Whilst at VivaTech 2026 last week, we caught up with Eliah Vanhove from Aikido Security with one aim in mind. What, we wanted to know, was the company’s secret sauce? And it’s worth knowing: this is a company that raised $60 million in a Series B round of funding in January, valuing Aikido at $1 billion.
I see that Aikido Security’s services are divided into Code, Cloud, Attack, Protect. Can you explain how that works?
Eliah Vanhove, Aikido Security, at VivaTech 2026
So we’re actually an all-in-one platform where we secure your code – your application, actually, from code all the way to runtime. We also offer code quality scanning to apply the standards. Then for both code and containers, we do the open source dependency scanning.
We also check for licencing risks. We map those out in an SBOM [software bill of materials], so we have a view on all your licences you’re using in your application. It’s quite important, because sometimes you see people using non-commercial licences that you cannot commercialise. Then we will flag that as well.
We’re also going to check if your software is outdated or not, so you still get security updates, and that’s both on the code and container parts. Further, we also offer cloud configuration checks, and we map out all the vulnerabilities in the compliance reports.
That’s very high level, but it gives you an idea.
So it means companies can relax and let you handle the complexities of keeping everything secure and up to date?
The companies, and even more of our focus, I think, is the developer. Because sometimes for the developer there is friction with the cyber security part, because they just want to create, develop, create code, generate code, write code, and they don’t want to get blocked on security issues. That’s what we really want to focus on: getting the developer to do what he wants to do and what he likes to do.
It’s also by integrating, for example, in their workspace directly within their IDE, within their pipeline, and providing them with results of the scanning there directly. They don’t have to go to Aikido, they can just keep on working.
For Revolut, I know they only use part of your service, not all of it. How does that work?
As I said, we offer an all-in-one platform that covers all the way from code to runtime, but in some cases, for example where a company already [uses an alternative], it’s possible to add specific modules, to be a modular contract if needed. So, for example, Revolut are using Aikido for the open-source dependency scanning.
I don’t know the specifics for Revolut, but we will integrate in alerting tools like Slack channels or Teams, where each specific team will get an alert if something is flagged.
So that’s the open-source side. How does the cloud infrastructure side work?
The main scanning we will do is the configurations of your cloud, which is quite often an important factor for all the compliance checks. For example, the very known one is the buckets, the public buckets. You see a lot of data leakage coming from there, or over-permissive IAM [identity access management] roles. That’s what we’re going to check with Aikido.
We’re also going to give you a full inventory of what is in your cloud with all the assets. You can do a search for what is in the assets, and you can also create rules based on that search.
To finish off, how does Aikido Security’s Attack and Protect offering work?
Let’s start with device protection. Here, it’s an agent sitting on the workstation of the developer, and it’s going to block all malicious installations, for example, Chrome extensions, IDEs, packages.
And that’s really, I would say, a hot topic now. There are enormous supply chain attacks with a lot of vulnerable packages being pushed, so Aikido is there to block it even before it gets installed.
Then on the attack side we have some more classic tools, like the authenticated task scanning, where you’re going to scan behind the login. So you log in and then we do the DAST scanning behind the login, also some API [checks], and also the pen testing, which is 100% agentic.
Our thanks to Eliah for that race through Aikido Security’s main features. As he said, that’s a high level overview, but even so it’s easy to see why this company has grown to such heights in the space of four years.
Tim Danton
Tim has worked in IT publishing since the days when all PCs were beige, and is editor-in-chief of the UK's PC Pro magazine. He has been writing about hardware for TechFinitive since 2023.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.