Welcome to our blog.

Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Altar is our first open-weight AI model, and the first step toward sovereign security intelligence. It runs entirely inside a customer's own infrastructure, powering Aikido Machine's autonomous pentesting without any code ever leaving the building.

Aikido achieves AWS Security Competency for Application Security
AWS checked our homework: we're officially an AWS Security Competency Partner for Application Security.

The CVE spike across major software companies is a remediation problem
A viral chart this month showed CVEs climbing sharply across 21 major software companies, and the industry split into two camps arguing about what it means. Both are missing the number that actually determines risk: how fast the vulnerabilities that matter get fixed.
2026 State of AI in Pentesting
Our latest report captures the perspectives of 400 CISOs, CTOs, and senior engineering leaders across Europe and the US. It explores how AI is changing penetration testing, why traditional approaches are struggling to keep pace with modern software delivery, and what security leaders want from the next generation of penetration testing.

What is a CVE?
CVEs are the security world's shared language for known vulnerabilities, but in 2026, the system is under serious strain. This guide covers how CVEs work, how they're scored with CVSS, and why the databases teams rely on are no longer complete. It also covers what to do about it, including how Aikido Intel surfaces vulnerabilities that never make it into any public database.
New Aikido Security Features: August 2023
In the last few weeks, we’ve released many new features and expanded support for different tool stacks. We’ve upgraded our reachability engine to fully support PNPM, expanded AWS rules, pointed Autofix toward Python, and increased support for containers registries.
Aikido’s 2025 SaaS CTO Security Checklist
SaaS companies have a huge target painted on their backs when it comes to security. Aikido's 2024 SaaS CTO Security Checklist gives you over 40 items to enhance security 💪 Download it now and make your company and code 10x more secure. #cybersecurity #SaaSCTO #securitychecklist
Aikido’s 2024 SaaS CTO Security Checklist
SaaS companies have a huge target painted on their backs when it comes to security. Aikido's 2024 SaaS CTO Security Checklist gives you over 40 items to enhance security 💪 Download it now and make your company and code 10x more secure. #cybersecurity #SaaSCTO #securitychecklist
15 Top Cloud and Code Security Challenges Revealed by CTOs
CTOs all face challenges in securing their product. We wanted to find the trends and discover the needs and concerns of SaaS CTOs. We consulted 15 CTOs from cloud-native software companies about their cloud and code security challenges. Priorities, blockers, flaws, desired outcomes!
What is OWASP Top 10?
The OWASP Top 10 serves as a vital checklist, identifying the most critical web application security risks and guiding developers in mitigating these vulnerabilities. By adhering to the OWASP Top 10, not only do you protect sensitive data, but you also foster a culture of security awareness, ensuring your application remains resilient in the face of emerging threats.
How to build a secure admin panel for your SaaS app
Avoid common mistakes when building a SaaS admin panel. We outline some pitfalls and potential solutions specifically for SaaS builders!
How to prepare yourself for ISO 27001:2022
ISO 27001:2022 replaces ISO 27001:2013. Aikido helps you quickly comply with the new security controls so you and your customers can sleep at night. This blog post walks you through the new requirements and how Aikido supports you.
Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Aikido Altar is a compressed, open-weight AI model built for sovereign security intelligence, powering Aikido Machine's on-prem, air-gapped pentesting.
Novel supplychain.local Go worm appears
"supplychain.local": malicious code found in MemTensor's npm plugin (0.1.21, 0.1.23) and PyPI's MemoryOS (2.0.34).
5 Socket security alternatives and why they are better
Socket built its name on malware detection. But detection speed alone is no longer the whole story. Here's how Aikido and four other alternatives compare on supply chain security, reachability analysis, licensing, and more.
AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors
Learn how to evaluate AI pentesting vendors with practical buying criteria, research from 1,000+ AI pentests, and a downloadable evaluation checklist.
A practical CTO security checklist to be Mythos-ready
A practical checklist for SaaS CTOs navigating a world with Mythos and agentic AI threats. Built around the defender's advantage: you have context attackers have to work to get. Covers the controls, practices, and operational habits that determine whether your team finds and fixes issues before someone else does.
Get secure today,
quickly and for free.
Secure your code, cloud, and runtime in one central system.
Connect a repo to discover what the reasoning agents find in your codebase.