The Aikido CSPM homepage
Score7.3
Rank#2 of 34
From$300/mo
Free planYes
Runs onAPI, Linux, macOS, Web, Windows

Summary

Aikido CSPM gives teams a consolidated view of cloud misconfigurations, exposures, overly permissive IAM, and compliance gaps. It connects to cloud accounts through read-only APIs and requires no agents. Listed providers include AWS, Azure, GCP, and select others such as DigitalOcean. Checks look for risks including public storage buckets, unencrypted databases, open SSH ports, and permissive IAM policies. Context-aware scoring is intended to elevate higher-impact production issues over lower-impact staging issues. Cloud Search lets users query cloud resources in plain language, and a search can become a real-time alert for matching assets. For some issues, Aikido offers guided fixes and auto-generated pull requests, but it does not change infrastructure automatically. Scanning features also cover container images, AWS EC2 vulnerabilities, Infrastructure as Code, and outdated runtimes. Checks map to SOC 2 and ISO 27001, and compliance reporting can sync with Vanta and Drata. The free Developer plan includes one cloud account. Basic costs 300.00 USD per month; Pro and Advanced each cost 600.00 USD per month.

Who it is for

It suits teams that need visibility into cloud risks and compliance gaps across multiple cloud environments. The free plan includes one cloud account, while larger listed plans include more accounts and support options.

What is good

  • Connects through read-only APIs without agents
  • Searches cloud resources in plain language
  • Offers guided fixes and generated pull requests
  • Includes IaC and container scanning
  • Free Developer plan includes one cloud account

What to know first

  • Does not automatically change infrastructure
  • Basic costs 300.00 USD per month
  • Enterprise pricing is tailored, with no price listed

Everything Xiaomi review

Aikido CSPM: the full review

Aikido CSPM combines cloud risk visibility, search, and remediation workflows, with scanning beyond configuration checks. The free plan is limited to one cloud account, and automatic infrastructure changes are not included.

Overview

Aikido CSPM brings cloud configuration problems, exposed resources, risky permissions, and compliance gaps into one view. It covers AWS, Azure, GCP, and selected additional providers such as DigitalOcean. The checks include public storage buckets, databases without encryption, open SSH ports, and IAM policies that grant too much access.

Cloud accounts connect through read-only APIs, and Aikido says no agents are required. The deployment model is listed as hybrid. Context-aware scoring helps teams distinguish higher-impact production findings from lower-impact staging issues. Aikido was founded in 2022 and lists its European headquarters in Ghent, Belgium.

CSPM is part of a wider set of security capabilities that also includes container image scanning, AWS EC2 vulnerability scanning, Infrastructure as Code checks, outdated runtime detection, SBOM management, identity risk analysis, and attack path analysis. The breadth may be useful to teams seeking posture checks alongside related cloud and application security work, though the available plan limits and support vary by tier.

Key features

  • Cloud inventory and misconfiguration checks: Maintain an inventory of cloud assets and review common exposure and configuration risks across multiple providers.
  • Risk prioritization: Context-aware scoring elevates higher-impact production issues over less critical staging findings.
  • Cloud Search and alerts: Search cloud resources using plain-language queries, then turn a search into a real-time alert for assets that match.
  • Guided remediation: Aikido offers guided fixes and can generate pull requests for some cloud issues. It says it does not automatically alter infrastructure, and automated remediation is listed as unavailable.
  • Adjacent scanning: The offering describes container image and AWS EC2 vulnerability scanning, Infrastructure as Code checks, and detection of outdated runtimes. IaC scanning, container scanning, and SBOM management are also listed among its capabilities.
  • Compliance: Checks map to SOC 2 and ISO 27001, with compliance reporting that can sync with Vanta and Drata. Listed frameworks also include OWASP Top 10, CIS, NIS2, and PCI.

Aikido's Trust Center lists GDPR, ISO 27001:2022, ISO/IEC 42001:2023, SOC 2, CSA STAR Level 1, TX-RAMP Level 2, and AWS Security Competency. These are company-level security and compliance credentials; they are distinct from the compliance frameworks listed for CSPM checks.

Pricing

The Developer plan is free forever and includes CSPM, one cloud account, two users, 10 repositories, two container images, one domain, 10 AI AutoFixes per month, and 250,000 protected requests per month. This makes the free tier a limited entry point rather than an unrestricted cloud posture plan.

PlanPriceListed limits and features
Developer0.00 USD per freeFree forever; 2 users; 10 repos; 2 container images; 1 domain; 1 cloud account; 10 AI AutoFixes/mo; 250k protected requests/mo
Basic300.00 USD per monthTotal fee includes 10 users; 100 repos; 50 container images; 3 domains; 3 cloud accounts; unlimited AI AutoFixes/mo; 10M protected requests/mo
Pro600.00 USD per monthTotal fee includes 10 users; 200 repos; 100 container images; 10 domains; 10 cloud accounts; 30 VM scaling groups; unlimited AI AutoFixes/mo; 20M protected requests/mo
Advanced600.00 USD per monthTotal fee includes 10 users; 500 repos; 200 container images; 20 domains; 20 cloud accounts; 100 VM scaling groups; unlimited AI AutoFixes/mo; 50M protected requests/mo
EnterprisePrice not listedTailored pricing; Enterprise-grade modules

The Pro plan includes same-day support. Advanced includes priority support in Slack or MS Teams. The listed prices are total monthly fees for the paid plans, with 10 users included.

Platforms

Listed platforms are API, Linux, macOS, web, and Windows. The service connects to cloud accounts through read-only APIs and is described as using a hybrid deployment model.

