Aikido

AI pentesting entirely under your control

Aikido Machine is a GPU server that runs continuous penetration tests on your critical applications, fully within your premises. For regulated industries.

Attackers are weaponizing AI while security teams are stuck defending critical infrastructure with old-school technology. Aikido Machine puts autonomous penetration testing on-premises at your command, 24/7.

Your best defense, is offense.

A real attacker starts with nothing but a login page and time. Your own agents start with the source code, so they go straight for the flaws an outsider would need months to find, if they ever did. You attack yourself with every advantage a real adversary will never have, and close the gaps before someone without those advantages comes looking.

Download Cloud vs on-prem benchmark

Eliminate exploitable risk at scale

Keep your code on-prem

Your source code, documentation, and runtime never leave the building. Inference runs on the box's own GPUs, so nothing reaches a cloud provider or a third-party model API. For banks, defence, and healthcare, that's the difference between running white-box pentesting and running nothing at all.

Completely air-gapped environment

The box runs inside your network with no internet connection required. Your data never reaches any third-party. Updates arrive through a single whitelisted domain, or an encrypted USB for sites that stay fully air-gapped.

Run 24/7 offensive AI

Autonomous agents test every application on every release, continuously. Inference is local, so there are no per-pentest fees, and no reason to stop between engagements.

Prove every exploit and verify every fix

Request a technical briefing

Find every way in

Agents enumerate the entry points an attacker could reach: exposed endpoints, forgotten admin routes, feature-flagged code, and paths a signature-based tool walks right past.

Map your app

With access to your source code, dependencies, and runtime, agents build a working model of the app: its roles, data flows, and trust boundaries. That's the type of context a malicious actor could hardly get.

Exploit every attack path

Agents chain findings into working attacks: multi-step exploits, IDORs, broken access control, and the logic flaws that static analysis usually ignores. Done at scale, across far more paths than a human team can reach in a fixed engagement.

Prove the exploit

Every finding ships with the traces to reproduce it, so you get confirmed exploits instead of thousands of maybes. Fixes come as ready-to-merge pull requests, and one click re-tests the same scope to confirm the hole is closed.

Continuous AI pentesting that keeps your code on-prem.

Finance, healthcare, and pharma ship constantly, but compliance expects regular pentesting and your code can't leave the network. The Aikido Machine continuously pentests every deployment, validates exploitability, generates patches, and retests the fix.

  • Continuous compliance

    Frameworks like SOC 2 and ISO 27001 expect regular penetration testing, and the Aikido Machine tests every release so you stay covered between audits.

  • Your data stays local

    Source code, customer records, and findings never leave your network, which is what makes white-box testing possible for a bank or hospital.

  • Nothing to ration

    Inference runs on the Aikido Machine's own GPUs at no token cost.

  • Findings auditors accept

    Every result ships with the traces to reproduce it, so you hand over a confirmed issue instead of a maybe.

Autonomous pentesting for networks that never touch the internet.

Classified and mission systems can't send code to a cloud, and often can't let outside operators near them at all. The Aikido Machine runs entirely inside your enclave, air-gapped, with its own models on its own hardware, so nothing leaves the network.

  • Fully air-gapped

    The Aikido Machine runs with no outbound connection at all, and updates can also load from a separate device, so even patching stays off your network.

  • Model agency

    Run the open-weight model the Aikido Machine ships with or an approved alternative. 

  • No operator bottleneck

    Testing is autonomous and runs on your hardware, so you're not waiting on external pentesters to be scheduled and cleared.

  • Built for disconnected sites

    Aikido’s AI pentesting stack and the models it needs run locally, reaching locations that cloud tools can't.

Test critical systems without citizen data leaving.

Government systems hold people's personal data and tend to run for decades. Rules like GDPR and FedRAMP often mean that data has to stay in the country and off the public cloud, which rules out most AI pentesting tools. The Aikido Machine runs entirely on your own infrastructure, so you get it without sending anything out.

  • Data stays in jurisdiction

    Code, data, and findings never leave your network, so there's no question of where they're processed or which country they land in.

  • Meets your testing mandates

    FedRAMP, NIST 800-53, and CMMC all require regular penetration testing. The Aikido Machine runs it continuously on your own hardware, so you stay covered without booking an outside pentest every cycle.

  • Works with legacy stacks

    The Aikido Machine tests modern and older systems alike, including languages like COBOL that a lot of public infrastructure still runs on.

  • Predictable to budget

    One annual fee covers hardware, software, support, and repairs, with no per pentest or token costs to forecast mid-year.

