Aikido Security acquires Root to automate open-source patching

The Belgian cybersecurity unicorn will use Root's agentic patching technology to fix open-source vulnerabilities without breaking changes or forced upgrades.

Aikido Security acquires Root to automate open-source patching

Aikido Security, the Ghent-based cybersecurity company that reached unicorn status earlier this year, has acquired Root, the automated vulnerability remediation startup formerly known as Slim.AI. The deal unites Aikido's developer-focused security platform with Root's agentic patching engine, which the company says can research, patch, test and deliver validated fixes across container images and application dependencies in minutes rather than weeks.

The combined offering, branded as Aikido Libraries, targets what both companies describe as a broken status quo in open-source security: organisations must either upgrade a dependency and risk breaking their application, or leave known vulnerabilities unpatched. Root's approach generates what Aikido says are hundreds of verified patches a day, applying fixes directly to the version a team is already running rather than forcing a migration to a newer release.

The deal

Root was founded by Ian Riopel, John Amaral, Benji Kalman and Mickey Gordon, and traces its origins to the Slim Toolkit (formerly DockerSlim), a widely used open-source container optimisation tool. The company is backed by Insight Partners, Decibel Ventures, Boldstart Ventures, Lama Partners and TechAviv. Insight Partners co-led Root's $31 million Series A in 2022. Aikido did not disclose acquisition price or terms.

Willem Delbare, co-founder and chief executive of Aikido, said the acquisition addresses a supply chain security problem that conventional tooling has failed to crack. "We fix what teams are actually running, generating hundreds of verified patches a day: no upgrades, no migrations, no breaking changes. That's how supply chain security gets solved for everyone, not just the 1%."

Aikido also announced that it will make backported fixes for critical, actively exploited open-source vulnerabilities freely available to the community across supported ecosystems, rather than restricting them to paying customers. Adrian Estrada, CTO of NodeSource and an OpenJS Board Director, welcomed the move, noting that open-source maintainers are "drowning in security work" and that upstream contributions from vendors help relieve the burden.

This acquisition follows three others in 2025: AI code-review startup Trag and autonomous penetration-testing companies Allseek and Haicker. Aikido said it became the fastest European cybersecurity company to reach unicorn status after closing a $60 million Series B at a $1 billion valuation earlier in 2026.

Market context

Supply chain security has become one of the most active sub-categories in cybersecurity after a series of high-profile incidents, including the 2021 Log4Shell vulnerability in Log4j, which the release notes still runs in millions of systems today. Attackers are increasingly hiding malware inside open-source packages, and Aikido's release cites data suggesting roughly a third of known vulnerabilities are now exploited on or before the day of public disclosure, a trend the company attributes partly to AI-assisted attack tooling.

The automated vulnerability remediation market is beginning to attract analyst attention. Gartner recognised Root as an emerging technology vendor in this category earlier in 2026. Established players in adjacent software composition analysis and developer security tooling include Snyk, Mend (formerly WhiteSource) and GitHub's Dependabot. Aikido's acquisition strategy appears aimed at building an end-to-end platform that spans detection and remediation, differentiating from point solutions that surface CVE lists without resolving them.

The EU Cyber Resilience Act, which will begin to apply from late 2027, will require software vendors placing products with digital elements on the European market to address known vulnerabilities in a timely manner. Aikido's Ghent base puts it directly in scope, and an automated patching capability could become a compliance differentiator for European software teams navigating that requirement.