• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. RapidFort Platform
Logo of RapidFort Platform

RapidFort Platform

byRapidFort
in
4.8
Market Presence: Software Supply Chain Security, Vulnerability Assessment

Overview

Product Information on RapidFort Platform

Updated 13th January 2026

What is RapidFort Platform?

RapidFort Platform is a software designed to enhance security and optimize performance for containerized applications by automatically analyzing and reducing unused components within container images. The software provides vulnerability management by identifying and removing unnecessary packages, thereby minimizing attack surfaces and improving compliance with security standards. It integrates with existing development workflows and supports continuous monitoring to detect risks in real time. RapidFort Platform helps organizations streamline their DevSecOps processes, ensuring that deployed containers are lightweight and contain only essential code needed for operation. Through automated image optimization and comprehensive reporting features, the software addresses challenges related to container security, resource management, and regulatory compliance.

RapidFort Platform Pricing

RapidFort Platform is a software that follows a subscription-based pricing model, typically structured around usage tiers which may include variables such as the number of workloads, features accessed, or level of support selected. The software may offer different plans to accommodate various organizational needs, and pricing can vary based on specific deployments or user requirements. Detailed and custom pricing information is generally available upon request.

Overall experience with RapidFort Platform

Director of Engineering
500M - 1B USD, Software
FAVORABLE

“RapidFort Enables FedRAMP SaaS Migration With Responsive Support and Timely Updates”

5.0
Feb 6, 2026
RapidFort has been very responsive to our requirements. We were starting off on migrating out product to FedRAMP SaaS, by containerizing the components and making them FIPS compliant. RapidFort truly partnered with us, being very flexible in their pricing, to provide us "everything that we need to meet the FedRAMP goals", rather than limiting us to a particular count. Plus, they got us what we needed, within short time - for example, we were using a couple of components that they did not have in their curated list, and they committed to and delivered them in 2 weeks - helping us to stay on course.
There are no reviews in this category.
CRITICAL

About Company

Company Description

Updated 22nd May 2025

RapidFort is a comprehensive vulnerability management platform that helps organizations reduce software risk across the software development lifecycle. RapidFort combines RF Near Zero CVE Images with a Software Attack Surface Management (SASM) system to identify, prioritize, and reduce vulnerabilities without source code changes. RF Near Zero CVE Images are FIPS 140-3 validated and hardened using STIG and CIS benchmarks aligned with NIST SP 800-70 guidance. Built on open-source LTS distributions, these container images provide a secure foundation for application deployment. The platform includes DevTime and RunTime tools that perform binary and runtime analysis to generate Software and Runtime Bills of Materials (SBOM and RBOM), detect unused components, and reduce the attack surface based on execution behavior. Organizations use RapidFort to improve visibility into software supply chain risks and support compliance readiness.

Company Details

Updated 22nd May 2025
Company type
Private
Year Founded
2020
Head office location
Sunnyvale, United States
Number of employees
51 - 200
Website
https://www.rapidfort.com/

Do You Manage Peer Insights at RapidFort?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Reviewer Insights for: RapidFort Platform
Performance of RapidFort Platform Across Market Features

RapidFort Platform Likes & Dislikes

Like

They provide near-zero CVE base images, and keep their library up-to-date. This had been a nightmare for us earlier - by the time we patch our base version, a few more CVEs get reported and we ended up chasing our tail. Now, we pull their latest version on a daily basis - and if we do find any CVEs in our internal scans and report it to them, we get a fresh update pretty quick. Their portal also provides an exploitability score for the CVEs, plus an instrumentation & tracking mechanism to identify the actual binaries that are loaded by our services (ie: many DLLs may be included in a package, but not necessarily used). This gives us a realistic view when reviewing the Security aspects of a build, prior to release - ie: there are X number of CVEs reported by the scanners, but they are in DLLs that are not loaded - or have low/zero exploitability score. Their CLI interface helps us to integrate their tools easily into our build pipelines.

Like

The vast majority of our environments use open source images and RapidFort has directly swappable vuln reduced or vuln free images. Their tooling allows easy scanning, profiling and hardening of images that are custom or not offered by RapidFort. Their documentation is top notch and their customer success engineers have yet to not find an ideal solution for the issues that have cropped up.

Like

The platform is simple and just works. I've tried other base images and they all work exactly as you'd expect them to. RapidFort support is stellar--we share a Slack channel with some of their engineers. While it's rare that we need to reach out, any time we have, they've responded quickly and knowledgeably. Closing out the last few CVEs in a system is always the hardest part. Sometimes you can't fix them and need to provide justification. RapidFort takes care of that by providing details when CVEs remain open--text I can often copy and paste as-is into a remediation report.

