Review
“Aikido makes your security one of your USPs thanks to their integrated automated reporting solution, which helps for ISO & SOC2 certification”

Fabrice G
Managing director at Kadonation
Identify risky open-source licenses in your dependencies and generate SBOMs for compliance.
Importance of License Risk
Get a complete overview of all licenses in use and the risk associated with each.
Export a CycloneDX SBOM with one click (or a CSV list, if needed).
License noise is overwhelming. Aikido filters the signal using an LLM-powered engine and multiple data sources to score severity. Risky licenses rise to the top—so you can act fast, assign tasks, and clean up your SBOM as you go.
Aikido’s vetted license database translates complex legal jargon into plain, actionable language. Quickly understand each license’s obligations and risks.
Most license tools only scan your repositories. Aikido gives you full coverage by scanning the licenses inside your container images as well.
Replace your scattered toolstack with one platform that does it all—and shows what matters.
Code & Containers
Continuously monitors your code for known vulnerabilities, CVEs and other risks.
Code
Scans your source code for security risks before an issue can be merged.
Domain
Dynamically tests your web app’s front-end to find vulnerabilities through simulated attacks.
Cloud
Detects cloud infrastructure risks across major cloud providers.
Code
Checks your code for leaked and exposed API keys, passwords, certificates, encryption keys, etc...
Code & Containers
Monitors your licenses for risks such as dual licensing, restrictive terms, bad reputation, etc..
Code
Prevents malicious packages from infiltrating your software supply chain.
Code
Scans Terraform, CloudFormation & Kubernetes infrastructure-as-code for misconfigurations.
Code & Containers
Checks if any frameworks & runtimes you are using are no longer maintained.
Containers
Scans your container OS for packages with security issues.
Yes. We run a yearly pentest on our platform and also have an ongoing bug bounty program to ensure our security is continuously tested by a wide range of experts.
You can create a CycloneDX SBOM or csv export with one click. Just go to the Licenses & SBOM report where you'll get a full overview of all the packages & licenses you're using.
Aikido does not store your code after analysis has taken place. Some of the analysis jobs such as SAST or Secrets Detection require a git clone operation. More detailed information can be found on docs.aikido.dev.
When you log in with your VCS we don’t get access to any of your repositories. You can manually give access to the repositories you’d like to scan. It’s also possible to test out the platform using sample repositories.
Of course! When you sign up with your git, don’t give access to any repo & select the demo repo instead!
We can’t & won’t, this is guaranteed by read-only access.
Review
Fabrice G
Managing director at Kadonation