At a glance
- Aikido replaced three code security tools, SonarQube among them
- New projects get onboarded in five minutes instead of about two hours
- Each vulnerable dependency shows up as one issue with its full dependency chain, instead of one alert per CVE
- Aikido was the first service to flag a new GitLab CVE affecting the team, ahead of its own vulnerability management tool
A growing codebase had outgrown three separate tools
Engel & Völkers, the Hamburg real estate company, uses Aikido to secure a codebase of roughly two million lines from one place, after replacing SonarQube and two other tools.
Elizaveta Katiushina, Senior Security Analyst, owns the web security stack and is the person developers go to when they onboard to the company's code security tooling. Thorben Wagner, Team Lead Information Security and CISO, covers the organizational side. Engel & Völkers has brokered residential and commercial property since 1977, and today more than 16,700 people work under the brand across about 1,000 locations in 35 countries.
For about three years, the team ran SonarQube for SAST. Dependency checks and secrets ran through two more tools, so findings lived in three places. Every new project also meant manual work: Elizaveta created a token for the repository's team lead, then checked that the integration worked.
The licensing model added a planning problem. SonarQube priced its developer license by lines of code, and the codebase grew with the product, so the team couldn't predict what security would cost a year out. Add-ons, even open-source ones, came with extra fees once the team passed the business-tier limits.
"With that setup, we could never put a clear number on the budget," says Thorben.
One place for every finding
Aikido now handles SAST, SCA, and secrets detection for the team. For Elizaveta, the difference showed up in her own workload:
"In SonarQube, onboarding a new project took me around two hours. In Aikido it takes five minutes."
Dependency analysis is where Aikido pulls ahead for her. It shows the full dependency chain, so developers can see when a vulnerable package is actually in use. It also groups related CVEs under one issue instead of opening a ticket for each.
"I'm sure Aikido works better for dependency analysis. One dependency can have three CVEs. In SonarQube that meant three issues, it spammed our feed. In Aikido it's one issue: this dependency is vulnerable, here are the related CVEs, fix it."
During the rollout, Elizaveta relied on Aikido's support chat.
"I wrote a message and got an answer in five minutes. I didn't expect that."
Why Engel & Völkers chose Aikido
- Coverage and impact that came out ahead of SonarQube Cloud Enterprise, Snyk, and GitLab Ultimate in the team's procurement process
- A switch with less effort than migrating their self-hosted SonarQube instance to the cloud
- Pricing based on user seats, which the team can plan around as the codebase grows, at a significantly lower cost than the competition
"Aikido gave us the balance of coverage and impact we were looking for. It was the overall package, technical capabilities included, that made us switch," says Thorben.
Aikido flagged a GitLab CVE before anything else did
Shortly before this interview, a new CVE hit GitLab. Aikido was the first service to warn the team that their GitLab environment was affected.
"Aikido isn't even responsible for telling us about that. It's responsible for issues in our code. But it was the first service to report it. It was faster than our vulnerability management tool, which specializes in our environment," says Elizaveta.
How Engel & Völkers uses Aikido today
Engel & Völkers isn't in a highly regulated market, and the team invests in security to strengthen its own posture and build it into the design process, not because they need to.
"We don't have to do this, but we want to, and we're able to, thanks to Aikido."
- SAST and SCA across the codebase, plus secrets detection
- Slack and Jira integrations for alerts and tickets
- A white-box AI pentest of one product
- A set of security KPIs planned for the end of the year, with Aikido supplying the data for reports to the management board and internal teams
Final verdict
"We reviewed every tool we have in place, and Aikido is one we consider state of the art."
Thorben Wagner, Team Lead Information Security and CISO
"From a technical perspective, I only have one word: fast"
Elizaveta Katiushina, Senior Security Analyst

