Aikido Security
Aikido Security is a Ghent, Belgium-based unicorn ASPM platform that consolidates 15+ AppSec scanners into one developer-facing tool and acquired container-patching startup Root (formerly Slim.AI) in 2026.
Visit Website ↗ + Add to CompareOverview
Aikido Security is a Ghent, Belgium-based application security company, founded in 2022, that built an all-in-one Application Security Posture Management (ASPM) platform consolidating more than fifteen previously separate scanner categories — SAST, software composition analysis, secrets detection, infrastructure-as-code scanning, container scanning, DAST, and cloud posture management — into a single developer-facing interface. Rather than selling security teams a stack of point tools developers route around, Aikido surfaces findings directly in pull requests and IDEs with auto-generated fixes, aimed at closing the gap between the team that owns the risk and the team that owns the code.
In June 2026, Aikido acquired Root (formerly Slim.AI, the container-security startup behind the open-source Slim Toolkit, which had rebranded to Root in March 2024) for a reported $70-100 million. The acquisition adds Root’s ability to backport security patches onto open-source dependencies at the exact version an organization is already running, without forcing a disruptive version upgrade — directly targeting the "patch now versus break the build" tradeoff that stalls vulnerability remediation in most application security programs.
Aikido reached a $1 billion valuation in roughly three years off a $60 million Series B led by DST Global, with PSG Equity, Notion Capital, and Singular participating — a pace the company and multiple trade outlets describe as the fastest for a European cybersecurity firm. Named customers include the Premier League, Revolut, SoundCloud, and Niantic, putting checkable enterprise logos behind the platform.
Innovation Matrix Assessment
Rapid, well-documented expansion from a single scanner-consolidation idea in 2022 to 15+ integrated scan types plus a strategic acquisition (Root) within roughly four years - genuinely fast product and company build-out.
Developer-native workflow (pull requests, IDE, CI/CD) designed to reduce alert fatigue and tool sprawl; consolidating 15+ scanners into one interface is itself an operational simplification for security teams.
A $1B valuation in about three years on $84M+ total raised, backed by DST Global, plus a cash acquisition (Root) funded from that capital, is strong and independently verifiable momentum.
The developer-first, consolidate-everything model is a genuine bet against the historical pattern of buying six-to-ten separate AppSec point tools, and the Root acquisition attacks a specific, well-known remediation bottleneck (patch fatigue).
Named, verifiable enterprise customers (Premier League, Revolut, SoundCloud, Niantic) go beyond vendor marketing since these are public, checkable brand names, but no independent third-party benchmark of detection accuracy was found.
ASPM-style tool consolidation is one of the more active buying trends in application security today, and the Root acquisition directly targets a widely-cited pain point around patching known-vulnerable dependencies.
Why CISOs Should Care
For CISOs whose AppSec programs have accumulated six or more disconnected scanning tools that developers route around, Aikido offers one consolidated pipeline plus, via the Root acquisition, a way to patch known-vulnerable open-source dependencies without forcing teams onto a disruptive version upgrade.
What Makes It Different
Combines ASPM-style scanner consolidation (15+ tools in one interface) with Root's patch-in-place technology, letting teams fix a vulnerability at their current dependency version instead of being forced onto a newer, potentially breaking release - most competitors only alert on the vulnerability, they do not backport the fix.
The Matrix Verdict
73/100 — MEANINGFUL INNOVATOR
A fast-growing, well-capitalized, unicorn-valued AppSec platform with real named customers and a recent, strategically coherent acquisition that fills a specific vulnerability-remediation gap. Still young enough that independent, third-party efficacy benchmarking is limited, but the growth and customer signals are independently verifiable rather than vendor-only claims.
Editorial Note: Claims vs. Verified Findings
The $60M Series B, $1B valuation, and roughly $84M total funding are independently confirmed by SecurityWeek, SC Media, and TechFundingNews. Named customers (Premier League, Revolut, SoundCloud, Niantic) appear in company and press materials describing the funding round; this profile could not independently confirm the exact scope of each customer engagement beyond the vendor's own description. The Root (formerly Slim.AI) acquisition and its reported $70-100M price are independently reported by SiliconANGLE, BankInfoSecurity, and Calcalistech, with the price itself varying by source and reflected here as a range. Aikido's own claims about scanner count and specific detection-rate statistics are vendor-sourced and not independently benchmarked. Note: this profile replaces a CSV entry for 'Slim.AI,' whose website now redirects through Root.io to Aikido's site following the March 2024 rebrand and June 2026 acquisition - Aikido Security is the current operating entity.
Sources
Alternatives to Aikido Security
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…