Compare
Code-to-cloud security platform with DAST
Aikido is a code-to-cloud security platform: SAST, SCA, secrets, IaC, containers and cloud posture, with DAST and attack surface monitoring on higher plans. Decloak is narrower and sits at the website layer: it scans what a browser sees, including third-party scripts and AI app-builder misconfigurations, and needs no repository access.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Aikido Security: Code-to-cloud security platform with DAST, Belgium
“Not advertised” means we could not confirm the capability from Aikido Security's public website, not that it is absent.
| Capability | Decloak | Aikido Security |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Partial Free plan needs an account: 1 domain, 10 repos |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Yes Free, Basic, Pro and Advanced are listed; Enterprise is custom |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Free; Basic $300/mo; Pro $600/mo; Advanced from $600/mo; Enterprise custom |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes DAST and surface monitoring; attack surface monitoring on Pro and above |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Authenticated DAST |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes Automatic API discovery and scanning |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Yes Attack surface scan covers subdomains |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Partial SSL configuration in the attack surface scan |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Yes SCA for dependencies in connected repositories |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Extra cost AI pentest priced separately; a typical pentest is listed at about €3,500 to $4,000 |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Yes Container and VM scanning |
| Internal network scanning | No External scanning only | Not advertised |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Yes Cloud posture management for connected cloud accounts |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Yes SOC 2, ISO 27001 and HIPAA audit reports; Vanta and Drata integrations |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Partial AI AutoFix for remediation |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Yes Audit-grade reports |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes Jira, Linear, Slack and Microsoft Teams |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Partial REST API on Pro and above; MCP mentioned but not detailed |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Yes SAML SSO on Advanced and above |
Aikido figures come from its public pricing page and are in US dollars, with some pentest figures in euros. Plans include user, repository and domain limits, and Enterprise is custom. Decloak prices are flat monthly plans in GBP.
Decloak scans a URL in about 15 seconds with no sign-up and no code access. Aikido's free plan needs an account and is built around connected repositories.
Decloak renders pages in a real browser and inspects third-party scripts, tag manager containers and every external domain contacted. Aikido does not advertise this layer.
Decloak checks Supabase, Lovable, Base44, Bubble and Next.js apps for readable databases and exposed service keys, on the free tier too.
Decloak Starter is £29/month and Enterprise, with DAST and AI pentesting, is £99/month. Aikido's paid plans start at $300/month.
Aikido includes SAST, SCA, secrets, IaC, container and cloud posture scanning. Decloak is an external scanner and does not read source code or cloud accounts.
Aikido lists Jira and Linear integrations plus GitHub, GitLab and Bitbucket. Decloak has Slack, webhooks and email today; native Jira is planned.
Aikido offers AI AutoFix and an in-app firewall. Decloak reports and explains findings but does not open fix pull requests.
Aikido lists SAML SSO and Vanta and Drata integrations. SSO is only proposed on Decloak's roadmap.
If your main need is checking the live website and its third-party scripts, yes. Decloak is free to try and starts at £29 per month. If you need code, container and cloud scanning, Aikido covers those and Decloak does not.
Not if you use Aikido for source code and cloud scanning. Many teams use a code-to-cloud tool alongside an external website scanner, because they see different layers.
Aikido has a free plan, Basic at $300 per month and Pro at $600 per month, with limits on users, repositories and domains. Decloak is free for single-page scans, then £29, £79 or £99 per month.
Aikido Security details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with Aikido Security. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: