At a glance
- Brought security across a large, diverse estate of technologies and teams into one view
- Rolling out Aikido in phases, starting with the code product
- Matched Aikido to KEYES's own sovereignty priorities, with data residing in the EU under Belgian law
- Cut the manual work of checking findings by hand, freeing time for other priorities
- Saw a requested feature ship as a PR, fix and deployment within a few days
- Watched developers ask for Aikido to be built deeper into their workflow
Centralizing security across a large estate
KEYES, formerly the NRB Group, is one of Belgium's largest ICT groups. Headquartered in Herstal and founded in 1987, it employs around 3,700 people, runs its own data centers in Belgium, and delivers sovereign services across a wide range of teams and technologies. That scale is the backdrop for its security work: a mature security organization managing a wide range of environments.
Fabrice Servais, a security engineer at KEYES, sits in the security and operations team that runs SOC, vulnerability management and incident response. His group is working to bring application security further into the development lifecycle, and the first problem to solve was visibility across a broad set of technologies and teams.
"We support a lot of different technologies and different tech stacks within a lot of different teams. Aikido helps us bridge the gaps, centralize our security findings, and increase our overall security posture."
The challenge
Complexity across many technologies
KEYES supports many different tech stacks across many teams, and runs its own data centers with payloads on site. For a security and operations team already running a mature security operation, the hard part was never structure. It was pulling findings from every one of those environments into one place, instead of tracking them stack by stack and team by team.
One view across every environment
Findings lived across many environments by design, each team close to its own. KEYES wanted them in one place too, so the security team could see across every environment at once, not just team by team.
Why KEYES chose Aikido
Less noise, faster triage
When the team compared alternatives, the cost of working across many tools was the operational load of checking findings layer by layer by hand. Aikido grouped findings by what mattered most and triaged them inside the platform, which cut the time the team spent analyzing and freed it for other work.
Sovereignty, a KEYES priority
Sovereignty is a strategic priority for KEYES. As a Belgian player with its own data centers and sovereign service offerings, it fields the same questions from its own clients more and more often: what happens to my data, what happens to my findings, where does my application live. Aikido aligning with that position, a Belgian company with data residing in the EU under Belgian law, was an added benefit on top of the platform's fit. Fabrice noted room to go further still, toward data residing on premises, which the team plans to keep exploring.
"One of the comments we hear more and more is: what happens to my data, where is my application located. Aikido being a Belgian company, with data residing in the EU and operated under Belgian law, fit that priority."
Starting with code, built to expand
Rather than a single big-bang rollout, KEYES is bringing Aikido in one module at a time, a deliberate choice given the size of the estate. The team started with the code product, prioritizing getting it into developers' hands before widening the footprint. The plan is already visible: cloud and attack scanning are next as the rollout continues, and the infrastructure teams are expected to lean on the posture Aikido builds along the way.
"We're starting our journey to integrate Aikido into our development lifecycle with the code product, but we directly see the need for cloud and attack scanning as well."
Developers who asked for more
Developer reception was strong from the first rollout. Rather than pushing the tool onto teams, the security function watched developers understand the benefits themselves and ask for Aikido to be built further into how they work.
"When we rolled out Aikido, it had one of the best receptions we've had. Developers understood the benefits themselves and asked us to build it further into their workflow."
A fix that shipped in days
The partnership showed itself during integration. KEYES needed a feature it was missing to deploy Aikido's broker using GitOps, so the team could run Aikido against its private repositories. After Fabrice raised it, a pull request, fix and deployment followed within a couple of days. That short feedback loop shaped how the team saw Aikido as much as any single feature did.
"We were missing a feature to deploy the broker with GitOps. I reached out, and within a couple of days there was a PR, a fix, and a deployment. The feedback loop is very short. It shows Aikido listens and takes immediate action."
Where KEYES goes next
KEYES currently uses Aikido for code scanning. Cloud and attack scanning are the next modules planned as the rollout continues. AI pentesting is under consideration as an additional tool alongside the pentesting services KEYES already delivers to its own customers, folded into the development lifecycle in a more automated way rather than run separately.
Final verdict
Fabrice's read on the relationship is that it held up well past the sales process.
"The discussion doesn't stop when the contract is signed. We were supported before engaging with Aikido, and the support is still there as we plan and integrate."

