Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybersecurity Funding

RapidFort Raises $42M to Automate Software Supply Chain Security

The company will use the latest capital to scale its go-to-market efforts and expand its platform’s capabilities.

Funding

Software supply chain security firm RapidFort announced on Tuesday that it has raised $42 million in a Series A funding round to accelerate the development of its automated vulnerability elimination technology.

The investment was led by Blue Cloud Ventures and Forgepoint Capital, with participation from Felicis Ventures, Alumni Ventures, Boulder Ventures, Brave Capital, Evolution Ventures, Florida Funders, Gaingels, and Mana Ventures.

The San Francisco-based company has raised more than $50 million to date and will use the latest capital to scale its go-to-market efforts and expand its platform’s capabilities.

RapidFort provides a software attack surface management platform that secures the entire lifecycle by continuously analyzing and hardening software artifacts. The technology is designed to eliminate vulnerabilities before they reach production environments.

The platform offers a three-step approach to security, starting with tools that scan and profile containers in the CI/CD pipeline. This process generates a Software Bill of Materials (SBOM) and identifies unused packages that can be removed.

The company also maintains a catalog of thousands of curated, near-zero-CVE container images built on major Linux distributions. These images allow teams to replace vulnerable third-party base images with hardened versions that are FIPS 140-3 validated and STIG/CIS benchmarked.

Advertisement. Scroll to continue reading.

RapidFort’s runtime intelligence further reduces the attack surface by removing components that are never executed during an application’s operation. The company claims this hardening process occurs with less than 1% compute overhead while ensuring compliance with federal standards such as FedRAMP and CMMC.

“The problem isn’t that organizations don’t know they have vulnerabilities, it’s that they can’t fix them fast enough,” said Mehran Farimani, founder and CEO of RapidFort. “RapidFort exists to eliminate vulnerabilities continuously — at machine speed — before they reach production.”

Related: Kasada Raises $20 Million for Anti-Bot Expansion

Related: Aisy Launches Out of Stealth to Transform Vulnerability Management

Related: Mesh Security Raises $12 Million for CSMA Platform

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.