ComplyGuideComplyGuide
HomeSoftwareLearn
Submit a Tool
ComplyGuideComplyGuide

Find and compare compliance automation tools.

Directory

  • All Vendors

Frameworks

  • SOC 2
  • HIPAA
  • GDPR
  • ISO 27001
  • PCI DSS
  • FedRAMP
  • NIST CSF

Resources

  • Learn

For Vendors

  • Submit a Tool
  • Pricing & Premium
  • Claim Your Listing

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 ComplyGuide. All rights reserved.

Made for compliance professionals

Get a RecommendationBrowse Tools
Home/Vendors/Rapid7
Rapid7 logo

Rapid7

Security analytics and compliance for hybrid environments

4.3
Editorial
based on 28 data points
PCI DSS
HIPAA
NIST CSF
ISO 27001
GDPR
Visit Rapid7See pricing
Customer quotes
28
Customers
8
Case studies
7
Years active
26

founded 2000

Companies referencing Rapid7

W
Wyndham Hotels
PaddlePaddle
Z
Zoopla
A
Arcadis
C
Capital on Tap
E
EVRi
K
Keyloop
V
Visier
“We're not buying tools. We're buying outcomes. And we're not just outsourcing the work, we're partnering with a team that knows our environment and shares our goals.”
Paddle
Colin Barr
Head of InfoSec and IT, Paddle · Paddle
AboutReferences28Case studies7PricingFAQSimilar tools

About Rapid7

Rapid7 provides security analytics and automation solutions including InsightVM for vulnerability management and InsightConnect for SOAR. The platform helps organizations manage security compliance, detect threats, and demonstrate regulatory adherence across cloud and on-premise environments.

Editorial summary

ComplyGuide

Rapid7 users value the platform's combined security analytics, vulnerability management, and compliance capabilities, particularly the InsightVM product for maintaining continuous compliance visibility. The platform is well-suited for organizations needing both security operations and compliance reporting, though dedicated GRC users may find it less comprehensive than purpose-built tools.

Strengths
  • Strong vulnerability management with continuous compliance monitoring
  • Good integration of security operations with compliance reporting
  • InsightVM provides excellent visibility across hybrid environments
  • Comprehensive compliance templates for PCI DSS, HIPAA, and NIST
Considerations
  • Primarily a security platform rather than a dedicated GRC tool
  • Resource-intensive scanning can impact system performance
  • Compliance features are secondary to security capabilities

What customers say

Showing 12 of 28. The rest are locked.

W
Wyndham Hotels

12 references · Hospitality

The Rapid7 platform has made a difference as far as our ability to have this wide casting net and visibility.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
We use over 150 different applications today which includes a mix of security, IT and general business applications. We're always looking at how we can better secure those applications that we don't necessarily have much control over. And how we can keep better tabs on who and why and when they're being used.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
We left a competitor to implement InsightAppSec and bring things closer together in the Rapid7 world. We're running scans twice a month or monthly for some of our web apps, and sending those reports to our internal customers.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
We had several machines impacted and we had them all remediated within 30 days. I've never seen us work that fast before. But again, that was Rapid7. That was us dashboarding. We were 100% reliant on Rapid7 and we got the job done.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
The agents provide real-time data. We make tremendous use of the InsightVM dashboards for vulnerability management and our internal customers expect reports on a regular basis. But, we were a spreadsheet organization for many, many years; the whole vulnerability management program hinged on a spreadsheet.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
We cleaned up all of our tags, our asset groups, and we said everything is going to be in a dashboard. If you want to know how an asset's doing, you've got to login to view it. We're not doing spreadsheets anymore.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
That was the fastest I've ever seen us remediate 100% of the organization over a holiday period, at Christmas. We had several machines impacted and we had them all remediated within 30 days.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
If we have EDR and we have Rapid7 on an endpoint, we're good. And that's the impression that we make across the board as far as deployments go.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
And so, we started to ingest stuff into IDR, things like our web-proxy data and identity management logs.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
Having everything in one spot, one login, one place certainly helps with the day-to-day work that's going on, especially for the teams that are cross-platform.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
It's a lot fewer vendors that we have to be on the phone with. We've certainly been called over the last 10 years from competitors looking for us to move our operation, but really, we don't want to leave Rapid7. We feel like we have such a good thing going with Rapid7. We've got the entire Rapid7 team on our regular calls, because it's a cross-platform today with InsightAppSec and vulnerability management, all of our SOC people, and all of our IR people, all together.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
That was a huge success, everyone is feeling better. We're across the board very happy with everything that Rapid7 is delivering today.
Joseph Gothelf·Vice President for Cybersecurity, Wyndham Hotels
Paddle

Paddle

10 references · Locked

We're not buying tools. We're buying outcomes. And we're not just outsourcing the work, we're partnering with a team that knows our environment and shares our goals.

