MASHINIi

Rapid7, Inc..

RPD.US | Computer programming activities

Rapid7, Inc. is a cybersecurity company that provides security solutions and services. Its offerings include vulnerability management, application security, incident detection and response, and security automation. The company's products and services help organizations to assess, monitor, and improv...Show More

Ethical Profile

Mixed.

Rapid7, a cybersecurity firm, has a mixed ethical profile. In 2021, a software supply chain breach allegedly compromised internal credentials and exposed alert-related data for some MDR customers, raising concerns about "Safe & Smart Tech." Critics also point to a 111:1 CEO pay ratio in 2024. However, Rapid7 invests 22.2% of revenue in R&D for cybersecurity and maintains robust compliance, including GDPR, ISO 27001, and annual SOX audits. The company has a formal whistleblower policy and an anti-corruption policy, with no major regulatory fines in three years, though occasional warning letters have been issued. Rapid7 aims for 100% carbon neutrality by 2030, with 50% by 2027.

Value Scores

Better Health for All0
-100100
Fair Money & Economic Opportunity0
-100100
Fair Pay & Worker Respect0
-100100
Fair Trade & Ethical Sourcing0
-100100
Honest & Fair Business-40
-100100
Kind to Animals0
-100100
No War, No Weapons0
-100100
Planet-Friendly Business-30
-100100
Respect for Cultures & Communities-10
-100100
Safe & Smart Tech-10
-100100
Zero Waste & Sustainable Products0
-100100

Better Health for All

0

Rapid7, Inc. is a cybersecurity company that provides security solutions and services, including for healthcare providers to address HIPAA compliance.

1
Its core products do not directly provide health benefits or cause health damage, nor do they involve health-related R&D, pricing, or access for vulnerable populations.
2
The company's operations do not directly intersect with healthcare workforce development, preventative health, or health crisis response.
3
There is no evidence that Rapid7 itself collects or manages health-related data, conducts clinical trials, or produces food/nutritional products.
4
Therefore, all KPIs are scored as 'Not applicable' or 'Neutral' as its business activities do not directly promote or harm health outcomes in the context of the rubric.

Fair Money & Economic Opportunity

0

Rapid7, Inc. is a cybersecurity company that provides security solutions and services to organizations. The company does not offer lending, deposit, or other consumer financial services.

1
Therefore, all KPIs related to financial products, services, or customer financial outcomes, such as underserved client share, pricing fairness, exploitative fee exposure, inclusion initiatives (loan/insurance book), data accessibility (open-banking APIs), fair lending compliance, wealth building outcomes, debt burden ratio, geographic inclusion (banking deserts), and product simplicity (financial products), are not applicable to its core business model.
2
While Rapid7 engages in philanthropic activities and initiatives to promote diversity and access to cybersecurity education and careers for underserved communities, these do not fall under the scope of 'community finance' or 'financial literacy' as defined by the rubric for financial institutions.
3

Fair Pay & Worker Respect

0

Rapid7's CEO to median employee pay ratio was 111:1 in 2024.

1
The company's overall employee rating on Glassdoor is 3.7 out of 5 stars, with 64% of employees recommending working there.
2
However, layoffs affecting 18% of the workforce were mentioned in 2022 and 2023, indicating high turnover.
3
The company has received awards such as 'Best Workplace in Boston' in 2022 and inclusion in the 2020 Bloomberg Gender-Equality Index.
4
No specific regulatory actions, violations, fines, or compliance issues related to labor laws are mentioned in the provided articles.
5

Fair Trade & Ethical Sourcing

0

Rapid7 states it considers itself at 'low risk' of slavery, unlawful child labor, or human trafficking within its business due to its software and cloud-based cybersecurity business model.

1
The company has a Global Human Rights Policy, a Modern Anti-Slavery Statement, and a Supplier Code of Conduct that prohibits child labor, forced labor, and human trafficking.
2
Rapid7 expects its suppliers and partners to uphold principles of fair labor and anti-slavery practices, and its channel partners have a contractual commitment to respecting applicable laws and the Partner Compliance Guide.
3
However, no quantitative data is provided for any of the KPIs, such as the percentage of spend covered by fair-trade certifications, audit frequency, number of forced or child labor incidents, traceability coverage, remediation speed, percentage of supplier contracts with enforceable ethical clauses, share of spend on high-risk materials, or supplier diversity spend.
4

Honest & Fair Business

-40

Rapid7 has a formal whistleblower protection policy that includes confidential and potentially anonymous reporting channels such as a hotline, online form, and email.

1
The company explicitly prohibits bribery, facilitation payments, kickbacks, and corrupt practices in its anti-corruption policy, referencing compliance with the FCPA and UK Bribery Act.
2
Rapid7 undergoes annual SOC 2 Type II and Sarbanes-Oxley Act (SOX) audits, and holds ISO 27001 certification, which involves annual audits.
3
The company also maintains compliance with GDPR, EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, and the UK Extension to the EU-U.S. Data Privacy Framework.
4

Kind to Animals

0

Rapid7, Inc. is a cybersecurity company providing software and services. The provided articles, including its Code of Business Conduct and Ethics and Social Good Reports, focus on ethical conduct, legal compliance, human rights, workplace safety, environmental sustainability, and cybersecurity initiatives.

1
There is no information or data related to animal welfare, animal testing, animal-derived products, animal agriculture, or wildlife conservation.
2
Therefore, all KPIs under the 'Kind to Animals' value are not applicable to the company's operations and no relevant evidence was found in the provided articles.
3

No War, No Weapons

0

No evidence available to assess Rapid7, Inc. on No War, No Weapons.

Planet-Friendly Business

-30

Rapid7 has set a carbon neutrality goal to achieve 50% by 2027 and 100% by 2030.

1
The company has an Environmental Sustainability Committee, conducts waste audits, recycles electronic waste, and minimizes landfill waste through recycling and composting.
2
Greenhouse gas emissions for 2019 and 2020 have been calculated and are awaiting third-party audit, with 2021 calculations underway.
3
Rapid7 is hosted by Amazon Web Services (AWS), which commits to 100% renewable energy by 2025.
4

Respect for Cultures & Communities

-10

Rapid7 partners with 8 specific schools, universities, and organizations globally, including BoSTEM, BUILD, Latinitas, Queen’s University Belfast, University of Canberra, Women Who Code, Hack.Diversity, and the University of South Florida, to foster STEM interest among youth from underserved communities.

1
The company targets that 30% or more of its new hires in Tampa will be emerging talent and/or recently retired military.
2
Rapid7 supports Latinitas, a digital magazine for young Latinas, and the New Commonwealth Racial Equity and Social Justice Fund.
3
In 2021, the company donated over half a million dollars to various charitable organizations, and in 2020, it contributed $350,000 to the Rapid7 for Good Fund.
4
The Rapid7 Cybersecurity Foundation was formed and seeded with $1,000,000.
5
Rapid7 committed resources to ensure ongoing support for its multi-language network fingerprinting library, Recog.
6
Employees can access diversity, inclusion, and belonging courses through LinkedIn Learning.
7

Safe & Smart Tech

-10

Rapid7 has achieved numerous privacy and security certifications, including annual SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and IRAP PROTECTED Level for several Insight Platform solutions.

1
The company also certifies compliance with the EU-U.S., Swiss-U.S., and UK Extension Data Privacy Frameworks, and the Dubai Electronic Security Center (DESC) Cloud Service Provider (CSP) Security Standard.
2
Rapid7 has implemented controls for GDPR and SOX compliance.
3
In May 2021, Rapid7 disclosed a breach from April 2021 where a limited subset of source code repositories for internal tooling was accessed, and internal credentials and alert-related data for a subset of MDR customers were exposed.
4
No production environments were affected.
5
Rapid7's Privacy Policy states that it only processes customer information to deliver its sites, solutions, and services, and retains personal information only as long as reasonably necessary.
6
Users have the right to access, correct, update, or request deletion of their personal information, and can opt-out of marketing communications and interest-based advertising.
7
Rapid7 may challenge government or law enforcement requests for customer data that they consider overly broad or unlawful.
8

Zero Waste & Sustainable Products

0

No evidence available to assess Rapid7, Inc. on Zero Waste & Sustainable Products.

Own Rapid7, Inc.?

Upload your portfolio and see how all your holdings score across 11 ethical dimensions.

Audit My Portfolio

AI-generated analysis based on publicly available data. Not financial advice. Ratings are expressions of opinion derived from automated models and may contain inaccuracies. See our Risk Disclosure for full details.