Deals
AICybersecuritySaaS

Aikido acquires Root to backport open source fixes without forcing upgrades

Aikido acquires Root to backport open source fixes without forcing upgrades
TypeAcquisition
Value$70M
  • Aikido SecurityAcquirer

Aikido Security has agreed to acquire Root for $70 million, integrating Root’s vulnerability‑patching tech into a new Aikido Libraries product that backports fixes without forcing upgrades.

Deal Terms

Aikido Security announced on June 30, 2026 that it will acquire Root for $70 million. The transaction folds Root’s automated patch‑backporting technology into a new offering called Aikido Libraries, and includes a commitment to backport critical fixes for actively exploited vulnerabilities to the open‑source community for free across npm, PyPI, Maven and other ecosystems.

Strategic Rationale

The acquisition closes the gap between Aikido’s existing detection capabilities—code scanning, cloud security, supply‑chain malware detection, and AI‑powered penetration testing—and the remediation step that many customers struggle to automate. By embedding Root’s ability to patch known flaws directly into the version a team already runs, Aikido can address mounting compliance pressure to remediate CVEs, especially those on the CISA Known Exploited Vulnerabilities (KEV) list. The free backporting commitment is positioned as a public‑good service that sits alongside Aikido’s paid long‑tail CVE remediation, allowing the company to monetize the broader vulnerability surface while supporting the open‑source ecosystem.

Aikido, a Belgian‑based unicorn that raised $60 million at a $1 billion valuation in January, is on its fourth acquisition in just over a year, signaling an aggressive build‑out of end‑to‑end security capabilities. Root, founded in 2021 as Slim.AI and backed by a $31 million Series A in 2022, pivoted from container optimization to automated vulnerability remediation before rebranding. Its core tech patches known vulnerabilities into the exact open‑source package version a team uses, avoiding costly upgrades or migration to vendor‑locked ecosystems.

The deal arrives amid heightened AI‑driven security activity, including the Linux Foundation’s launch of Akrites, a coordinated vulnerability disclosure body backed by major AI players. Aikido’s leadership says the timing is coincidental but underscores that AI is making large‑scale, human‑verified patching feasible. By combining detection, AI‑enhanced triage, and now automated backporting, Aikido aims to become a one‑stop shop for developers who need both visibility and rapid remediation.

Overall, the $70 million acquisition expands Aikido’s product stack, deepens its foothold in the open‑source supply‑chain market, and creates a clear differentiation from competitors that bundle fixes behind proprietary ecosystems.

For Aikido, the Root acquisition adds a remediation layer that directly addresses the most painful part of the vulnerability lifecycle—triage and patch deployment. By offering free backports for CISA‑listed exploits, Aikido can attract security‑focused enterprises that need to meet regulator‑driven CVE remediation timelines while still upselling its paid long‑tail coverage. Competitors such as Snyk or GitHub Advanced Security, which rely on customers upgrading to newer package versions or purchasing separate remediation tools, may find their value proposition eroded as Aikido delivers fixes in‑place.

Root’s technology also strengthens Aikido’s position in the open‑source supply‑chain arena, a segment where many vendors still struggle to balance security with developer friction. The free‑backport commitment could set a new industry baseline, pressuring rivals to either open their own patch pipelines or risk losing market share among teams that prioritize minimal disruption. In the longer term, the combined platform may command higher gross margins as automated remediation reduces manual effort and drives subscription stickiness.

  1. Aikido Security is acquiring Root for $70 million.
  2. The deal creates a new product, Aikido Libraries, that backports critical fixes without forcing upgrades.
  3. Aikido commits to providing free backports for vulnerabilities on the CISA KEV list across major ecosystems.
  4. Root, formerly Slim.AI, raised a $31 million Series A in 2022 before pivoting to automated remediation.
  5. The acquisition is Aikido’s fourth in just over a year as it builds an end‑to‑end security platform.

The $70 million price tag, while undisclosed in terms of Root’s ARR, suggests Aikido is willing to pay a premium for a technology that closes the remediation gap in the SaaS security stack. In a market where security‑focused SaaS firms typically command 8‑12 times revenue multiples, the deal hints at a valuation that could be justified by the potential to upsell existing Aikido customers on a higher‑margin, automated patching service. The move also reflects a broader industry shift toward AI‑enabled end‑to‑end vulnerability management: detection, prioritization, and now rapid, in‑place fixing. As regulators tighten CVE remediation requirements, platforms that can automate compliance while minimizing developer disruption are likely to see accelerated adoption and pricing power. Investors may view Aikido’s strategy as a play for market share in the open‑source supply‑chain security niche, where the combination of AI triage and backporting could create defensible recurring revenue and higher gross margins. The acquisition underscores the growing appetite for integrated security suites that reduce the operational overhead of patch management, positioning Aikido as a potential acquisition target for larger cloud or security conglomerates seeking a complete vulnerability lifecycle solution.

Aikido acquires Root to backport open source fixes without forcing upgradesthenewstack.io