Aikido alternative: is its AI pentest enough?
TL;DR
Aikido Security is the fastest European cybersecurity unicorn of 2026. It raised $60 million at a $1 billion valuation on 14 January 2026, led by DST Global, and says the platform serves more than 100,000 teams. The pitch is consolidation: SAST, DAST, IaC, container scanning, secrets, cloud posture, plus an AI pentest module, all in one UI. Since 24 February 2026 that module is Aikido Infinite, which tests continuously rather than at a point in time. For an EU mid-market CISO choosing between consolidate-vendors and specialist-pentest:
- Pick Aikido if the buying logic is "consolidate 9+ point-tools into one suite", the org has not yet shipped a mature AppSec programme, and a pentest module wired into the deploy pipeline is good-enough for the current threat model.
- Pick Fleuret AI if pentest is a primary buying centre (not a module), continuous agentic depth + signed audit PDFs + DORA / NIS2 mappings are non-negotiable, and the SAST / cloud / runtime layers are already covered by other tools.
Both ship in EU mid-market. The decision is whether pentest is a feature in a suite or a specialist deliverable in a compliance workflow.
Why CISOs search "Aikido alternative"
The query is common at two profiles:
- Pentest-heavy buyer. A buyer whose binding requirement is depth on pentest specifically, not breadth across AppSec, finds Aikido's consolidation pitch under-spec for the pentest module and goes looking for a specialist.
- Auditor-driven procurement. A buyer whose procurement gate is "what does this look like in a regulator audit" finds Aikido's SOC 2 / ISO 27001 framing strong but wants a vendor that ships DORA Article 24 / NIS2 Annex I mappings by default.
- Sovereignty-strict review. Aikido has EU hosting available; some EU regulated buyers prefer a French-headquartered specialist with documented open-weight LLMs over a Belgian unicorn with broader suite logic.
Aikido Security: the reference, in one paragraph
Aikido Security is headquartered in Ghent, Belgium, founded in 2022 by Willem Delbare and team. It hit unicorn status faster than any other European cybersecurity firm, on $60 million at a $1 billion valuation in January 2026 and more than $84 million raised in total. The product is a unified AppSec suite covering SAST, DAST, SCA, IaC scanning, container, secrets, cloud posture, plus agentic pentest. EU and US hosting flexibility, SOC 2 and ISO 27001 certified. The buying logic is "one platform replaces 9+ point tools". Delbare frames it as software that secures itself: "Software delivery is now continuous, but security testing isn't."
What changed at Aikido in 2026, and why it matters to your shortlist
If you evaluated Aikido in 2025 and shelved it, the file is out of date. Three things moved.
It bought its way into offensive security. The pentest capability is acquired, not grown. Aikido absorbed the pentest companies Allseek and Haicker, the code review platform Trag, and on 30 June 2026 the open-source patching startup Root for a reported $70 to $100 million, which it is folding into an Israeli development centre. For a vendor-risk reviewer, that is a question to ask out loud: which module in the suite is native, and which one arrived last quarter with a different team behind it.
The pentest module became continuous. Aikido Infinite launched on 24 February 2026. It runs on every code change, validates that a finding is actually exploitable, opens a merge-ready patch pull request, and retests the fix before the code ships. Aikido describes the agents as hunting undocumented endpoints and multi-step logic flows that are expensive for human testers to reach. Continuous cadence used to be the specialist's argument. It is now table stakes on both sides.
It published the number that sells the category. In an Aikido survey of 500 security and engineering leaders, 76% said they deploy significant production changes weekly or faster, only 21% validate security on every release, and 85% said findings go stale before the final report lands.
The vendors now agree that annual pentest is dead. They still disagree about what the report has to prove, and that is the part your auditor reads.
The question Infinite does not answer
Infinite closes the cadence gap. It does not close the evidence gap, and for a regulated EU buyer that is the expensive one.
If you fall under DORA, your testers are not a free choice. Article 24 of Regulation (EU) 2022/2554 requires that testers be of the highest suitability and reputability, hold demonstrated expertise in threat intelligence and penetration testing, be certified by an accreditation body in a Member State or bound to a formal code of conduct, and, when external, carry professional indemnity insurance and supply independent assurance on how test results are handled. The final RTS on threat-led penetration testing, published by the three European Supervisory Authorities in July 2024 and adopted as Commission Delegated Regulation (EU) 2025/1190, sets the scope, methodology and remediation record for each phase.
None of that is satisfied by a pull request. A patch PR is a good engineering outcome and a poor audit artefact. The practical test on a demo call is simple: ask the vendor to export the last test as the document you would hand a supervisor, then check whether anyone had to reformat it by hand.
On processing location, Aikido's answer for teams that cannot use the cloud is The Aikido Machine, on-premise pentesting that stays inside your network. That is a real option. It is also a different deployment, so price and operating burden both change. Ask which one the quote covers.
Side-by-side: Fleuret AI vs Aikido Security
| Axis | Fleuret AI | Aikido Security |
|---|---|---|
| Headquarters | France | Belgium |
| Scope | Agentic pentest specialist (web app, API, infra) | Unified AppSec suite (SAST/DAST/IaC/container/secrets/cloud + Infinite pentest module) |
| Pentest module orientation | Pentest is the product | Pentest is one module among 9+ tools |
| Architecture | Multi-agent hierarchical (recon, plan, exploit, validate, sign) | Infinite agents on every code change, validate then patch PR, plus suite components |
| LLM stack | Open-weight (gpt-oss-120b, Kimi K2.5, Mistral) on Scaleway France | Disclosed within product security pages; on-premise option via The Aikido Machine |
| DORA / NIS2 eligibility | Yes, with shipped Article 24 / Annex I mappings | Yes, EU hosting available |
| Default report format | DORA Article 24 + NIS2 mappings, Ed25519-signed PDF | SOC 2, ISO 27001 mappings within suite |
| Compliance workflow surfaces | Jira ticket creation, audit PDF, board export, weekly re-test by default | Suite-wide ticketing + remediation across all modules |
| Buying logic | Specialist deliverable, auditor + CISO-led | Consolidate vendors, dev + security-led |
| Continuous cadence | Weekly or per-deploy on Continuous tier | Per code change since Infinite (February 2026) |
| Pricing transparency | Public per-test pricing (Pentest €4k / Advanced €8k), Continuous on quote | Mid-market suite pricing |
| Best-fit ICP | EU regulated mid-market with DORA / NIS2 scope, pentest as primary buying centre | Mid-market consolidating 5+ AppSec tools into one |
| Pentest capability origin | Built in-house | Acquired (Allseek, Haicker), plus Trag and Root |
A few reading notes.
Specialist vs suite. This is the question. A specialist agentic pentest with shipped DORA / NIS2 mappings versus a unified AppSec suite where pentest is one module among many. Both are valid. The right answer depends on what the rest of the buyer's stack already covers.
Scope clarity. Aikido's scope is breadth: 9+ tools in one UI. Fleuret's scope is depth: agentic pentest with end-to-end recon-to-signed-PDF. If the buyer already has SAST + cloud + container under control, Aikido's suite logic loses some of its leverage and the pentest-module question becomes a head-to-head with Fleuret.
Sovereignty posture. Both are EU-headquartered. Fleuret runs documented open-weight LLMs on Scaleway France. Aikido provides EU hosting and documents its security stack. For EU AI Act high-risk audit preparedness from August 2026, ask both for model identifier / version / training data / inference location disclosure at the same depth.
Architecture differences that matter at scale
Specialist agent depth vs suite module depth. Fleuret's multi-agent hierarchical engine is built end-to-end for pentest. Aikido Attack is one module inside a suite optimised for breadth. The benchmark question is what validated-finding rate Aikido Attack delivers on identical scope vs Fleuret, with both vendors running on the same target.
Workflow surfaces inside vs across modules. Aikido's ticketing and remediation work across the whole suite, which is a real strength when the buyer wants one queue for SAST + pentest + cloud findings. Fleuret's workflow is pentest-deliverable-first: Jira ticket per finding with severity + PoC, signed audit PDF, board export, weekly re-test. Different operating models, both legitimate.
Compliance mapping defaults. Fleuret ships DORA Article 24 and NIS2 Annex I mappings on the default audit PDF. Aikido ships SOC 2 and ISO 27001 mappings at the suite level. Buyers with a specific DORA or NIS2 mandate often find Fleuret's default closer to their auditor's expectations without configuration.
Buying guide
Mid-market consolidating 5+ AppSec point tools into one platform. Aikido is the direct fit. Suite logic, broad coverage, fast time-to-value.
EU regulated mid-market 300-5000 employees, DORA / NIS2 scope, pentest is primary buying centre. Fleuret is the direct fit. Specialist depth, shipped regulatory mappings, signed PDF defaults.
Dev-team-owned security, code-cloud-runtime is the buying logic. Aikido covers more of the stack in one UI, faster to onboard. Fleuret often complements at this profile, plugging in for the pentest layer specifically.
Auditor-driven procurement where the report must map directly to DORA Article 24 / NIS2 Annex I without manual reformatting. Fleuret leads on shipped-by-default. Aikido is a fit if the buyer is willing to map findings to regulatory annexes during the procurement cycle.
What each vendor does best
Aikido Security. The "everything platform" play, and since Infinite a genuinely continuous one. More than 100,000 teams use the broader suite. Strong fit when the buying logic is "consolidate vendors", not "pick the best pentest". EU and US hosting flexibility, an on-premise option, SOC 2 and ISO 27001 mature.
