Rapid7

Last updated: Aug 12, 2026


How does Fluid Attacks' solution compare to Rapid7's?

The following comparison table enables you to discern the performance of both providers across various attributes essential for meeting your company's cybersecurity needs. To better understand each attribute, read their descriptions in the dedicated page.

Organization

AttributeEssentialAdvancedRapid7
Focus

Native ASPM with in-house scanners

AI-powered PTaaS on top of native ASPM with in-house scanners

Exposure management and managed detection and response (MDR)

ExtrasNoneNone

Application security testing (DAST), attack surface management (ASM), cloud-native application protection platform (CNAPP), penetration testing and threat intelligence

Headcount

157

Same

3728
Headcount distribution

Engineering 40%, IT 14%, sales 15%, marketing 2%, operations 4% and others 25%

Same

Engineering 25%, IT 17%, sales 14%, operations 6% and others 38%

Headcount growth

+14%, +15%, -1%

Same

-2%, +4%, +13%
Headquarters

CO and US

Same

AE, AU, CZ, DE, GB, IE, IL, IN, JP, SG and US

Countries

AR, BO, CA, CL, CO, DO, MX, PA, PE and US

Same

BR, GB and US
Reputation

9.44 from 228 reviews over 8 years on Gartner and Clutch

Same

8.65 from 2,592 reviews over 10 years on Capterra, G2, Gartner, PeerSpot and TrustRadius

Followers

22K based on the following: Facebook, Instagram, LinkedIn, X and YouTube

Same

387K based on the following: Facebook, Instagram, LinkedIn, X and YouTube

Research firmsNoneNone

Forrester, Frost & Sullivan, Gartner, IDC, Nucleus Research and Omdia

Founded2001Same2000
FundingBootstrappedSame$350.5M USD in 8 rounds from 5 investors
AcquisitionsNoneNone

Acquired 0 times and made 14 acquisitions

Revenue

10M to 15M

Same

800M to 900M
Third-Party CVEs Discovered

289 CVEs reported to MITRE, ranked in the top 10 CVE labs worldwide

Same

48 CVEs reported to MITRE
Compliance

GDPR, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701:2019, PCI DSS, SOC 2 Type II and SOC 3

Same

Cyber Essentials Plus, EU-US DPF, FedRAMP Authorized, GDPR, GovRAMP, ISO/IEC 27001 and SOC 2 Type II

Bug bounty

Yes

Yes

No
Visits

64K per month. Top 3: 18% CO, 9% US, 5% BR. Others 68%

Same

775K per month. Top 3: 30% US, 7% IN, 7% GB. Others 56%

Authority

33 out of 100

Same

50 out of 100
Public vulnerability DB

Discovered and third-party

SameDiscovered and third-party
Content

Blog, documentation, e-books, glossary, reports, success stories, videos, webinars and white papers

Same

Blog, documentation, e-books, glossary, infographics, podcasts, reports, success stories, videos, webinars and white papers

Comprehensive documentation

13 documentation sections

Same

11 documentation sections, 8 in common and 3 additional

CommunityForumSameForum
Sync training

1 workshop

Same

2 live product use courses (paid)

Async training

3 product use courses, all free

Same

Security education platform (subscription-based)

Distribution

Direct or with any of its 14 partners

SameDirect or with any of its partners
Marketplaces

AWS

Same

AWS, Azure and GitHub
FreemiumNoNoNo
Free trial

21-day free trial

PoV30-day free trial
DemoYesYesYes
Open demoNoNoNo
Pricing

Contact sales and marketplace

Contact sales

Contact sales, marketplace and public web
Pricing tiers1 plan1 plan

3 plans (Essentials, Advanced and Ultimate). None transparent.

