Overview
Roeland co-founded Aikido Security, a developer-focused security platform that makes vulnerability scanning and code security accessible without requiring a dedicated security team. The company has grown quickly in the European DevSecOps market.
Beyond his operational role, Roeland is an active angel investor in the Belgian ecosystem. He has backed Eagl and participates in Syndicate One as an LP, connecting him to the Brussels-based investor community.
Career history
- Cofounder: CRO & COOSep 2022 - PresentAikido Security
- Freelance ContractorJul 2021 - Sep 2022
- Senior Product ManagerJul 2018 - Jul 2021Showpad
- Product ManagerJan 2017 - Jun 2018Showpad
- Account ExecutiveJan 2016 - Apr 2017Showpad San Francisco
- Corporate Banking AnalystMar 2014 - Oct 2014KBC Bank, New York
Education
Master, International Business2012 - 2013Hult International Business SchoolSan Francisco
Master, Business Engineering2010 - 2012Ghent University
Insights & ideas
The through-line
Across Delrue's public statements, one preoccupation dominates: security has to move at the same speed as AI-accelerated software development, and that means shifting from finding vulnerabilities to autonomously fixing them. Early in the run of sources this shows up as a series of product launches, Endpoint Protection [12], Code Audit [11], and a State of AI in Pentesting report built on survey data from 400 security leaders [10]. By mid-2026 the emphasis moves to acquisitions that bring fixing capability in-house, Root for supply-chain patching [9] and Milou for on-prem pentesting [3], and by August he is explicitly arguing that the orchestration layer around a model matters more than the model itself [1][4]. The founding frustration that started the company, being a user of security tools that were hard to use, false-positive-prone, and expensive, still underlies the pitch for every new product [14].
On harness versus model
Delrue's clearest and most repeated claim in the later material is that how you run a model matters more than which model you run. He frames this directly: "Harness > Model" [1], after testing Claude Security with Mythos and Codex Security with GPT-5.6 Sol against Aikido's own Code Security Audit on a shared repo of 89 vulnerabilities, reporting that "Mythos found 60 of them for $157," "GPT-5.6 Sol found 58 of them for $125," and "Aikido Code Security Audit found 68 of them for $75" [1]. The same logic shows up in his read of Opus 5: it "found the most bugs, but it's a tradeoff: it also produced the most noise to sort through" [4], reinforcing that raw detection power isn't the point if it costs more or drowns teams in noise.
On fixing, not just finding
A second recurring position is that vulnerability detection is no longer the hard part, remediation is. He describes agents "that don't just find vulnerabilities, they prove them with a working exploit and hand you a fix" [3], and makes the same point about Root: "agents that don't just find vulnerabilities, they fix them, in precise package versions, at machine-speed," producing "Hundreds of verified CVE patches produced daily, autonomously" [9]. His stated rationale is that open source "needs patching, and it needs it fast" [9], and that deterministic scanning is no longer enough because "complex vulnerabilities hide in the logic" that only agentic reasoning can catch [11].
On continuous testing for continuous shipping
Delrue repeatedly frames the security industry's core mismatch as a tempo problem: "Software changes continuously. Security testing doesn't" [10]. He backs this with survey data he commissioned, that "48% of organizations said pentest findings are already outdated by the time they arrive" [10], and treats this as the justification for pushing pentesting into a continuous, on-demand model rather than a scheduled one [11].
On bringing AI pentesting on-prem
He also argues that autonomous offensive security has been artificially limited to cloud-based teams, locking out exactly the organizations that need it most. "Continuous AI pentesting has only ever run in the cloud, so teams like banks, hospitals, governments, and defense couldn't use it, because their code isn't allowed to leave the network" [3]. His answer is a GPU appliance that keeps everything in-house, "AI pentesting entirely under your control" [2], built on the Milou acquisition, framed with the maxim "Offense is your best defense" [3].
From the stage
In interview settings Delrue gives the origin story and the labor-market thesis that his written posts don't spell out. He says he and his co-founders built Aikido directly out of their own frustration as users of existing security tools, "which they found difficult to use, prone to false positives, and expensive" [14]. He also lays out a specific claim about how AI is reshaping the discipline: AI-generated code is "accelerating software development by 3-4 times," which increases the sheer volume of vulnerabilities even when code quality holds steady or improves slightly, turning security into the new bottleneck [15]. From this he draws a role-level prediction not found in the product posts, that both developers and security teams will evolve into "orchestrators" rather than hands-on workers as agents take over more of the coding and finding work [15].
Takeaways
- Judge AI security tools by the full harness and cost, not the underlying model alone; in Delrue's own benchmark, Aikido's audit found more vulnerabilities at lower cost than either Claude/Mythos or Codex/GPT-5.6 Sol [1].
- Expect vendors in this space to compete on remediation, not just detection, since Delrue frames "prove and fix" agents as the differentiator over agents that merely flag issues [3][9].
- If you're in a regulated industry (banking, healthcare, government, defense), on-prem AI pentesting appliances like Aikido Machine exist specifically because cloud-only tools couldn't serve you [2][3].
- Treat scheduled pentesting as structurally behind modern release cadences; Delrue cites his own survey finding that 48% of organizations get outdated pentest results [10].
- The founding motivation behind Aikido was direct user frustration with existing tools being hard to use, false-positive-heavy, and expensive, not a top-down market analysis [14].
- Delrue expects AI to raise vulnerability volume by accelerating code output 3-4x, and predicts security and dev roles will shift toward "orchestration" rather than hands-on work [15].
Media & appearances
- SuperintelligenceYouTubeAI Agents Are Creating a New Cybersecurity Crisis | with Roeland Delrue (Aikido Security)Roeland Delrue discusses how AI-generated code is accelerating software development by 3-4 times, which increases the volume of vulnerabilities even if individual code quality remains the same or improves slightly. He explains that software security is becoming a bottleneck because security teams must now manage this dramatically increased code production rate, and he describes how developers and security teams will evolve into "orchestrators" rather than hands-on workers as AI agents take over more coding tasks.
- Syndicate OneYouTubeA chat with Roeland Delrue, co-founder and COO at Aikido Security.Roeland Delrue discusses Aikido Security as a software security startup that scans codebases, cloud environments, and web applications for companies with in-house developers. He explains that he and his co-founders created Aikido because they were frustrated as users of existing security tools, which they found difficult to use, prone to false positives, and expensive.
- ProductLedYouTubeNo Sales Call Required: Roeland Delrue on Scaling Aikido to a Cybersecurity Unicorn
Investments
Eagl
Eagl is a Belgian AI startup automating the month-end close process for finance teams, having raised EUR 825K in September 2025 with backing from notable Belgian angel investors.
In the news
- Day 2 at GISEC GLOBAL ✅🇦🇪 Busy booth, Roeland on stage, dinner after hours. One more day at Booth H3-C40. 💜 Roeland Delrue Bart Jonckheere Abdelilah Takhrifa Tarek B. Tarık Çelebi Tom Schelstraete Anisha P. Fouad Moukaddem
- Day 1 at GISEC GLOBAL ✅🇦🇪 The Aikido team is at booth H3-C40 today and tomorrow. Come see continuous, autonomous security that gets developers back to building. 💜 Roeland Delrue Bart Jonckheere Abdelilah Takhrifa Tarek B. Tarık Çelebi Tom Schelstraete
- 𝗪𝗲 𝗿𝗮𝗶𝘀𝗲𝗱 €𝟭.𝟭𝗠 𝗲𝗮𝗿𝗹𝗶𝗲𝗿 𝘁𝗵𝗶𝘀 𝘆𝗲𝗮𝗿. Sorry to whoever already published the Q2 funding numbers. Led by JK INVEST, with imec.istart, ⚡ Super Capital ⚡ and a group of exceptional business angels. Sixteen years in finance and one thing still makes no sense to me. The business changes every day. Finance finds out last. Finance still has to explain it. Most tools just help you build and update your forecast faster. But they still wait for the numbers. Four days or four minutes. Who cares. 👀 Enter Peaky. We
- A while ago it was just a beer and a crazy idea. And earlier this year we closed our €𝟭.𝟭𝗠 𝗳𝘂𝗻𝗱𝗶𝗻𝗴 𝗿𝗼𝘂𝗻𝗱 with Peaky. What a ride. 🤩 I come from design, not finance. But you don't need a finance background to see that something is broken when the people running a business are always the last to know what's happening in it. Peaky fixes that. A living financial plan that moves with your business and tells you what's changing before it costs you. Oh, and we were named Belgium's Best FinTech Startup of the Year. Still
- Driving at 120 km/h while looking exclusively in the rearview mirror sounds like a terrible idea, yet that’s how most companies still run their business. Traditional tools only tell you about the wall three weeks after you’ve hit it. Turns out, people prefer seeing the road ahead. Enter Peaky. We just raised €1.1M to build the future of financial planning, and we’re ready to accelerate well beyond 120 km/h. Thanks to our customers and early pilots for their trust. Aikido Security, Tout Bien Pils, ProPlanner, Holmes, The Harbour,
- This is the part where Europe usually screws it up. Everyone agrees on the problem. A European founder trying to build across Europe still runs into 27 different company systems, registries and rulebooks. Everyone agrees on the solution, too. EU–INC: one European company standard that lets startups incorporate once and operate across the Single Market. And then comes the dangerous bit: the political compromise. Because an EU–INC without one central registry, free choice of registered office and automatic recognition across all 27
- Today we're launching Code Coverage 🚀. You can now see, per repository, file, and line, how much of your code is covered by tests. This further strengthens our overall Code Quality offering. For every file, you can see exactly where you're lacking coverage, and across your whole estate, you can spot the repos that have gone under-tested. Run your tests in CI, upload with our GitHub Action, and it's in the Code Coverage tab. Learn more: https://lnkd.in/ehshC3DR
Related profiles
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.










