

Aikido Security
By Aikido Security BV
The implementation process for Aikido Security software is designed to be quick and straightforward, allowing organizations to secure their environments efficiently. Here are the key steps and details:
Integration: Aikido Security integrates seamlessly with CI/CD workflows and popular development environments. This includes integration with GitHub, GitLab, Bitbucket, and other version control systems.
Setting Up Scans: Configure the types of scans you want to run, such as static code analysis (SAST), infrastructure-as-code (IaC) scanning, and open-source dependency scanning (SCA).
Review Results: Review the scan results through the Aikido Security dashboard, which provides detailed insights and recommendations for remediation.
Manual Fixes: For more complex issues, developers can follow the detailed remediation guidance provided by Aikido Security.
Alerts and Notifications: Configure alerts and notifications to stay informed about critical security issues in real-time.
Audit Logs: Maintain audit logs for tracking changes and actions taken within the Aikido Security platform.
The initial setup and configuration can be completed in as little as 2 minutes, making it one of the fastest security platforms to implement. The time required for the initial scan and remediation will vary based on the size and complexity of your codebase, but the platform is designed to provide quick and actionable insights.
Aikido Security software can be customized to fit specific business needs. Here are some key customization options:
Custom Rules: Users can create custom rules to apply context while triaging issues. This allows for setting rules for irrelevant paths, packages, and more.
Compliance Reporting: The platform supports customizable compliance reporting for standards like SOC 2, ISO 27001, and OWASP Top 10. Users can decide which information to share, such as benchmarks, scan history, issue insights, and more.
Integration with Tools: Aikido Security integrates with various task trackers (e.g., Jira, Linear) and compliance tools (e.g., Drata, Vanta), allowing businesses to tailor the platform to their existing workflows.
Custom SAST Rules: For advanced security needs, users can define custom static application security testing (SAST) rules.
API and Webhooks: The platform provides APIs and webhooks for further customization and integration with other tools and systems.
These customization options ensure that Aikido Security can be tailored to meet the unique requirements of different organizations.
Aikido Security offers straightforward pricing plans with no hidden fees. Here are the details:
Setup Fees: There are no setup fees for Aikido Security. The platform is designed for quick and easy implementation.
Maintenance Costs: Maintenance costs are included in the subscription plans. Regular updates and improvements are part of the service.
Developer Plan: Basic support included.
Basic Plan: Enhanced support with task tracker integrations and compliance reporting.
Pro Plan: Advanced support with features like on-prem code scanning, malware detection, and custom SAST rules.
Scale Plan: Enterprise support with advanced data analytics, multi-tenant portal, and training and onboarding.
The pricing plans are as follows:
Developer Plan: Free, includes basic features for up to 2 users.
Basic Plan: $350 per month, includes additional features for small teams.
Pro Plan: $700 per month, includes advanced features for growing teams.
Scale Plan: Custom pricing for enterprises with advanced needs.
These plans are designed to accommodate different team sizes and security requirements, ensuring that businesses only pay for what they need.
Aikido Security provides comprehensive training and support to ensure new users can effectively utilize the platform. Here are the key aspects:
Documentation: Aikido offers extensive online documentation covering all aspects of the platform, including setup, configuration, and best practices.
Live Online Training: New users can participate in live online training sessions to get hands-on experience and guidance from Aikido experts.
Knowledge Base: A detailed knowledge base is available, providing answers to frequently asked questions and step-by-step guides.
Customer Support: Aikido offers responsive customer support through various channels, including email and chat. Users can reach out for assistance with any issues or questions.
Community Support: Users can join the Aikido community on platforms like Slack to interact with other users and get support from the community.
Onboarding Assistance: For enterprise customers, Aikido provides dedicated onboarding assistance to ensure a smooth implementation process.
These resources are designed to help users quickly get up to speed with the platform and effectively secure their environments.
Aikido Security implements robust security measures to protect user data. Here are some key measures:
Data Privacy and Compliance: Aikido is fully compliant with GDPR and other data protection regulations. They are also ISO 27001:2022 and SOC 2 Type II certified.
