AI ToolSecurity Tools

Aikido

Aikido Machine is an on-premises GPU server that executes continuous penetration tests entirely within a client's network, with no data egress to cloud infrastructure.

Aikido is an on-premises GPU server, priced at $350/month on the Basic plan. InnovaAI scores it 3.4/10 for agency resale.

Situational Fit3.4/10

Agency Audit

Aikido Machine is an on-premises GPU server that runs continuous penetration tests entirely within a client's network, keeping source code, runtime, and findings local. It's designed for regulated industries (finance, healthcare, pharma), defense, and government agencies that cannot use cloud-based security tools. For agencies, this is a niche resell opportunity: your clients must have air-gapped networks and compliance requirements that prohibit cloud testing. The continuous pentest model ($4,000 per typical engagement, with a 'no critical findings = don't pay' guarantee) creates recurring revenue potential, but only if your client base includes enterprises with strict data residency rules.

Situational FitNo WLTiered
Fit

3.4/10

Typical Margin

49%

Time-to-Value

3d about 3 days

Complexity
High
Situational Fit
Fit34
Visit Aikido
Best For
  • Your agency serves defense contractors, government agencies, or financial institutions with air-gapped networks and cannot use cloud-based penetration testing tools.
  • You want to offer continuous penetration testing as a retainer service with the 'no high or critical finding = don't pay' pricing model, which aligns risk with client outcomes.
  • You have clients running legacy systems (including COBOL) that need offensive security testing but cannot expose code or runtime to external cloud infrastructure.
Not For
  • Your typical client is a small to mid-market SaaS or e-commerce business without air-gapped infrastructure or strict data residency requirements.
  • You lack in-house technical staff to manage on-premises GPU hardware, troubleshoot local deployments, or interpret advanced penetration test findings.
  • Your clients expect white-label security tools with branded client portals; Aikido Machine does not offer a verified white-label program for resellers.

Profit Path

Your Cost (USD)

$350/mo

Market Range

$1.2K–$3K/mo

Revenue Model

Monthly Recurring

Planning benchmark at United States price levels. Not a measured market survey.

Platform Features

Core capabilities of Aikido

Continuous AI-driven penetration testing

Aikido Machine runs automated offensive security tests on every deployment, chaining findings into working multi-step exploits and proving exploitability with reproduction traces. Agencies can offer this as a recurring retainer service rather than one-time engagements.

On-premises GPU inference with air-gap support

The entire testing engine runs locally on client hardware with no data egress to cloud infrastructure. This is critical for regulated industries and government agencies that cannot expose source code or runtime to external networks.

Automatic attack surface enumeration

Aikido Machine maps application entry points and identifies exploitable paths without manual scoping. This reduces the time agencies spend on pre-test reconnaissance and accelerates time-to-report.

Ready-to-merge pull request generation

When vulnerabilities are found, Aikido generates pull requests with fixes that developers can review and merge directly. Agencies can then re-test to confirm the vulnerability is closed, creating a closed-loop remediation workflow.

Legacy and modern system coverage

Aikido tests COBOL, Java, Python, and modern cloud-native applications in the same workflow. This breadth allows agencies to serve enterprise clients with heterogeneous tech stacks.

SOC 2 and ISO 27001 compliance reporting

Full PDF reports are generated automatically, meeting documentation requirements for regulated industries. Agencies can deliver compliance-ready findings without additional report writing overhead.

What Makes Aikido Different

Unique advantages vs similar tools in this niche

On-premises GPU server runs full pentesting stack locally

vs Cloud-based pentesting tools that require sending code to third-party APIs

Aikido Machine is a 4U server with enterprise GPUs, installed in your data center, running the full Aikido pentesting stack and AI models locally.

Unlimited pentesting with no per-pentest or token fees

vs Per-pentest pricing models that ration testing

Inference runs on Aikido Machine's own GPUs. No tokens, no per-pentest pricing. Test every application, on every release, continuously.

Air-gapped operation for classified and mission systems

vs Cloud tools that cannot operate without internet connectivity

The Aikido Machine runs with no outbound connection at all, and updates can also load from a separate device, so even patching stays off your network.

Latest Updates

Recent releases and improvements for Aikido

Code Coverage: find what your tests miss

New

New Code Coverage feature to identify gaps in test coverage.

Deep Review: the agentic PR review that cuts merge time and bugs shipped

New

Agentic PR review feature designed to reduce merge time and bugs shipped.

Device Protection for Linux and VM Scanning for Google Cloud

New

Extended device protection to Linux and added VM scanning support for Google Cloud.

DSPM: Find data exposure risks without connecting your data stores

New

New Data Security Posture Management feature to identify data exposure risks without direct data store connections.