Minimum termMonthlyMonthlyAnnually
Minimum payment periodMonthlyMonthlyAnnually
Minimum capabilities

ASPM, binary SAST, containers, CSPM, DAST, IaC, SAST, SCA and secrets

Same plus: AI SAST, API security testing, MAST, PTaaS, RE and SCR

ASM
Minimum scope1 authorSame1 asset or app
Pricing driversAuthorsSameApps, assets or instances
Free implementationYesYesNo information available
Free supportYesYesYes

Service

AttributeEssentialAdvancedRapid7
PTaaSNoYesMPT and PTaaS
Reverse engineeringNo

Yes

No information available
Secure code reviewNo

Yes

No information available
PivotingNoYesYes
ExploitationNoYesYes
Manual reattacksNot applicable

Unlimited reattacks

No information available
Zero-day vulnerabilities

Scanner-based zero-day vulnerability detection

Continuous zero-day vulnerability research

Continuous zero-day vulnerability research
SLA

Availability

Accuracy, availability and response

Availability
Minimum availability

99.95% per year

Same

99.95% per month
After-sale guaranteesNoYesYes
Accreditations

CNA, Penetration Testing by CREST and OpenSSF Gold Badge

Same

AWS Security Competency and CNA

Pentester certificationsNot applicable

202 from 59 different types

No information available
Type of contractEmployeeSameEmployee
Endpoint controlNo

Total

No information available
Channel controlNoTotalNo information available
Standards

Some requirements from 67 standards

All requirements from the same standards

31 standards, 19 in common and 12 additional

Detection method

Automated tools

AI, automated tools and human intelligence

AI, automated tools and human intelligence
Remediation

5

Same, plus 1

4, 3 in common and 1 additional
Output

5

Same, plus 2

6, 2 in common and 4 additional

Product

AttributeEssentialAdvancedRapid7
ASPM

Yes

Yes

No
API

GraphQL with JSON

Same

REST with JSON
IDE5 functionalities

Same, plus 1 functionality

No
CLIYesYesYes
CI/CD

Breaks the build

Same

Breaks the build
Vulnerability sources

18 sources, 5 in common and 13 additional

Same

7 sources, 5 in common and 2 additional

Threat model alignment

Yes

Yes

No
Priority criteria

CVSS v4.0, CVSSF, EPSS and KEV

SameCVSS and KEV
Custom prioritization

Priority score

Same

Risk score
Scanner originIn-houseIn-houseIn-house
SCA

19 package managers

Same

No
AI securityNoYesYes
Reachability

12 languages

Same

No
Reachability type

Deterministic

Same

Not applicable
SBOM

22 package managers

Same

No
Malware detectionYesYesNo
Autofix on componentsNoNoNo
Containers

4 distributions, 3 in common and 1 additional

Same

12 distributions, 3 in common and 9 additional

Source SAST (languages)

12

Same

No
Source SAST (frameworks)

23

Same

No
Custom rulesNoNoCustom attack modules
IaC

6, 2 in common and 4 additional

2, all in common

2, all in common
Binary SAST

1 type of binary

Same, plus 2 types of binaries

No
DAST

7 attack surface types

Same

Yes. No information available
API security testingNo

4 types of APIs, 3 in common and 1 additional

3 types of APIs, all in common

MASTNoYesNo
IASTNoNoNo
CSPMYesYesYes
Secrets

171 secrets types

Same, plus verify other attack vectors and secrets exploitability

No
AI

4 functions, 1 in common and 3 additional

Same, plus 1 function

4 functions, 1 in common and 3 additional
AI SASTNoYesNo
MCPYesYesYes
Open-sourceNoNoBSD 3-Clause license
Deployment

SaaS (multi-tenant)

Same

SaaS (multi-tenant) + on-premises (no tenancy information)

RegionsUSAP, AU, CA, EU, ME and US
StatusYesYesYes
Incidents3 per yearSame1.8 per year

Integrations

AttributeEssentialAdvancedRapid7
SCM

6, 4 in common and 2 additional

Same

4, all in common
Binary repositoriesNoneNone1
Ticketing

3, 1 in common and 2 additional

Same

2, 1 in common and 1 additional

ChatOpsNoneNone2
IDE3

Same

None
CI/CD

21, 6 in common and 15 additional

Same

6, all in common
SCANativeSameNone
ContainerNativeSameNative
SASTNativeSameNone
DASTNativeSameNative
MASTNoneNativeNone
IASTNoneNoneNone
Cloud

1 in common

Same

3, 1 in common and 2 additional

CSPMNativeSameNative
Secrets

Native

Same

Native powered by GitGuardian
RemediationNoneNone4
Bug bountyNoneNoneNone
Vulnerability managementNoneNone13
ComplianceNoneNoneNone

More like Rapid7

Tags

aisecurityapiasmcomparecontainerscspmdastexploitationiacmcpmptopensourcepivotingptaasrt

On this page