Who it's for

Aikido CSPM may suit teams managing resources across several cloud providers that want configuration checks, asset inventory, identity risk analysis, and compliance reporting in a shared workflow. Its production-versus-staging prioritization and search-based alerts are relevant when teams need to sort findings by context and monitor for matching assets.

The free Developer tier provides one cloud account, while the paid plans list progressively higher account and workload limits. Teams needing automatic infrastructure changes should note that Aikido describes guided fixes and generated pull requests instead, and says it does not automatically change infrastructure.

Pros and cons

  • Pros: Multi-cloud coverage includes AWS, Azure, GCP, and selected other providers; read-only API connections require no agents; checks span misconfiguration, identity, IaC, containers, and compliance; plain-language search can become real-time alerts; guided fixes and pull requests are available for some issues.
  • Cons: The free plan is limited to one cloud account; automatic remediation is not offered; the Enterprise price is not listed; several capabilities are presented as part of a broader platform, so plan-specific availability should be confirmed where it matters.

Alternatives

For a wider comparison of posture tools, see Cloud Security Posture Management Software. Teams evaluating adjacent development-security categories can also browse DevSecOps Platforms and Infrastructure as Code Security Software. The supplied alternative apps are HCL AppScan, New Relic IAST, DongTai IAST, Contrast Assess, Veracode DAST, NowSecure Platform, Waratek IAST, and Acunetix; these are IAST or DAST-oriented names, rather than a directly specified CSPM comparison set.

Verdict

Aikido CSPM's strongest fit is teams that want cloud posture checks joined with inventory, contextual prioritization, search and alerting, and related scanning capabilities. Read-only connections and a free plan with CSPM lower the barrier to evaluating its scope, while account limits and plan-based workload allowances shape how far that tier can go. Its remediation is guided rather than automatic, an important distinction for teams expecting infrastructure changes to happen without review.

Aikido CSPM plans and pricing

All plans
Developer Free free forever; includes 2 users 10 repos · 2 container images · 1 domain · 1 cloud account · 10 AI AutoFixes/mo · 250k protected requests/mo aikido.dev · 28 Sept 2026
Basic $300/mo total fee (incl. 10 users) 100 repos · 50 container images · 3 domains · 3 cloud accounts · unlimited AI AutoFixes/mo · 10M protected requests/mo aikido.dev · 28 Sept 2026
Pro $600/mo total fee (incl. 10 users) 200 repos · 100 container images · 10 domains · 10 cloud accounts · 30 VM scaling groups · unlimited AI AutoFixes/mo · 20M protected requests/mo aikido.dev · 28 Sept 2026
Advanced $600/mo total fee (incl. 10 users) 500 repos · 200 container images · 20 domains · 20 cloud accounts · 100 VM scaling groups · unlimited AI AutoFixes/mo · 50M protected requests/mo aikido.dev · 28 Sept 2026
Enterprise Not published tailored pricing Enterprise-grade modules aikido.dev · 28 Sept 2026

Compared on cloud security posture management software

Free plan
Yesaikido.dev
Multi-cloud support
Yesaikido.dev
Cloud asset inventory
Yesaikido.dev
Compliance frameworks
SOC 2, ISO 27001, OWASP Top 10, CIS, NIS2, PCIaikido.dev
IaC scanning
Yesaikido.dev
Identity risk analysis
Yesaikido.dev
Attack path analysis
Yesaikido.dev
Automated remediation
Noaikido.dev

Facts

What it does
Aikido CSPM provides a unified view of cloud misconfigurations, exposures, overly permissive IAM, and compliance gaps across cloud environments.aikido.dev · 28 Sept 2026
Cloud providers
The CSPM page lists AWS, Azure, GCP, and select other providers such as DigitalOcean.aikido.dev · 28 Sept 2026
Agentless access
Aikido connects to cloud accounts through read-only APIs and says it requires no agents.aikido.dev · 28 Sept 2026
Misconfiguration checks
Checks cover risks such as public storage buckets, unencrypted databases, open SSH ports, and overly permissive IAM policies.aikido.dev · 28 Sept 2026
Risk prioritization
Context-aware scoring prioritizes higher-impact production issues over lower-impact staging issues.aikido.dev · 28 Sept 2026
Cloud search and alerts
Cloud Search supports plain-language queries across cloud resources, and searches can become real-time alerts for matching assets.aikido.dev · 28 Sept 2026
Remediation
Aikido provides guided fixes and auto-generated pull requests for some cloud issues, while stating it does not automatically change infrastructure.aikido.dev · 28 Sept 2026
Scanning features
The CSPM offering also describes container image scanning, AWS EC2 vulnerability scanning, Infrastructure as Code checks, and outdated runtime detection.aikido.dev · 28 Sept 2026
Compliance and integrations
The CSPM page says checks map to SOC 2 and ISO 27001 and that compliance reporting can sync with Vanta and Drata.aikido.dev · 28 Sept 2026
Free tier limits
The Developer plan is free forever, includes one cloud account, and lists CSPM among its cloud features.aikido.dev · 28 Sept 2026
Paid tier support
The Pro plan includes same-day support, while Advanced includes priority support in Slack or MS Teams.aikido.dev · 28 Sept 2026
Security and compliance
Aikido's Trust Center lists GDPR, ISO 27001:2022, ISO/IEC 42001:2023, SOC 2, CSA STAR Level 1, TX-RAMP Level 2, and AWS Security Competency.trustcenter.aikido.dev · 28 Sept 2026
Company
Aikido says it was founded in 2022 and lists its European headquarters in Ghent, Belgium.aikido.dev · 28 Sept 2026

Company

Founded
2022aikido.dev · 28 Sept 2026
Headquarters
Ghent, Belgiumaikido.dev · 28 Sept 2026

Best Aikido CSPM alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Aikido CSPM yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources