Aikido

How NEURA Robotics scaled security across 200+ repositories

Migrated from -
Semgrep,  
Open source tools,  
200+
Repositories
1
Security view
117h
Of manual triage saved
~400
Repositories planned

At a glance

  • Brought security across more than 200 repositories into one platform, with plans to expand coverage to around 400
  • Added SAST and SCA for C and C++, the languages behind NEURA’s robot control systems
  • AutoTriage’s ignore feature saved more than 117 hours in just a few months
  • Received intelligence on a malicious npm package campaign via Aikido Intel before it became widely known
  • Generates compliance reports that can be shared directly with customers

Growing fast meant rethinking how security worked

NEURA Robotics develops cognitive collaborative robots, autonomous mobile robots and humanoid robots, alongside Neuraverse, the software platform that connects them through digital twins and a growing marketplace. It is the fastest-growing start-up in Germany, with backers including Nvidia, Amazon, Qualcomm, Bosch and the European Investment Bank.  

Following its recent Series C funding round, NEURA is expanding its robotics platform, production capacity and the software behind its products. That growth added more repositories, applications and teams to an already varied engineering environment.

Previously, NEURA had tools for SAST, SCA and DAST to keep on top of security. However, the security team still had to pull findings together from separate workflows to understand the posture of a particular product.

Today, NEURA uses Aikido Security to gain visibility across SAST, DAST and SCA, across more than 200 repositories, with plans to roughly double that coverage as its engineering organization continues to grow.

The challenge

Before adopting Aikido, NEURA relied on several security tools. Semgrep handled SAST, OSV-Scanner identified vulnerable dependencies and Trivy generated SBOMs. Burp Suite and OWASP ZAP supported DAST and continue to run alongside Aikido.

Each tool covered a specific requirement. Building a reliable view of risk across a product still meant gathering results from several places and maintaining separate pipeline jobs.

“We could achieve some specific requirements, but it wasn’t manageable at scale. There was no centralized vulnerability management platform where I could look and understand the overall security posture for one product or part of the group.” 

- Sounak Ray, Lead Security Architect at NEURA Robotics.

The workload increased as NEURA extended its security programme across Neuraverse, customer-facing applications and software used by its robots. The team also needed to demonstrate compliance with the EU Cyber Resilience Act and produce reports that customers could review.

Why NEURA Robotics chose Aikido

NEURA evaluated several vendors, including Snyk and Veracode, before selecting Aikido. Its requirements reflected the mix of software, hardware and customer-facing services it develops.

  • C and C++ support

Support for C and C++ was a hard requirement because those languages power NEURA’s robot control systems. The security team needed SAST and SCA across its primary languages within the same security programme. Aikido also supports custom rules, allowing NEURA to adapt static analysis to its own code and development practices.

  • One view across products and repositories

NEURA wanted to see code findings, dependency issues and application testing in the context of the product they affected. That made it easier to understand exposure across a repository, application and wider product line.

The correlation between repository findings and dynamic testing results stood out during the evaluation.

“Correlating a repository with DAST was a cool feature that I found attractive in Aikido.”

This became particularly useful for Neuraverse, the company's software paltform for connecting, programming and operating robots. This is the first product it rolled Aikido out to.

The team then extended Aikido into software used directly by its robots, including robot control systems.

“We started using it for Neuraverse, which is our biggest product, where all the robots can be integrated together and operated via digital twins. At the same time, we recently integrated internal code related to robots, for example robot control software.”

Aikido now covers more than 200 repositories across these product areas. NEURA plans to increase that figure to around 400.

  • Automating security triage across hundreds of repositories

Reviewing findings previously required substantial manual effort. The security team now uses AutoTriage to assess issues against the context of its applications. A vulnerable dependency may be present while the relevant code path remains difficult to exploit in NEURA’s environment.

“Often the reason for ignoring a vulnerability is not that the vulnerability is invalid. The reason is that it’s hard to exploit in our context.”

This context helps engineers decide where investigation is worthwhile. NEURA tracks the relationship between automatically ignored findings and open issues as an internal health indicator, and Sounak reports that the trend continues to improve.

For the Neuraverse workspace alone, Aikido estimates that AutoTriage has saved approximately 117 hours of engineering time. Ray believes the total time-saved is actually higher. 

Aikido also connects with NEURA’s ticketing workflow, allowing findings to move through triage, assignment and remediation within an established process.

  • Bringing developers into the workflow

NEURA's security team owns the platform, so most NEURA developers do not use the Aikido platform directly. Merge request checks surface findings during code review, allowing engineers to review and address issues in their existing workflow.

“Using the merge request checks, we could engage a lot of developers without providing them access to the Aikido platform at all.”

This gave the security team a way to extend security feedback across the engineering organisation while keeping platform administration focused within a smaller group.

  • Producing compliance evidence for customers

Compliance reporting has become part of NEURA’s customer-facing security process. The security team can generate reports from Aikido and share them with external stakeholders.

“The compliance report generated by Aikido has exactly the right amount of information to be shared with external customers.”

The reports reduce the work involved in assembling evidence from several tools and give customers a clearer account of how NEURA manages software security across its products.

  • Responding faster to supply chain threats

NEURA also uses Aikido Intel to monitor malicious activity across its software dependencies.

Aikido Intel, the real-time supply chain intelligence feed, analyses new package releases as they go live, which helps surface malicious packages before they appear in public advisories.

During a malicious npm package campaign where next.js was vulnerable to RCE, NEURA received an alert through Intel,  before the incident had been widely disclosed, giving its engineers time to review and update affected packages early.

“Even before it was public, or on the very same day, I got this intelligence from Aikido to upgrade the packages. It was very helpful.” 

Ready for the next phase of growth

NEURA plans to expand Aikido from more than 200 repositories to around 400 as its engineering organisation grows. The team is also evaluating broader use of Aikido’s cloud security capabilities and expects to revisit Zen, Aikido’s in-app firewall, as adoption continues.

The security team now has one place to understand findings across a growing software estate. New repositories and products can enter an existing workflow, giving NEURA a clearer path for expanding security alongside its engineering programme.

Get secure now

Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

No credit card required | Scan results in 32secs.