Security?
Access Vendor Portal to update and manage your profile.
The product itself does everything we need and more. The way they support us is insane and I've never seen anything like it. We have a shared Slack channel and someone always responds, usually within minutes and often the CTO/CEO himself engages with us and our issues directly. They often fix issues the same day, and sometimes even on weekends. Their auto-ignore functionality, while not perfect, is best in class and does an amazing job at reducing the noise so we can concentrate on the security signal (i.e. actual problems). The web UI, while not perfect, is much better than any of the competitors I looked at (by a long way) and includes very powerful filtering functionality that always allows me to narrow down to the subset of our product that I want to focus on. They have a good API and quickly add anything we find missing from it. The reporting functionality is great and super valuable to make our GRC work easier by providing reporting based on standards (such as SOC 2) that we're trying to maintain. The integrations are expansive and cover everything we need and were easy to setup. Good SSO integration and audit logging.
Unified security view across code, cloud providers and dependencies with clear risk priorities that developers can understand and action. This allows the security team to have accountability and control as well as progression towards a tighter environment. Centric platform where efficiency is clear and logical. Vulnerability scanning and pen tests to find constant exposures and risks in new or refined features.
Integration with JIRA
Honestly, these are all very minor (almost petty concerns). 1) The web UI, while great overall, has some weird inconsistencies (e.g. not being able to choose how to sort tables by column on some pages) 2) The docs, while expansive, are a little sprawling and hard to search, I tend to resort to asking a web-search enabled LLM to help me find what I need 3) The secret detection, whilst good overall, is probably the most prone to false positives. 4) The filtering is extremely powerful but can be somewhat unintuitive at times.
Advanced customization options are still in development and evolving, but the roadmap and responsiveness help offset these limitations.
Many false postives in exposed secrets