
Aikido
Founded Year
2022Stage
Series A | AliveTotal Raised
$24.51MLast Raised
$17M | 1 yr agoMosaic Score The Mosaic Score is an algorithm that measures the overall financial health and market potential of private companies.
+50 points in the past 30 days
About Aikido
Aikido operates as a security platform that focuses on code and cloud security, offering tools for vulnerability detection and compliance automation. The company provides services such as static and dynamic application security testing, infrastructure as code scanning, and automated fixes for identified security issues. Aikido's solutions integrate into the development process, providing feedback and protection for applications and their underlying cloud infrastructure. It was founded in 2022 and is based in Ghent, Belgium.
Loading...
Aikido's Product Videos



ESPs containing Aikido
The ESP matrix leverages data and analyst insight to identify and rank leading companies in a given technology landscape.
The secrets management & detection market focuses on tools and solutions designed to manage and detect sensitive information, often referred to as secrets, within an organization's IT infrastructure. Secrets can include sensitive data such as passwords, API keys, cryptographic keys, and other confidential information that, if exposed, could lead to security vulnerabilities and unauthorized access.…
Aikido named as Challenger among 15 other companies, including HashiCorp, Google Cloud, and Microsoft.
Aikido's Products & Differentiators
Aikido Security
Secure your code, cloud, and runtime in one central system. Find and fix vulnerabilities fast and automatically.
Loading...
Expert Collections containing Aikido
Expert Collections are analyst-curated lists that highlight the companies you need to know in the most important technology spaces.
Aikido is included in 1 Expert Collection, including Cybersecurity.
Cybersecurity
11,029 items
These companies protect organizations from digital threats.
Latest Aikido News
Sep 9, 2025
'Stay vigilant.' Other maintainers have been targeted, too. NPM team quickly removed backdoored versions. 18 packages hit, with 2B+ downloads every week. A new digital supply chain attack has targeted popular open-source npm packages with at least two billion downloads per week. 'I've been pwned' On Sept. 8, Josh Junon, a package maintainer whose account was at the center of the attack, revealed that a sophisticated phishing attack was to blame, impacting npm packages linked to his account. Also known as qix , Junon said, "I've been pwned. 2FA reset email, looked very legitimate." In a Bluesky thread , the developer added that the phishing email originated from a domain impersonating the legitimate npmjs[. ]com domain, and the only indicator of fraud was the use of ".help" in the "support[at]npmjs[dot]help" phishing email. The email in question claimed to be a security notice, warning users that unless they updated their two-factor authentication (2FA) credentials, their accounts would be temporarily locked starting Sept.10. On Hacker News , Junon said he logged into the fake website with a TOTP code while on mobile. "The email was a '2FA update' email telling me it's been 12 months since I updated 2FA. That should have been a red flag, but I've seen similarly dumb things coming from well-intentioned sites before," Junon commented. "Since npm has historically been in contact about new security enhancements, this didn't smell particularly unbelievable to my nose. The email went to the npm-specific inbox, which is another way I can verify them." Josh Junon via Imgur Malicious updates added to npm packages Aikido Security researchers published a blog post outlining the incident, in which malicious updates were added to npm packages and pushed Monday at around 13:16 UTC. In total, it is believed that 18 npm packages were compromised in the attack, including chalk, debug, ansi-styles, color-string, and simple-swizzle. These packages alone accounted for approximately 1.1 billion downloads last week. Node Package Manager (npm) is a package manager for JavaScript's Node.js, allowing code to be freely downloaded, installed, and shared by the open source developer community. "The packages were updated to contain a piece of code that would be executed on the client of a website, which silently intercepts crypto and web3 activity in the browser, manipulates wallet interactions, and rewrites payment destinations so that funds and approvals are redirected to attacker-controlled accounts without any obvious signs to the user," the researchers said. According to the team, the index.js file in these packages was modified with malicious code, obfuscated to hide a browser-based interceptor. Furthermore, a WHOIS lookup of the phishing domain, npmjs[. ]help, shows it was registered only last week. When Aikido reached out to Junon to make him aware of the security incident, he began cleaning up the packages before access to his account was revoked, although it has since been restored. The npm team said in an update that all impacted packages have now been revoked. Other maintainers have been affected In a footnote to its blog post, Aikido Security said another maintainer was targeted, which could indicate that we are yet to see the end of this digital supply chain attack campaign -- a prospect shared by Junon, who has said that other maintainers have also been impacted, but no further information has been disclosed at this time.
Aikido Frequently Asked Questions (FAQ)
When was Aikido founded?
Aikido was founded in 2022.
Where is Aikido's headquarters?
Aikido's headquarters is located at Keizer Karelstraat 15, Ghent.
What is Aikido's latest funding round?
Aikido's latest funding round is Series A.
How much did Aikido raise?
Aikido raised a total of $24.51M.
Who are the investors of Aikido?
Investors of Aikido include Connect Ventures, Notion Capital, Singular, Syndicate One, Christina Cacioppo and 8 more.
Who are Aikido's competitors?
Competitors of Aikido include Kondukto, Bastazo, Chainguard, Adlumin, Oxeye and 7 more.
What products does Aikido offer?
Aikido's products include Aikido Security and 1 more.
Loading...
Compare Aikido to Competitors

Snyk operates in the technology sector and provides a platform for code security, open source vulnerability management, container environment protection, and infrastructure as code misconfiguration resolution. Its services offered by Snyk include continuous monitoring and actionable fix advice. It was founded in 2015 and is based in Boston, Massachusetts.

Checkmarx provides a platform for securing application development from code to cloud across various sectors. The company's offerings include static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and tools for API security, container security, infrastructure as code security, and malicious package protection. Checkmarx serves a range of industries, with an aim to integrate security within the software development lifecycle. It was founded in 2006 and is based in Paramus, New Jersey.

Veracode provides application security solutions across sectors, including government, financial services, software, technology, retail, and healthcare. The company offers services for the software development life cycle, including vulnerability detection, static and dynamic application security testing, software composition analysis, container security, application security posture management, and penetration testing. Veracode's platform integrates into development processes, providing feedback and remediation supported by artificial intelligence to improve developer efficiency and security. It was founded in 2006 and is based in Burlington, Massachusetts.

Chainguard operates within the cybersecurity and software supply chain security sectors. The company offers hardened container images that aim to reduce vulnerabilities and integrate into security processes. Its solutions provide tools for vulnerability remediation, compliance, and risk mitigation, and the security of artificial intelligence and machine language workloads. It was founded in 2021 and is based in Kirkland, Washington.

Contrast Security focuses on runtime application security within the cybersecurity domain. The company provides products that integrate code analysis and attack prevention into software, aimed at enhancing security observability and protection for applications. Contrast Security works with developers, application security (AppSec) teams, and security operations (SecOps) teams in various industries. It was founded in 2014 and is based in Pleasanton, California.

Bright Security specializes in dynamic application security testing (DAST) and API security within the cybersecurity industry. The company offers solutions that integrate with continuous integration and delivery (CI/CD) pipelines to identify and manage vulnerabilities in web applications and APIs, catering to the needs of developers and security teams. Bright Security's services are designed to validate business logic, provide extensive vulnerability coverage, and offer clear remediation guidelines with a focus on low false positives. It was founded in 2018 and is based in San Rafael, California.
Loading...