Aikido Security has achieved FedRAMP Moderate authorization, enabling federal agencies in the US to benefit from AI-native remediation speed.
We got there fast, with an internal team with over 15 years of experience in US federal security and Aikido's own platform doing the brunt of the work inside the authorization itself, from remediation to evidence generation.
That speed is exactly what federal agencies now need most.
Federal remediation timelines are collapsing
Remediation timelines that once ran 15 to 30 days flat, or longer under earlier directives, have been replaced entirely. CISA’s Binding Operational Directive 26-04, issued in June 2026, ties remediation speed to actual risk. For the most dangerous vulnerabilities, federal agencies must complete mandatory forensic triage in as little as 3 days. Full compliance is required by federal agencies by December 7, 2026.
Once a working exploit exists, the remediation clock compresses, regardless of the severity label. That means every agency running FedRAMP workloads is on the CVE remediation treadmill, and it’s accelerating faster than most tooling can keep up with.
For federal buyers
For federal buyers, this closes a real gap
Aikido for Government, Aikido’s separate US government edition, gets agencies off this CVE treadmill because while AI has commoditized CVE detection and exploitation capabilities, our AI-native platform is built to actually fix CVEs and cloud misconfigrations. Aikido flags a new CVE, triages it via AutoTriage, analyzes real-world exploitability, and produces a validated fix via AutoFix (backported where needed) end-to-end.
That differentiates Aikido for Government from most of the FedRAMP marketplace, including established incumbents who handle triage, exploitability and remediation as separate manual steps. Aikido for Government is the only security platform that provides the efficient workflow loop that federal agencies require.
It’s common for federal agencies to wait two to five years to gain access to use the latest technology. We’re bringing new capabilities weeks after we’ve launched them in the commercial realm directly to government users.
Our shipping speed, mixed with deep public sector domain expertise and engineering excellence, is what let Aikido achieve its own FedRAMP authorization faster than the industry norm.
We used our platform to get FedRAMP authorized, and we can help others do the same
Aikido has gone from zero federal footprint to achieving FedRAMP Moderate, GovRAMP, and Texas DIR’s TX-RAMP, and onto contract vehicles like SEWP and CDM, in a matter of months, reaching a list normally reserved for a handful of long-established incumbents,
We succeeded by running our own platform on ourselves. This is how:
- Knox, our FedRAMP-as-a-Service partner, surfaced daily vulnerability scans, AutoTriage prioritized them, and we directed our attention accordingly
- AutoFix drew on Aikido Libraries, secured drop-in replacements for vulnerable packages, and used Aikido-built images, including FIPS-compliant images, to produce a fix, backported into the version already running wherever that was possible, within 15 to 30 minutes of a CVE being flagged. FIPS-compliant container images in particular are one of the most time-consuming requirements for FedRAMP authorization.
- AutoShip pushed the fix through for review
- One of Aikido’s team approved each merge.
Aikido’s team includes Ian Riopel and John Amaral, who have 15+ years working together in federal security, including counterintelligence experience. They have deep FedRAMP knowledge and therefore understood how best to utilize Aikido's platform.
This same combination will support other companies pursuing FedRAMP authorization.
Aikido’s AI-native foundation runs deeper than remediation
The same pressures compressing remediation SLAs also appear upstream. NIST’s own CVE pipeline has fallen behind the volume of new submissions. Aikido Intel steps up to fill the void left by NIST. It watches how open-source projects actually change, catching undisclosed security fixes shipped by maintainers. Our AI agents read new commits and releases as they land and flag what looks like a real fix, then Aikido’s world-class security research team validates them by hand before an advisory ships with a severity score attached. Intel's output has scaled with that demand, from finding roughly 60 vulnerabilities per month last year, to 900 a month today.
Being AI-native isn’t unique on its own. What’s harder to deliver is providing these new capabilities in a format that works for the most sensitive workloads: on-prem. Aikido Machine already runs live AI pentesting and code analysis entirely inside a customer’s own infrastructure today, air-gapped by design, with more of the platform’s full capabilities following over time.
And because Aikido continuously benchmarks frontier and open-weight models against a set of 32 known vulnerabilities across 30 repositories, we understand which models perform best for specific tasks and how to optimize for speed, size, and accuracy.
That knowledge empowered us to build Altar, our first open-weight security model. It is purpose-built to run entirely on Aikido Machine’s hardware, so its reasoning and target codebase never has to leave the environment it's protecting. We call this sovereign security intelligence.
What next?
Aikido brings its AI-native security platform to federal agencies through its FedRAMP Moderate authorized SaaS offering, helping teams triage and remediate vulnerabilities at the speed today’s requirements and risk profiles demand. For workloads that must remain entirely within customer infrastructure, Aikido Machine offers a separate, on-premises solution.
Check out our docs here and our Customer Responsibility Matrix here.
Check out our FedRAMP marketplace listing through our FedRAMP-as-a-service partner Knox here.
Talk with our federal team to see Aikido’s remediation workflow in action and explore which deployment model fits your agency.

