Aikido
Aikido Machine is an on-premises GPU server that executes continuous penetration tests entirely within a client's network, with no data egress to cloud infrastructure. It enumerates application attack surfaces, chains findings into working multi-step exploits, generates ready-to-merge pull requests for fixes, and re-tests to confirm remediation. The tool operates fully air-gapped and supports legacy systems including COBOL, making it the only penetration testing option for regulated industries (finance, healthcare, pharma), defense contractors, and government agencies with strict data residency rules. Agencies reselling Aikido target a narrow but high-value segment: enterprises that cannot use cloud-based security tools and require SOC 2 and ISO 27001 compliance documentation.
Aikido is an on-premises GPU server, priced at $350/month on the Basic plan. InnovaAI scores it 3.4/10 for agency resale.
Agency Audit
Aikido Machine is an on-premises GPU server that runs continuous penetration tests entirely within a client's network, keeping source code, runtime, and findings local. It's designed for regulated industries (finance, healthcare, pharma), defense, and government agencies that cannot use cloud-based security tools. For agencies, this is a niche resell opportunity: your clients must have air-gapped networks and compliance requirements that prohibit cloud testing. The continuous pentest model ($4,000 per typical engagement, with a 'no critical findings = don't pay' guarantee) creates recurring revenue potential, but only if your client base includes enterprises with strict data residency rules.
3.4/10
49%
3d about 3 days
- Your agency serves defense contractors, government agencies, or financial institutions with air-gapped networks and cannot use cloud-based penetration testing tools.
- You want to offer continuous penetration testing as a retainer service with the 'no high or critical finding = don't pay' pricing model, which aligns risk with client outcomes.
- You have clients running legacy systems (including COBOL) that need offensive security testing but cannot expose code or runtime to external cloud infrastructure.
- Your typical client is a small to mid-market SaaS or e-commerce business without air-gapped infrastructure or strict data residency requirements.
- You lack in-house technical staff to manage on-premises GPU hardware, troubleshoot local deployments, or interpret advanced penetration test findings.
- Your clients expect white-label security tools with branded client portals; Aikido Machine does not offer a verified white-label program for resellers.
Profit Path
$350/mo
$1.2K–$3K/mo
Monthly Recurring
Planning benchmark at United States price levels. Not a measured market survey.
Platform Features
Core capabilities of Aikido
Continuous AI-driven penetration testing
Aikido Machine runs automated offensive security tests on every deployment, chaining findings into working multi-step exploits and proving exploitability with reproduction traces. Agencies can offer this as a recurring retainer service rather than one-time engagements.
On-premises GPU inference with air-gap support
The entire testing engine runs locally on client hardware with no data egress to cloud infrastructure. This is critical for regulated industries and government agencies that cannot expose source code or runtime to external networks.
Automatic attack surface enumeration
Aikido Machine maps application entry points and identifies exploitable paths without manual scoping. This reduces the time agencies spend on pre-test reconnaissance and accelerates time-to-report.
Ready-to-merge pull request generation
When vulnerabilities are found, Aikido generates pull requests with fixes that developers can review and merge directly. Agencies can then re-test to confirm the vulnerability is closed, creating a closed-loop remediation workflow.
Legacy and modern system coverage
Aikido tests COBOL, Java, Python, and modern cloud-native applications in the same workflow. This breadth allows agencies to serve enterprise clients with heterogeneous tech stacks.
SOC 2 and ISO 27001 compliance reporting
Full PDF reports are generated automatically, meeting documentation requirements for regulated industries. Agencies can deliver compliance-ready findings without additional report writing overhead.
What Makes Aikido Different
Unique advantages vs similar tools in this niche
On-premises GPU server runs full pentesting stack locally
vs Cloud-based pentesting tools that require sending code to third-party APIsAikido Machine is a 4U server with enterprise GPUs, installed in your data center, running the full Aikido pentesting stack and AI models locally.
Unlimited pentesting with no per-pentest or token fees
vs Per-pentest pricing models that ration testingInference runs on Aikido Machine's own GPUs. No tokens, no per-pentest pricing. Test every application, on every release, continuously.
Air-gapped operation for classified and mission systems
vs Cloud tools that cannot operate without internet connectivityThe Aikido Machine runs with no outbound connection at all, and updates can also load from a separate device, so even patching stays off your network.
Latest Updates
Recent releases and improvements for Aikido
Code Coverage: find what your tests miss
NewNew Code Coverage feature to identify gaps in test coverage.
Deep Review: the agentic PR review that cuts merge time and bugs shipped
NewAgentic PR review feature designed to reduce merge time and bugs shipped.
Device Protection for Linux and VM Scanning for Google Cloud
NewExtended device protection to Linux and added VM scanning support for Google Cloud.
DSPM: Find data exposure risks without connecting your data stores
NewNew Data Security Posture Management feature to identify data exposure risks without direct data store connections.
Protect Company Devices From Supply Chain Attacks
NewNew device protection capability to defend company devices against supply chain attacks.
Investment ROI Calculator
Value equation analysis for Aikido, based on the Hormozi framework
What is the Hormozi framework? A four-factor score: (what the service delivers × how reliably it delivers) divided by (how long it takes × how much effort it requires). A higher Value Multiplier means a better return on the time and money invested: faster, easier, and more proven results.
1.1× value multiple: invest $350/mo and agencies typically charge $1.2K–$3K/mo for the work it powers.
Why This Succeeds
Higher is betterClient Results Potential
What your clients actually get
High-impact results: clients get measurable improvements in delivered value
Aikido Machine puts autonomous penetration testing on-premises at your command, 24/7.
Reliability Score
How consistently this delivers results
Early-stage track record: validate with a small pilot first
How reliably this solution delivers promised results. Based on case studies, reviews, and track record.
Implementation Challenges
Lower is betterTime to First Revenue
How long until you can start earning
Standard ramp-up: accelerate to 1 day with Academy SOPs
Expect a few days from signup to first client delivery
Setup Effort
What it takes to get running
Hands-on build required: Academy SOPs significantly reduce implementation effort
Moderate effort: standard configuration with some customization needed
High friction. Aikido currently returns 1.1×: reduce implementation complexity before scaling to more clients.
Pricing
Aikido platform cost to your agency
Starts at an estimated $50 one-time (Rightsized Pentest), scales to $4K one-time (Typical Pentest)
Basic
- Includes 10 users
- 100 repos
- 50 Container Images
- 3 Domains
Pro
- Includes 10 users
- 200 repos
- 100 Container Images
- 10 Domains
Advanced
- Includes 10 users
- 500 repos
- 200 Container Images
- 20 Domains
Enterprise
- Custom repos and fair-usage limits
- Custom Container Images
- Custom Domains and Cloud Accounts
- Unlimited AI AutoFixes/mo
Typical Pentest
- Full PDF report for SOC 2 & ISO 27001
- One application, one set of APIs
- Free re-testing for up to 6 months
- Same-day results
Rightsized Pentest
- Estimated price from the vendor's calculator, for scoped to your application
- Full PDF report for SOC 2 & ISO 27001
- Coverage scales with your application
- Scope set automatically from your repos
Continuous Testing
- Continuous reports and real-time findings
- Always-on, scales with your releases
- Pentest on every deploy
- Broker support for internal applications
No verified white-label program for Aikido: client-facing delivery runs under the platform's native branding.
Market Intelligence
How agencies monetize Aikido: real offer economics and market positioning
- Regulated industries (finance, healthcare, pharma)
- Defense and government agencies
- Enterprise security teams with air-gapped networks
- Small agencies without on-prem infrastructure
- Teams seeking cloud-only security tools
Hybrid (Project + Retainer)
ai-toolsmixed offersAgency mixes project fees for setup/implementation with ongoing retainers for optimization.
Offer Economics: What You Charge vs. What It Costs
Margin includes platform cost + agency labor at $75/hr.
Small software companies or SaaS startups needing a one-time AI-powered penetration test for SOC 2 readiness without exposing source code to cloud tools
Mid-market fintech, healthtech, or regulated SaaS companies requiring continuous AI penetration testing across multiple repos, containers, and cloud accounts with full audit trail
Mid-market companies post-deployment that need ongoing monthly AI-driven penetration testing, finding triage, and compliance reporting without maintaining internal security staff
Defense contractors, government agencies, or Fortune 5000 enterprises requiring fully air-gapped, on-premises continuous AI penetration testing across large-scale infrastructure with zero cloud data exposure
Scale Economics: Based on Starter Offer
Using Aikido Continuous Security Retainer at $3.2K/client. Platform: $350/mo. Labor: 16h/client × $75/hr.
Net = MRR - platform cost - labor (16h/client × $75/hr).