Protect Company Devices From Supply Chain Attacks

New

New device protection capability to defend company devices against supply chain attacks.

Investment ROI Calculator

Value equation analysis for Aikido, based on the Hormozi framework

What is the Hormozi framework? A four-factor score: (what the service delivers × how reliably it delivers) divided by (how long it takes × how much effort it requires). A higher Value Multiplier means a better return on the time and money invested: faster, easier, and more proven results.

Value MultiplierConsider

1.1× value multiple: invest $350/mo and agencies typically charge $1.2K–$3K/mo for the work it powers.

Outcome40
÷
Friction35

Why This Succeeds

Higher is better

Implementation Challenges

Lower is better

High friction. Aikido currently returns 1.1×: reduce implementation complexity before scaling to more clients.

Best if:Your agency serves defense contractors, government agencies, or financial institutions with air-gapped networks and cannot use cloud-based penetration testing tools.You want to offer continuous penetration testing as a retainer service with the 'no high or critical finding = don't pay' pricing model, which aligns risk with client outcomes.You have clients running legacy systems (including COBOL) that need offensive security testing but cannot expose code or runtime to external cloud infrastructure.Your clients require SOC 2 and ISO 27001 compliance reports and need full PDF documentation of penetration test results delivered on-premises.

Pricing

Aikido platform cost to your agency

~49% margin

Starts at an estimated $50 one-time (Rightsized Pentest), scales to $4K one-time (Typical Pentest)

Basic

$350/mo
  • Includes 10 users
  • 100 repos
  • 50 Container Images
  • 3 Domains

Pro

$700/mo
  • Includes 10 users
  • 200 repos
  • 100 Container Images
  • 10 Domains

Advanced

$1.1K/mo
  • Includes 10 users
  • 500 repos
  • 200 Container Images
  • 20 Domains
Enterprise

Enterprise

Custom
  • Custom repos and fair-usage limits
  • Custom Container Images
  • Custom Domains and Cloud Accounts
  • Unlimited AI AutoFixes/mo

Typical Pentest

$4K one-time
  • Full PDF report for SOC 2 & ISO 27001
  • One application, one set of APIs
  • Free re-testing for up to 6 months
  • Same-day results

Rightsized Pentest

$50 one-time
Vendor's estimate
  • Estimated price from the vendor's calculator, for scoped to your application
  • Full PDF report for SOC 2 & ISO 27001
  • Coverage scales with your application
  • Scope set automatically from your repos
Enterprise

Continuous Testing

Custom
  • Continuous reports and real-time findings
  • Always-on, scales with your releases
  • Pentest on every deploy
  • Broker support for internal applications

No verified white-label program for Aikido: client-facing delivery runs under the platform's native branding.

Market Intelligence

How agencies monetize Aikido: real offer economics and market positioning

Service Applications
Delivery & ProductionAutomation & IntegrationsReporting & Analytics
Best For
  • Regulated industries (finance, healthcare, pharma)
  • Defense and government agencies
  • Enterprise security teams with air-gapped networks
Not Ideal For
  • Small agencies without on-prem infrastructure
  • Teams seeking cloud-only security tools

Hybrid (Project + Retainer)

ai-toolsmixed offers

Agency mixes project fees for setup/implementation with ongoing retainers for optimization.

Offer Economics: What You Charge vs. What It Costs

Margin includes platform cost + agency labor at $75/hr.

Aikido SMB Security Auditgrowth smb

Small software companies or SaaS startups needing a one-time AI-powered penetration test for SOC 2 readiness without exposing source code to cloud tools

$8K
Tool: $350/mo (2 mo = $700)Labor: 60h setup × $75 = $4.5KMargin: 35%Benchmark: $3K–$8K/project
• Deploy Aikido on-premises GPU server within client network environment• Configure white-box scan scope across up to 50 repos and 3 domains• Document all critical and high findings with remediation guidance in a SOC 2-ready PDF report• Train client security lead on interpreting results and managing re-test workflow
Aikido Mid-Market Pentestmid marketHIGH MARGIN

Mid-market fintech, healthtech, or regulated SaaS companies requiring continuous AI penetration testing across multiple repos, containers, and cloud accounts with full audit trail

$18K
Tool: $350/mo (2 mo = $700)Labor: 120h setup × $75 = $9KMargin: 46%Benchmark: $8K–$20K/project
• Deploy and harden Aikido on-premises server within client's air-gapped or regulated network• Configure full-scope scanning across up to 200 repos, 100 container images, and 10 cloud accounts• Build custom finding triage workflow integrated with client's existing ticketing system• Deliver ISO 27001 and SOC 2 aligned PDF report with executive summary and remediation roadmap
Aikido Continuous Security Retainermid market

