Aikido Security, the Belgian cybersecurity startup, has just launched Aikido Machine: a server with its own GPUs that runs autonomous AI-powered pentesting entirely inside the customer's data center. No code, documentation, or results ever leaves your network. fuubo is Aikido's partner in the region, and it is worth explaining what this tool is and what it means for regulated companies in Chile and Latin America.
The problem it solves
Attackers are already using AI to find and exploit vulnerabilities faster and more cheaply than ever. Meanwhile, much of the defense still relies on tools built for a different era: signature-based scanners that do not understand application logic, and manual pentesting scheduled once or twice a year (while software ships every week).
The gap between how fast companies release changes and how often they actually validate their security has become the norm, not the exception.
For banks, insurers, healthcare companies, and the public sector, the problem has an extra layer: most AI-powered pentesting available today runs in the cloud. And there, source code, repositories, and sensitive data simply cannot go, whether due to internal policy or direct regulation. Until now, that constraint left them out of the conversation.
What Aikido Machine actually is
It is a physical server (4U form factor with enterprise-grade GPUs) that Aikido installs, operates, and maintains directly inside the customer's data center. It runs the full AI pentesting and code analysis stack locally: proprietary models, on-premise inference, and results that never touch an external provider.
In practical terms, the solution works like this:
- White-box testing: agents work with full access to source code, documentation, and the execution environment.
- Real application map: they identify roles, data flows, trust boundaries, and every possible entry point.
- Real exploits: they chain findings such as broken access control, IDORs, and multi-step logic flaws that traditional scanners miss.
- Immediate remediation: every finding comes with the trace proving the exploit works, a pull request ready to apply the fix, and a button to retest and confirm the issue is closed.
The server can also operate fully air-gapped (no internet connection) or with a single authorized domain for updates. It covers modern languages and legacy stacks including COBOL, which is critical for banking and public sector institutions.
Its commercial model is a fixed annual fee covering hardware, software, support, and GPU replacement if one fails. There are no per-pentest or per-token charges, because all inference is local.
The technology behind the product
Behind this development is the acquisition of Milou, a team of pentesters and bug hunters specialized in offensive tools for local hardware.
The first deployment is already in production: Belfius, the Belgian government's bank-insurer with more than €190 billion in assets, has over 200 AI agents testing its systems around the clock from within its own infrastructure. Aikido also closed a Series B round in early 2026 led by DST Global, valuing the company at one billion dollars and making it the fastest European cybersecurity startup to reach that milestone.
Why it matters for regulated companies in Latin America
In our experience with regulated companies in the region, the main barrier to adopting advanced AI is rarely the software's capability. The real bottleneck is operational: what happens after installation? Continuous pentesting only works if the security team knows how to absorb that volume of findings, prioritize fixes, and integrate it into their workflows without disrupting operations or conflicting with local regulatory requirements.
That is the value of this combination. Aikido delivers the technical capability to test your systems 24/7 in a fully local environment; fuubo provides the strategic accompaniment to turn that capability into a mature, governed, and sustainable practice within your organization. For an institution that needs this level of testing without exposing its code, this combination addresses a problem that until now had no complete solution in the region.
If your company is evaluating on-premise AI security tools, we can help you assess whether it makes sense and how to implement it.



