At a glance
- Connected Aikido directly to source in GitHub, GitLab and Azure DevOps, with scanning starting immediately and no pipeline to orchestrate
- Gave security coverage across every team in the organization, including teams that arrive through acquisitions
- Cut a zero-day exposure check across the whole estate to seconds
- Let developers onboard themselves with their existing source-control account and handle their own issues
- Traced findings, including issues inside containers, back to the exact file in the repository
- Moved off Black Duck without a heavy migration
- Built an AI agent on the Aikido API that searches the estate and returns a ready-made report
Keeping security in step with AI development
NiCE builds customer-experience and financial-crime software for more than 25,000 organizations across over 150 countries. Founded in 1986 and public on NASDAQ, it runs an engineering organization of several thousand developers spread across many products, and that estate keeps growing through acquisitions.
Matan Keret has spent about 16 years at NiCE, moving from software developer to principal architect. He leads security for the engineering organization, and he frames the job in the AI era in a single line.
"In the era of AI, we need to enable our teams to work as if they have no security concerns, while we keep everything under control and secured."
Meeting that test at NiCE's size is the hard part. Scaling any practice across several thousand developers is difficult, and security most of all.
The challenge
Getting results meant orchestrating everything
NiCE's previous tool was Black Duck. Getting results out of it meant orchestrating scans and running everything through pipelines before anything showed up. For an organization of NiCE's size, re-orchestrating all of that to move tools was close to unworkable, which is the reason many enterprises stay on a tool that no longer fits.
The gap showed most during a zero-day
The cost was clearest when a new vulnerability was disclosed. The team could not quickly confirm which groups were even covered, because onboarding each group into the old tool took time and manual effort. Every acquisition made the picture harder to hold.
Why NiCE chose Aikido
A proactive switch, not a rescue
This was not a rescue. NiCE was not unhappy with Black Duck. The agreement was ending, the team was moving into AI development, and after three years on the same tool they decided to see what else was available.
"The agreement was ending, and we thought there were probably newer, better things out there now. So we looked around."
Findings the team could trust
In the proof of concept, the team compared findings on real repositories, one cloud-based and one more on-premise, and rated Aikido's accuracy higher than the tool they were using. Malware sits in its own view rather than mixed in with everything else, and end-of-life components are flagged clearly, both of which the previous tool did not do well.
A product team that moved fast
The team behind the product stood out as much as the product.
"The team itself surprised me. We opened a channel, and when we found issues they were acknowledged and fixed very quickly. That is on a different level."
Connecting straight to the repositories
Aikido connects directly to the source repositories in GitHub, GitLab and Azure DevOps, and scanning starts immediately. That change is what made the tool workable at NiCE's scale, because it removed the orchestration work that had made switching feel impossible.
Because dependencies are read from the actual project files, the team can trace any finding to the exact place it comes from. Matan describes answering a developer who doubted a result.
"Someone says they do not think we use a library. I open the repository, click reachability, and it shows the exact file on GitHub. I can tell them, no, it is here, in your repository. It is not coming from anywhere else."
Containers get the same treatment. NiCE runs most of its containers on ECR in AWS, and linking them to the source repositories makes it easy to see where an issue in a container actually lives. With the previous tool, base images and the teams' own images were scanned together and mixed, so teams could not tell what was theirs to fix. Connecting to the repositories separated the two.
Developers who onboard themselves
Onboarding follows the same pattern. Developers sign in with their existing source-control account, see their repositories, and handle their own issues without waiting on permissions from anyone else. At NiCE's headcount, removing that dependency mattered.
Cleaner findings the team can act on
The accuracy from the proof of concept carried into daily use. Because a finding is tied to the actual file and version, it needs less second-guessing, and low-value, low-risk findings are auto-ignored, which keeps the team focused on what matters.
Answering a zero-day in seconds
The clearest change shows up when a new vulnerability lands. The team built an AI agent on top of Aikido that searches across the estate, reaches into the connected source control, and returns a ready-made report.
"When a zero-day comes in, we can search every workspace in seconds and know exactly where we are exposed, if we are exposed at all. We did not have that visibility before."
That confidence extends to acquisitions. Where the old tool left the team unable to confirm whether a new group was covered, coverage is now in place without manual follow-up.
Where NiCE goes next
NiCE relies on Aikido for software composition analysis, container scanning, license scanning, malware and end-of-life detection, reachability analysis, AutoTriage, and access through the API and MCP server, and each product holds its own in its category.
The clearest direction from here is AI-assisted work. The team wants every developer to reach Aikido through the MCP server from their coding agent, so code is checked as it is created, and it is building a Power BI dashboard on the Aikido API to report across the organization. Cloud monitoring, EPSS scoring and SLA tracking, Safe Chain and device protection are under evaluation.
Final verdict
Matan's advice to other large enterprises is direct.
"If you are on traditional tooling and you get the chance to look around, do a proper comparison. You may be surprised by what you find."
Asked to sum up the impact on NiCE, he kept it to what the tool set out to do.
"It helped us make our AI development workflows much more secure, and raised our security posture across our products."

