Story
7 min read

Where UX meets AppSec: Gravity’s shift toward embedded, proactive security

Security is no longer an afterthought. With Aikido, we’re integrating it directly into our DevOps pipeline to ensure it’s a seamless part of our workflow.

Ruben de Baat
Digital Consultant
Table Of Contents
TOC Item
Website
https://www.gravity.nl/
Founded
2017
Industry
Agencies
Funding Raised
Headquarters
Amersfoort, NL
Development Team Size
From startups to enterprise-level security

Introduction on Gravity and Security in digital product design

Hey Ruben! Can you tell us a bit about yourself and Gravity?

Of course! I’m Ruben de Baat, Digital Consultant at Gravity.

Gravity started as a highly technical agency focused on developing custom platforms, mobile apps, and complex integrations. Since joining the Loyals Group, we’ve expanded our expertise while staying true to our core value: Simplicity moves. No matter how complex the technology behind the scenes, we always ensure a seamless and intuitive user experience.

As a Digital Consultant, I bridge the gap between business and technology, connecting clients and developers by leveraging my expertise in UI/UX, DevOps, and business. I help create scalable and secure digital solutions by translating client needs into technical requirements, ensuring the right architecture, security, and long-term value. 

“My goal is to challenge both clients and developers to collaborate effectively, pushing boundaries to build the best possible digital solution.”

What role does security play within a digital agency like Gravity?

Security is a key part of our work. We develop and manage custom digital solutions for clients, from full platforms and mobile apps to backend tools, admin portals, and integrations with all sorts of SaaS solutions like ERP and CRM systems.

As we take on more projects, security and testing are becoming increasingly important. But simply adding more manpower isn’t a sustainable solution. That’s why we turned to security automation. Previously, security was handled reactively, through periodic checks and contractual agreements with clients. But we saw a growing need for a proactive approach, which led us to Aikido.

How Aikido fits into the day to day workflow

How have you integrated Aikido into your workflow?

We built an internal security monitoring tool that integrates with Aikido. This allows us to share security insights with clients without giving them direct access to Aikido.

Clients receive a clear, concise overview of open security issues, resolved vulnerabilities, and overall platform performance. Think of it as a small viewing window, keeping things simple and manageable for our clients.

This approach not only provides transparency but also reassures clients that they’re staying ahead in security. While we don’t explicitly mention Aikido, security is a core part of our contractual services. This adds value and reinforces our expertise.

"By integrating security directly into our workflows, we make it a natural part of the process, not an afterthought."

You are now working with larger enterprises and government institutions. What does that mean for your security approach?

We originally worked with startups, where speed and functionality were the top priorities. But as those startups grew, and as we started working with larger businesses and government clients, security requirements became much stricter.

To keep up, we’re focused on automating security processes so that every new project starts efficiently and at scale. Security is no longer an afterthought. With Aikido, we’re integrating it directly into our DevOps pipeline to ensure it’s a seamless part of our workflow.

"As we scale, security must scale with us—automation is the key to making that happen."

Why did you choose Aikido, and how has your experience been working with them?

The timing couldn’t have been better, just as we were searching for a solution, we came across Aikido’s website and started chatting. What immediately stood out to us was their agency-friendly model. Unlike tools like Snyk, which are built for end-users, Aikido is specifically designed with agencies in mind. Additionally, Aikido is European-based and GDPR-compliant, aligning well with the regulatory framework our clients in the EU are subject to.

Another key factor was their fast and direct communication. Our questions are always answered promptly, and being able to communicate in Dutch is incredibly convenient. Cost efficiency is also a significant benefit. Thanks to Aikido’s agency model, we can offer even smaller clients high-quality security at an affordable price.

Moreover, Aikido integrates seamlessly with DigitalOcean, our preferred hosting solution for clients without existing infrastructure, making it a perfect fit. Lastly, Aikido's AI autofix feature sounds promising, and while I haven’t tested it yet, I’m eager to explore it further in the coming months.

What are the next steps for security at Gravity?

We’ve laid a solid foundation for better security practices, and now our focus is on refining and scaling our approach. Aikido is a crucial part of this process, helping us keep security top-of-mind without slowing down development. Security is no longer a separate process, it’s now an integral part of our DevOps workflow.

By embedding Aikido into their DevOps workflows, Gravity transformed security from a periodic task into a continuous, scalable process. As they grow from startup-focused projects to enterprise and government clients, Aikido helps deliver secure, high-performance platforms, without slowing down.

The result? Security that’s proactive, automated, and invisible to end users – but essential to long-term trust.

Download Case As pDF

Other great stories told by our customers

Other
Executing on a long-term security roadmap
View story
SecWise
Software Development
From a patchwork of open-source tools to a centralized security posture.
View story
Kunlabora
Agencies
From startup speed to enterprise scale, Gravity unites UX and AppSec with Aikido.
View story
Gravity
Other
Easily securing InviteDesk's growth by acquisition.
View story
InviteDesk
Other
From SOC 2 audit preparation to continuous compliance.
View story
OutboundSync
Agencies
Securing 100+ repositories across clients and projects.
View story
CORE
Agencies
Streamlining security across 1.500+ repositories without breaking the bank.
View story
November Five
HRTech
Replaced noisy tools with <1 min fixes and dev-first workflows.
View story
Simployer
FinTech
CertifID's previous solution let them chase too many false positives.
View story
CertifID
PE & Group Companies
Delivering SCA and beyond to 6,000+ developers.
View story
Visma
FinTech
Minimizing false-positives, while keeping GitHub as the single source of truth.
View story
Bound
HealthTech
Birdie's fastest time to resolution? 30 seconds.
View story
Birdie
Software Development
Marvelution weaves security into its one-word business plan: "fun".
View story
Marvelution
HealthTech
Realizing efficiency gains, from one intuitive interface to pentests behind the login wall.
View story
Mediquest