View & download information relating to our security practices and data handling
Security at Rapid7 encompasses more than just our products. Rapid7 has policies and procedures in place to keep both our data and products secure, so that we can continue to keep our Customers secure.At Rapid7, we strive to create a great experience for customers and make the most successful security technologies and practices accessible to all. It is our priority to ensure you have information you need to trust Rapid7 as a security partner. We have created this Trust Profile to provide transparency and to give you access to latest security information and security artifacts to help you successfully conduct due diligence on Rapid7. If you still have questions after reviewing our documentation, we are happy to address them. Kindly contact your account representative via email with your additional questions.

HIPAA

PCI DSS

NIST CSF

NIST SP 800-171

NIST SP 800-53

NIS2

GDPR

FedRAMP




A high-level security and compliance roadmap has been published outlining upcoming initiatives, assessments, and control enhancements.
The roadmap is intended to provide visibility into the continuous improvement of security and risk management programs.
The Trust Center has been updated to improve clarity and organization of security and compliance documentation.
This update reflects an ongoing commitment to transparency for customers, prospects, and the public.
A scheduled review of access control and user provisioning policies has been completed.
The review validated role-based access controls, least-privilege principles, and periodic access review procedures.
An incident response tabletop exercise was conducted to test escalation paths, communication workflows, and response procedures under simulated scenarios.
Lessons learned were documented and incorporated into response playbooks.
The third-party risk assessment framework has been updated to reflect evolving security and compliance expectations.
Enhancements include updated due diligence questionnaires, clearer risk scoring, and standardized remediation tracking.
All employees have completed annual security awareness training.
Training topics included phishing awareness, data protection, and incident reporting, with completion tracked internally.
An annual review of Business Continuity and Disaster Recovery (BC/DR) plans has been completed.
Testing scenarios included simulated system outages and recovery procedures to validate recovery time and recovery point objectives.
The annual enterprise risk assessment has been completed.
This process included identifying key operational, security, and compliance risks, validating control coverage, and documenting mitigation plans reviewed by leadership.
A recent independent penetration test has been completed. A high-level executive summary is available in the Trust Center.
The assessment evaluated application security and infrastructure controls. Identified findings were reviewed, prioritized, and addressed through established risk management processes.
"(Required)" indicates required fields
You will receive an account activation email once our team approves your registration. Once logged in, you may download any file or report.
You will receive regular e-mails unless you unsubscribe from this service. You can find a link at the bottom of your emails to unsubscribe.