At a glance
- Built scanning into GitLab from the ground up
- Moved from local scanning to a fully integrated setup after its security team cleared how Aikido handles code
- Checks every push and merge request across the code behind IQM's quantum systems
- Tracks its worldwide container fleet daily with Aikido
Securing a company built on quantum research
IQM builds full-stack quantum computers, hardware and software, from its base in Espoo, Finland. It was founded in 2018 as a spin-out of Aalto University, and in 2026 it became the first European quantum computing company to list publicly, trading on Nasdaq as IQMX. The code behind that hardware sits close to the company's most sensitive work, so the bar for security is high.
Shabeeb Khalid is a staff engineer on IQM's platform and DevSecOps team, and has been close to the company almost from the start. His view on what the technology demands is straight to the point:
Anything that touches a critical technology has to go through a proper security review.
The challenge
No security tooling to build on
When IQM began tightening its security around 2022, it had nothing dedicated in place. Checks were ad-hoc: the occasional open source scan across scattered repositories, with no shared view of what they turned up. As the company moved toward its public listing, that gap mattered more.
Data that could not simply leave
There was also a hard rule. IQM handles data it cannot hand freely to a third party, so at the start it would only consider tools that could run locally.
We were always willing to use only solutions that could run on-prem.
Scanning that starts the moment code is pushed
IQM put security at the front of its development loop. Code is checked for vulnerabilities as soon as it lands in GitLab, before it moves anywhere else, so review is part of the everyday flow.
Security is embedded in our whole development cycle now. It starts the moment code is pushed to GitLab, before it goes anywhere else.
Bringing the security team along on data
IQM started with Aikido's local scanning. Everything ran inside its own environment against its self-hosted GitLab, and only the results went to the Aikido dashboard. The security team then looked at how Aikido handles code during a scan: each one runs in a throwaway container that is destroyed automatically once it finishes. That was enough to give the fully integrated setup a shot, and IQM now connects GitLab directly to Aikido, covering both repositories and containers.
After we reviewed how Aikido handles our data, the security team was comfortable moving to the integrated cloud setup.
A shift in how people treat security
The effect reached past the security team. Since Aikido went live, people across engineering pay closer attention to security than they did before. Not everyone works from the Aikido dashboard, and they do not need to. Every merge request passes through Aikido inside GitLab, so developers get what they need at the point of the change, while the five to eight security champions who own release issues work from the results directly.
People started taking the security side more seriously once we brought in Aikido.
Keeping track of a fleet that runs worldwide
IQM runs containers in production around the world and has to watch them constantly. Using Aikido, it groups each deployment and its versions and checks them on the daily. Turning on EPSS-based AutoIgnore brought the overall issue count down and left fewer alerts to chase.
We track our deployments daily now, and that has improved our life a lot.
Why IQM chose Aikido
- Coverage of the security aspects that matter for critical technology, tested in a proof of concept against SonarQube and other tools
- Local scanning at first, so it could drive adoption without sending data out
- A data-handling model the security team could inspect and approve later down the line
Where IQM goes next
Currently using:
- Open source dependency scanning and static code analysis across GitLab repositories
- Container scanning
- Merge request gating
- Surface monitoring (HTTP domain testing)
- EPSS-based AutoIgnore
- Teams-based deployment tracking
- SBOM and SOC 2 audit reports
Evaluating:
- Device protection, being trialed with a small group first before the wider rollout
- AI pentesting to produce audit reports IQM can share with its customers
Final verdict
The best thing about Aikido is the people who listen. We ask for something on Slack, and we have seen the features we asked for ship within about two weeks.

