Operating ProcedureExecution layer

Aikido Machine Client Onboarding (Onboarding)

A sequence with 7 steps: Confirm the client's data center can host a 4U GPU server and that the network is air-gapped.

By InnovaAI ResearchPublished Updated

What are the steps?

sequence

Aikido Machine Client Onboarding (Onboarding)

  1. 01

    Confirm the client's data center can host a 4U GPU server and that the network is air-gapped

    Aikido Machine is a 4U GPU server installed in the client's data center. Verify rack space, power draw, and that no outbound internet path exists before scheduling installation. Coordinate with Aikido for the update mechanism: either a whitelisted domain or an encrypted USB.

  2. 02

    Capture the vendor's flat-fee quote and the unpublished hardware and installation costs in the client SOW

    Aikido publishes flat-fee pricing for the Machine, but hardware and installation costs are not published. Get both figures from the vendor in writing before you commit to a retainer number, because the agency margin depends on the gap between the flat fee and what the client will pay.

  3. 03

    Load the client's application source code, runtime environment, dependencies, and exposed entry points into Aikido Machine

    White-box testing requires source access. Feed the login page, API endpoints, and dependency manifest so the platform can map the attack surface. Keep all of this local; nothing leaves the client network.

  4. 04

    Run the initial continuous AI pentest and let it chain findings into working multi-step exploits

    The first run enumerates entry points and produces confirmed exploits with reproduction traces. Do not hand the client raw output; the reproduction traces are for your delivery team to validate before anything goes into a report.

  5. 05

    Review the ready-to-merge pull requests Aikido generates for each confirmed fix

    Every finding comes with a fix delivered as a pull request. Your delivery lead should review each PR against the client's code standards before merging, then trigger one-click re-testing to confirm the vulnerability is closed.

  6. 06

    Configure the scan scope to the contracted limits: up to 50 repos and 3 domains for the SMB Security Audit engagement

    The Aikido SMB Security Audit productized offer is scoped at 50 repos and 3 domains for an $8,000 fee and roughly 60 hours of setup. Anything beyond that scope is a change order, not a favor.

  7. 07

    Produce the SOC 2-ready PDF report and train the client security lead on interpreting findings

    Document all critical and high findings with remediation guidance. The training session is what converts a one-time audit into a recurring retainer, because the client's own team needs to read the dashboard without calling you every week.