Aikido Security
Effortless Security Testing with Comprehensive Coverage
Fast, Easy Security Scanning Across Repos and IDEs with Great Aikido Support
UI is good and easy go thorugh
easy to integrate wth multiple IDES
its quick and scan fast
have good support from aikido team via slack channels etc
have AI intelligent scaninng support and reports vulerablities and susgegstions
Aikido: A Modern, SMB-Friendly Security Tool with Great Elixir Support
Automated scans have streamlined vulnerability workflows and now provide clear daily risk reports
What is our primary use case?
My main use case for Aikido Security is to utilize it as part of our vulnerability management program, where we also scan our images, codes, and manage our SBOM.
A specific example of how I use Aikido Security in our vulnerability management program occurs every time new code is pushed into our repositories. Aikido scans for this new code and raises new vulnerabilities within these new codes. Then, with our automations, a Jira ticket gets created, our engineering team takes a look at it, and adjusts security if needed, resolving it within a few days.
Additionally, we use Aikido Security to generate a current status of our software, and I have created an automation that daily exports all of the vulnerabilities our software has, groups them by severity, and generates a report that can be shared with our customers.
What is most valuable?
In my experience, the best feature Aikido Security offers is its ease of use, as it was really easy to onboard our engineers into adopting Aikido Security in their day-to-day lives.
The reason onboarding my engineers with Aikido Security was so easy is the user interface. The first thing our engineers see when they log in is a feed of vulnerabilities that their own repositories are affected by, which helps them focus only on their work at hand.
I would also like to add that the integrations part is really useful, as all of the integrations we have added so far, mainly Jira, IDE, and API integrations, are really easy to use because they are backed by strong documentation that they maintain daily. This is a commendation to them.
Aikido Security has positively impacted our organization by helping us reduce the complexity in managing our vulnerabilities. We now have a single source of truth with Aikido Security, allowing us to get rid of manually maintained automations that we previously had.
What needs improvement?
I think Aikido Security could be improved by addressing its Jira integration, which I feel needs a bit of work. For my preferences, it is a bit too rigid. They recently added the capability of having custom fields, but before that, they did not have it.
Additionally, I would love to see a Terraform module for Aikido Security, although I know this might be a bit much to ask.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Customer support for Aikido Security is incredibly efficient. I can get an answer to a question within two or three minutes.
I chose a rating of ten because after reviewing several other products, Aikido Security was the easiest to use, the easiest to onboard, and the one with the most active customer support. I have a Slack channel with them where I can ask whatever I need and they will respond within minutes, which really helps us.
Which solution did I use previously and why did I switch?
How was the initial setup?
My experience with the pricing, setup cost, and licensing was very easy, as all information is already public. They have their pricing tiers publicly available to everyone. We also had help from our customer success manager who was with us the whole way.
What was our ROI?
While I cannot talk about money saved because I do not manage any financial decisions or have access to financial information, I can say that we have saved a lot of time. We no longer need our internal automations that were running in our internal Lambda deployments, which were quite slow and needed a lot of maintenance from our engineers. Since we got rid of that, our productivity has increased, I believe, by thirty-two percent.
Which other solutions did I evaluate?
Before choosing Aikido Security, we evaluated Aqua Security and Ox Security.
What other advice do I have?
Since switching to Aikido Security, I have noticed a positive impact on my team's productivity with measurable results, as we now have measurements. Before, we did not even know how many vulnerabilities were raised per new functionality. We lacked a lot of visibility because reporting of vulnerabilities was not automated. New vulnerabilities were being raised by our automations, but tickets were not created automatically. We have gained a lot of productivity by not having to review the vulnerability reports themselves, but only needing to review the Jira tickets, which makes it much easier for our engineers.
My advice for others looking into using Aikido Security is to invest time in reading their documentation, as Aikido Security functionality can be exploited very much. I would rate this review a ten overall.