Dislike

The fact that I have to pay for them? (:-) just kidding, we did our build-v/s-buy analysis, and they are value for money) Nothing really. This is a very specific need - to have secure base images - and they do it well, and maintain the expected security levels. Plus, they are very responsive to specific asks.

Dislike

This is a nit pick, but the way Projects/Clusters are setup in their control panel shows every vulnerability on the cluster that has ever shown up in the cluster until it's manually curated to remove old images with those vulnerabilities.

Dislike

The price. The platform is not cheap. But let's be honest: how much would it cost in labor and opportunity cost to task an experienced software engineer with working through a list of 200 vulnerabilities? Looking at it from that perspective, the platform does pay for itself.

Top RapidFort Platform Alternatives

Logo of Mend
1. Mend
4.4
(111 Ratings)
Logo of Veracode
2. Veracode
4.5
(16 Ratings)
Logo of Black Duck Software Composition Analysis
3. Black Duck Software Composition Analysis
4
(13 Ratings)
View All Alternatives

Peer Discussions

RapidFort Platform Reviews and Ratings

Showing data for 10 ratings and reviews for Software Supply Chain Security market. View all 11 ratings and reviews across markets for a complete picture.

4.8

(10 Ratings)

Rating Distribution

5 Star
80%
4 Star
20%
3 Star
0%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.9

Integration & Deployment

4.7

Service & Support

5.0

Product Capabilities

4.7

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Director of Engineering
    50M-1B USD
    Software
    Review Source

    RapidFort Enables FedRAMP SaaS Migration With Responsive Support and Timely Updates

    5.0
    Feb 6, 2026
    RapidFort has been very responsive to our requirements. We were starting off on migrating out product to FedRAMP SaaS, by containerizing the components and making them FIPS compliant. RapidFort truly partnered with us, being very flexible in their pricing, to provide us "everything that we need to meet the FedRAMP goals", rather than limiting us to a particular count. Plus, they got us what we needed, within short time - for example, we were using a couple of components that they did not have in their curated list, and they committed to and delivered them in 2 weeks - helping us to stay on course.
  • Engineering Manager
    50M-1B USD
    Software
    Review Source

    Avoid building out a team that solely patches containers, focus on building your product.

    5.0
    Jan 30, 2026
    RapidFort is extremely knowledgeable in how images for containerized deployments are built, hardened, and made to adhere to compliance standards. Their pre-sales team made it extremely easy to demo their product and helped us see a path to dramatically reduce the number of engineers needed to maintain highly compliant environments that demand vulnerability patching with strict SLAs and very tedious reporting. Their curated and hardened images can be directly swapped into existing high compliance environments without the need for costly audits and government security reviews because the images are what you already have authorization to run, they just have demonstrably fewer or zero vulnerabilities. Finally, their tooling makes it a breeze to build your images on top of their images, scan them, profile them and then harden them to reduce the bulk or all of the vulnerabilities.
  • Director of Software Development
    <50M USD
    Software
    Review Source

    RapidFort handles my platform security so I can focus on building great software

    5.0
    Feb 6, 2026
    The software engineers at my company love writing software and building innovative solutions to real-world problems. But developing a good program isn't enough--the platform has to be secure. That involves scanning the software, identifying vulnerabilities, and going through a painstaking process of fixing, remediating, or explaining away each issue. That's not fun work; it's a chore, and it's the very thing that RapidFort takes care of for us. We use their curated images with FIPS-validated cryptography as the base for all of our production applications.
  • Engineer
    10B+ USD
    IT Services
    Review Source

    RapidFort: A Secure Way to Get a Handle on the Proliferation of Container Images.

    5.0
    Feb 6, 2026
    Outstanding product operation. Very fast and accurate scanner. Excellent support from the dev and operations team. Weekly sync ups and continual support for implementation and testing. Slack channel is very helpful. The web GUI is simple and effective. The CLI tool and documentation is very easy to use and understand. There are frequent features being added that help make the system much more valuable. Curated images are of great value for vulnerability remediation, FIPS and STIG.
  • Chief Technology Officer
    <50M USD
    Software
    Review Source

    Turn key reduction in container supply chain risk

    5.0
    Nov 20, 2025
    The RapidFort team has been a great partner to work with, working with us to find ways to address our security hardening needs. They were key to us getting and maintaining our SOC 2 compliance, allowing us to implement strong proactive controls for container vulnerability management.
Showing Result 1-5 of 10

Recommended Gartner Research

  • Market Guide for Software Supply Chain Security

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.