Mid-market companies post-deployment that need ongoing monthly AI-driven penetration testing, finding triage, and compliance reporting without maintaining internal security staff

$3.2K/mo
Tool: $350/moLabor: 16h/mo × $75 = $1.2KMargin: 51%Benchmark: $1.2K–$3K/mo
• Monitor continuous Aikido scan results and triage new critical or high findings monthly• Optimize scan configuration as client repos, containers, and cloud accounts evolve• Deliver monthly security posture report with trend analysis and remediation status• Integrate updated findings into client's compliance evidence repository for SOC 2 or ISO 27001
Aikido Enterprise Defense ProgramenterpriseHIGH MARGIN

Defense contractors, government agencies, or Fortune 5000 enterprises requiring fully air-gapped, on-premises continuous AI penetration testing across large-scale infrastructure with zero cloud data exposure

$45K
Tool: $350/mo (2 mo = $700)Labor: 280h setup × $75 = $21KMargin: 52%Benchmark: $20K–$60K/project
• Deploy and validate Aikido on-premises GPU server cluster within classified or air-gapped network environment• Configure enterprise-scale scanning across 500+ repos, 200 container images, and 20 cloud accounts with custom retention policies• Integrate findings pipeline with enterprise SIEM, ticketing, and compliance management platforms• Build executive security dashboard and deliver full audit-ready documentation package for regulatory review

Scale Economics: Based on Starter Offer

Using Aikido Continuous Security Retainer at $3.2K/client. Platform: $350/mo. Labor: 16h/client × $75/hr.

5 clients
$15.8K
MRR
$9.5K net (60%)
10 clients
$31.7K
MRR
$19.4K net (61%)
20 clients
$63.4K
MRR
$39.0K net (62%)

Net = MRR - platform cost - labor (16h/client × $75/hr).

Weighted Avg Margin
49%
Across all offer tiers, incl. labor at $75/hr
Run your agency audit

Investment Decision Framework

Strategic vetting analysis for Aikido

Vetting Verdict

Situational Fit

Fit depends on your client mix

Agency Fit(white-label + resell pathway)
34/100
0255075100
Resell Friction(WL + mode + complexity)
60/100
0255075100

Buy If

4
OPERATIONAL FIT

Your agency serves defense contractors, government agencies, or financial institutions with air-gapped networks and cannot use cloud-based penetration testing tools.

OPERATIONAL FIT

You want to offer continuous penetration testing as a retainer service with the 'no high or critical finding = don't pay' pricing model, which aligns risk with client outcomes.

OPERATIONAL FIT

You have clients running legacy systems (including COBOL) that need offensive security testing but cannot expose code or runtime to external cloud infrastructure.

OPERATIONAL FIT

Your clients require SOC 2 and ISO 27001 compliance reports and need full PDF documentation of penetration test results delivered on-premises.

Skip If

4
CAUTION

Your typical client is a small to mid-market SaaS or e-commerce business without air-gapped infrastructure or strict data residency requirements.

CAUTION

You lack in-house technical staff to manage on-premises GPU hardware, troubleshoot local deployments, or interpret advanced penetration test findings.

CAUTION

Your clients expect white-label security tools with branded client portals; Aikido Machine does not offer a verified white-label program for resellers.

CAUTION

You need a tool that scales across 50+ client accounts with minimal per-client setup overhead; Aikido's on-premises model requires dedicated infrastructure per deployment.

Bottom Line

Aikido Machine is an on-premises GPU server that runs continuous penetration tests entirely within a client's network, keeping source code, runtime, and findings local. It's designed for regulated industries (finance, healthcare, pharma), defense, and government agencies that cannot use cloud-based security tools. For agencies, this is a niche resell opportunity: your clients must have air-gapped networks and compliance requirements that prohibit cloud testing. The continuous pentest model ($4,000 per typical engagement, with a 'no critical findings = don't pay' guarantee) creates recurring revenue potential, but only if your client base includes enterprises with strict data residency rules.

Reality Check

Trade-offs & Gotchas

Aikido Machine requires on-premises GPU infrastructure and air-gapped network architecture, which most SMB clients lack. Reselling this means you're targeting a small subset of enterprise and government buyers, not your typical SaaS client base. Setup and support complexity is high, and you'll need technical staff to manage the hardware and interpret findings.

Implementation Reality

Moderate effort: standard configuration with some customization needed

Effort: 7/10Time: 5/10

Academy for Aikido

Work through it in order: the course for this service first, then the modules behind it.

Core concepts

The mental model you need to price and scope the work.

