Today we’re launching the Aikido Machine, and welcoming the team that helped build it. Aikido Machine is an on-prem server that runs Aikido Security's AI pentesting and AI Code Analysis (+ many more to come) entirely inside your network: local GPUs, local models, local results. No source code, no repositories, and no prompts ever leave your infrastructure.
Some teams can't send their code outside their network
For a bank, a government agency, a defense contractor, or a hospital, two things are true at the same time.
The first: the pressure keeps climbing. Attackers move faster than ever, and AI has lowered the cost of finding and weaponizing a vulnerability. This isn't hypothetical to regulators. The ECB recently gave 110 banks a four-month deadline to produce action plans against AI-driven cyber threats, while the European Systemic Risk Board raised its systemic cyber risk assessment to "severe" and called the latest models "a paradigm shift for cyber security." Meanwhile the old defenses are showing their age. Signature-based DAST was built for a world where attackers ran scripts. Now they run models that understand an application better than a scanner does.
The second: continuous, AI-driven pentesting exists, but until now it only ran in the cloud, and these teams couldn’t use it. Either internal policy or regulation often says that source code, repository data, and prompts can't go to an external cloud or a third-party. So these teams have been left choosing between infrequent manual pentests and nothing at all.
The only way to give these teams continuous AI pentesting is to put the whole server, models included, physically inside their network. That's the Aikido Machine.

Aikido Security acquires Milou
Aikido has been working on building a reliable, state of the art AI pentesting product for a while.
To do it locally and deliver a level of excellence that is ahead of the curve and can satisfy our buyers’ needs, our own demands became clear. We needed to work with people who live and breathe offensive security and have a proven track record at delivering.
We’re proud to announce that Aikido has acquired Milou to further that mission. Behind the Belgium-based company stand two experienced pentesters and bounty hunters, Tiburce Gridello and Selim Decamps. The goal behind Milou was simple: Make pentesters’ lives easier by automating reporting to allow testers to focus on the core job, hacking. We acquired Milou to bring that expertise, and a lot more ambition, to our on-prem work. Since joining, the team has focused on R&D, and testing models on the fastest hardware available to find the best setup for pentesting that runs fully on-device.
"Milou was focused on running offensive tooling on local hardware, to be usable in highly regulated environments. Aikido developed the AI pentesting technology to run on it. Aikido Machine puts those two things together for an entire security team to use".
Selim Decamps, co-founder of Milou.
What on-prem AI pentesting unlocks
Aikido Machine is a GPU server that Aikido Security installs, runs, and maintains. Here are the benefits for you:
- Everything stays on-prem: Inference runs on the Machine's own GPUs. Nothing you feed it ever touches a cloud provider or an external model. Air-gapped by design, with no internet connection required.
- Always on: Run continuous pentests. Local inference means no token or per-pentest fees, so there's no reason for ration testing between engagements.
- Complete visibility: With full access to your source code, documentation, and runtime, the Aikido Machine works from context inaccessible to a black-box attacker, and can match or beat a frontier model testing your app from the outside.
- A real harness: Single or multi-factor authentication,, session handling, a proxy layer, and scope enforcement. That scaffolding is what lets the Aikido Machine test behind real login flows and stay inside the targets you define.
- Proof: Every finding comes with a working exploit, so your team can focus on confirmed issues. The Aikido Machine also delivers ready-to-merge pull requests and retesting on the same scope.
- Running on day one: An Aikido Security engineer comes on-site, connects power and network, and gets your first pentest going before they leave.
AI pentesting and AI Code Analysis are live on the Aikido Machine today, with a lot more of the Aikido Security stack still to come.

A €192.8 billion European bank has already deployed it
Belfius, the bank-insurer owned by the Belgian federal government, with €192.8 billion in assets, is among the first to run the Aikido Machine inside its own data centre. More than 300 AI agents now test the bank's systems around the clock, from inside Belfius's own infrastructure. Belfius brings the operational complexity and expertise of a major financial institution to Aikido's technology stack.
"Cybersecurity is no longer a periodic exercise. It has become a continuous mission. By deploying AI agents that test our systems around the clock, we can identify risks faster, strengthen our resilience continuously, and further enhance the trust that millions of customers place in Belfius every day. AI is becoming one of our strongest allies in protecting what matters most."
Fabian Delava, Belfius
Why on-prem pentesting matters now
Until today, the best AI-driven security testing was only available to teams that could send everything to the cloud. The organizations with the strictest rules, and often the most at stake, were the ones locked out, unless they built their own solution in-house. Aikido Machine closes that gap.
A warm welcome to Tiburce and Selim. Bringing AI pentesting on-prem was already underway, and their work is what let us do it properly.
If you run security for a heavily regulated industry, and "it can't leave our network" has ended every pentesting conversation you've had, we'd like to show you the Aikido Machine.

