At a glance
- Reduced security checks on Deel’s largest monorepositories from 14–15 hours to about 10 minutes
- Reduced 99% of critical false positives and 92% of critical issues compared to the previous vendor in the pilot phase.
- Onboarded 400 developers in one training session
- Gives developers scoped access based on existing repository permissions
- Prioritizes exploitable vulnerabilities before they reach development teams
- Increased integrated development environment adoption through managed deployment
- Extended Device Protection beyond engineering with vibe coding taking off
Turning security findings into fixes
Deel runs payroll and HR operations for more than 40,000 companies across over 150 countries. Its 1400+ devs merge more than 20,000 pull requests every month, including changes to monorepositories with over five million lines of code.
When Kadir Burak Mavzer joined Deel as Platform Security Team Lead, the company already had application security checks in place. Pull requests were checked, the codebase was reviewed nightly, and compliance requirements were covered.
The findings rarely led to action.
Developers had stopped trusting the results, some members of the security team were ignoring them, and checks on Deel’s largest repositories could take most of a working day. Deel selected Aikido Security to give teams faster feedback, clearer prioritization and a workflow developers could use directly.
“We noticed that those results were being ignored by developers, even by some of the security team. It was just there as a compliance checkbox.”
The challenge
Security had become background noise
Deel’s previous application security product covered the expected checks, but its findings were often unreliable and difficult to use.
Pull requests were reviewed automatically and the codebase was checked each night. Developers still had little confidence that the results reflected issues worth fixing.
“It was checking all the boxes, but it wasn’t actionable. The results weren’t as reliable as you would expect from an application security tool.”
That lack of confidence created more work for the security team and less urgency among developers.
Pull-request checks took up to 15 hours
The scale of the problem became clear when Kadir reviewed activity across Deel’s engineering organization.
Some of Deel’s largest monorepositories contain more than five million lines of code. The previous vendor ran a full check for each change, and a single pull-request review could take 14–15 hours.
Some checks never ran. Others were cancelled before completion.
“The checks were all over the place. Some of them were not run at all, and some were running for 15 hours and then cancelling. It was a disaster.”
Developer adoption remained low
The previous vendor also offered an integrated development environment extension, but only around 2–3% of developers used it.
Most security feedback therefore arrived later in the development process, after code had already reached version control.
Why Deel selected Aikido
Deel evaluated several vendors before choosing Aikido. Three factors stood out: clearer prioritization, AI-assisted analysis built into the workflow, and direct access to a fast-moving product team.
Clear prioritization of exploitable findings
Aikido evaluates vulnerabilities in the context of the application and shows which findings are genuinely exploitable.
Kadir describes this as a funnel. A large set of vulnerabilities is narrowed to the smaller group developers need to address.
As an illustration, he describes a situation where 1,000 critical vulnerabilities may contain roughly 250 exploitable issues.
“There are vulnerabilities, and then there are exploitable vulnerabilities. Aikido shows that very clearly. We know what to go to developers with, and we can tell them that this is after verification, so they need to fix it.”
This gave the security team greater confidence in the issues it escalated and helped developers focus on findings with clear impact.
This was clear during the pilot period where Aikido resolved 92% of critical issues and reduced critical false positives by 99% compared to the previous vendor.
AI built into the workflow
Deel’s developers were already using AI tools to build software. Kadir wanted the security team to benefit from the same increase in speed.
Aikido’s AI-assisted analysis helps verify findings and reduce the manual work required before an issue reaches a developer.
“I like that the AI is built in. It isn’t an extra or an add-on. Developers are already using AI to build, and security teams need to use AI to keep up with the pace.”
Direct access to the product team
The pace of Aikido’s product development also stood out during the evaluation.
Kadir recalls requesting a capability and seeing it ready the following day. Deel also communicates directly with Aikido’s leadership when questions or product ideas arise.
“We have a communication channel where even the CEO and CTO of Aikido are answering questions within around three minutes. It’s amazing to see that level of support and that level of obsession with the customer.”
