RapidFort

Attack surface reduction platform: curated near-zero-CVE images plus runtime profiling that strips unused components from your own images.

https://www.rapidfort.com
best_for

Platform teams that want to harden existing first-party images, and federal/defense-adjacent programs that need attack surface evidence, not just CVE counts.

strengths

  • Two tools in one: curated hardened images and a profiling pipeline that hardens the images you already have
  • Runtime profiling (RBOM) removes components you provably never execute, cutting attack surface beyond CVE counts
  • Free community catalog of hardened images lowers the evaluation barrier
  • Meaningful US federal and DoD traction

weaknesses

  • Profiling-based hardening adds a pipeline step and operational learning curve versus a pure image swap
  • Smaller commercial catalog than Chainguard or Bitnami
  • Brand recognition trails the category leader outside federal circles

Attribute detail

Company
Founded
Headquarters
Funding / backing
Approach
Core approach
Base OS / distro
libc
Shell / package manager in runtime images
Catalog
Catalog size
Coverage scope
Custom / BYO image support
End-of-life version support
Security posture
Zero-CVE posture
CVE remediation SLA
Rebuild cadence
SBOM
VEX statements
Signing & provenance
Compliance
FIPS 140-3 variants
STIG hardening
Compliance fit (FedRAMP / PCI / HIPAA)
Operations
Migration effort
Private registry / air-gap delivery
Commercial
Pricing model
Free tier