For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/cloud/is-aikido-a-cspm.md.
Cloud Security ↗

Is Aikido a CSPM? Yes, and here is what it covers

Aikido has a cloud posture management module for AWS, Azure and Google Cloud. Here is what it checks and where the scope ends.

Aikido logo and CSPM, FM CyberSecurity branded cover

Yes. Aikido includes a cloud security posture management module, and it is one module inside a wider application security platform rather than a standalone cloud posture product. That difference decides whether it fits the requirement list you are holding.

I get this question in most Aikido scoping calls, usually from someone reading a security questionnaire with CSPM written in one of the rows.

What people are buying when they ask for a CSPM

Cloud security posture management means continuous checking of how cloud accounts are configured, with alerts on risky settings so someone can fix them. CISA built the posture management part of its Cloud Security Technical Reference Architecture around that idea: watch the cloud accounts, find configuration that could lead to a breach or data loss, report it.

In a buying conversation it usually comes down to four answers. Which storage is public. Which identities carry far more permission than the job needs. Which databases run unencrypted. And what you hand an auditor who asks how cloud settings get checked.

What Aikido’s cloud posture module checks

Aikido’s Cloud Posture Management module reads cloud configuration through an API and reports misconfiguration, overly permissive IAM and compliance gaps. Aikido describes the connection on its own CSPM product page as read-only and agentless, set up with minimal permissions.

The findings it names there are the ones a buyer expects on the list: public S3 buckets, unencrypted databases, open SSH ports, IAM policies that grant more than the role needs, resources deployed outside allowed regions, and out-of-support runtimes across container base images, AWS Lambda, Elastic Beanstalk and Kubernetes. Aikido states that each check maps to SOC 2 and ISO 27001, and that results sync to compliance platforms including Vanta and Drata.

You can connect AWS, Azure and Google Cloud. Aikido’s connection documentation also lists DigitalOcean, Supabase, Alibaba Cloud, Oracle Cloud and Render.

Where cloud posture sits next to the rest of the platform

The cloud module answers what is running now. The scanners next to it answer how it got that way, which is why we rarely look at cloud findings on their own.

IaC scanning reads Terraform, CloudFormation and Kubernetes manifests before anything reaches an account, so a public bucket can be caught in a pull request rather than in production. Container image scanning covers the base images those workloads run on. When the cloud module reports an out-of-support runtime on a live service, the fix usually belongs in the image or the manifest, not in the cloud console.

Our product documentation lists 18 Aikido modules. Cloud posture is one of them.

Where the scope ends

Aikido reads cloud configuration, and it does not run an agent inside your cloud workloads. Configuration and asset inventory come back. Process-level telemetry from a running server does not. Workload runtime detection on cloud servers is a separate control, worth naming before you compare quotes.

Aikido’s help documentation covers eight scanner areas, and cloud infrastructure entitlement management (CIEM) and data security posture management (DSPM) are not among them. If a line in your requirement list names those categories, settle it before you sign anything.

Remediation runs through review. Aikido generates guided fixes and pull requests for findings such as Terraform misconfiguration and vulnerable base images, and a person approves the merge. It does not change cloud infrastructure by itself.

How we run it at FM CyberSecurity

FM CyberSecurity is a certified Aikido partner and operates the platform for customers. We connect the cloud accounts, tune what gets reported, and route findings to whoever owns the fix. Those findings usually land with the team that owns the accounts rather than with security alone, and that handover is most of the first month’s work. The reasoning behind choosing Aikido at all is written up in why Aikido is our only pentest provider.

If you are holding a requirement list with CSPM on it, send it to Christian Vik. We mark it line by line: covered by the cloud module, covered by another Aikido scanner, or not covered.

FAQ

Is Aikido a CSPM?

Yes. Aikido includes a Cloud Posture Management module that scans cloud accounts for misconfiguration, overly permissive IAM and compliance gaps. It sits inside a wider platform that also scans source code, open source dependencies, containers and infrastructure as code, so CSPM describes one module rather than the whole product.

Does Aikido replace a dedicated cloud posture tool?

It depends on the requirement list. For misconfiguration detection, IAM findings and SOC 2 or ISO 27001 mapping across AWS, Azure and Google Cloud, the cloud module covers the ground. For agent-based workload runtime detection, entitlement management or data classification, Aikido does not document those as modules, so plan a separate control.

Does Aikido need an agent in our cloud?

No. Aikido connects through a read-only API and describes the setup as agentless with minimal permissions. Nothing gets installed on your instances, which is also why the cloud module reports on configuration rather than on what a process is doing at runtime.

Can we use Aikido findings as ISO 27001 evidence?

Partly. Aikido maps each cloud check to SOC 2 and ISO 27001, which gives you technical evidence for cloud configuration controls. The management system still has to be built: policies, risk assessment and internal audit. That part is where our compliance consultants work.

Drafted with AI assistance, reviewed and edited by Christian Vik and the FM CyberSecurity editorial team.

← Back to all insights
Questions or inquiry? [email protected] Contact us →