xlogs vs Aikido
Aikido is a serious application-security platform, and a good one. It is built for teams with repositories and cloud accounts to connect. xlogs scans a single deployed URL and needs no account at all. These are different jobs, and for a lot of people the honest answer is Aikido.
Try the small version first
When Aikido is the right answer
If you have a codebase, a team, and CI, Aikido does things xlogs does not attempt: dependency and licence scanning, static analysis of your source, container and cloud posture, and secrets detection across your repository history. Its free Developer tier is genuinely usable, covering 10 repos, 1 domain, 1 cloud account and all core scanning modules with no card.
That tier does have limits worth knowing before you rely on it: 10 AI AutoFixes per month, rescans every 3 days, and the cheapest paid tier is 300 US dollars per month. And every path in requires connecting a repository or a cloud account.
When xlogs fits instead
If you built one app with an AI tool, shipped it, and want to know within a minute whether it is leaking anything, connecting a repository is a larger ask than the question deserves. xlogs takes a URL, needs no account, has no cap on scans or fixes, and answers the specific question of what a stranger can reach right now.
It is a smaller product on purpose. If you outgrow it, a platform like Aikido is the direction to grow into, and we would rather say that than pretend otherwise.
| xlogs | Aikido | |
|---|---|---|
| What you connect | Nothing. Paste a URL, or a public repo URL. No account, no OAuth grant | A repository or cloud account |
| Free tier | Unlimited scans, findings and fixes | 10 repos, 1 domain, 10 AI AutoFixes/month, rescan every 3 days |
| Cheapest paid tier | No paid tier yet | 300 USD per month |
| Source code analysis | Yes, for supply-chain risk: 29 checks on a public repo, read-only, never executed. Not SAST | Yes, a core strength |
| Dependency and licence scanning | Lockfile-pinned npm dependencies checked against the OSV advisory database, plus sources, mirrors and licence | Yes |
| Live database tested anonymously | Yes | Not the same check |
| AI at scan time | None. Deterministic | AI AutoFix, metered on the free tier |
| Built for | One person with one deployed app | Engineering teams |
| Access log analysis | Drop an access log: parsed in your browser, never uploaded | Not offered |
| Joins probes to exposure | Yes: 40 requests for /.env, and your app serves it | No, it has no access-log side |
Common questions
Is xlogs an Aikido alternative?
No, not for a team with a codebase. Aikido scans source, dependencies, containers and cloud, and xlogs does none of that. For checking whether one deployed app is exposing data or keys right now, xlogs is faster and needs nothing connected. Plenty of people need one and not the other.
Why does xlogs have no paid tier?
Because we have not built the thing worth charging for yet. When we do, it will be monitoring and recurrence, not findings or fixes. Those stay free and uncapped.
