RapidFort
Sunnyvale, US · Founded 2020 · Delaware corporation · 119 employees on LinkedIn · 14 known investors
RapidFort provides a software supply chain security platform that analyzes and hardens container images to eliminate vulnerabilities and reduce attack surface across development and production environments. The platform offers vulnerability scanning, runtime profiling, curated base images, and compliance validation to help organizations secure containerized applications.
Also known as RapidFort, Inc.
Founders & leadership
RapidFort was founded in 2020 by Mehran Farimani, Russ Andersson, Rajeev Thakur, George Manuelian, and Rajeev T.




Board
Investors · 14
Funding
SEC filings, press & company announcements$51.4M disclosed across 2 rounds · 2022–2026
- $42MSeries AFeb 2026 · 4 sources
Blue Cloud Ventures (lead), Forgepoint Capital (lead), Alumni Ventures, Boulder Ventures, Brave Capital, Evolution Ventures, Felicis Ventures, Florida Funders, Gaingels, Mana Ventures
Source ↗
▶$9.4MraisedMar 2022 · 29 investors · Other TechnologyRule 506(b)
- Rajeev ThakurDirector
- Robert MeeDirector
- Mehran FarimaniExecutive Officer, Director
- Russell AnderssonDirector
- Offering amount
- $9.5M
- Amount sold
- $9.4M
- First sale
- Feb 2022
- Incorporated
- Corporation, Delaware, 2020
- Federal exemptions
- 06b
Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.
Company profile
researched Aug 2026RapidFort develops a software supply chain security platform for containerized applications. The platform spans vulnerability analysis, runtime behavior profiling, curated base images, automated hardening, and compliance validation, and is positioned to work without application code changes, operating-system changes, or CI/CD pipeline modifications [0][1][3].
The product set comprises six named components: RapidFort Analyzer (vulnerability scanning across images, registries, CI pipelines and Kubernetes clusters, with reconciliation across scanners and reduced finding noise); RapidFort Profiler (runtime visibility into which components actually execute, producing a Runtime Bill of Materials, marketed under the registered RBOM trademark); RapidFort Curated Images (more than 35,000 near-zero-CVE, continuously patched base images built on LTS Linux distributions including Ubuntu, RHEL, Debian and Alpine); RapidFort Curated Libraries (malware-scanned open-source libraries); RapidFort Optimizer (removal of unused packages, binaries and libraries with rebuilds on a 24-hour cadence); and RapidFort CART (continuous compliance validation against security baselines with audit-ready reporting) [0][1][3].
The company markets outcome claims including elimination of up to 99.9% of CVEs, 60-90% attack surface reduction, roughly 10% development cost reduction, and release acceleration of two to three weeks, alongside cumulative platform statistics of 82 million packages secured, 124 million vulnerabilities removed and more than one million images hardened [0][1][3].
Business model
RapidFort offers a commercial platform sold to enterprises and public-sector organizations, gated behind "Request Access" and demo workflows on its website, with product modules covering analysis, profiling, curated images and libraries, hardening and compliance reporting. Sources do not disclose pricing or contract structure; the site references an ROI calculator, a partner program and a datasheet download [0][1][2][3].
Traction
Company-reported figures include more than 100 customers and 15,000 curated hardened images as of October 2025, growing to over 35,000 curated near-zero-CVE images on the current website, plus cumulative totals of 82 million packages secured, 124 million vulnerabilities removed and over one million images hardened. A named customer/partner example is The Modern Data Company, which selected RapidFort's curated images and platform in November 2025 [0][1][6].
Latest developments
On 3 February 2026 RapidFort announced a $42 million Series A led by Blue Cloud Ventures and Forgepoint Capital with participation from Felicis Ventures, Alumni Ventures, Boulder Ventures, Brave Capital, Evolution Ventures, Florida Funders, Gaingels and Mana Ventures, earmarked for go-to-market scaling, automated remediation and near-zero-CVE delivery, enterprise deployments in regulated industries, and lifecycle software supply chain assurance. The company also lists an appearance at the Billington CyberSecurity Summit 2026 (Sept. 8-10) [0][1][4][5].
▸Full profile — market position, technology, go-to-market, geography, history, risks & controversies
Market position
The company describes itself as a technical leader in software supply chain security and reports inclusion in Gartner research; its site references a 2026 Gartner Magic Quadrant for Software Supply Chain Security report. An investor describes it as "a leader in Software Supply Chain Security." It reported surpassing 100 customers in October 2025 and won the 2025 CyberShark Pitch Competition [2][4][6].
Stated differentiators are runtime-validated hardening that removes unused components without requiring code, OS or pipeline changes; curated images built on mainstream LTS Linux distributions to avoid proprietary OS vendor lock-in; patched rather than daily-rebuilt images intended to remain production stable; coverage of both first-party and third-party components; and integrated STIG/CIS benchmark support for regulated and federal environments [0][1][3].
