threat_intelligence1070 wordsRead on Arc Codex

The Aikido Machine: on-prem AI pentesting that never leaves your network

Today we’re launching the Aikido Machine, and welcoming the team that helped build it. Aikido Machine is an on-prem server that runs Aikido Security's AI pentesting and AI Code Analysis (+ many more to come) entirely inside your network: local GPUs, local models, local results. No source code, no repositories, and no prompts ever leave your infrastructure. Some teams can't send their code outside their network For a bank, a government agency, a defense contractor, or a hospital, two things are true at the same time. The first: the pressure keeps climbing. Attackers move faster than ever, and AI has lowered the cost of finding and weaponizing a vulnerability. This isn't hypothetical to regulators. The ECB recently gave 110 banks a four-month deadline to produce action plans against AI-driven cyber threats, while the European Systemic Risk Board raised its systemic cyber risk assessment to "severe" and called the latest models "a paradigm shift for cyber security." Meanwhile the old defenses are showing their age. Signature-based DAST was built for a world where attackers ran scripts. Now attackers run models that understand an application better than a scanner does, and manual pentesting is falling behind too: 51% of CISOs and CTOs say logic flaws, broken access controls and multi-step vulnerabilities are missed always or often. The second: continuous, AI-driven pentesting exists, but up until now it has run in the cloud, meaning these teams within highly-regulated industries couldn’t use it. That's because either internal policy or regulation says that source code, repository data, and prompts can't go to an external cloud or a third-party. The only way to give these teams continuous AI pentesting is to put the whole server, models included, physically inside their network. That's the Aikido Machine. Aikido Security acquires Milou Aikido has been working on building a reliable, state of the art AI pentesting product for a while. To do it locally and deliver a level of excellence that could satisfy the needs of highly complex, regulated organizations, meant we had to think outside of the box. We needed to work with people who live and breathe offensive security and have a proven track record at delivering. And that's why Aikido has acquired Milou to further that mission. Behind the Belgium-based company stand two experienced pentesters and bounty hunters, Tiburce Gridello and Selim Decamps. The goal behind Milou was simple: make pentesters’ lives easier by automating reporting to allow testers to focus on the core job, hacking. We acquired Milou to bring that expertise, and a lot more ambition, to our on-prem work. Since joining, the team has focused on R&D, and testing models on the fastest hardware available to find the best setup for pentesting that runs fully on-device. "Milou was focused on running offensive tooling on local hardware, to be usable in highly regulated environments. Aikido developed the AI pentesting technology to run on it. Aikido Machine puts those two things together for an entire security team to use". Selim Decamps, co-founder of Milou. What on-prem AI pentesting unlocks Aikido Machine is a GPU server that Aikido Security installs, runs, and maintains. Here are the benefits for you: - Everything stays on-prem: Inference runs on Aikido Machine's own GPUs. Nothing you feed it ever touches a cloud provider or an external model. Air-gapped by design, with no internet connection required. - Always on: Run continuous pentests. Local inference means no token or per-pentest fees, so there's no reason for ration testing between engagements. - Complete visibility: With full access to your source code, documentation, and runtime, the Aikido Machine works from context inaccessible to a black-box attacker, and can match or beat a frontier model testing your app from the outside. - A real harness: Single or multi-factor authentication, session handling, a proxy layer, and scope enforcement. That scaffolding is what lets the Aikido Machine test behind real login flows and stay inside the targets you define. - Proof: Every finding comes with a working exploit, so your team can focus on confirmed issues. The Aikido Machine also delivers ready-to-merge pull requests and retesting on the same scope. - Running on day one: An Aikido Security engineer comes on-site, connects power and network, and gets your first pentest going before they leave. AI pentesting and AI Code Analysis are live on the Aikido Machine today, with a lot more of the Aikido Security stack still to come. A European bank with €192.8 billion in assets has already deployed it Belfius, the bank-insurer owned by the Belgian federal government, with €192.8 billion in assets, is among the first to run the Aikido Machine inside its own data centre. More than 200 AI agents now test the bank's systems around the clock, from inside Belfius's own infrastructure. Belfius brings the operational complexity and expertise of a major financial institution to Aikido's technology stack. The bank will help to refine the product to meet strict security and regulatory requirements. "Cybersecurity is no longer a periodic exercise. It has become a continuous mission. By deploying AI agents that test our systems around the clock, we can identify risks faster, strengthen our resilience continuously, and further enhance the trust that millions of customers place in Belfius every day. AI is becoming one of our strongest allies in protecting what matters most." Fabian Delava, Head of Technology at Belfius Why on-prem pentesting matters now AI is simultaneously speeding up software development, while also providing attackers with easier, cheaper ways to target organizations. That means they can do this more frequently. To keep up with this, organizations need to be able to test their systems as often as possible. But we know there is a gap: 76% deploy significant changes weekly or faster, and 21% validate security on every release. Until today, the best AI-driven security testing was only available to teams that could send everything to the cloud. The organizations with the strictest rules, and often the most at stake, were the ones locked out, unless they built their own solution in-house. Aikido Machine closes that gap. A warm welcome to Tiburce and Selim. Bringing AI pentesting on-prem was already underway, and their work provided us with the foundation we needed to deliver a product that is ahead of the curve. If you run security in a heavily regulated industry, and "it can't leave our network" has ended every AI pentesting conversation you've had, it's time to meet Aikido Machine. {{cta}}

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.