No more typing reviews! Try our Samantha, our new voice AI agent.

Share your experience using Continuous Dynamic (formerly WhiteHat Dynamic)

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 114,000+ reviews on PeerSpot:

Eucharia Okafor - PeerSpot reviewer
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
MSP
Top 5
Sep 5, 2026
Centralized security scanning has reduced vulnerabilities and simplifies managing code to cloud risks
Pros and Cons
  • "Aikido Security has positively impacted my organization by allowing us to rely on a single tool for scanning, which saves us money, time, and reduces overhead, making it more cost-optimized for our environment."
  • "One area I think Aikido Security could improve is the depth of their reporting and remediation guidance; sometimes, the platform flags a vulnerability but the suggested fix lacks detail, requiring engineers to research the solution themselves."

What is our primary use case?

My main use case for Aikido Security is to consolidate all our application security scanning into one platform, primarily to manage multiple tools more efficiently. I use it to scan our code for vulnerabilities with SAST, check for open-source dependencies with SCA, scan our Docker images, detect hardcoded secrets, or API keys in our database, and integrate it directly into our CI/CD pipeline so that every code commit is automatically scanned before reaching production.

During the microservice migration to AWS, Aikido Security flagged critical vulnerabilities and detected hardcoded API keys, allowing us to fix both issues before they reached production.

What is most valuable?

One of the best features Aikido Security offers is the ability to scan everything in the same place, allowing us to check for vulnerabilities in our source code.

Aikido Security scans our source code for security issues, checks open-source libraries for known vulnerabilities, scans Docker images, checks AWS and cloud configurations for misconfigurations, and finds hardcoded passwords or API keys. It combines multiple security tools in one platform, making it unnecessary to have separate tools for each type of scan, which is particularly helpful for developers and DevSecOps engineers.

Aikido Security has positively impacted my organization by allowing us to rely on a single tool for scanning, which saves us money, time, and reduces overhead, making it more cost-optimized for our environment. We have been able to save at least 60% of our overall costs because we use one tool to capture different vulnerabilities across various areas on a single platform.

What needs improvement?

One area I think Aikido Security could improve is the depth of their reporting and remediation guidance; sometimes, the platform flags a vulnerability but the suggested fix lacks detail, requiring engineers to research the solution themselves. I would love to see step-by-step remediation guidelines built directly into the alerts and better integration options with more third-party ticketing tools like Jira for automation.

The user interface can feel overwhelming when there are many alerts, so a better way to prioritize and group vulnerabilities by severity would make focusing on the most critical issues easier. Additionally, I would like to see deeper integration with third-party tools like Jira and more detailed remediation guidelines built into each alert.

For how long have I used the solution?

I have been using Aikido Security for about two years.

What do I think about the stability of the solution?

In my experience, Aikido Security has been very stable, with no significant outages or downtime impacting our environment, and being a SaaS tool, it handles maintenance and updates without our concern.

What do I think about the scalability of the solution?

Aikido Security scales very well as our organization expands, handling growth without performance issues, and its licensing model scales with the number of repositories and developers, ensuring fast and consistent scans even as our code base grows.

How are customer service and support?

The customer support experience has been very positive; they are responsive, knowledgeable about their product, and provide clear guidance on configuration and integrations. They also offer a solid documentation library for common questions, though 24/7 support for enterprise customers would be an improvement.

Which solution did I use previously and why did I switch?

Before using Aikido Security, we had a combination of separate tools like Sneak for open-source dependency scanning, SonarQube for static security analysis, and Trivy for container scanning. Managing these three platforms with different dashboards, alerts, and CI/CD integrations was time-consuming and often led to issues falling through the cracks, which is why we switched to Aikido Security for its consolidated capabilities.

How was the initial setup?

The setup and onboarding took less than a day, requiring no dedicated staff to manage it since it runs automatically in the background.

What was our ROI?

There is absolutely a return on investment with Aikido Security; After implementation, we saw a 35% reduction in vulnerabilities reaching production, and our security review time per deployment dropped significantly as issues were caught much earlier in the development process.

