No more typing reviews! Try our Samantha, our new voice AI agent.

Share your experience using Continuous Dynamic (formerly WhiteHat Dynamic)

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 115,000+ reviews on PeerSpot:

Francisco Pulido - PeerSpot reviewer
SecOps Engineer at a real estate/law firm with 501-1,000 employees
Real User
Top 5Leaderboard
Sep 18, 2026
Automation has transformed cloud vulnerability monitoring and has reduced response times
Pros and Cons
  • "Upwind has positively impacted my organization by reducing time to action and time to response by half."
  • "Upwind can be improved because its UI is a bit difficult to navigate."

What is our primary use case?

My main use case for Upwind is vulnerability management program automation, CSPM, Cloud Security Posture Management, and overall monitoring of security vulnerabilities across the company. For example, I have my cloud provider connected to Upwind, and it scans every resource existing inside and alerts me if there is any vulnerability, such as an instance with port 22 open to the world.

How has it helped my organization?

Upwind has positively impacted my organization by reducing time to action and time to response by half. I save time because any change that is non-compliant is automatically triggered in the form of an alert, so I do not have to wait for any other scans from any other tools. Instead of having many alerts at the beginning of the day, I have an alert at the moment it happens.

What is most valuable?

The best features Upwind offers are the ability to see everything globally across many different cloud accounts, which I appreciate the most, and its ability to reduce noise is also very helpful.

Upwind helps reduce noise for me by not only firing findings but also using context to ensure that those findings are truly as critical as they claim to be. For example, a critical finding on a resource that does not have internet reachability is not as critical, but another one with high criticality that is exposed to the internet may have a raised criticality.

The accuracy and reliability of Upwind's AI output are really useful. It provides great summaries upon findings, is able to generate full investigations upon findings as well, and the ability to talk to the AI myself to get any more context or any other summaries or related information from a finding is really useful.

What needs improvement?

Upwind can be improved because its UI is a bit difficult to navigate. I find myself getting lost many times, not being able to find the option, and sometimes completely forgetting where some of the functionality is.

For how long have I used the solution?

I have been using Upwind for six months.

What do I think about the stability of the solution?

Upwind is stable.

What do I think about the scalability of the solution?

The scalability of Upwind is great so far.

How are customer service and support?

The customer support is amazing, with a sub-two-minute response time. I rate the customer support a ten on a scale of one to ten.

How was the initial setup?

My experience with pricing, setup cost, and licensing was really easy to figure out. I received a request from the support team or the sales team asking for what my needs were, and right from that email, I automatically received a quote.

What was our ROI?

I have seen a return on investment because I am basically saving costs on some monitoring tools offered on AWS, since they are now taken care of by Upwind. The amount of people needed to check all of the alerts has drastically lowered, and now I can take care of it myself. The response times are two times faster.

What other advice do I have?

My advice to others looking into using Upwind is that it is a great tool to use and can take care of many things across many areas of security, and it will save you a lot of headaches. I gave this review a rating of nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 18, 2026
Flag as inappropriate
Eucharia Okafor - PeerSpot reviewer
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
MSP
Top 5
Sep 5, 2026
Centralized security scanning has reduced vulnerabilities and simplifies managing code to cloud risks
Pros and Cons
  • "Aikido Security has positively impacted my organization by allowing us to rely on a single tool for scanning, which saves us money, time, and reduces overhead, making it more cost-optimized for our environment."
  • "One area I think Aikido Security could improve is the depth of their reporting and remediation guidance; sometimes, the platform flags a vulnerability but the suggested fix lacks detail, requiring engineers to research the solution themselves."

What is our primary use case?

My main use case for Aikido Security is to consolidate all our application security scanning into one platform, primarily to manage multiple tools more efficiently. I use it to scan our code for vulnerabilities with SAST, check for open-source dependencies with SCA, scan our Docker images, detect hardcoded secrets, or API keys in our database, and integrate it directly into our CI/CD pipeline so that every code commit is automatically scanned before reaching production.

