Aikido Security could be improved by allowing us to scan the entire network, not just the applications, but also devices such as computers and servers, to have all vulnerability reports for my entire infrastructure. Everything else is fine for me regarding needed improvements. The interface of Aikido Security is intuitive and very easy to use.
Technical leader at a government with 5,001-10,000 employees
Real User
Top 5
Jul 19, 2026
There is still a lot of scope for improving the automated fixes with Aikido Security. I would like to see some alerts and configurations added as specific improvements. I rate it an eight because there are some gaps and issues with certain features, particularly in identifying issues and marking them as positive, as well as finding real false positives. By addressing these issues, they can improve the score. Regarding Aikido Security's AI capabilities, it lacks in governance and security; while it uses contextual AI to dismiss false positives automatically, we still conduct manual reviews. Since it's still a premature feature, we do double-check AI-related fixes and review any custom AI rules that allow the team to write guidelines for AI-powered PR checks. The accuracy of Aikido Security's output is still not very high, and there are a few features where they are still lacking behind regarding accuracy.
There are a few areas for improvement. The first is scan speed. For large repositories, initial scans can be slow. Incremental scanning helps, but full scans still take considerable time. The second thing is the false positive rate. While Auto-Triage is good, it is not perfect. Occasionally, genuine issues get filtered out and real false positives slip through. The third one is remediation guidance. Aikido Security tells you what is vulnerable, but sometimes the fix suggestions are generic. More specific, actionable remediation steps would save developer time. The fourth one is IDE integrations. It currently works best in CI/CD pipelines. A proper VS Code or JetBrains plugin for real-time scanning while coding would be a significant improvement. From a customer point of view, the following things could change. The first thing is documentation for custom rules. Aikido Security allows you to create custom scanning rules, but the documentation for this feature is surprisingly thin. I spent considerable time in community forums and with trial and error just to configure basic custom rules. Step-by-step guides with real-world examples would make this feature much more accessible. The second thing is better Slack and communication integrations. Currently, security alerts come through email and dashboard notifications, but our team lives in Slack. A more configurable Slack integration that sends contextual alerts directly to the relevant developer, not just a generic channel notification, would dramatically improve response time. The third one is historical trend reporting. While Aikido Security shows current vulnerability status well, generating historical reports showing security posture improvement over time is limited. For presenting security progress to management or stakeholders, better exportable trend reports would be very valuable.
To improve Aikido Security, the main thing I would suggest is regarding the UUID that was being flagged in the codebase. I had a certain object with a UUID that was being considered as a private secret key or API key, which was not the case. It was a false positive alarm, and if Aikido Security solves that, then it will be perfectly fine.
The biggest challenge with Aikido Security initially was the alert volume, as connecting everything could result in hundreds or thousands of findings. Prioritization helps, but there is still work involved in deciding what should be fixed first. Deeper customization around policies and reporting would be beneficial, since some organizations have specific compliance requirements and the customization can feel limited compared to larger, enterprise-focused platforms. The documentation for Aikido Security is generally good for setup, but more details in troubleshooting scenarios would be helpful. There were times when a finding was generated that the developer did not fully understand. More real-world examples explaining why a finding was generated and how to verify it would help, along with additional FAQs or troubleshooting guides.
I think Aikido Security could be improved by addressing its Jira integration, which I feel needs a bit of work. For my preferences, it is a bit too rigid. They recently added the capability of having custom fields, but before that, they did not have it. Additionally, I would love to see a Terraform module for Aikido Security, although I know this might be a bit much to ask.
Aikido Security is the no-nonsense platform that empowers developers by centralizing code-to-cloud security issues and providing rapid guidance for fixing vulnerabilities.With over 6,000 teams utilizing its features, Aikido Security prioritizes effective security management by consolidating 11 comprehensive scans into one platform. This approach translates complex vulnerabilities into understandable insights, targeting non-enterprise SaaS businesses with engineering teams of 10-500...
Aikido Security could be improved by allowing us to scan the entire network, not just the applications, but also devices such as computers and servers, to have all vulnerability reports for my entire infrastructure. Everything else is fine for me regarding needed improvements. The interface of Aikido Security is intuitive and very easy to use.
There is still a lot of scope for improving the automated fixes with Aikido Security. I would like to see some alerts and configurations added as specific improvements. I rate it an eight because there are some gaps and issues with certain features, particularly in identifying issues and marking them as positive, as well as finding real false positives. By addressing these issues, they can improve the score. Regarding Aikido Security's AI capabilities, it lacks in governance and security; while it uses contextual AI to dismiss false positives automatically, we still conduct manual reviews. Since it's still a premature feature, we do double-check AI-related fixes and review any custom AI rules that allow the team to write guidelines for AI-powered PR checks. The accuracy of Aikido Security's output is still not very high, and there are a few features where they are still lacking behind regarding accuracy.
There are a few areas for improvement. The first is scan speed. For large repositories, initial scans can be slow. Incremental scanning helps, but full scans still take considerable time. The second thing is the false positive rate. While Auto-Triage is good, it is not perfect. Occasionally, genuine issues get filtered out and real false positives slip through. The third one is remediation guidance. Aikido Security tells you what is vulnerable, but sometimes the fix suggestions are generic. More specific, actionable remediation steps would save developer time. The fourth one is IDE integrations. It currently works best in CI/CD pipelines. A proper VS Code or JetBrains plugin for real-time scanning while coding would be a significant improvement. From a customer point of view, the following things could change. The first thing is documentation for custom rules. Aikido Security allows you to create custom scanning rules, but the documentation for this feature is surprisingly thin. I spent considerable time in community forums and with trial and error just to configure basic custom rules. Step-by-step guides with real-world examples would make this feature much more accessible. The second thing is better Slack and communication integrations. Currently, security alerts come through email and dashboard notifications, but our team lives in Slack. A more configurable Slack integration that sends contextual alerts directly to the relevant developer, not just a generic channel notification, would dramatically improve response time. The third one is historical trend reporting. While Aikido Security shows current vulnerability status well, generating historical reports showing security posture improvement over time is limited. For presenting security progress to management or stakeholders, better exportable trend reports would be very valuable.
To improve Aikido Security, the main thing I would suggest is regarding the UUID that was being flagged in the codebase. I had a certain object with a UUID that was being considered as a private secret key or API key, which was not the case. It was a false positive alarm, and if Aikido Security solves that, then it will be perfectly fine.
The biggest challenge with Aikido Security initially was the alert volume, as connecting everything could result in hundreds or thousands of findings. Prioritization helps, but there is still work involved in deciding what should be fixed first. Deeper customization around policies and reporting would be beneficial, since some organizations have specific compliance requirements and the customization can feel limited compared to larger, enterprise-focused platforms. The documentation for Aikido Security is generally good for setup, but more details in troubleshooting scenarios would be helpful. There were times when a finding was generated that the developer did not fully understand. More real-world examples explaining why a finding was generated and how to verify it would help, along with additional FAQs or troubleshooting guides.
I think Aikido Security could be improved by addressing its Jira integration, which I feel needs a bit of work. For my preferences, it is a bit too rigid. They recently added the capability of having custom fields, but before that, they did not have it. Additionally, I would love to see a Terraform module for Aikido Security, although I know this might be a bit much to ask.