Aikido buys Root to patch open-source flaws without forced upgrades
What's the deal? Belgian cybersecurity firm Aikido Security has acquired Root.io, a startup that patches vulnerable open-source software at the exact versions companies already run.
Root uses what it calls agentic vulnerability remediation. When a new flaw appears, swarms of AI agents research, write, test, and ship a patch in 15 to 40 minutes — work that takes weeks by hand.
The fixes go straight into the container images and dependencies a company already runs, with no rebuild or migration.
Why now? Most teams face a bad choice when a dependency turns vulnerable: upgrade and risk breaking the app, or migrate to a vendor's locked-down replacement.
Root sidesteps both. Aikido is folding the technology into its platform as a feature called Aikido Libraries, which generates hundreds of verified patches a day.
"Open source needs patching and it needs it fast," said co-founder and chief executive Willem DelbareDealroom has a profile for this one. Try Dealroom →. "We fix what teams are actually running: no upgrades, no migrations, no breaking changes."
Founded in 2020 as Slim.AI, Root had raised $37.6 million, including a $31 million Series A in 2022 co-led by Insight Partners and StepStone Group.
What could go wrong? In more than four out of five cases, Root makes no code changes at all, leaving a human reviewer to sign off rather than write the patch.
That speed depends on trust. Shipping AI-generated fixes into production at scale leaves little room for error if a patch slips through.
One early customer, data security firm BigID, cleared more than 1,000 vulnerabilities — over 300 rated high or critical — across six production images in two weeks without abandoning its Debian and Ubuntu stacks.
The signal: The deal caps a busy run for Aikido, which bought AI code-review startup Trag and penetration testing firms Allseek and Haicker in 2025, then raised $60 million in a January Series B.
Aikido also plans to back-port fixes for actively exploited open-source flaws to the wider community, contributing patches upstream rather than locking them behind a paywall.
Gartner this year named Root an emerging vendor in automated vulnerability remediation — a sign the category is heating up as AI agents move from writing code to securing it.
Read more: SiliconANGLE