Aikido acquires Root to patch open-source software without forced upgrades

Belgian cybersecurity company Aikido Security NV today announced that it has acquired Root.io Inc., a company that offers patching for vulnerable open-source software at the exact versions organizations are already running.

Founded in 2020 as Slim.AI Inc., the startup offered a popular open-source container tool called Slim Toolkit. It rebranded last year as its technology shifted from shrinking container images to securing them.

Root sells what it calls agentic vulnerability remediation. When a new vulnerability is published, swarms of specialized AI agents research, write, test and ship a patch in roughly 15 to 40 minutes, against the weeks the process can take by hand. The fixes go straight to the container images and software dependencies a company is already running, at the versions it has pinned, so there’s no rebuild and no migration.

In more than four out of five cases, Root makes no code changes at all, with a human reviewer signing off rather than writing the patch. The company says that approach let data security firm BigID Inc. clear more than 1,000 vulnerabilities, in excess of 300 of them rated high or critical, across six production images in two weeks without abandoning its Debian and Ubuntu-based stacks.