What is Aikido Security, when did it become a unicorn and how can it keep your code safe?

Whilst at VivaTech 2026 last week, we caught up with Eliah Vanhove from Aikido Security with one aim in mind. What, we wanted to know, was the company’s secret sauce? And it’s worth knowing: this is a company that raised $60 million in a Series B round of funding in January, valuing Aikido at $1 billion.

There are some things we already knew. Aikido Security counts Revolut, the Premier League and SoundCloud among its 50,000+ clients. And in March, Frost & Sullivan awarded it with 2026 Global Customer Value Leadership Recognition in Application Security Posture Management (ASPM). Not bad for a company founded in 2022.

Here’s what Eliah told me.

I see that Aikido Security’s services are divided into Code, Cloud, Attack, Protect. Can you explain how that works?

Eliah Vanhove at VivaTech 2026
Eliah Vanhove, Aikido Security, at VivaTech 2026

So we’re actually an all-in-one platform where we secure your code – your application, actually, from code all the way to runtime. We also offer code quality scanning to apply the standards. Then for both code and containers, we do the open source dependency scanning.

We also check for licencing risks. We map those out in an SBOM [software bill of materials], so we have a view on all your licences you’re using in your application. It’s quite important, because sometimes you see people using non-commercial licences that you cannot commercialise. Then we will flag that as well.

We’re also going to check if your software is outdated or not, so you still get security updates, and that’s both on the code and container parts. Further, we also offer cloud configuration checks, and we map out all the vulnerabilities in the compliance reports.

That’s very high level, but it gives you an idea.

So it means companies can relax and let you handle the complexities of keeping everything secure and up to date?

The companies, and even more of our focus, I think, is the developer. Because sometimes for the developer there is friction with the cyber security part, because they just want to create, develop, create code, generate code, write code, and they don’t want to get blocked on security issues. That’s what we really want to focus on: getting the developer to do what he wants to do and what he likes to do.

It’s also by integrating, for example, in their workspace directly within their IDE, within their pipeline, and providing them with results of the scanning there directly. They don’t have to go to Aikido, they can just keep on working.

For Revolut, I know they only use part of your service, not all of it. How does that work?

As I said, we offer an all-in-one platform that covers all the way from code to runtime, but in some cases, for example where a company already [uses an alternative], it’s possible to add specific modules, to be a modular contract if needed. So, for example, Revolut are using Aikido for the open-source dependency scanning.

I don’t know the specifics for Revolut, but we will integrate in alerting tools like Slack channels or Teams, where each specific team will get an alert if something is flagged.

So that’s the open-source side. How does the cloud infrastructure side work?

The main scanning we will do is the configurations of your cloud, which is quite often an important factor for all the compliance checks. For example, the very known one is the buckets, the public buckets. You see a lot of data leakage coming from there, or over-permissive IAM [identity access management] roles. That’s what we’re going to check with Aikido.

We’re also going to give you a full inventory of what is in your cloud with all the assets. You can do a search for what is in the assets, and you can also create rules based on that search.

To finish off, how does Aikido Security’s Attack and Protect offering work?

Let’s start with device protection. Here, it’s an agent sitting on the workstation of the developer, and it’s going to block all malicious installations, for example, Chrome extensions, IDEs, packages.

And that’s really, I would say, a hot topic now. There are enormous supply chain attacks with a lot of vulnerable packages being pushed, so Aikido is there to block it even before it gets installed.

Then on the attack side we have some more classic tools, like the authenticated task scanning, where you’re going to scan behind the login. So you log in and then we do the DAST scanning behind the login, also some API [checks], and also the pen testing, which is 100% agentic.

Aikido Security's agentic pentest
Aikido Security’s agentic pentest (source: Aikido Security)

Our thanks to Eliah for that race through Aikido Security’s main features. As he said, that’s a high level overview, but even so it’s easy to see why this company has grown to such heights in the space of four years.

Avatar photo
Tim Danton

Tim has worked in IT publishing since the days when all PCs were beige, and is editor-in-chief of the UK's PC Pro magazine. He has been writing about hardware for TechFinitive since 2023.