Aikido

How First National Bank of America secured its first customer-facing product with Aikido

1h40m
AI Pentest runtime
1
High-severity finding
<1 day
To set up an AI Pentest

At a glance

  • Aikido SAST and SCA running across every repository through the GitHub integration
  • IntelliJ plugin gives developers feedback while they write code
  • Jira integration turns findings into fix tickets that developers pick up
  • Aikido AI Pentest on the new customer portal completed in 1 hour 40 minutes
  • One high-severity finding remediated before the portal went public
  • Pentest ran white-box because Aikido already had repository access
  • Evaluated against Veracode, Checkmarx and Snyk

Challenge

First National Bank of America is a family-owned, nationally chartered bank headquartered in East Lansing, Michigan. FNBA lends across the country to borrowers who fall outside conforming mortgage criteria, and until recently almost everything its developers built stayed inside the bank.

As the bank grew, so did what regulators expected of it, and FNBA set out to add security review to a development process that had covered code quality and Java review. Eric Tucker, Servicing Development Manager, also wanted coverage for known gaps in its older in-house applications, which run on a database-heavy Java framework dating to the early 2000s.

Then came the customer portal. Matt Keeler, Identity and Access Management Engineer, had run external and internal network pentests at FNBA for years, but the bank's application code had sat behind other controls until this project. The portal changed that, and as a federally regulated institution FNBA had to pentest the application before making it public.

Solution

The development team moved first. Eric and his colleagues ran the evaluation, and how quickly Aikido connected to what FNBA already had weighed heavily in the decision.

"The GitHub integration was really simple. It was nice and easy for us to get running on all of our repos."

Eric Tucker

Aikido now reports static code analysis and open source dependency findings across FNBA's repositories, and Eric's team works through them at least weekly. The IntelliJ plugin gives developers feedback while they write, findings appear on pull requests in GitHub, and notifications flag new critical issues as they arrive. The Jira integration turns those findings into tickets any developer can pick up.

"We assign them version updates or SQL injection changes as we're trying to lower our vulnerabilities on our in-house applications. Any of our developers with a GitHub login can go in, pick a vulnerability and fix it, create the ticket, and then we can run it through our SDLC after that. It's very easy at that point."

Eric Tucker

When the portal was ready, security took over. Matt ran an Aikido AI Pentest in March 2026. It completed in 1 hour 40 minutes and returned open issues, each with a severity rating and an estimated time to fix, which let Matt judge priority and hand remediation straight to the developers. The pentest found one high-severity finding, and FNBA fixed it before the portal went public.

Why First National Bank of America chose Aikido

FNBA evaluated four or five products, and named Veracode, Checkmarx and Snyk among them. Partway through, the team raised a detection gap it needed covered in its own codebase. Aikido built it and shipped it while FNBA was still working through the other evaluations, which settled the decision.

The pentesting decision came later and followed from the first one. Aikido was already connected to FNBA's repositories for code security, so a pentest could reason over the code better rather than attack the application from the outside.

"This white-box pentest had more impact because it had the context of all the repos and could do that correlation of how stuff would work in reality."

Matt Keeler

FNBA was also working against the clock and needed a quick and reliable pentest done as fast as possible.

"We were on a deadline and we could just fire up a pentest, which was fantastic. We were able to fire up a pentest within a day of us deciding we should use Aikido."

Matt Keeler

What drove the decision:

  • GitHub integration that covered every repository quickly
  • Detection FNBA asked for, built and shipped mid-evaluation
  • IntelliJ plugin for immediate developer feedback
  • Jira integration that fit the existing SDLC
  • Repository context that made the pentest white box by default
  • A pentest the team could start within a day of deciding to run one

Results

The portal went live with the high-severity finding closed, thanks to how quickly the pentest had finished. By Matt’s own estimate, the team would have got there eventually, but weeks or a month or two later.

On the development side, the result is a record Eric can hand to examiners.

" We are consistently eliminating found problems and consistently getting reporting of new vulnerabilities and dependency issues, and then correcting them."

Eric Tucker

Setup time counted too, as Eric evaluates Aikido's setup and integration as simple next to what the other products cost his team before they could even begin evaluating.

Final verdict

"Being able to immediately fire off a pentest, and for the price we fired it off for, gave us incredible value."

Matt Keeler

‍

Get secure now

Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

No credit card required | Scan results in 32secs.