What's my experience with pricing, setup cost, and licensing?

The pricing for Aikido Security is very reasonable compared to other application security platforms, and since it is a SaaS platform, the setup was minimal with no infrastructure to maintain. The licensing model is straightforward and scales based on the number of repositories and developers, making it easy to budget for.

Which other solutions did I evaluate?

We explored other options like Checkmarx for static application security testing and Prisma Cloud for container and cloud security, but they were either too expensive or too complex to set up and manage with more engineers. Aikido Security was easier to implement, more affordable, and covered all the key scanning capabilities we needed.

What other advice do I have?

My advice for anyone considering Aikido Security is to proceed and try it as the onboarding process is straightforward and can be completed within a day. Start by connecting critical repositories and integrating with CI/CD pipelines from day one for automatic scanning, and prioritize alerts systematically to avoid feeling overwhelmed.

My overall impression of Aikido Security is very positive; it simplifies the life of a DevSecOps engineer by consolidating tools into one platform, making application security accessible and manageable without a large dedicated team. I would recommend Aikido Security for any organization serious about shifting security left and embedding it into their development lifecycle. I give this product a rating of 8.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 5, 2026
Flag as inappropriate
Brandi Lea - PeerSpot reviewer
Regional Information Security Analyst, Lead at a healthcare company with 10,001+ employees
Real User
Top 20
Sep 6, 2026
Rapid risk detection has transformed how I uncover hidden vulnerabilities in new applications
Pros and Cons
  • "Rapid7 MDR has positively impacted my organization by allowing me to discover vulnerabilities, both publicly known and zero-day, much faster and efficiently than I ever did in the past, ultimately saving the company a lot of money in compliance issues, fines, and possibly even lawsuits."
  • "While Rapid7 MDR is getting better with each update or version, it needs to enhance its zero-day detection for anomalous things without relying on third-party solutions like Vericode."

What is our primary use case?

My main use case for Rapid7 is onboarding all new applications both built in house and third party acquired, where I run them through a sandbox environment and allow Rapid7 to conduct an initial scan looking for vulnerabilities that might not otherwise be publicly announced. On an ongoing basis, while applications live and survive within the McKesson environment, I use Rapid7 to aggregate data about new vulnerabilities to determine if I have to do any kind of hardening or shelf the application.

A specific example of how I used Rapid7 during the onboarding process involves a recent scenario with Change Healthcare. I had just purchased or acquired a new practice in the United States that was still using Change Healthcare software, and during the onboarding process of all the applications they have in their environment, I used Rapid7 in the sandbox to figure out if those were still vulnerable to the breach that occurred in twenty twenty four. Almost all of the applications that practice was using were in fact filled with the vulnerabilities that caused the twenty twenty four breach.

What is most valuable?

Rapid7 InsightAppSec offers excellent features including a cloud-based platform that allows for detailed breakdowns of information into more digestible bits. The platform is user-friendly with a broad range of tools, although it does require quite a bit of a learning curve. It allows me to aggregate data and put it into presentations to send to executives about the security status across the entire enterprise.

My favorite aspect of the user-friendly interface of Rapid7 is the primary cloud-based dashboard, which I find most useful. I love that even inside a browser, the intuitive help options are available for figuring out what things are, whether it's hovering over a particular option for insights or using right-click features that offer tools and tips on managing the vulnerabilities when found. The interface is very clean, not overly convoluted or difficult to navigate, which I do enjoy.

Rapid7 has positively impacted my organization by allowing me to discover vulnerabilities, both publicly known and zero-day, much faster and efficiently than I ever did in the past, ultimately saving the company a lot of money in compliance issues, fines, and possibly even lawsuits. The number of vulnerabilities I am discovering has improved by almost thirty seven percent in the last two years alone. Remediation especially has increased significantly because I am finding these vulnerabilities faster, and Rapid7 provides tips on how to remediate or harden against them, whether through hardening options or upgrading to better versions, which does save the company money.

