Aikido

Aikido achieves AWS Security Competency for Application Security

Written by
Michiel Denis

We're officially an AWS Security Competency Partner for Application Security.

Which is a rather corporate way of saying: AWS took a proper look under Aikido's hood, checked whether our security actually works across applications running on AWS, spoke to customers, and gave us the thumbs up.

And unlike some badges you can slap on a website, this one required technical and commercial validation from AWS.

So, what does AWS Security Competency actually mean?

Merely being available on AWS Marketplace doesn't require validation from AWS. For customers seeking clarification beyond a vendor’s own marketing, AWS Security Competency provides rigorous independent validation that Aikido meets AWS’s bar for application security. 

AWS Security Competency Partners go through technical and commercial validation designed to assess their expertise, technology, and track record helping customers secure workloads on AWS.

Why does it matter?

Because an application running on AWS isn't just "an application" anymore.

It's your code, a mountain of open-source dependencies, containers, Terraform and CloudFormation, Lambda functions, IAM (Identity and Access Management) permissions, and increasingly, code your developers didn't personally write because an AI assistant had a productive afternoon.

Every one of those layers creates another place for something nasty to hide.

A vulnerability can start in an open-source dependency, enter through a pull request, get packaged into a container and eventually run on AWS. Traditional security tooling treats each of those as its own problem, with its own tool and its own dashboard.

Aikido connects application security, open-source dependencies, containers, infrastructure as code, cloud posture, application testing and runtime security in one platform, so instead of stitching together seven different dashboards, teams can see which vulnerabilities actually matter in production.

AWS has now independently validated that approach through its Security Competency for Application Security.

Where Aikido fits into your AWS stack

The competency builds on an existing relationship between AWS and Aikido. Aikido is an AWS Partner Network member, an AWS Qualified Software vendor, available through AWS Marketplace, and was AWS’s AI-powered IDE Kiro's first go-to-market security partner.

These are security capabilities teams can already use across their AWS environments on Aikido today:

  • Scan Amazon EC2 agentlessly for vulnerable packages, outdated runtimes and risky licenses.
  • Scan Amazon ECR container images for vulnerabilities, malware and outdated packages before they reach production.
  • Find AWS Cloud and IAM misconfigurations such as public S3 buckets, open ports and overly permissive IAM roles through read-only API access.
  • Scan Infrastructure as Code including Terraform and CloudFormation before infrastructure is deployed.
  • Search your AWS environment with AI Cloud Search, using plain language to find exposed or misconfigured resources and create real-time alerts.
  • Secure AI-assisted development in Kiro, bringing security directly into the development workflow.

And because Aikido is available through AWS Marketplace, eligible customers can purchase it using existing AWS spend commitments.

AWS secured the cloud. We'll help with the stuff you put in it.

AWS operates the infrastructure underneath your applications. You're still responsible for what you build and run on top of it. That surface is getting bigger, faster and considerably more complicated.

Our State of AI in Security & Development report found that teams splitting AppSec and Cloud Security were 50% more likely to report a security incident. Tool sprawl correlated with more incidents too.

So we'd rather connect the dots. Code → dependency → container → cloud → runtime.

And now AWS has checked that we can.

Want to see what's hiding in your AWS environment?

Connect Aikido and get your first results in about 30 seconds. No agents and no changes made to your code or infrastructure.

Get started at aikido.dev/partners/aws.

Share:

https://www.aikido.dev/blog/aws-security-competency-announcement

Subscribe for news

4.7/5
Tired of false positives?

Try Aikido like 100k others.
Start Now
Get a personalized walkthrough

Trusted by 100k+ teams

Book Now
Scan your app for IDORs and real attack paths

Trusted by 100k+ teams

Start Scanning
See how AI pentests your app

Trusted by 100k+ teams

Start Testing

Get secure now

Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

No credit card required | Scan results in 32secs.