TECH Signal 250
The Aikido Machine: on-prem AI pentesting that never leaves your network
Aikido Security released an on-premises server that runs its AI-driven penetration testing and code-analysis entirely within a customer’s own network.
Teams in regulated sectors such as banking, government, defense, and healthcare can now use continuous AI-powered security testing without violating policies that forbid sending source code or prompts to external clouds. The solution removes the need to balance testing frequency against per-run fees, enabling always-on assessment. It also delivers exploitable findings and ready-to-merge fixes, shortening remediation cycles.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The Aikido Machine hosts GPUs, AI models, and test results on-site, guaranteeing that no code or prompts ever leave the organization’s perimeter.
Continuous testing runs locally with no token or per-pentest charges, and each finding includes a working exploit and an auto-generated pull request.
Deployment requires a dedicated GPU server, on-site installation by Aikido staff, and ongoing hardware or software maintenance.
THE READ
What elseif makes of it.
Aikido Security’s new offering replaces cloud-hosted AI pentesting with a self-contained appliance that performs inference on local GPUs. This shift addresses regulatory mandates that prohibit moving proprietary code or repository data outside protected environments. By keeping the entire AI stack inside the customer’s network, the product sidesteps the compliance hurdles that previously blocked continuous AI testing for highly regulated entities.
The appliance is delivered as a pre-configured GPU server that Aikido engineers install and connect to power and network on the customer site. Once hooked up, the system can launch AI-driven scans continuously, eliminating the need to schedule discrete engagements or manage token-based usage limits. The on-prem design also means the organization retains full visibility into the models, prompts, and results, which is impossible with a black-box cloud service.
From an operational perspective, the machine provides built-in authentication, session handling, proxying, and scope enforcement, allowing it to exercise real login flows and stay within defined target boundaries. Each vulnerability discovered is accompanied by an executable exploit and a ready-to-merge code change, giving development teams concrete remediation steps without additional manual analysis. Early adopters, such as a major European bank, have already integrated the appliance into their security workflow.
Adopting the solution entails purchasing or leasing a GPU-equipped server and entering a service agreement for installation, updates, and support. Organizations must allocate rack space, power, and network connectivity, and they may need to plan for periodic hardware refreshes to keep pace with model performance requirements. The cost model is therefore centered on capital expenditure for the appliance and ongoing maintenance rather than per-test cloud fees.
The appliance’s effectiveness is limited to assets that reside within the protected network; code stored in external cloud repositories or services that require internet access cannot be scanned directly. Additionally, environments lacking sufficient GPU capacity or those that cannot accommodate the physical server will be unable to run the AI models at full speed. Finally, while the system can be updated manually, any need for rapid model upgrades may be constrained by the air-gapped design.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