At a glance
- Aikido Device Protection for ~1,000 seats, split between engineering and non-technical teams
- A step up from Aikido Safe Chain, which Deriv already ran in GitHub pipelines
- A full software bill of materials (SBOM) for every protected device, searchable through Aikido's API
- Critical CVE fixes that skip the 48-hour minimum package age
- Device Protection alerts wired into Deriv's own investigation workflow
- Coverage extending to more operating systems as support rolls out
AI coding assistants can pull any package from a public registry
Deriv offers round-the-clock trading in forex, derived indices, stocks, stock indices, commodities, cryptocurrencies, and ETFs, with a mission to make trading available to anyone, anywhere.
Because Deriv is a financial platform, David Usher (VP of Security Engineering) and his team treats security as the top priority, and much of that work centers on the software supply chain. The team uses AI on both sides of that job, for attack testing and for defense.
Deriv has more than 300 developers, and any of them could always pull a package from a public registry. Even more so, their AI coding assistants such as Cursor and Claude Code, now also do that all the time.
"We need to make sure those packages are not malware. So having a protection mechanism is very important."
Deriv already had a first layer in place. Before buying a commercial product, the team ran Aikido Safe Chain, the open-source wrapper that checks packages for malware before a package manager installs them, in its GitHub pipelines and on its devices. David says it did a great job, but visibility remained a gap: the team couldn't see everything already installed on each machine.
Prevention on each device
For David, Device Protection took Safe Chain's approach a step further by preventing malware on the device itself. Deriv now runs it on about 1,000 devices across several operating systems. That gives the security team an overview of every enrolled device and the versions each one runs. Each device also reports its software bill of materials (SBOM), an inventory of the packages installed across the ecosystems.
"We can see the full SBOM for every device, and that gives us additional insight into what packages are on the devices."
The team tests the setup regularly with the test packages Aikido provides for supported ecosystems. David also built an alert automation on top: if Device Protection stops malware from entering the organization, Deriv's security operations team immediately investigates what led to the install attempt.
Why an agent on the device won the evaluation
Deriv looked at other tools before choosing Aikido, but Aikido runs an agent on each device, and David saw that design as harder to bypass than the centralized approaches Deriv looked at. It also gives the security team the context it needs when something happens.
"If an alert goes off, it's very important to understand who did what, where, and when. Then we can immediately investigate and make sure we're containing anything else that could be happening on that device."
Retrospective checks, and critical patches that don't wait
David used the device inventory to look for old packages still sitting on machines from before the rollout, which he found reassuring. It also powers retrospective checks. Aikido Intel catches new malware quickly, and when a package is identified as malware after its release, Deriv's automation checks whether that version sits on anyone's machine.
Device Protection also keeps urgent patching fast. Its minimum package age holds newly published versions for 48 hours by default, which blocks attacks that rely on freshly published malware. When a new version fixes a critical CVE, Device Protection now lets it through straight away, with controls in place. It does this automatically and only for that version, so Deriv's team has nothing to configure.
"You don't have to wait two days before you can patch a critical CVE. That's the point."
That exception had come up in Deriv's own conversations with Aikido. David raises requests in a shared support channel with Aikido's team, and he counts at least two new ecosystems added since Deriv started, including Homebrew and Linux support.
"A lot of other companies can be very lethargic in their response. They'll put it on the roadmap and check back in six months, and by that time it's too late and we've moved on."
Coverage beyond engineering
Deriv splits its Device Protection seats between engineering and non-technical teams.
"Non-tech teams are becoming more technical and everyone's using AI to do their jobs, so having Aikido across the company is really important."
Anyone could try to install something that isn't approved. Deriv has other controls for that, and the same device inventory also helps with compliance. To bring more of its machines into that inventory, Deriv is extending Device Protection to more of its operating systems now that Aikido supports them.
Working on the supply chain problem together
David is clear that no solution is perfect. What he values is a vendor that moves at Deriv's pace. Deriv uses AI to ship quickly, and he sees the same speed in how Aikido responds:
"It feels like we're working together to improve the product and also to improve the supply chain security problem."