During the microservice migration to AWS, Aikido Security flagged critical vulnerabilities and detected hardcoded API keys, allowing us to fix both issues before they reached production.

What is most valuable?

One of the best features Aikido Security offers is the ability to scan everything in the same place, allowing us to check for vulnerabilities in our source code.

Aikido Security scans our source code for security issues, checks open-source libraries for known vulnerabilities, scans Docker images, checks AWS and cloud configurations for misconfigurations, and finds hardcoded passwords or API keys. It combines multiple security tools in one platform, making it unnecessary to have separate tools for each type of scan, which is particularly helpful for developers and DevSecOps engineers.

Aikido Security has positively impacted my organization by allowing us to rely on a single tool for scanning, which saves us money, time, and reduces overhead, making it more cost-optimized for our environment. We have been able to save at least 60% of our overall costs because we use one tool to capture different vulnerabilities across various areas on a single platform.

What needs improvement?

One area I think Aikido Security could improve is the depth of their reporting and remediation guidance; sometimes, the platform flags a vulnerability but the suggested fix lacks detail, requiring engineers to research the solution themselves. I would love to see step-by-step remediation guidelines built directly into the alerts and better integration options with more third-party ticketing tools like Jira for automation.

The user interface can feel overwhelming when there are many alerts, so a better way to prioritize and group vulnerabilities by severity would make focusing on the most critical issues easier. Additionally, I would like to see deeper integration with third-party tools like Jira and more detailed remediation guidelines built into each alert.

For how long have I used the solution?

I have been using Aikido Security for about two years.

What do I think about the stability of the solution?

In my experience, Aikido Security has been very stable, with no significant outages or downtime impacting our environment, and being a SaaS tool, it handles maintenance and updates without our concern.

What do I think about the scalability of the solution?

Aikido Security scales very well as our organization expands, handling growth without performance issues, and its licensing model scales with the number of repositories and developers, ensuring fast and consistent scans even as our code base grows.

How are customer service and support?

The customer support experience has been very positive; they are responsive, knowledgeable about their product, and provide clear guidance on configuration and integrations. They also offer a solid documentation library for common questions, though 24/7 support for enterprise customers would be an improvement.

Which solution did I use previously and why did I switch?

Before using Aikido Security, we had a combination of separate tools like Sneak for open-source dependency scanning, SonarQube for static security analysis, and Trivy for container scanning. Managing these three platforms with different dashboards, alerts, and CI/CD integrations was time-consuming and often led to issues falling through the cracks, which is why we switched to Aikido Security for its consolidated capabilities.

How was the initial setup?

The setup and onboarding took less than a day, requiring no dedicated staff to manage it since it runs automatically in the background.

What was our ROI?

There is absolutely a return on investment with Aikido Security; After implementation, we saw a 35% reduction in vulnerabilities reaching production, and our security review time per deployment dropped significantly as issues were caught much earlier in the development process.

What's my experience with pricing, setup cost, and licensing?

The pricing for Aikido Security is very reasonable compared to other application security platforms, and since it is a SaaS platform, the setup was minimal with no infrastructure to maintain. The licensing model is straightforward and scales based on the number of repositories and developers, making it easy to budget for.

Which other solutions did I evaluate?

We explored other options like Checkmarx for static application security testing and Prisma Cloud for container and cloud security, but they were either too expensive or too complex to set up and manage with more engineers. Aikido Security was easier to implement, more affordable, and covered all the key scanning capabilities we needed.

What other advice do I have?

My advice for anyone considering Aikido Security is to proceed and try it as the onboarding process is straightforward and can be completed within a day. Start by connecting critical repositories and integrating with CI/CD pipelines from day one for automatic scanning, and prioritize alerts systematically to avoid feeling overwhelmed.

My overall impression of Aikido Security is very positive; it simplifies the life of a DevSecOps engineer by consolidating tools into one platform, making application security accessible and manageable without a large dedicated team. I would recommend Aikido Security for any organization serious about shifting security left and embedding it into their development lifecycle. I give this product a rating of 8.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 5, 2026
Flag as inappropriate