The One-Line Difference
Aikido is an all-in-one AppSec dashboard - SAST, SCA, secrets, IaC, container and cloud posture scanning, plus a web/API AI pentest - sold as flat-rate SaaS with automated validation on every finding.
Lory is an AI pentester that runs full engagements across web, API, mobile, network, cloud, and source code, where a named Lorikeet Security pentester reads the evidence and signs every finding before it reaches you.
They overlap on one surface - web and API - and diverge everywhere else. Aikido's strength is breadth of static and dynamic scanning in a single developer-facing dashboard at a published, flat price. Lory's strength is depth of active testing across a wider estate, with a human accountable for every result.
At a Glance
| Dimension | Aikido Security | Lory by Lorikeet |
|---|---|---|
| Model | Flat-rate ASPM/CSPM platform with an AI pentest module | On-demand or repeating AI pentester engagements |
| Time to first result | Under 30 seconds after connecting a repo (static scans) | Immediately on request, or automatically on a schedule |
| AI pentest scope | Web apps and APIs only | Web, API, mobile, network (internal and external), cloud, source code |
| Validation model | Automated re-checks to rule out false positives and hallucinations | Automated evidence, then a named human pentester signs every finding |
| Exploit chaining | Pauses before escalating further unless you opt in | Chains a finding through to what it actually unlocks, as part of the signed report |
| Static analysis (SAST/SCA/secrets/IaC) | 15+ scanners in one dashboard, mature and dedicated | Included as one engagement type (secret hunting, sink tracing, supply chain), not a dedicated multi-scanner suite |
| Cloud | CSPM (configuration posture), not an active pentest | Active cloud pentest - IAM, metadata paths, privilege escalation |
| Pricing | Published flat rate: free, $300/mo, $600/mo | Prepaid credits, itemised quote within 24 hours |
| Compliance reporting | Audit-ready SOC 2 / ISO 27001 PDF in hours | CWE plus control mapping across 7 frameworks |
| Machine-readable output | Not published for the pentest module specifically | SARIF 2.1.0, GitHub code scanning, MCP |
| Coverage record | Not published | Vectors planned, run, and never reached, with the reason attached |
| Recurring coverage | Continuous scanning is the default model | Weekly, biweekly, monthly, quarterly, or yearly, queued and started automatically |
Coverage, Side by Side
| Asset Type | Aikido | Lory |
|---|---|---|
| Web app | Yes, AI Pentest | Yes |
| API | Yes, AI Pentest | Yes, crawl, auth testing, injection, access control |
| Mobile | Roadmap item, not shipped | Yes, iOS and Android plus their backends |
| Network, external | Not offered | Yes, services, versions, exposure |
| Network, internal | Not offered | Yes, via the mesh connector |
| Cloud (active pentest) | Not offered (CSPM posture scan only) | Yes, AWS, Azure, GCP, Kubernetes, containers, serverless |
| Source code / SAST / secrets / SCA | Yes, 15+ dedicated scanners, mature | Yes, one engagement type covering secrets, sink tracing, and supply chain |
| Physical | Not offered | Human-led, never run by Lory |
If everything you need to test is a web app or API, Aikido's AI Pentest reaches the same surface Lory does, just without a human signature on the result. Once mobile, network, or an active cloud pentest enters the picture, Aikido's own materials list those as roadmap items rather than shipped capability - check what has actually landed before assuming otherwise, since AppSec vendors in this space ship fast.
Where Aikido Differentiates
- Genuinely broad static coverage in one place. SAST, SCA, secrets detection, IaC scanning, container scanning, and CSPM sit in a single dashboard rather than five separate tools with five separate logins.
- Fast, self-serve, and cheap to start. A free tier and a published $300-$600/month price mean a small team can be scanning inside minutes, no sales call required - a real advantage over Lory's quote-based, credit-funded model for a team that just needs baseline SAST/SCA coverage.
- Restraint by design. Aikido's AI Pentest pauses before chaining an exploit further unless you explicitly opt in. That's a thoughtful safety posture, and one worth crediting regardless of who's building the comparison.
- Built into the developer's existing loop. One-click pull requests for remediation and inline findings in the tools engineers already use lower the bar to actually fixing what's found.
- Fast audit paperwork. A SOC 2 or ISO 27001-ready PDF in hours is a meaningful head start for a team facing its first audit.
Where Lory Differentiates
- A human signs every finding. Aikido's validation step rules out false positives and hallucinations automatically; it is not a named person reading the evidence and standing behind the result the way every Lory finding requires.
- Covers what Aikido's AI Pentest doesn't yet. Mobile apps, external and internal network, and an active cloud pentest that chains privilege escalation - not a config posture scan - are all in scope for Lory today.
- Cross-surface chains. Because one engagement can span code, cloud, and network, a finding can show the path from a leaked secret in a repo to what it actually unlocks in production - a chain that a code-only or app-only scanner can't demonstrate on its own.
- A coverage record. Every run reports which vectors were planned, run, and never reached, and why - useful for an auditor or a customer who wants to know what "clean" actually covered.
- Scope as an enforced gate. Every tool call is checked against a signed allowlist of targets and rules of engagement before it fires.
Picking Between Them
- Your scope is web apps and APIs, and you want SAST/SCA/secrets/IaC coverage in the same place
- You want self-serve pricing and results in minutes, not a scoped quote
- You need fast, automated audit-ready reports for SOC 2 or ISO 27001
- You don't need mobile, network, or active cloud exploitation testing right now
- You need mobile, network, or an active cloud pentest alongside web and API
- You need a named person to stand behind every finding for a customer, auditor, or board
- You want a written record of what wasn't tested, not just what was
- You want a scheduled, recurring engagement across your whole estate under one credit balance
Plenty of teams run both: Aikido in the CI pipeline catching issues on every commit, Lory for the signed engagement that goes in front of a customer or auditor.
See a Signed Engagement in Action
Book a scoping call and we'll walk you through what a Lory engagement covers beyond web and API - mobile, network, cloud, and source code - and how a named pentester signs off before anything reaches your report.
Book a Consultation