Investment Decision Framework
Strategic vetting analysis for Aikido
Situational Fit
Fit depends on your client mix
Buy If
4Your agency serves defense contractors, government agencies, or financial institutions with air-gapped networks and cannot use cloud-based penetration testing tools.
You want to offer continuous penetration testing as a retainer service with the 'no high or critical finding = don't pay' pricing model, which aligns risk with client outcomes.
You have clients running legacy systems (including COBOL) that need offensive security testing but cannot expose code or runtime to external cloud infrastructure.
Your clients require SOC 2 and ISO 27001 compliance reports and need full PDF documentation of penetration test results delivered on-premises.
Skip If
4Your typical client is a small to mid-market SaaS or e-commerce business without air-gapped infrastructure or strict data residency requirements.
You lack in-house technical staff to manage on-premises GPU hardware, troubleshoot local deployments, or interpret advanced penetration test findings.
Your clients expect white-label security tools with branded client portals; Aikido Machine does not offer a verified white-label program for resellers.
You need a tool that scales across 50+ client accounts with minimal per-client setup overhead; Aikido's on-premises model requires dedicated infrastructure per deployment.
Bottom Line
Aikido Machine is an on-premises GPU server that runs continuous penetration tests entirely within a client's network, keeping source code, runtime, and findings local. It's designed for regulated industries (finance, healthcare, pharma), defense, and government agencies that cannot use cloud-based security tools. For agencies, this is a niche resell opportunity: your clients must have air-gapped networks and compliance requirements that prohibit cloud testing. The continuous pentest model ($4,000 per typical engagement, with a 'no critical findings = don't pay' guarantee) creates recurring revenue potential, but only if your client base includes enterprises with strict data residency rules.
Reality Check
Aikido Machine requires on-premises GPU infrastructure and air-gapped network architecture, which most SMB clients lack. Reselling this means you're targeting a small subset of enterprise and government buyers, not your typical SaaS client base. Setup and support complexity is high, and you'll need technical staff to manage the hardware and interpret findings.
Moderate effort: standard configuration with some customization needed
Academy for Aikido
Work through it in order: the course for this service first, then the modules behind it.
No Academy modules are published for this service yet. Browse the full Academy
Why this category matters
The commercial case before the tooling.
Core concepts
The mental model you need to price and scope the work.
- Aikido Air-Gap Qualification GateConcept
Aikido Machine is a 4U GPU server installed in the client's data center, running the full pentest stack and AI models locally so source code, runtime, and findings never leave the network. That architecture only pays off when the client's compliance posture forbids cloud testing. Before quoting, run three checks: does the client operate an air-gapped or strictly segmented network, does a regulator (finance, healthcare, pharma, defense, government) prohibit sending source code to a cloud scanner, and can their data center host a 4U GPU server with whitelisted-domain or encrypted-USB update paths. If any answer is no, the client is better served by Aikido's cloud plans at $350, $700, or $1,050 per month. If all three are yes, the agency can position the $8,000 Aikido SMB Security Audit (60h setup, up to 50 repos and 3 domains) as a SOC 2 readiness engagement that cloud tools cannot legally win.
- Liability Ceiling FrameworkConcept
Every security retainer carries an implicit liability ceiling: the gap between what an agency promises and what an attack surface can actually guarantee. Agencies that sell "we will keep you secure" absorb unlimited downside; agencies that sell defined detection, response, and remediation scopes cap their exposure while still charging recurring fees. The framework asks three questions before signing: what specific asset is protected, what detection window is promised, and who owns the residual risk when a novel attack path emerges. Cogent's VR-1 model maps attack paths across enterprise infrastructure, which reframes the deliverable from "prevention" to "path visibility," a bounded promise. Sentrint grades repository security and generates fix prompts, giving clients a measurable artifact rather than an assurance. Vaultak monitors and rolls back AI agent actions in production, another bounded scope. California SB 813 and AB 1405, signed September 9, 2026, formalize third-party AI audit expectations, which pushes agencies toward documented, auditable scopes instead of blanket guarantees.
- Blast Radius BudgetingConcept
Blast Radius Budgeting treats security scope as a function of how much damage a single compromised asset can cause, not how many assets exist. An agency protecting a 40-person client with one shared drive has a smaller blast radius than a 12-person client whose AI agents hold production database credentials. The framework asks three questions per engagement: what can be reached from the weakest credential, how fast can it be revoked, and who eats the loss if it is not. That third question is the pricing lever. Runtime governance layers such as Vaultak intercept agent actions and roll them back automatically, which shrinks the radius and justifies a lower liability premium; frontier reasoning models like Cogent map attack paths across the same infrastructure, which expands the billable discovery phase. California SB 813 and AB 1405, signed September 9, 2026, now formalize third-party audit expectations, so documented radius estimates become client-facing evidence rather than internal notes.
