AI pentesting entirely under your control
Aikido Machine is a GPU server that runs continuous penetration tests on your critical applications, fully within your premises. For regulated industries.


.avif)

Attackers are weaponizing AI while security teams are stuck defending critical infrastructure with old-school technology. Aikido Machine puts autonomous penetration testing on-premises at your command, 24/7.

Your best defense, is offense.
A real attacker starts with nothing but a login page and time. Your own agents start with the source code, so they go straight for the flaws an outsider would need months to find, if they ever did. You attack yourself with every advantage a real adversary will never have, and close the gaps before someone without those advantages comes looking.
Eliminate exploitable risk at scale
Keep your code on-prem
Your source code, documentation, and runtime never leave the building. Inference runs on the box's own GPUs, so nothing reaches a cloud provider or a third-party model API. For banks, defence, and healthcare, that's the difference between running white-box pentesting and running nothing at all.
Completely air-gapped environment
The box runs inside your network with no internet connection required. Your data never reaches any third-party. Updates arrive through a single whitelisted domain, or an encrypted USB for sites that stay fully air-gapped.
Run 24/7 offensive AI
Autonomous agents test every application on every release, continuously. Inference is local, so there are no per-pentest fees, and no reason to stop between engagements.
Prove every exploit and verify every fix
Find every way in
Agents enumerate the entry points an attacker could reach: exposed endpoints, forgotten admin routes, feature-flagged code, and paths a signature-based tool walks right past.
Map your app
With access to your source code, dependencies, and runtime, agents build a working model of the app: its roles, data flows, and trust boundaries. That's the type of context a malicious actor could hardly get.
Exploit every attack path
Agents chain findings into working attacks: multi-step exploits, IDORs, broken access control, and the logic flaws that static analysis usually ignores. Done at scale, across far more paths than a human team can reach in a fixed engagement.
Prove the exploit
Every finding ships with the traces to reproduce it, so you get confirmed exploits instead of thousands of maybes. Fixes come as ready-to-merge pull requests, and one click re-tests the same scope to confirm the hole is closed.
Continuous AI pentesting that keeps your code on-prem.
Finance, healthcare, and pharma ship constantly, but compliance expects regular pentesting and your code can't leave the network. The Aikido Machine continuously pentests every deployment, validates exploitability, generates patches, and retests the fix.
- Continuous compliance
Frameworks like SOC 2 and ISO 27001 expect regular penetration testing, and the Aikido Machine tests every release so you stay covered between audits.
- Your data stays local
Source code, customer records, and findings never leave your network, which is what makes white-box testing possible for a bank or hospital.
- Nothing to ration
Inference runs on the Aikido Machine's own GPUs at no token cost.
- Findings auditors accept
Every result ships with the traces to reproduce it, so you hand over a confirmed issue instead of a maybe.
Autonomous pentesting for networks that never touch the internet.
Classified and mission systems can't send code to a cloud, and often can't let outside operators near them at all. The Aikido Machine runs entirely inside your enclave, air-gapped, with its own models on its own hardware, so nothing leaves the network.
- Fully air-gapped
The Aikido Machine runs with no outbound connection at all, and updates can also load from a separate device, so even patching stays off your network.
- Model agency
Run the open-weight model the Aikido Machine ships with or an approved alternative.
- No operator bottleneck
Testing is autonomous and runs on your hardware, so you're not waiting on external pentesters to be scheduled and cleared.
- Built for disconnected sites
Aikido’s AI pentesting stack and the models it needs run locally, reaching locations that cloud tools can't.
Test critical systems without citizen data leaving.
Government systems hold people's personal data and tend to run for decades. Rules like GDPR and FedRAMP often mean that data has to stay in the country and off the public cloud, which rules out most AI pentesting tools. The Aikido Machine runs entirely on your own infrastructure, so you get it without sending anything out.
- Data stays in jurisdiction
Code, data, and findings never leave your network, so there's no question of where they're processed or which country they land in.
- Meets your testing mandates
FedRAMP, NIST 800-53, and CMMC all require regular penetration testing. The Aikido Machine runs it continuously on your own hardware, so you stay covered without booking an outside pentest every cycle.
- Works with legacy stacks
The Aikido Machine tests modern and older systems alike, including languages like COBOL that a lot of public infrastructure still runs on.
- Predictable to budget
One annual fee covers hardware, software, support, and repairs, with no per pentest or token costs to forecast mid-year.

