Roeland Delrue

Roeland Delrue co-founded Aikido Security, a Belgian developer security platform, and is an active angel investor backing ecosystem companies including Eagl.

8 News mentions

Overview

Roeland co-founded Aikido Security, a developer-focused security platform that makes vulnerability scanning and code security accessible without requiring a dedicated security team. The company has grown quickly in the European DevSecOps market.

Beyond his operational role, Roeland is an active angel investor in the Belgian ecosystem. He has backed Eagl and participates in Syndicate One as an LP, connecting him to the Brussels-based investor community.

Career history

  1. Cofounder: CRO & COOSep 2022 - PresentAikido Security
  2. Freelance ContractorJul 2021 - Sep 2022
  3. Senior Product ManagerJul 2018 - Jul 2021Showpad
  4. Product ManagerJan 2017 - Jun 2018Showpad
  5. Account ExecutiveJan 2016 - Apr 2017Showpad San Francisco
  6. Corporate Banking AnalystMar 2014 - Oct 2014KBC Bank, New York

Education

  1. Master, International Business2012 - 2013Hult International Business SchoolSan Francisco
  2. Master, Business Engineering2010 - 2012Ghent University

Insights & ideas

The through-line

Across Delrue's public statements, one preoccupation dominates: security has to move at the same speed as AI-accelerated software development, and that means shifting from finding vulnerabilities to autonomously fixing them. Early in the run of sources this shows up as a series of product launches, Endpoint Protection [12], Code Audit [11], and a State of AI in Pentesting report built on survey data from 400 security leaders [10]. By mid-2026 the emphasis moves to acquisitions that bring fixing capability in-house, Root for supply-chain patching [9] and Milou for on-prem pentesting [3], and by August he is explicitly arguing that the orchestration layer around a model matters more than the model itself [1][4]. The founding frustration that started the company, being a user of security tools that were hard to use, false-positive-prone, and expensive, still underlies the pitch for every new product [14].

On harness versus model

Delrue's clearest and most repeated claim in the later material is that how you run a model matters more than which model you run. He frames this directly: "Harness > Model" [1], after testing Claude Security with Mythos and Codex Security with GPT-5.6 Sol against Aikido's own Code Security Audit on a shared repo of 89 vulnerabilities, reporting that "Mythos found 60 of them for $157," "GPT-5.6 Sol found 58 of them for $125," and "Aikido Code Security Audit found 68 of them for $75" [1]. The same logic shows up in his read of Opus 5: it "found the most bugs, but it's a tradeoff: it also produced the most noise to sort through" [4], reinforcing that raw detection power isn't the point if it costs more or drowns teams in noise.

On fixing, not just finding

A second recurring position is that vulnerability detection is no longer the hard part, remediation is. He describes agents "that don't just find vulnerabilities, they prove them with a working exploit and hand you a fix" [3], and makes the same point about Root: "agents that don't just find vulnerabilities, they fix them, in precise package versions, at machine-speed," producing "Hundreds of verified CVE patches produced daily, autonomously" [9]. His stated rationale is that open source "needs patching, and it needs it fast" [9], and that deterministic scanning is no longer enough because "complex vulnerabilities hide in the logic" that only agentic reasoning can catch [11].

On continuous testing for continuous shipping

Delrue repeatedly frames the security industry's core mismatch as a tempo problem: "Software changes continuously. Security testing doesn't" [10]. He backs this with survey data he commissioned, that "48% of organizations said pentest findings are already outdated by the time they arrive" [10], and treats this as the justification for pushing pentesting into a continuous, on-demand model rather than a scheduled one [11].

On bringing AI pentesting on-prem

He also argues that autonomous offensive security has been artificially limited to cloud-based teams, locking out exactly the organizations that need it most. "Continuous AI pentesting has only ever run in the cloud, so teams like banks, hospitals, governments, and defense couldn't use it, because their code isn't allowed to leave the network" [3]. His answer is a GPU appliance that keeps everything in-house, "AI pentesting entirely under your control" [2], built on the Milou acquisition, framed with the maxim "Offense is your best defense" [3].

From the stage

In interview settings Delrue gives the origin story and the labor-market thesis that his written posts don't spell out. He says he and his co-founders built Aikido directly out of their own frustration as users of existing security tools, "which they found difficult to use, prone to false positives, and expensive" [14]. He also lays out a specific claim about how AI is reshaping the discipline: AI-generated code is "accelerating software development by 3-4 times," which increases the sheer volume of vulnerabilities even when code quality holds steady or improves slightly, turning security into the new bottleneck [15]. From this he draws a role-level prediction not found in the product posts, that both developers and security teams will evolve into "orchestrators" rather than hands-on workers as agents take over more of the coding and finding work [15].

Takeaways

  • Judge AI security tools by the full harness and cost, not the underlying model alone; in Delrue's own benchmark, Aikido's audit found more vulnerabilities at lower cost than either Claude/Mythos or Codex/GPT-5.6 Sol [1].
  • Expect vendors in this space to compete on remediation, not just detection, since Delrue frames "prove and fix" agents as the differentiator over agents that merely flag issues [3][9].
  • If you're in a regulated industry (banking, healthcare, government, defense), on-prem AI pentesting appliances like Aikido Machine exist specifically because cloud-only tools couldn't serve you [2][3].
  • Treat scheduled pentesting as structurally behind modern release cadences; Delrue cites his own survey finding that 48% of organizations get outdated pentest results [10].
  • The founding motivation behind Aikido was direct user frustration with existing tools being hard to use, false-positive-heavy, and expensive, not a top-down market analysis [14].
  • Delrue expects AI to raise vulnerability volume by accelerating code output 3-4x, and predicts security and dev roles will shift toward "orchestration" rather than hands-on work [15].

Media & appearances

Investments

  • Eagl

    Eagl is a Belgian AI startup automating the month-end close process for finance teams, having raised EUR 825K in September 2025 with backing from notable Belgian angel investors.

In the news

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.