Aikido Machine Client Onboarding (Onboarding)
A sequence with 7 steps: Confirm the client's data center can host a 4U GPU server and that the network is air-gapped.
By InnovaAI ResearchPublished Updated
What are the steps?
Aikido Machine Client Onboarding (Onboarding)
- 01
Confirm the client's data center can host a 4U GPU server and that the network is air-gapped
Aikido Machine is a 4U GPU server installed in the client's data center. Verify rack space, power draw, and that no outbound internet path exists before scheduling installation. Coordinate with Aikido for the update mechanism: either a whitelisted domain or an encrypted USB.
- 02
Capture the vendor's flat-fee quote and the unpublished hardware and installation costs in the client SOW
Aikido publishes flat-fee pricing for the Machine, but hardware and installation costs are not published. Get both figures from the vendor in writing before you commit to a retainer number, because the agency margin depends on the gap between the flat fee and what the client will pay.
- 03
Load the client's application source code, runtime environment, dependencies, and exposed entry points into Aikido Machine
White-box testing requires source access. Feed the login page, API endpoints, and dependency manifest so the platform can map the attack surface. Keep all of this local; nothing leaves the client network.
- 04
Run the initial continuous AI pentest and let it chain findings into working multi-step exploits
The first run enumerates entry points and produces confirmed exploits with reproduction traces. Do not hand the client raw output; the reproduction traces are for your delivery team to validate before anything goes into a report.
- 05
Review the ready-to-merge pull requests Aikido generates for each confirmed fix
Every finding comes with a fix delivered as a pull request. Your delivery lead should review each PR against the client's code standards before merging, then trigger one-click re-testing to confirm the vulnerability is closed.
- 06
Configure the scan scope to the contracted limits: up to 50 repos and 3 domains for the SMB Security Audit engagement
The Aikido SMB Security Audit productized offer is scoped at 50 repos and 3 domains for an $8,000 fee and roughly 60 hours of setup. Anything beyond that scope is a change order, not a favor.
- 07
Produce the SOC 2-ready PDF report and train the client security lead on interpreting findings
Document all critical and high findings with remediation guidance. The training session is what converts a one-time audit into a recurring retainer, because the client's own team needs to read the dashboard without calling you every week.
More on Aikido
- StrategyWhy Aikido Machine Turns Compliance Budgets Into Agency Retainers
- ConceptAikido Air-Gap Qualification Gate
- Evaluation RuleWhen to Adopt Aikido: Client Data Residency Rules Block Cloud Pentesting
- Decision FrameworkAikido: Buy vs Skip (On-Prem Continuous Pentest for Regulated Clients)
- Failure PatternWhy Agencies Fail With Aikido in Air-Gapped Client Environments
- Implementation BlueprintAikido Regulated-Client Pentest Retainer (7-10 days)