What is our primary use case?
My main use case for Aikido Security is detecting security issues and triaging, and if there is any security risk, we detect and fix those security fixes.
I use Aikido Security for detecting and fixing security risks by implementing a DevOps pipeline using a static application security testing tool, which helps automate the detection of exposed secrets and checks for any malicious open-source packages, making it easier for developers to prepare a list of issues they need to fix. Our goal is to ensure all repositories are free from any security issues, monitor cloud configurations that are not done correctly, scan images for runtime threats, and perform automated penetration testing to simulate real-world attacks, detecting any loopholes. It also helps improve developers' productivity by filtering out false positives and generating AI fixes with a single click for identified vulnerabilities.
The main use case for Aikido Security is to perform static application security testing whenever a developer checks in code to ensure there is no malicious code checked in.
What is most valuable?
The best features Aikido Security offers include code supply chain scanning, cloud container security to monitor for misconfigurations or runtime threats, automated penetration testing, and the Autofixes feature, which is a new addition in recent versions and helps fix most security issues.
The feature I find myself relying on the most is code and supply chain scanning, which makes it easier to automate the detection of any security issues, helping to fail the build if there is any malicious code.
Aikido Security has positively impacted my organization by improving overall code quality, enabling us to develop a secure product, and drastically improving our reputation among customers. We now have all types of reports and dashboards, allowing any stakeholder or management to easily check how much work has been done and the product's security status.
The biggest outcome I have seen from using Aikido Security is improved code quality.
What needs improvement?
There is still a lot of scope for improving the automated fixes with Aikido Security.
I would like to see some alerts and configurations added as specific improvements.
I rate it an eight because there are some gaps and issues with certain features, particularly in identifying issues and marking them as positive, as well as finding real false positives. By addressing these issues, they can improve the score.
Regarding Aikido Security's AI capabilities, it lacks in governance and security; while it uses contextual AI to dismiss false positives automatically, we still conduct manual reviews. Since it's still a premature feature, we do double-check AI-related fixes and review any custom AI rules that allow the team to write guidelines for AI-powered PR checks.
The accuracy of Aikido Security's output is still not very high, and there are a few features where they are still lacking behind regarding accuracy.
For how long have I used the solution?
I have been working for two years in my current field.
What do I think about the stability of the solution?
Aikido Security is stable.
What do I think about the scalability of the solution?
Aikido Security's scalability is shifting; it helps to transition the clunky security approach to a developer-first AppSec.
How are customer service and support?
I would say customer support is average.
I would rate the customer support a six out of ten.
Which solution did I use previously and why did I switch?
I previously used different solutions such as the Semgrep open-source tool and other open-source tools for detecting configuration issues, including OWASP, and while some projects still use Semgrep and OWASP, we have switched to Aikido Security.
What was our ROI?
We were able to close 90% of issues with the help of Aikido Security tools, providing a return on investment.
What's my experience with pricing, setup cost, and licensing?
Regarding my experience with pricing, I know we have some open-source tools in use; however, Aikido Security has a plan for $4,200 annually for up to 10 users.
Which other solutions did I evaluate?
Before choosing Aikido Security, I evaluated other options such as TruffleHog, which is also free, and I also assessed Snyk, Checkmarx, Black Duck, and Veracode.
What other advice do I have?
We were able to close 90% of issues with the help of Aikido Security tools, providing a return on investment.
I would advise others looking into using Aikido Security to evaluate several options based on their specific requirements for SAST, DAST, and SCA, including how much they want to automate and their budget for security tools. While there are better options available, some might be expensive, and there are free options that don't provide the same features as Aikido Security.
I would rate this review an eight overall.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.