Vulnerability management results from Aikido are available in Kertos as evidence for ISO 27001, SOC 2, and NIS2. Beyond the integration, Kertos and Aikido have been selling their platforms together since September 2026.
Munich, September 22, 2026 — Kertos, the leading European Compliance-as-a-Service partner and Aikido Security, a software security platform, today announced their strategic partnership. By integrating their products, the technology partners aim to combine security risk management with compliance automation and help IT teams meet requirements like ISO 27001, SOC 2, and NIS2 without the manual work of proving it.
ISO 27001 and the EU's NIS2 directive both expect companies to show that they find and fix security weaknesses in their software, and to keep showing it between audits. Development teams already produce that proof every day, inside the tools they work in. Until now, getting it into the compliance record has meant copying it across by hand. The new integration carries it across to where customers document their compliance. "Evidence comes into being where the work happens, not in a spreadsheet somebody fills in three weeks before the audit," said Dr. Kilian Schmidt, Co-Founder and CEO of Kertos.
Aikido Security runs a security platform for development teams. It checks their code, cloud setup, and running applications for security problems, ranks those problems by how much risk each one really carries, and helps developers fix them. The records those checks leave behind are what auditors ask to see. "Developers fix security issues where they find them, in the code and in the pipeline," said Eric Gallegos, Head of Tech Alliances at Aikido Security.
Setting it up takes one connection. Kertos then reads the security findings from Aikido along with the deadlines the customer has set for fixing them and checks daily whether anything has passed its deadline. If nothing has, the check passes, and Kertos files that result as audit evidence against the ISO 27001 requirements for vulnerability management, secure development, and security testing. The connection is read-only, so it changes nothing in Aikido, and it refreshes once a day in the background or on demand.
For customers, this removes a recurring task. Showing an auditor that security issues get fixed on time has meant collecting screenshots and chasing colleagues across three teams. The answer is now already on file, and it is a pass or a fail rather than a spreadsheet of raw scan results.
Together, the two platforms cover the entire process from finding a security weakness to proving it was dealt with. Aikido does the finding and fixing inside the workflow developers already use. Kertos turns the result into the evidence an auditor, a procurement team, or a regulator asks for, and keeps it current between audits. Where both platforms are used together, the handover between the security work and the compliance record stops being a manual step.
For European companies, the pairing adds a European option. Aikido already connects to compliance platforms used in the US market. With Kertos, both sides of the workflow sit with European providers: a platform designed around European law, hosted on European infrastructure, with certified experts who work under that law.
"Having both halves with European providers matters more every year to European customers and their auditors, and it shortens the path to certification significantly," said Schmidt.
Kertos and Aikido have been offering their platforms together since September 2026. Companies source application security and compliance from one conversation, instead of running two vendor selections and two procurement processes. "Developers should not have to assemble screenshots afterwards to prove the work happened. With Kertos, that proof comes out the other side, in the form auditors and enterprise buyers expect," added Gallegos.
About Kertos
Kertos is the European compliance partner for companies that need to get certified and stay continuously compliant under European law. Its platform brings information security, data protection, and AI management into one system, covering ISO 27001, ISO 42001, ISO 27701, GDPR, NIS2, the EU AI Act, SOC 2, TISAX, and C5. Certified experts work alongside customers through preparation, audits, and the ongoing work that follows, and can take on external DPO mandates. The platform's agentic assistant, KAIA, carries the operational load by drafting policies, checking evidence against the relevant requirements, and monitoring controls. Designed around European law and hosted on European infrastructure, Kertos supports startups, scaleups and mid-sized companies such as Enpal, Blacklane, and Flink. Founded by Dr. Kilian Schmidt, Johannes Hussak, and Alexander Prams in 2021, Kertos GmbH operates from Berlin and Munich. Learn more: kertos.io
About Aikido Security
Founded in Ghent, Belgium, Aikido Security is building self-securing software for modern development teams. Aikido's unified security platform secures application testing, code, cloud and runtime, helping teams to reduce risk without slowing down development. Aikido is the fastest-ever European cybersecurity company to reach unicorn status and is trusted by over 150,000 teams, with a global customer base including Revolut, SoundCloud, Deel and Niantic.
Press contact Kertos
Catherine Higginson
Senior Content Marketing Manager
Kertos GmbH
press@kertos.io





