RapidFort's SASM platform automatically optimizes and secures modern cloud software, dramatically improving security and productivity of the organization.
RapidFort enables dev teams to focus on producing great software without worrying about mundane tasks such as remediating vulnerabilities.
Software vulnerabilities are a constant struggle for developers. The ever-growing number of threats creates a never-ending patching cycle, exposing organizations. New compliance regulations add another layer of complexity, especially for FedRAMP, DSS, PCI, and public companies facing breach notification mandates. RapidFort SASM platform and the bundled RapidFort Curated images provide a pathway to attain compliance without breaking a sweat in days vs months.
RapidFort Curated Images is a collection of Near-Zero CVE images of the most commonly used Operating Systems, Frameworks, and applications. They are patched and hardened daily from the source with the latest security fixes and CVE remediations, resulting in Zero or Near-Zero CVEs, high-quality SBOMs, and SLSA Level 2 Build compliance.
RapidFort offers custom pricing through Private Offers. Contact sales@rapidfort.com for more information on our pricing bundles.
Highlights
Remove 95% of CVEs automatically with no code change.
Reduces vulnerability and patch management backlogs, automatically.
Saves developers from unnecessarily patching and maintaining UNUSED code.
Start a free trial - https://hub.rapidfort.com/contact
Seamlessly integrates with your CI/CD pipeline using a few simple API calls. RapidFort supports many popular CI/CD and Container deployment platforms
Provides a variety of reports including SBOMs to simplify and address software supply chain and compliance issues upstream. Download SBOMs in raw JSON, SPDX or Cyclone DX formats. Saves time tracking updates and complicated OSS licenses
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing has one pricing dimension: the RapidFort SASM Platform, billed as a contract that covers unlimited containers. You pay a single committed price rather than per-container or usage-based fees, so cost stays flat as your container count grows. The platform combines Near-Zero CVE images, container scanning, runtime profiling, automated hardening, and compliance validation into one purchase. Because coverage is unlimited, pricing does not scale with the number of containers you protect. Contact the vendor to arrange the contract term that fits your team.
Top-of-mind questions for buyers
What counts as a container for the unlimited coverage in this platform?
A container is any containerized workload the platform scans, profiles, or hardens. The contract covers an unlimited number of them, so you can protect every image and running instance across your registries and clusters without counting each one for billing.
Does my cost change as I add more containers or more workloads?
No. The platform is billed as a single contract covering unlimited containers. Your committed price stays flat whether you protect a few images or thousands. Adding registries, clusters, or new containerized workloads does not trigger extra per-container or usage-based charges.
What capabilities are covered under this single contract price?
The one contract covers Near-Zero CVE images, container scanning and SBOM generation, runtime profiling with RBOM, automated hardening on 24-hour refresh cycles, and compliance validation for frameworks like STIG, CIS, NIST, HIPAA, and PCI. These functions bill together under the single committed price.
www.rapidfort.com+1
Helpful?
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support is available during normal business hours Mon - Friday by email
support@rapidfort.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Automatically removes up to 95% of CVEs without requiring code changes, reducing vulnerability and patch management backlogs.
Daily Security Patching and Hardening
Curated images are patched and hardened daily from source with latest security fixes and CVE remediations, resulting in Zero or Near-Zero CVEs.
Software Bill of Materials Generation
Generates high-quality SBOMs in multiple formats including raw JSON, SPDX, and Cyclone DX to address software supply chain and compliance requirements.
CI/CD Pipeline Integration
Integrates with CI/CD pipelines and container deployment platforms through simple API calls.
Build Compliance Certification
Achieves SLSA Level 2 Build compliance for container images and applications.
Daily Security Patching and Rebuilding
Container images are patched and rebuilt daily from source with the latest security fixes and CVE remediations.
Vulnerability Reduction
Minimal, hardened container images delivering on average a 97.6% reduction in CVEs with low-to-zero known vulnerabilities.
Supply Chain Security Compliance
Full SLSA Level 2 - Build compliance with verifiable image signatures, attestations, and high-quality SBOMs.
Multi-Language Runtime Support
Pre-built images available for popular programming languages and runtimes including Go, Python, Ruby, PHP, and Node.
FIPS Compliance Availability
Production images with FIPS validation available for regulatory compliance requirements.
Software Supply Chain Visibility
Generates and monitors Software Bill of Materials (SBOMs), Release Bill of Materials (RBOMs), and AI Model Bill of Materials (AIBOMs) with component version details measured against known vulnerabilities
Vulnerability Scoring and Prioritization
Scores vulnerabilities at each environment (dev, QA, SIT, Prod) using exploitation signals from CISA, EPSS and other sources to prioritize remediation actions
Continuous Monitoring and Detection
Discovers and rescores new vulnerabilities and unscheduled changes in real-time through continuous monitoring of software supply chain components
Multi-Cloud and Hybrid Infrastructure Support
Supports AWS, Azure, Google Cloud multi-cloud deployments, hybrid cloud-on-premise, and on-premises configurations with scalability from small to large enterprises
Knowledge Graph-Based Risk Visualization
Organizes business products, services, and process collections into actionable and auditable visualizations with role-based customizable dashboards and Business Assurance scoring
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.