Giving developers direct access
Deel made Aikido available to developers by default.
Anyone with access to Deel’s version control systems can log in and view findings relevant to their repositories. Existing permissions determine what each person can see.
“They can go to the application, log in and see the results themselves. It’s already scoped to their user, so they see only what they need to see.”
Deel supported the rollout with a training session delivered alongside the Aikido team. Between 300 and 400 developers attended.
Cutting pull-request checks from 15 hours to 10 minutes
Deel integrated Aikido across all its version control systems and now checks every pull request.
On large changes, the process takes about 10 minutes. The previous vendor could take 14–15 hours on the same large monorepositories.
Developers receive findings while the code and context are still fresh. They can also dismiss an issue or provide feedback directly from the pull request.
“The most it takes is about 10 minutes on large pull requests, and it’s been a game changer. Developers can ship faster, and you get to know the issues much faster and in a better manner.”
“Developers have the ability to ignore or provide feedback about findings directly in the pull request. It’s great for developer productivity and for the security teams.”
Catching issues earlier in development
Deel deployed Aikido’s integrated development environment extension through its device management system.
The previous extension had reached only 2–3% of developers. Managed deployment drove a clear increase in adoption and made the extension part of Deel’s standard development environment.
Developers can review and fix vulnerabilities while writing code, before the change reaches a repository or pull request.
“You can fix vulnerabilities before they reach production, before they even reach the version control system. We’ve seen a spike in adoption.”
Protecting an AI-assisted workforce
Deel was also among the early adopters of Aikido Device Protection.
The company had seen supply chain attacks affect developers across all levels of experience. A compromised package can expose a device regardless of how careful or senior its user may be.
“It doesn’t really matter if you are very careful. If the package is infected with malware, you’re affected by it. We need to protect developer machines. I think it starts there.”
Deel is extending this protection beyond engineering.
AI coding assistants are making it easier for people in other roles to build scripts, internal tools and applications. These users may have less experience assessing dependencies or recognizing the security implications of generated code.
“With the rise of AI coding assistants, everybody is a developer now. Non-developers have an idea and do whatever it takes to build it. I think they are even more vulnerable than developers themselves.”
Device Protection gives Deel a way to protect this wider group from malicious open-source packages.
A clearer view of code security
Aikido has helped Deel identify more impactful issues and build a clearer understanding of security across its codebase.
Developers receive findings they can act on, while the security team has greater confidence in the issues it asks them to resolve.
“Until we found Aikido, it became a lot clearer what we were missing. We started finding more issues, more impactful issues, and we understood our estate in terms of code security.”
Kadir also saw a change in how developers responded.
“Now it’s much more actionable. Developers are happier, and they are more collaborative. They understand the issues in a way that helps them resolve them.”
Where Deel goes next
Deel currently uses Aikido for static application security testing, software composition analysis, pull-request checks, integrated development environment security and Device Protection.
The team is also evaluating autonomous code analysis that could continuously review Deel’s codebase against newly emerging vulnerabilities.
“We want to continuously review our codebase against vulnerabilities that appear over time. The fact that it’s autonomous and agentic is a huge plus, because we don’t necessarily have the time or capacity to do that continuously.”
Final verdict
Kadir describes a relationship with Aikido that remained direct and responsive after the sales process.
Deel can speak with senior Aikido leaders, discuss product decisions with the people building the platform and help shape capabilities relevant to its own security program.
“I’ve never seen a company that operates like Aikido. You get to speak to high-level executives on Slack, and they answer your questions very thoughtfully. We have very good discussions around product features, and you get to shape the product as well.”
Some members of the team initially wondered whether that level of attention would disappear after Deel became a customer. Kadir says the relationship became stronger.
“Some people were worried that it was a sales tactic and they would ignore you after you signed the contract. It never happened. If anything, the response time improved.”
“It’s a great addition to our arsenal of tools. Developers are happier, and they are more collaborative.”

