Aikido acquires Root to patch open-source software without forced upgrades
Aikido Security acquires Root.io to integrate its unique open-source patching technology, allowing organizations to fix vulnerabilities without forcing version upgrades.

Signal Snapshot
Briefing Notes
What happened and why it matters
Aikido Security Strengthens Supply Chain Defense with Root.io Acquisition
Summary
Belgian cybersecurity firm Aikido Security NV has officially acquired Root.io Inc., a startup specializing in non-disruptive patching for open-source software. This strategic move integrates Root’s unique technology into Aikido’s platform, allowing enterprises to remediate vulnerabilities in their dependency trees without being forced to upgrade to new, potentially incompatible versions. Root.io, originally founded in 2020 as Slim.AI Inc., gained traction with its Slim Toolkit before rebranding to focus on its core patching innovation.
Why it Matters
The acquisition addresses a critical pain point in modern software development: the tension between security and stability. Traditionally, when a vulnerability is discovered in an open-source library, the standard response is to upgrade to a patched version. However, major version upgrades can introduce breaking changes, require extensive regression testing, and delay product releases. Root.io’s approach decouples security from versioning. By applying patches directly to the specific version currently in use, organizations can close security gaps immediately without the operational overhead and risk associated with upgrading. For Aikido, this enhances its value proposition as a comprehensive application security posture management (ASPM) provider, offering a more flexible and less intrusive path to compliance and security.
Related tools
Impact on AI tools/models
While this news primarily targets traditional software supply chains, the implications extend to AI tooling and model deployment. Modern AI applications rely heavily on open-source frameworks (like PyTorch, TensorFlow, and various Python libraries). Vulnerabilities in these underlying dependencies can compromise the integrity of AI models and the data they process. By enabling seamless patching of these foundational layers, Aikido helps ensure that AI infrastructure remains secure against supply chain attacks without requiring disruptive overhauls of the AI development environment. This stability is crucial for maintaining trust in AI-driven systems and ensuring continuous operation of machine learning pipelines.
What to watch
As the integration of Root.io’s technology proceeds, stakeholders should monitor how Aikido positions this capability within its broader security suite. Key areas to observe include:
- Adoption Rates: How quickly enterprises will shift from traditional upgrade-based patching to Root’s version-preserving method.
- Competitive Landscape: Other players in the AI news sector may accelerate similar acquisitions to address supply chain risks.
- Platform Updates: Check the latest rankings for ASPM tools to see if Aikido’s market position improves following this integration.
- Developer Experience: Assess whether the new patching mechanism introduces any latency or complexity in CI/CD pipelines.
For more insights on emerging security technologies, explore our coverage of ToolSeekAI tools dedicated to supply chain defense.
FAQ
Q: What problem does Root.io solve? A: It solves the risk and effort associated with upgrading open-source libraries by patching vulnerabilities at the current installed version.
Q: Is Root.io still available as a standalone product? A: Following the acquisition, Root.io’s technology is being integrated into Aikido Security’s platform.
Q: Who founded Root.io? A: The company was founded in 2020 as Slim.AI Inc. and later rebranded to Root.io.
Search FAQ
Frequently asked questions
FAQ
What does Root.io's technology do?
Why did Aikido acquire Root.io?
What was Root.io previously known as?
Keep Tracking
Related AI news

On theCUBE Pod: IBM’s AI test, Nvidia’s lead and the race for enterprise intelligence
IBM tests enterprise AI while Nvidia dominates accelerated computing. AMD and Broadcom vie for market share as the race for enterprise intelligence intensifies across hardware and software layers.

Hugging Face uses open-weights Z.ai GLM 5.2 to battle attacker after commercial frontier model refusal
Hugging Face detected a breach involving an attacker using agentic AI. Commercial frontier models blocked defensive requests due to strict safety guardrails. Hugging Face responded by deploying the open-weights Z.ai GLM 5.2 to counter the threat.

Anthropic settles with authors and publishers for $1.5B in landmark copyright case
Anthropic agrees to a $1.5 billion settlement with authors and publishers regarding the unauthorized use of creative works to train its Claude AI model, marking the largest copyright settlement in history.

Exclusive: Speakeasy service tracks enterprise-wide AI agent spending
Speakeasy Development Inc. launched an AI cost-management service to track enterprise spending on coding agents like Claude Code, Cursor, and Codex by consolidating token usage data for financial oversight.

AI materials science startup CuspAI raises $450M in funding
UK-based AI materials science startup CuspAI secures $450M Series B funding at a $2.6B valuation, backed by Kleiner Perkins and NEA to support a chemical research consortium with Nvidia and Samsung.

Block launches Buzz, an open-source workspace for humans and AI agents
Block Inc. launched Buzz, a free open-source workspace for human-AI collaborative teams. It unifies chat, code hosting, and workflows while granting AI dedicated accounts.
Site Discovery
Keep exploring the AI ecosystem
After this brief, continue into related tools, models, and rankings to understand whether the story affects your choices.