
Roeland Delrue
Roeland Delrue co-founded Aikido Security, a Belgian developer security platform, and is an active angel investor backing ecosystem companies including Eagl.
Roeland co-founded Aikido Security, a developer-focused security platform that makes vulnerability scanning and code security accessible without requiring a dedicated security team. The company has grown quickly in the European DevSecOps market.
Beyond his operational role, Roeland is an active angel investor in the Belgian ecosystem. He has backed Eagl and participates in Syndicate One as an LP, connecting him to the Brussels-based investor community.
Insights & takeaways
Roeland Delrue's thinking centers on a single structural observation: software is now produced far faster than it can be secured, and the tools built for the old cadence no longer work. He points to hard data to make the point rather than relying on intuition alone, noting that in Aikido's own research "48% of organizations said pentest findings are already outdated by the time they arrive" . That gap between shipping speed and testing speed is, in his telling, the defining problem of the moment. Teams that once released a few times a year now ship "every week, every day, sometimes every hour" , but security testing has stayed on a fixed schedule, which means the entire discipline is structurally out of sync with how software actually gets built.
Layered on top of this is his view of AI's effect on code production. He argues that AI-generated code is accelerating software development "3-4 times," and that this acceleration increases the raw volume of vulnerabilities even when individual code quality stays flat or improves slightly 12. The consequence isn't that AI makes code worse per line, it's that AI makes so much more of it that security becomes the bottleneck by sheer throughput. His response to this isn't more manual review, it's a bet on how roles themselves change: he describes developers and security teams evolving into "orchestrators" rather than hands-on workers, as agents absorb more of the actual coding and, increasingly, the actual defending 12. This is a consistent thread across his public commentary: security has to become agent-native to keep pace with agent-native development, not bolted-on tooling layered over a manual process.
That philosophy shows up directly in product decisions. When Aikido acquired Root, he framed the rationale in terms of the same tradeoff he sees teams facing everywhere: "upgrade and risk breaking your application, or replace what you run with something else entirely" . His answer is to reject the binary. Root's approach, agents that "don't just find vulnerabilities, they fix them, in precise package versions, at machine-speed" , reflects his broader stance that open source has become "the primary entry point for attackers" and that patching has to happen at the speed threats now move, not the speed humans review. The launch of Aikido Code Audit follows the same logic in a different register: he frames frontier models as having made it "cheap to find and exploit logic flaws" , which shifts the burden onto defenders to catch complex, logic-hidden vulnerabilities before shipping rather than relying on deterministic pattern-matching alone, since "deterministic analysis catches known patterns" but the harder bugs "hide in the logic" .
His view of the vendor landscape is shaped by his own frustration as a former buyer. He and his co-founders built Aikido because they experienced existing security tools as "difficult to use, prone to false positives, and expensive" 11, and that origin story recurs as a kind of design constraint on everything the company ships. It explains his comfort publicly weighing tradeoffs rather than oversimplifying: when benchmarking Opus, he noted plainly that it "found the most bugs, but it's a tradeoff: it also produced the most noise to sort through" and flagged the price as expected . This is characteristic of how he talks about tools generally, evaluative rather than promotional, willing to name the cost side of a capability rather than just the upside.
He also treats the developer's own environment as a security surface that's been neglected. Endpoint Protection was framed around the idea that "developer devices are the new Achilles' heel of the software supply chain" , and a lighter, almost provocative post asking "do you know what your devs have installed?" makes the same point in shorthand: visibility into what's actually running on developer machines is treated as a basic, often-missing control. Malicious packages get the same plain-spoken treatment, summarized as ensuring there are "no bad kitties at Aikido" , a phrasing that fits his generally unpretentious, direct communication style even on serious supply-chain risk topics.
Taken together, his public statements sketch a coherent worldview rather than a scattershot set of product pitches: shipping velocity has outrun testing velocity, AI accelerates that gap on both the offense and defense side, and the fix is agent-native, always-on security woven into the same pipeline that's producing code, not a periodic audit bolted onto the end of it. The concrete takeaway he keeps returning to, across the Root acquisition, Code Audit, and the pentesting research, is that point-in-time security testing is no longer sufficient on its own, and that both tooling and human roles need to shift toward continuous, orchestrated oversight of systems that are themselves increasingly run by agents 12.
Career History
Cofounder: CRO & COO at Aikido Security (Sep 2022 - Present)
- Freelance Contractor (Jul 2021 - Sep 2022)
Senior Product Manager at Showpad (Jul 2018 - Jul 2021)
Product Manager at Showpad (Jan 2017 - Jun 2018)
Account Executive at Showpad San Francisco (Jan 2016 - Apr 2017)
- Corporate Banking Analyst at KBC Bank, New York (Mar 2014 - Oct 2014)
Education
- Master, International Business, Hult International Business School, San Francisco (2012 - 2013)
Master, Business Engineering, Ghent University (2010 - 2012)
Media & appearances
3
10podcastNo Sales Call Required: Roeland Delrue on Scaling Aikido to a Cybersecurity UnicornProductLed · 2 months ago · 52:17 · 118 views
11interviewA chat with Roeland Delrue, co-founder and COO at Aikido Security.Syndicate One · 8 months ago · 31:10 · 496 viewsRoeland Delrue discusses Aikido Security as a software security startup that scans codebases, cloud environments, and web applications for companies with in-house developers. He explains that he and his co-founders created Aikido because they were frustrated as users of existing security tools, which they found difficult to use, prone to false positives, and expensive.
12interviewAI Agents Are Creating a New Cybersecurity Crisis | with Roeland Delrue (Aikido Security)Superintelligence · 2 months ago · 40:54 · 488 viewsRoeland Delrue discusses how AI-generated code is accelerating software development by 3-4 times, which increases the volume of vulnerabilities even if individual code quality remains the same or improves slightly. He explains that software security is becoming a bottleneck because security teams must now manage this dramatically increased code production rate, and he describes how developers and security teams will evolve into "orchestrators" rather than hands-on workers as AI agents take over more coding tasks.