Colin Barr · Head of InfoSec and IT, Paddle

Z

Zoopla

6 references · Real Estate Tech · Locked

We help them create their own website and offer them training. Zoopla is a much wider business than just one website.

Alikhan Uzakov · Application Security Engineer, Zoopla

16 more quotes from 2 companies locked

Claim this listing and upgrade to unlock the rest.

Claim listingTalk to us

Case studies

7 documented outcomes from Rapid7 customers. Showing 1 of 7 — the rest are locked.

E
EVRi

Logistics

EVRi compliance and security monitoring with Rapid7

Read original
A

Arcadis

Design/Consultancy · Locked

Arcadis security operations with Rapid7

Arcadis security operations with Rapid7

W

Wyndham Hotels

Hospitality · Locked

Wyndham Hotels security operations with Rapid7

Wyndham Hotels security operations with Rapid7

Z

Zoopla

Real Estate Tech · Locked

Zoopla security and threat detection with Rapid7

Zoopla security and threat detection with Rapid7

V

Visier

HR Analytics · Locked

Visier security operations with Rapid7

Visier security operations with Rapid7

C

Capital on Tap

FinTech · Locked

Capital on Tap security with Rapid7

Capital on Tap security with Rapid7

K

Keyloop

Automotive Tech · Locked

Keyloop security operations with Rapid7

Keyloop security operations with Rapid7

6 more case studies locked

Rapid7 is on the Verified tier. Upgrade to Premium to unlock every customer case study for prospects to see.

Claim listingTalk to us

Pricing

3 plans available.

InsightVM Essentials

Contact for pricing
  • Vulnerability management
  • Compliance reporting
  • Basic dashboards
  • Standard support
Learn More
Most Popular

InsightVM Professional

Contact for pricing
  • Advanced analytics
  • Remediation workflows
  • Custom reports
  • API access
Learn More

Insight Platform Enterprise

Contact for pricing
  • Full security suite
  • SOAR automation
  • Unlimited assets
  • Dedicated CSM
Learn More

User reviews

Be the first to write a community review of Rapid7.

Write a review

Share your experience with Rapid7 and help others make informed decisions.

Company details

rapid7.com
Founded 2000
1000+ employees
Boston, MA

Frameworks

PCI DSS
HIPAA
NIST CSF
ISO 27001
GDPR
Visit website

Get Pricing Info

Are you the vendor? Claim this listing.

Claim this listing

Similar tools

Sprinto logo

Sprinto

4.8
Featured

Compliance automation for cloud-first companies

SOC 2
HIPAA
GDPR
+1

79 customer references

1Password logo

1Password

4.7

Enterprise password and secrets management with compliance

SOC 2
GDPR
ISO 27001
+1

26 customer references

Drata logo

Drata

4.7
Featured

Continuous compliance automation with 85+ integrations

SOC 2
HIPAA
GDPR
+2

119 customer references

Wiz logo

Wiz

4.7

Cloud security platform with compliance capabilities

SOC 2
HIPAA
GDPR
+2

1 customer reference

Anecdotes logo

Anecdotes

4.6

Compliance operating system for modern enterprises

SOC 2
HIPAA
GDPR
+1

21 customer references

Vanta logo

Vanta

4.6
Featured

Automated compliance for SOC 2, HIPAA, ISO 27001 & more

SOC 2
HIPAA
GDPR
+2

70 customer references

Compliance guides

What Is PCI DSS? A Complete Guide to Payment Card Security

PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards created by major card brands (Visa, Mastercard, Amex, Discover, JCB) to protect cardholder data. Any organization that accepts, processes, stores, or transmits credit card information must comply.

PCI-DSS
14 min read

PCI DSS 4.0 Requirements: All 12 Explained in Detail

PCI DSS 4.0 has 12 core requirements organized under 6 goals: build secure networks, protect account data, manage vulnerabilities, control access, monitor and test networks, and maintain security policies. Together they contain approximately 400 individual test procedures.

PCI-DSS
22 min read

What Is HIPAA? A Complete Guide to HIPAA Compliance

HIPAA (Health Insurance Portability and Accountability Act) is a US federal law that sets national standards for protecting sensitive patient health information (PHI) from being disclosed without the patient's consent or knowledge.

HIPAA
12 min read

HIPAA Compliance Checklist for 2025

A comprehensive HIPAA compliance checklist covers risk assessments, administrative/physical/technical safeguards, Business Associate Agreements, workforce training, breach notification procedures, and ongoing documentation requirements.

HIPAA
10 min read
Browse all compliance guides →