Fleuret AI. Sovereign-by-default specialist agentic pentest with the compliance workflow (Jira, signed audit PDF, board export, weekly cadence) wired in on the default Continuous tier. Best fit when pentest is a primary buying centre and DORA / NIS2 deliverables are non-negotiable.
The wider Aikido alternative shortlist
Nobody replaces a suite with a suite on the first pass. Most of the buyers running this search are replacing one layer of it. Sort candidates by which layer you are actually short on.
- You want the pentest layer done properly and keep the rest. This is the specialist lane: agentic pentest with a deliverable an auditor accepts. Compare XBOW and the other agentic pentest tools EU buyers shortlist, and Fleuret.
- Your exposure is API-first. API and GraphQL discovery is its own problem, not a DAST setting. See the Escape comparison.
- You are buying validation of exploitability, not a list. That is the adversarial exposure validation lane. See Pentera, Horizon3, and the breach and attack simulation versus pentest breakdown.
- You want continuous external attack surface coverage. See FireCompass and Patrowl.
- You need a report a regulator will accept, first and last. Cadence is the easy half. Start from DORA penetration testing requirements or the NIS2 pentest cadence for mid-market and work backwards to the vendor.
If more than two of those bullets describe you, the suite argument is probably right and Aikido is a strong answer. If exactly one does, you are buying a specialist and the suite discount is not worth the depth you give up.
What to verify before signing either
Two checklists before the product demo:
- The 7-question sovereignty checklist for legal-review pre-clearance.
- The 7-question workflow-lock-in checklist for operational fit.
For Aikido Security, also ask:
- What is Infinite's validated-finding rate compared to a specialist agentic pentest on identical scope, same target, same week?
- Which regions run the model inference for Infinite, and does that change with The Aikido Machine?
- How does the suite map findings to DORA Article 24 / NIS2 Annex I if the buyer is regulated, and who does the mapping?
- What is the path to plug a specialist pentest tool into Aikido's ticketing if Infinite is under-spec for some scopes?
For Fleuret AI, also ask:
- When does Fleuret recommend a buyer pick Aikido instead, and what scopes does the suite cover better?
- How does Fleuret coexist with an Aikido deployment when the buyer wants both?
- What is the specialist depth on agentic pentest that justifies a standalone purchase over a suite module?
Five moves before the next procurement call
- Name the layer you are short on. Write one sentence: "we are buying X because Y is uncovered." If the sentence needs three clauses, you are buying a suite and should say so.
- Run both vendors on the same scope in the same week. Identical target, identical window. Count validated findings, not raw findings. Anything else is a feature list read aloud.
- Ask for the export, not the dashboard. Request the artefact you would hand a supervisor under DORA Article 24 or NIS2 Annex I, and check whether a human reformatted it.
- Pin down where inference runs. Model identifier, version, and the region the model runs in, for each vendor, in writing. Cloud and on-premise are different answers to the same question.
- Price the cadence you will actually use. Testing on every code change is only worth the licence if someone triages every result. If the queue has one owner, weekly is honest and cheaper.
Both are valid EU mid-market answers. The honest answer to "Aikido alternative" is Fleuret AI when pentest is a primary buying centre, not a feature in a wider suite.
Fleuret builds agentic pentest that is EU-sovereign by design and ships the DORA and NIS2 mappings in the default report. If that is the lane you are buying in, See Fleuret in action.
Sources
- Aikido Security Raises $60 Million at $1 Billion Valuation, SecurityWeek, 2026-01-14
- Aikido Infinite introduces continuous, self-remediating AI penetration testing, Help Net Security, 2026-02-24
- Aikido Infinite: Continuous AI Pentesting for Every Release, Aikido Security, 2026-02-24
- Cyber unicorn Aikido acquires Israeli startup Root for $70-$100 million, Calcalist CTech, 2026-06-30
- Aikido Security Introduces Aikido Infinite, CIO Influence, 2026-02-26
- Security testing was built for a slower world, Help Net Security, 2026-06-24
- Allseek and Haicker are joining Aikido, Aikido Security, 2025-09-24
- Regulation (EU) 2022/2554 (DORA), Article 24, Official Journal of the European Union, 2022-12-27
- JC 2024-29 Final report on the DORA RTS on threat-led penetration testing, EBA / EIOPA / ESMA, 2024-07-17
Related reading
- DORA pentest compliance for fintech
- NIS2 pentest requirements for healthcare
- XBOW alternative in Europe: 5 agentic pentest tools EU regulated buyers actually consider
- Sovereign EU AI pentest in 2026: why CLOUD Act, Schrems II, and the EU AI Act disqualify US providers
- The pentest moat is workflow lock-in: Jira, audit PDF, board export, weekly re-test
- Agentic AI pentesting explained
- DORA penetration testing requirements: what financial entities must do in 2026