What needs improvement?

While Rapid7 InsightAppSec is getting better with each update or version, it needs to enhance its zero-day detection for anomalous things without relying on third-party solutions like Vericode. Having that capability in-house would be a much better feature, and a couple of menu options might need cleaning up on the cloud platform.

Integration with ServiceNow and One Trust as a GRC platform would be beneficial and would be significantly valuable to many enterprises, especially in McKesson.

For how long have I used the solution?

I have been using Rapid7 for application vulnerability assessments and management for about a year and a half as I was recently put on the team using it.

What do I think about the stability of the solution?

I consider Rapid7 to be a very stable platform. Thanks to continuous updates and the transparency from the company, I have not encountered any real issues with it.

What do I think about the scalability of the solution?

Rapid7 InsightAppSec is very scalable and caters to both small and large enterprise solutions. I was able to deploy it globally in less than three months across fourteen different countries and over fifty thousand endpoints and employees.

How are customer service and support?

Customer support for Rapid7 is superb. Whenever I have confusion or issues, a quick email or phone call resolves the issue within fifteen minutes, and I have never had a problem getting the right answers.

The transparency of Rapid7 in terms of gaining visibility into detections and investigations is wonderful, and the support I receive from the company has also been outstanding. During massive audits or when things are flagged that might become problematic in the future, I have had nothing but astounding support and transparency regarding the findings produced by Rapid7.

Which solution did I use previously and why did I switch?

I was part of the team long enough to see only the end of the previous solution, which revolved around RSA's Archer platforms, but I did not use it extensively.

How was the initial setup?

In my experience on the incident recovery team, though it has been less than six months, the tools provided by Rapid7 allow me to rapidly collect all necessary data, pulling everything from drives and RAM, and coalesce that into a report that helps me break down exactly what happened, when it happened, and who did it. I am taking advantage of the expanded ecosystem telemetry support, which has significantly improved my visibility and efficiency in correlation. It allows me to generate reports on the spot for executives, senior managers, and vice presidents, speeding up remediation techniques considerably.

What about the implementation team?

I unfortunately did not have the opportunity to attend discussions about pricing, setup costs, or licensing for Rapid7, so I do not have enough authority to comment on that.

What was our ROI?

Speaking from an information security officer's point of view about the return on investment, Rapid7 does not necessarily reduce the number of staff as I already operate lean. However, it does reduce the issues my company faces regarding compliance, laws, and potential lawsuits, which probably saves a significant amount of money, not to mention the time I save by fixing things faster, identifying issues quicker, and remediating them even more efficiently, ultimately freeing me up to conduct other tasks like forensic investigations or rebuilding the enterprise.

Which other solutions did I evaluate?

I am not sure if my team evaluated other options before choosing Rapid7. I imagine they might have, but I was not part of that decision-making group.

What other advice do I have?

If you are looking for a solution that will help identify vulnerabilities and provide remediation tips for hardening your infrastructure, I think Rapid7 does an excellent job. While I do not know the specifics of licensing costs, I imagine it is significantly less costly than a federal lawsuit.

I find Rapid7's AI capabilities and governance to be very malleable, which is valuable to a lot of my teams. I can also lock it down and harden it, which I find very useful. The AI integration tool has been very helpful for simulations and for identifying the dependencies that software requires to operate correctly and the vulnerabilities in those dependencies.

The accuracy and reliability of Rapid7 output are decent for an AI platform, but it does require double-checking the sources of information to ensure that the output is not misleading.

I find the risk-aware detection features in Rapid7 extremely valuable. The fact that Rapid7 includes this on all platforms, whether on-prem or cloud or hybrid, offers great insight into what to look for, especially as it pertains to software in the healthcare industry, while also allowing me to widen the scope to a global level if needed.

Currently, I am not utilizing the AI-assisted risk-aware investigation workflows as they are not enabled yet. This is pending an AI review board's approval to ensure usefulness and security. I gave this product a rating of nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 6, 2026
Flag as inappropriate