Aikido Regulated-Client Pentest Retainer (7-10 days)
Stand up an on-premises Aikido Machine inside a regulated client's network and convert continuous AI pentesting into a recurring compliance retainer, with all source code, runtime, and findings staying local. Time: 7-10 days.
By InnovaAI ResearchPublished Updated
How do you implement it?
Aikido Regulated-Client Pentest Retainer (7-10 days)
Stand up an on-premises Aikido Machine inside a regulated client's network and convert continuous AI pentesting into a recurring compliance retainer, with all source code, runtime, and findings staying local.
- Client data center capacity for a 4U GPU server plus network prerequisites for air-gapped operation
- Aikido vendor engagement for installation and update mechanism (whitelisted domain or encrypted USB)
- Written client sign-off on white-box scope: which repos, domains, and entry points are in bounds
- Named client security lead who will own interpretation of findings after handover
- Baseline inventory of the client's exposed entry points (login pages, endpoints) for scan scoping
- 1.Assess client data center capacity for the 4U GPU server and confirm air-gapped network prerequisites
- 2.Open vendor coordination for installation and update path (whitelisted domain or encrypted USB)
- 3.Capture actual hardware and installation costs from the vendor, since these are not published
- 1.Install the Aikido Machine in the client's data center and verify the full pentesting stack and AI models run locally
- 2.Confirm no source code, runtime data, or findings leave the client network boundary
- 1.Load the client's application source code, runtime environment, and dependencies into Aikido Machine
- 2.Register exposed entry points (login page, endpoints) so the scanner can map the attack surface
- 1.Run the initial continuous AI pentest to enumerate attack surface
- 2.Review generated confirmed exploits with reproduction traces alongside the client security lead
- 1.Triage findings into critical and high severity, mapping each to the client's compliance framework
- 2.Walk the client through how Aikido chains findings into working multi-step exploits so the risk is legible to non-engineers
- 1.Generate ready-to-merge pull requests for fixes and route them into the client's normal code review queue
- 2.Run one-click re-testing to confirm each vulnerability is closed
- 1.Produce the SOC 2-ready PDF report documenting all critical and high findings with remediation guidance
- 2.Train the client security lead on interpreting findings and re-running tests between agency visits
- 1.Set the continuous testing cadence and define what triggers an agency escalation versus client self-service
- 2.Agree the retainer scope: number of repos, domains, and cloud accounts under continuous coverage
A one-time Aikido SMB Security Audit bills $8,000 against roughly 60 hours of setup, and the same deployment then supports a monthly retainer where the client's Aikido tier (from $350/month on Basic up to $1,050/month on Advanced) is a pass-through line item rather than agency margin. The agency margin sits in the recurring interpretation, remediation routing, and compliance reporting work, not in the license, so the retainer only pays if the client keeps the machine running and re-tests on a schedule.
- Deployed Aikido Machine running the full pentesting stack and AI models inside the client's data center
- White-box scan scope document covering the agreed repos, domains, and exposed entry points
- SOC 2-ready PDF report of all critical and high findings with remediation guidance
- Ready-to-merge pull requests for fixes plus one-click re-test confirmation records
- Client security lead trained on interpreting findings and running re-tests between agency visits
The Aikido Machine is running air-gapped in the client's data center, has completed at least one full continuous pentest cycle with confirmed exploits and re-tested fixes, and the client security lead can independently read findings and trigger a re-test.
More on Aikido
- StrategyWhy Aikido Machine Turns Compliance Budgets Into Agency Retainers
- ConceptAikido Air-Gap Qualification Gate
- Evaluation RuleWhen to Adopt Aikido: Client Data Residency Rules Block Cloud Pentesting
- Decision FrameworkAikido: Buy vs Skip (On-Prem Continuous Pentest for Regulated Clients)
- Failure PatternWhy Agencies Fail With Aikido in Air-Gapped Client Environments
- Operating ProcedureAikido Machine Client Onboarding (Onboarding)