Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybersecurity Funding

RapidFort Raises $42M to Automate Software Supply Chain Security

The company will use the latest capital to scale its go-to-market efforts and expand its platform’s capabilities.

Funding

Software supply chain security firm RapidFort announced on Tuesday that it has raised $42 million in a Series A funding round to accelerate the development of its automated vulnerability elimination technology.

The investment was led by Blue Cloud Ventures and Forgepoint Capital, with participation from Felicis Ventures, Alumni Ventures, Boulder Ventures, Brave Capital, Evolution Ventures, Florida Funders, Gaingels, and Mana Ventures.

The San Francisco-based company has raised more than $50 million to date and will use the latest capital to scale its go-to-market efforts and expand its platform’s capabilities.

RapidFort provides a software attack surface management platform that secures the entire lifecycle by continuously analyzing and hardening software artifacts. The technology is designed to eliminate vulnerabilities before they reach production environments.

The platform offers a three-step approach to security, starting with tools that scan and profile containers in the CI/CD pipeline. This process generates a Software Bill of Materials (SBOM) and identifies unused packages that can be removed.

The company also maintains a catalog of thousands of curated, near-zero-CVE container images built on major Linux distributions. These images allow teams to replace vulnerable third-party base images with hardened versions that are FIPS 140-3 validated and STIG/CIS benchmarked.

Advertisement. Scroll to continue reading.

RapidFort’s runtime intelligence further reduces the attack surface by removing components that are never executed during an application’s operation. The company claims this hardening process occurs with less than 1% compute overhead while ensuring compliance with federal standards such as FedRAMP and CMMC.

“The problem isn’t that organizations don’t know they have vulnerabilities, it’s that they can’t fix them fast enough,” said Mehran Farimani, founder and CEO of RapidFort. “RapidFort exists to eliminate vulnerabilities continuously — at machine speed — before they reach production.”

Related: Kasada Raises $20 Million for Anti-Bot Expansion

Related: Aisy Launches Out of Stealth to Transform Vulnerability Management

Related: Mesh Security Raises $12 Million for CSMA Platform

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Malwarebytes has named Chung Ip as Chief Financial Officer.

Semperis has appointed John Podboy as Chief Information Security Officer.

Randy Menon has become Chief Product and Marketing Officer at One Identity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.