  1. Aikido Air-Gap Qualification GateConcept

    Aikido Machine is a 4U GPU server installed in the client's data center, running the full pentest stack and AI models locally so source code, runtime, and findings never leave the network. That architecture only pays off when the client's compliance posture forbids cloud testing. Before quoting, run three checks: does the client operate an air-gapped or strictly segmented network, does a regulator (finance, healthcare, pharma, defense, government) prohibit sending source code to a cloud scanner, and can their data center host a 4U GPU server with whitelisted-domain or encrypted-USB update paths. If any answer is no, the client is better served by Aikido's cloud plans at $350, $700, or $1,050 per month. If all three are yes, the agency can position the $8,000 Aikido SMB Security Audit (60h setup, up to 50 repos and 3 domains) as a SOC 2 readiness engagement that cloud tools cannot legally win.

  2. Liability Ceiling FrameworkConcept

    Every security retainer carries an implicit liability ceiling: the gap between what an agency promises and what an attack surface can actually guarantee. Agencies that sell "we will keep you secure" absorb unlimited downside; agencies that sell defined detection, response, and remediation scopes cap their exposure while still charging recurring fees. The framework asks three questions before signing: what specific asset is protected, what detection window is promised, and who owns the residual risk when a novel attack path emerges. Cogent's VR-1 model maps attack paths across enterprise infrastructure, which reframes the deliverable from "prevention" to "path visibility," a bounded promise. Sentrint grades repository security and generates fix prompts, giving clients a measurable artifact rather than an assurance. Vaultak monitors and rolls back AI agent actions in production, another bounded scope. California SB 813 and AB 1405, signed September 9, 2026, formalize third-party AI audit expectations, which pushes agencies toward documented, auditable scopes instead of blanket guarantees.

  3. Blast Radius BudgetingConcept

    Blast Radius Budgeting treats security scope as a function of how much damage a single compromised asset can cause, not how many assets exist. An agency protecting a 40-person client with one shared drive has a smaller blast radius than a 12-person client whose AI agents hold production database credentials. The framework asks three questions per engagement: what can be reached from the weakest credential, how fast can it be revoked, and who eats the loss if it is not. That third question is the pricing lever. Runtime governance layers such as Vaultak intercept agent actions and roll them back automatically, which shrinks the radius and justifies a lower liability premium; frontier reasoning models like Cogent map attack paths across the same infrastructure, which expands the billable discovery phase. California SB 813 and AB 1405, signed September 9, 2026, now formalize third-party audit expectations, so documented radius estimates become client-facing evidence rather than internal notes.

11 modules selected for Aikido

Frequently Asked Questions

Answers about pricing, setup, implementation, and more

Aikido Machine is an on-premises GPU server that runs continuous AI-driven penetration tests entirely within a client's network. It enumerates entry points, chains findings into working multi-step exploits, generates ready-to-merge pull requests for fixes, and re-tests to confirm vulnerabilities are closed. All source code, runtime, and findings remain local, making it suitable for air-gapped networks in regulated industries.

Aikido offers 7 pricing tiers, starting at $350/mo (Basic) up to $4000 one-time (Typical Pentest). Estimated prices come from Aikido's own price calculator and change with usage. Agencies typically achieve 49% profit margins when reselling to clients.

No verified white-label program is documented for Aikido Machine. Client-facing surfaces display the Aikido brand, so you cannot present a fully white-labeled portal or reports to your clients. This limits resale positioning to clients who accept Aikido branding or who use the tool internally without client-facing delivery.

Aikido Machine is designed as a standalone on-premises security testing engine. The scraped content does not specify native integrations with popular agency tools (HubSpot, Salesforce, Slack, etc.). Integration would likely require custom API work or manual data export, so confirm integration requirements with Aikido sales before committing to a resale model.

Setup time depends on client infrastructure readiness. Deploying the GPU server on-premises, configuring network access, and connecting to the client's repositories typically requires 1-2 weeks of coordination with the client's IT and security teams. Once deployed, onboarding new applications into the testing engine is faster, but initial infrastructure setup is not a same-day process.

Aikido Machine is designed for regulated industries including financial services (banking, fintech), healthcare and pharmaceutical companies, and defense and government agencies. These verticals have strict data residency and air-gap requirements that prohibit cloud-based security tools. Startups and SMBs without air-gapped networks are not a good fit.

Yes. Aikido Machine tests legacy systems including COBOL alongside modern languages and cloud-native applications. This breadth allows agencies to serve enterprise clients with heterogeneous tech stacks that span decades of code.

Aikido's typical pentest pricing includes a 'no high or critical finding = don't pay' guarantee. If the test uncovers only low or medium severity issues, the client is not charged for that engagement. This risk-sharing model aligns Aikido's incentive with the client's security posture and can be a strong selling point for agencies positioning continuous testing as a retainer.