Aikido Security
Security · #3 of 3 in category · #18 of 27 overall
All-in-one AppSec platform (SAST, SCA, secrets, cloud) with AI autotriage and autofix PRs, built on tuned open-source scanners.
[ Where it fits ]
On the documented evidence, Aikido Security suits larger orgs willing to buy an enterprise plan for self-hosting.
[ Documented strengths ]
No standard is fully documented as met in public sources.
[ Documented gaps ]
- Business Logic Validation. Jira/Linear sync creates tickets from findings; no validation of code against requirements.
- Sandbox Validation. Static and reachability analysis; no sandbox execution of code or fixes.
- Economic Transparency. Vendor-managed LLM (Claude on Bedrock) with credit-metered AI features; no model choice.
[ Facts ]
- Category
- Security
- Open source
- No — proprietary
- Pricing
- Free Developer plan (2 users); Basic $300/mo and Pro/Advanced from $600/mo (10 users incl., scales by users); Enterprise custom; 10% off annual billing source ↗
- Self-hosted
- Enterprise only — SaaS-first; Pro adds on-premises/local scanning and Enterprise offers on-premises deployment options.
- Platforms
- GitHub GitLab Bitbucket AD Azure DevOps
- Model control
- Fixed vendor models (Claude via AWS Bedrock) for AutoFix and AutoTriage; no BYOK
- Last verified
- 2026-08-11
[ Against the 9 standards ]
Based on public documentation as of 2026-08-11. ✓ documented · ~ partial · ✗ not offered · ? undocumented. Undocumented scores zero — see the methodology.
Reachability engine plus code and cloud context feed AI autotriage; no multi-repo or requirements context.
Curated scanner rules with rule-based plus LLM autotriage; noise reduction is the core pitch.
IDE plugins, CI gating, and PR security reviews; no documented distinct local-vs-PR behavior modes.
Jira/Linear sync creates tickets from findings; no validation of code against requirements.
No documented learning from team feedback beyond standard ignore/triage states.
Vendor-managed LLM (Claude on Bedrock) with credit-metered AI features; no model choice.
AI AutoFix opens fix PRs for 91 SAST rules (JS/TS, Python, Java, .NET, PHP) plus SCA/IaC fixes.
[ Closest alternatives ]
[ FAQ ]
Is Aikido Security open source?
No. Aikido Security is proprietary — you can use it, but you cannot read or fork the review engine.
Can Aikido Security be self-hosted?
Enterprise only. SaaS-first; Pro adds on-premises/local scanning and Enterprise offers on-premises deployment options. Verified against the vendor's own documentation on 2026-08-11.
How much does Aikido Security cost?
Free Developer plan (2 users); Basic $300/mo and Pro/Advanced from $600/mo (10 users incl., scales by users); Enterprise custom; 10% off annual billing. Seat price is only part of the bill: Aikido Security handles models as fixed vendor models (claude via aws bedrock) for autofix and autotriage; no byok, which is what usually decides the real monthly cost.
How does Aikido Security score against the 9-pillar AI code review standard?
2.5 out of 9. It fully documents 0 standards, partially documents 5, does not offer 3, and leaves 1 undocumented. The score is coverage of documented capability, not a measure of review quality.
What are the alternatives to Aikido Security?
The closest tools in this directory are Snyk Code, Semgrep, Bito, Cursor BugBot. Each is scored against the same 9 standards, so the matrices are directly comparable.
Evaluating Aikido Security?
Run it through the two-week trial protocol before you commit a team to it.