Decision and risk
How to judge the fit, and the ways it goes wrong.
- When to Adopt Aikido: Client Data Residency Rules Block Cloud PentestingEvaluation Rule
Adopt Aikido Machine only for clients whose data residency rules make cloud pentesting impossible, and price the engagement to cover the 60-hour on-prem setup before promising recurring testing.
- Security Tools Rule: Price the Liability Before You Price the RetainerEvaluation Rule
Scope every security engagement as detection, evidence, and response support, and never contract for absolute protection.
- Aikido: Buy vs Skip (On-Prem Continuous Pentest for Regulated Clients)Decision Framework
IF your client roster includes regulated enterprises (finance, healthcare, pharma) or government/defense agencies with air-gapped networks that prohibit cloud-based security tools, THEN Aikido Machine's on-premises GPU server model is the only viable continuous pentest option, and the $8,000 Aikido SMB Security Audit offer (60h setup) can be productized as a one-time engagement. IF your clients are cloud-native SaaS startups without data residency restrictions, THEN the cloud Aikido tiers at $350/month (Basic, 10 users, 100 repos) through $1,050/month (Advanced, 500 repos) are the correct fit, and the on-prem Machine is unnecessary overhead.
- Why Agencies Fail With Aikido in Air-Gapped Client EnvironmentsFailure Pattern
- The Absolute-Security Trap: Why Security Tools Collapse Under Agency Retainer PromisesFailure Pattern
Delivery system
Blueprints and procedures for running it as a service.
- Aikido Regulated-Client Pentest Retainer (7-10 days)Implementation Blueprint
Stand up an on-premises Aikido Machine inside a regulated client's network and convert continuous AI pentesting into a recurring compliance retainer, with all source code, runtime, and findings staying local.
- Aikido Machine Client Onboarding (Onboarding)Operating Procedure
11 modules selected for Aikido
Frequently Asked Questions
Answers about pricing, setup, implementation, and more
Aikido Machine is an on-premises GPU server that runs continuous AI-driven penetration tests entirely within a client's network. It enumerates entry points, chains findings into working multi-step exploits, generates ready-to-merge pull requests for fixes, and re-tests to confirm vulnerabilities are closed. All source code, runtime, and findings remain local, making it suitable for air-gapped networks in regulated industries.
Aikido offers 7 pricing tiers, starting at $350/mo (Basic) up to $4000 one-time (Typical Pentest). Estimated prices come from Aikido's own price calculator and change with usage. Agencies typically achieve 49% profit margins when reselling to clients.
No verified white-label program is documented for Aikido Machine. Client-facing surfaces display the Aikido brand, so you cannot present a fully white-labeled portal or reports to your clients. This limits resale positioning to clients who accept Aikido branding or who use the tool internally without client-facing delivery.
Aikido Machine is designed as a standalone on-premises security testing engine. The scraped content does not specify native integrations with popular agency tools (HubSpot, Salesforce, Slack, etc.). Integration would likely require custom API work or manual data export, so confirm integration requirements with Aikido sales before committing to a resale model.
Setup time depends on client infrastructure readiness. Deploying the GPU server on-premises, configuring network access, and connecting to the client's repositories typically requires 1-2 weeks of coordination with the client's IT and security teams. Once deployed, onboarding new applications into the testing engine is faster, but initial infrastructure setup is not a same-day process.
Aikido Machine is designed for regulated industries including financial services (banking, fintech), healthcare and pharmaceutical companies, and defense and government agencies. These verticals have strict data residency and air-gap requirements that prohibit cloud-based security tools. Startups and SMBs without air-gapped networks are not a good fit.
Yes. Aikido Machine tests legacy systems including COBOL alongside modern languages and cloud-native applications. This breadth allows agencies to serve enterprise clients with heterogeneous tech stacks that span decades of code.
Aikido's typical pentest pricing includes a 'no high or critical finding = don't pay' guarantee. If the test uncovers only low or medium severity issues, the client is not charged for that engagement. This risk-sharing model aligns Aikido's incentive with the client's security posture and can be a strong selling point for agencies positioning continuous testing as a retainer.