"By deploying AI agents that test our systems around the clock, we can identify risks faster, strengthen our resilience continuously, and further enhance the trust that millions of customers place in Belfius every day."
Fabian DelavaHead of Technology
Trusted by leading eneterprises


A GPU server that pentests everything you run. Physically installed. Locally operated.
Aikido Machine is a 4U server with enterprise GPUs, installed in your data center. It runs the full Aikido pentesting stack and the AI models behind it, locally.
Unlimited pentesting
Inference runs on Aikido Machine's own GPUs. No tokens, no per-pentest pricing. Test every application, on every release, continuously.
Models managed by Aikido
Ships with the strongest open-weight model at deploy time. We benchmark every new release and swap in better models without reinstallation.
The Aikido platform, on-prem
Code, container, and VM scanning served from Aikido Machine itself. Same platform, no cloud.
Full cloud parity
Every AI pentesting capability of Aikido's cloud platform runs identically on Aikido Machine. Nothing is a reduced on-prem version.
One annual fee
Hardware, software, support, and repairs in a single contract. The hardware stays Aikido's responsibility; if a GPU fails, we replace it.
No borrowed guardrails
The Aikido Machine runs its own open-weight models, so you depend on no one else's rules and no filter leaves attack paths untested.
Run AI offensive security, securely.
.avif)
Frequently Asked Questions
Nothing leaves: not your code, not your findings, not even telemetry. Aikido Machine pulls updates from a separate machine and everything else runs locally. If you'd rather have updates arrive automatically, you can whitelist a single update domain instead. In that mode Aikido Machine reaches out only to check for and pull updates on demand. Your code, repositories, and findings stay inside your network either way.
Everything runs in isolated containers, and every request the agents make passes through a proxy that checks it against the scope you defined. Data at rest is encrypted, and Aikido Machine sits inside your network under your own access controls, so it's governed like any other asset in your data center.
Because the model is only part of the picture. A real attacker works from the outside, guessing at how your application is built. Aikido Machine works with your source code, dependencies, and runtime in front of it, so it reasons about the app the way your own engineers do. That context finds real, exploitable flaws that a few extra points of raw model capability won't. Combined with a harness built specifically to drive offensive work, open-weight models running locally consistently match or beat what a frontier model manages blind.
Not without your say-so. The models are fixed to the version you're running, so nothing shifts underneath you mid-engagement. Our engineers test new model releases as they come out, and as soon as one outperforms the model you're on, we propose the change to you. Updates, including model changes, arrive on your schedule and only when you choose to apply them, so your results stay consistent from one pentest to the next.
Today Aikido Machine runs AI pentesting and AI Code Analysis. Capabilities that already run on-prem like static analysis, dependency, secrets, container, and virtual machine checks are planned by redirecting those existing tools. Two things won't run on Aikido Machine by nature: attack surface management and dynamic application security testing (DAST), because both work from outside your network looking in. Runtime protection ships as a software development kit (SDK) that goes into your own backend.
Yes. Because Aikido Machine works from your actual source code, dependencies, and runtime rather than guessing from the outside. The language coverage is broad thanks to the use of models that were trained on a large variety of ecosystems. Therefore, older stacks, including COBOL, are in scope.
You define the scope, and the agents stay inside it. Every request they make passes through a proxy on Aikido Machine that checks it against your scope and blocks anything outside of it. Testing runs non-destructively by default, and anything more aggressive, like pushing an exploit further to confirm it, is something you turn on deliberately. These are the same controls the cloud pentesting agents run under, so Aikido Machine doesn't add risk.
Two configurations are available, mostly depending on the size of your largest target codebase and the total number of lines of code (LOCs) that ought to be pentested in a year.
Aikido handles the on-site install with a forward deployed engineer who sets it up in your data center and works through your network restrictions with your team. We plan it with you and send prerequisites ahead of time, things like network access rules, ports, power, and cooling.
You lease Aikido Machine, which means that one annual fee covers the hardware, the software, upgrades, support, and the service level agreement (SLA). If a GPU fails, we replace it. There are no per-pentest fees and no token costs, because inference runs locally.