Aikido

How Reward Gateway replaced Snyk with Aikido

Migrated from -
Snyk,  
SonarQube,  
3 → 1
Tools consolidated
4 in 1
SAST, SCA, Secret scanning and Licensing
500
People in scope across the org.
100%
Critical and high findings gated

At a glance

  • Consolidated three separate tools, Snyk for SCA, Sonar for static analysis and OWASP ZAP for build-time scanning, into one Aikido code component
  • Used reachability analysis at a PCI audit to show that audit-blocking high findings were client-side and not exploitable
  • Replaced fictional gates with real ones that block critical and high findings before a merge or a build
  • Won over the engineering teams that had owned the previous tools
  • Moved to consolidate after the Shai-Hulud supply chain attack exposed the old stack

Too many findings, not enough fixes

Reward Gateway builds employee engagement and benefits software, the recognition, rewards, wellbeing and discounts that companies use to look after their people. Founded in London in 2006 and now part of Edenred, it runs as a SaaS platform that handles a high volume of transactions and sensitive data, which puts it under PCI scope. Its platform reaches more than 10 million employees at client organisations.

Angel Indzhov is head of cybersecurity at Reward Gateway, where he leads security operations, product security and financial crime. He describes a problem most security leaders now recognise: the finding is no longer the hard part.

"We are getting better at finding things. We are not getting better at fixing them."

The volume keeps rising, especially with newer models generating more findings, and an old code base is far harder to fix than a greenfield one. What Reward Gateway needed was not more findings. It was a way to know which ones actually mattered.

The challenge

A stack that did not work together

Before Aikido, security ran across three separate tools that were never designed to operate as one.

"We were using Sonar for static code, Snyk only for SCA, and OWASP ZAP in the build pipelines. So many tools that people try to use together, but they don't really work together."

A supply chain attack exposed it

The fragmentation became a real problem when the Shai-Hulud supply chain attack hit. The existing setup could not answer the questions that mattered fast enough.

"When Shai-Hulud happened last year, we felt our tooling wasn't fit for purpose. That pushed us to look for something new and to consolidate."

Security did not own the tools

Part of why the stack was so fragmented is that engineering had bought each tool to solve a specific problem at the time. Security did not own the process, and the budget sat elsewhere, so any change meant winning engineering over first.

"All this tooling was bought by engineering, so we had to convince them. It wasn't our budget."

Why Reward Gateway chose Aikido

Consolidation, in deliberate stages

Reward Gateway did not swap everything at once. It came to Aikido first through Safe Chain, liked what it saw, then ran a full proof of concept scoped to the parts that mattered most, the code and the attack side, rather than taking on a full-breadth rollout it could not finish.

Reachability the team could trust

The feature that settled it was reachability analysis. With so many findings, and so many of them low priority, the team needed a way to separate what could actually be exploited from what could not.

"For me the answer is reachability. It shows what actually has to happen to exploit something, so you know which vulnerability is really going to be a problem. That was golden."

A team that answered fast

The people behind the product stood out as much as the product during the proof of concept.

"There is no other vendor we have worked with that communicates this much and really cares what we say. We raise an issue, we sit down, and we fix it."

Reachability at the PCI audit

The clearest proof came during a PCI audit. Reward Gateway had highs sitting in its payment repository, the kind that have to be cleared before an audit signs off, and the timing was tight.

"We had a PCI audit, and in Snyk there were highs in the payment repository that had to be fixed very quickly, right before the deadline. Aikido's reachability showed they were client-side issues that did not affect the server side at all. That cleared the risk and showed everyone this is what we need."

That audit did more than clear the findings. It was what sold Aikido to the engineering teams who had owned the old tools, because it showed them where the real risk was and, just as usefully, where it was not.

Gates that actually stop things

Reachability changed which findings the team acted on. The gates changed what happened when one slipped through.

"Before, we had fictional gates. Almost nothing was really stopped. Now everything critical and high is blocked. You cannot merge your PR and you cannot build."

The next step is to run the same gates consistently across every stage, so a check that gets skipped in one place is still caught in another.

Replacing the point tools in total

With reachability and real gates in place, the separate tools no longer had a job to do.

"We are using the code component top to bottom: static code analysis, secret scanning, and licensing. Snyk, Sonar, OWASP ZAP, we are replacing them in total."

Where Reward Gateway goes next

Reward Gateway runs Aikido's code component across static code analysis, secret scanning, software composition analysis with reachability, and license scanning, with blocking gates on critical and high findings.

From here, the team is extending those gates across more stages of the pipeline. It is evaluating AI pentesting, though it wants to prepare the right environments first so the results are meaningful. It has flagged device protection as a high priority after an incident, aimed squarely at the browser and IDE extension gap, where there is no version pinning and no consistency to rely on. Aikido's code audit is also on the list of things to try. None of these are live yet.

Final verdict

Reachability gave the team a filter, consolidation gave them one place to work from, and real gates gave them something that actually stops risky code.

"The goal is to achieve improvements gradually, and that is the part I like with the product."

Get secure now

Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

No credit card required | Scan results in 32secs.