Data Handling: Aikido does not store user code after analysis. Code is cloned into temporary environments (e.g., Docker containers) for analysis, and these environments are wiped clean after the process.
Access Control: The platform uses read-only access for integrations, ensuring that no changes can be made to user codebases.
Pentesting and Bug Bounty: Aikido conducts annual external penetration tests and maintains an active bug bounty program to identify and address potential vulnerabilities.
Encryption: All data in transit and at rest is encrypted to protect against unauthorized access.
No Token Storage: For integrations like GitHub, Aikido does not store refresh or access tokens, minimizing the risk in case of a database breach.
Local Scanning Option: Users have the option to run Aikido locally (on-prem), providing an additional layer of control over their data.
These measures ensure that user data is handled securely and that the platform remains resilient against potential threats.
Aikido Security releases updates regularly to ensure the platform remains secure and up-to-date with the latest features and improvements. Here are some key points:
Regular Updates: Aikido Security provides frequent updates to address new security threats, add new features, and improve existing functionalities. These updates are typically rolled out on a monthly basis.
Patch Management: Critical security patches are released as needed to address vulnerabilities promptly. These patches are prioritized to ensure that users are protected against emerging threats.
User Notifications: Users are notified of updates through the platform's dashboard and via email. Detailed release notes are provided to inform users about the changes and improvements included in each update.
Automated Deployment: Updates are deployed automatically to minimize disruption. Users can configure their settings to control the timing of updates, ensuring that they do not interfere with critical operations.
Aikido Security has a clear policy on data ownership and portability to ensure users have control over their data. Here are the key aspects:
Data Ownership: Users retain full ownership of their data. Aikido Security does not claim any ownership rights over the data processed through its platform.
Data Portability: Users have the right to request the export of their data in a structured, commonly used, and machine-readable format. This allows users to transfer their data to another service provider if needed.
Data Deletion: Users can request the deletion of their data at any time. Aikido Security will comply with such requests promptly, ensuring that all user data is permanently removed from their systems.
Compliance with Regulations: Aikido Security complies with data protection regulations such as GDPR, ensuring that users' rights to data access, portability, and deletion are respected.
Data Retention: Aikido retains service data for the duration of the customer’s business relationship with Aikido and for a period of time thereafter for historical and archiving purposes. Personal data can be deleted upon verified request from data subjects or their authorized agents.
These policies ensure that users have full control over their data and can manage it according to their needs.
Aikido Security offers flexible terms for scaling up or down based on organizational needs. Here are the key points:
Flexible Plans: Aikido Security provides multiple pricing tiers (Developer, Basic, Pro, and Scale) to accommodate different team sizes and security requirements.
Easy Upgrades: Users can easily upgrade their plan as their needs grow. This can be done through the platform's dashboard, allowing for immediate access to additional features and resources.
Downgrades: Similarly, users can downgrade their plan if their requirements decrease. This flexibility ensures that organizations only pay for what they need.
Custom Plans: For large enterprises with specific needs, Aikido offers custom plans under the Scale tier. This includes tailored features, advanced support, and unlimited resources.
Negotiation: Users can negotiate terms and pricing before renewal, especially if their usage or requirements have changed.
Aikido Security meets several key compliance standards to ensure the highest level of data protection and security:
ISO 27001:2022: Aikido Security is certified under ISO 27001:2022, a globally recognized standard for information security management systems (ISMS).
SOC 2 Type II: The platform is also compliant with SOC 2 Type II standards, which focus on the security, availability, processing integrity, confidentiality, and privacy of customer data.
GDPR: Aikido Security complies with the General Data Protection Regulation (GDPR), ensuring that personal data is handled in accordance with European data protection laws.
Annual Penetration Testing: The platform undergoes annual external penetration tests to identify and address potential vulnerabilities.
Bug Bounty Program: Aikido maintains an active bug bounty program to continuously improve its security posture.
These compliance measures demonstrate Aikido Security's commitment to maintaining a secure and trustworthy platform for its users.