"By deploying AI agents that test our systems around the clock, we can identify risks faster, strengthen our resilience continuously, and further enhance the trust that millions of customers place in Belfius every day."

Fabian DelavaHead of Technology

€192.8B in assets
3.4Mcustomers

Trusted by leading eneterprises

A GPU server that pentests everything you run.
Physically installed. Locally operated.

Aikido Machine is a 4U server with enterprise GPUs, installed in your data center. It runs the full Aikido pentesting stack and the AI models behind it, locally.

Unlimited pentesting

Inference runs on Aikido Machine's own GPUs. No tokens, no per-pentest pricing. Test every application, on every release, continuously.

Models managed by Aikido

Ships with the strongest open-weight model at deploy time. We benchmark every new release and swap in better models without reinstallation.

The Aikido platform, on-prem

Code, container, and VM scanning served from Aikido Machine itself. Same platform, no cloud.

Full cloud parity

Every AI pentesting capability of Aikido's cloud platform runs identically on Aikido Machine. Nothing is a reduced on-prem version.

One annual fee

Hardware, software, support, and repairs in a single contract. The hardware stays Aikido's responsibility; if a GPU fails, we replace it.

No borrowed guardrails

The Aikido Machine runs its own open-weight models, so you depend on no one else's rules and no filter leaves attack paths untested.

Run AI offensive security, securely.

Frequently Asked Questions

Does any of our source code or data ever leave our network?

Nothing leaves: not your code, not your findings, not even telemetry. Aikido Machine pulls updates from a separate machine and everything else runs locally. If you'd rather have updates arrive automatically, you can whitelist a single update domain instead. In that mode Aikido Machine reaches out only to check for and pull updates on demand. Your code, repositories, and findings stay inside your network either way.

How is Aikido Machine secured?

Everything runs in isolated containers, and every request the agents make passes through a proxy that checks it against the scope you defined. Data at rest is encrypted, and Aikido Machine sits inside your network under your own access controls, so it's governed like any other asset in your data center.

You run open-weight models that trail the frontier. How does that beat a frontier-model attacker?

Because the model is only part of the picture. A real attacker works from the outside, guessing at how your application is built. Aikido Machine works with your source code, dependencies, and runtime in front of it, so it reasons about the app the way your own engineers do. That context finds real, exploitable flaws that a few extra points of raw model capability won't. Combined with a harness built specifically to drive offensive work, open-weight models running locally consistently match or beat what a frontier model manages blind.

Does the model change under us during the contract?

Not without your say-so. The models are fixed to the version you're running, so nothing shifts underneath you mid-engagement. Our engineers test new model releases as they come out, and as soon as one outperforms the model you're on, we propose the change to you. Updates, including model changes, arrive on your schedule and only when you choose to apply them, so your results stay consistent from one pentest to the next.

What can Aikido Machine do today, and what's coming?

Today Aikido Machine runs AI pentesting and AI Code Analysis. Capabilities that already run on-prem like static analysis, dependency, secrets, container, and virtual machine checks are planned by redirecting those existing tools. Two things won't run on Aikido Machine by nature: attack surface management and dynamic application security testing (DAST), because both work from outside your network looking in. Runtime protection ships as a software development kit (SDK) that goes into your own backend.

Does it support our stack, including legacy like COBOL?

Yes. Because Aikido Machine works from your actual source code, dependencies, and runtime rather than guessing from the outside. The language coverage is broad thanks to the use of models that were trained on a large variety of ecosystems. Therefore, older stacks, including COBOL, are in scope.

Will the agents break our systems or go out of scope?

You define the scope, and the agents stay inside it. Every request they make passes through a proxy on Aikido Machine that checks it against your scope and blocks anything outside of it. Testing runs non-destructively by default, and anything more aggressive, like pushing an exploit further to confirm it, is something you turn on deliberately. These are the same controls the cloud pentesting agents run under, so Aikido Machine doesn't add risk.

What’s the capacity of Aikido Machine?

Two configurations are available, mostly depending on the size of your largest target codebase and the total number of lines of code (LOCs) that ought to be pentested in a year.

What does installation and getting started look like?

Aikido handles the on-site install with a forward deployed engineer who sets it up in your data center and works through your network restrictions with your team. We plan it with you and send prerequisites ahead of time, things like network access rules, ports, power, and cooling.

How does the commercial model work?

You lease Aikido Machine, which means that one annual fee covers the hardware, the software, upgrades, support, and the service level agreement (SLA). If a GPU fails, we replace it. There are no per-pentest fees and no token costs, because inference runs locally.