Technology
The platform combines static vulnerability scanning with runtime instrumentation. Profiling captures which binaries, libraries and packages actually execute in production, generating a Runtime Bill of Materials (RBOM) that drives automated removal of dormant or unreachable components from container images; the company states profiling overhead is under 1%. Curated images are built and continuously patched on LTS Linux distributions rather than a proprietary OS, and hardened images are rebuilt every 24 hours. Compliance tooling evaluates images against STIG, CIS and FIPS-related benchmarks and produces remediation guidance and audit evidence [0][1][3].
Go-to-market
Go-to-market is direct enterprise and federal sales supported by partners, conference presence (for example a booth and session at the Billington CyberSecurity Summit 2026) and content assets such as webinars, blogs, an ROI calculator and analyst-report offers. Following its Series A the company stated it would scale sales, marketing and partnerships, deepen integrations, and improve onboarding for regulated-industry deployments [0][1][2][5].
Development, DevOps and security teams at software vendors and enterprises running containerized applications, with industry pages for finance, healthcare, public sector, AI and software. The company emphasizes regulated and mission-critical environments, including federal customers and vendors serving classified infrastructure, and says its customer base ranges from startups to Fortune 500 enterprises [0][1][2][5].
Geography
Headquarters address listed as 440 North Wolfe Road, Sunnyvale, CA 94085; one funding report datelines the company as San Francisco, CA-based. Sources describe federal and enterprise customers in the United States; no other offices are identified [2][3][5].
History
The company's press archive references an earlier $8.5M seed round for its attack surface management platform, and the February 2026 Series A release names Felicis Ventures as the prior lead investor. Publicly documented milestones include the 2025 CyberShark Pitch Competition win (October 2025), reported customer and image-count milestones plus Gartner research inclusion (October 2025), The Modern Data Company deployment (November 2025), and the $42M Series A (February 2026) [4][5][6].
Risks & controversies
No controversies are reported in the sources. Most performance figures (99.9% CVE elimination, 90% attack surface reduction, cost and release-time savings, cumulative package and image counts) are company-published claims without independent verification, and the curated-image count differs between the October 2025 announcement (15,000) and the current website (35,000+), reflecting different points in time [0][1][6].
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Competitors · 10
by search overlapCompanies competing with RapidFort for the same Google search keywords, organic and paid, via search-intersection analysis.
Non-dilutive funding · 11 SBIR/STTR awards
Federal grants — no equity taken| Agency | Phase | Year | Amount |
|---|---|---|---|
| U.S. Air ForceAir Force | Phase II | 2023 | $1.7M |
| U.S. Air ForceAir Force | Phase II | 2023 | $1.7M |
| U.S. Air ForceAir Force | Phase IISTTR | 2023 | $1.2M |
| U.S. Air ForceAir Force | Phase I | 2023 | $75K |
| U.S. Air ForceAir Force | Phase ISTTR | 2023 | $75K |
| U.S. Air ForceAir Force | Phase II | 2022 | $1.5M |
| U.S. Air ForceAir Force | Phase II | 2022 | $750K |
| U.S. Air ForceAir Force | Phase II | 2022 | $750K |
| U.S. Air ForceAir Force | Phase ISTTR | 2022 | $250K |
| U.S. Air ForceAir Force | Phase I | 2022 | $49.2K |
| U.S. Air ForceAir Force | Phase I | 2021 | $49.2K |
Source: SBIR.gov award data (U.S. Small Business Administration). SBIR/STTR awards are competitive federal R&D grants and contracts — non-dilutive capital alongside any venture rounds above.
Timeline · 4
launches, deals, and filingsRapidFort announced $42 million in Series A funding led by Blue Cloud Ventures and Forgepoint Capital, with participation from prior lead investor Felicis Ventures plus Alumni Ventures, Boulder Ventures, Brave Capital, Evolution Ventures, Florida Funders, Gaingels and Mana Ventures. Stated uses include go-to-market expansion, platform innovation (automated remediation, near-zero-CVE software delivery, continuous attack surface reduction), enterprise adoption in regulated industries, and end-to-end software supply chain assurance.
$42M source ↗
Press item states The Modern Data Company selected RapidFort's Curated Images and platform to enhance and accelerate customer data security.
Company announcement citing market traction milestones: more than 100 customers, 15,000 curated near-zero-CVE hardened images, and inclusion in Gartner research.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
Legal entities · 1
corporate structureIn the news
▸Research sources · 8
primary sources listed
- RapidFortrapidfort.com · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does RapidFort do?
- RapidFort sells a software supply chain security platform that hardens container images and removes unused components to cut CVEs.
- Who founded RapidFort?
- RapidFort was founded by Mehran Farimani, Russ Andersson, Rajeev Thakur, George Manuelian, Rajeev T in 2020.
- Who are RapidFort's investors?
- RapidFort's investors include ForgePoint Capital, Cheyenne Ventures, Delta-v Capital, Evolution Ventures, Felicis Ventures, Florida Funders, Rembrandt Venture Partners, Alumni Ventures and 6 more.
- How much funding has RapidFort raised?
- RapidFort has disclosed $51.4M raised across 2 rounds.
- Where is RapidFort headquartered?
- RapidFort is headquartered in Sunnyvale, US.



__Twitter.png)



