Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightCloudSec vs Snyk comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightCloudSec
Ranking in Cloud Management
30th
Ranking in Cloud Security Posture Management (CSPM)
28th
Average Rating
7.2
Reviews Sentiment
6.9
Number of Reviews
5
Ranking in other categories
Cloud-Native Application Protection Platforms (CNAPP) (19th)
Snyk
Ranking in Cloud Management
14th
Ranking in Cloud Security Posture Management (CSPM)
15th
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
49
Ranking in other categories
Application Performance Monitoring (APM) and Observability (18th), Application Security Tools (6th), Static Application Security Testing (SAST) (8th), GRC (5th), Vulnerability Management (14th), Container Security (6th), Software Composition Analysis (SCA) (1st), Software Development Analytics (2nd), DevSecOps (2nd), Application Security Posture Management (ASPM) (2nd)
 

Mindshare comparison

As of October 2025, in the Cloud Management category, the mindshare of Rapid7 InsightCloudSec is 0.6%, up from 0.3% compared to the previous year. The mindshare of Snyk is 1.3%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Management Market Share Distribution
ProductMarket Share (%)
Snyk1.3%
Rapid7 InsightCloudSec0.6%
Other98.1%
Cloud Management
 

Featured Reviews

ChennaRao Vemula - PeerSpot reviewer
Enhances security posture with cost efficiency and powerful APIs
We have been using it for almost four years. We are one of the top first customers who implemented it. It's a cloud security solution With this tool, we have a neat security posture at least in terms of securing our environment. It helps us handle all the misconfigurations, and we do day-to-day…
meetharoon - PeerSpot reviewer
Affordable tool boosts code scanning efficiency but faces integration hurdles
I lead a code security practice for our organization. We integrated Snyk into our GitHub, using CLI to automatically scan codebases and identify issues. We are a large organization with three independent entities, consolidating Snyk across all entities.  We also provide access through numerous…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool provides centralized visibility through dashboards and alerts, allowing customers to receive reports on cloud vulnerabilities and security posture. Rapid7 InsightCloudSec provides customers with a robust understanding of cloud security."
"ICSE is cheaper compared to other tools and has a pleasant user experience with good support."
"It runs every hour and has been reliable since I started."
"ICSE is cheaper compared to other tools and has a pleasant user experience with good support."
"Agentless scanning is a possible use with Rapid7 InsightCloudSec."
"I find the security frameworks and security tools valuable. I think they're good in the infrastructure of the code security. They are also good at threat protection."
"The tool's most valuable feature is workload protection for Kubernetes and container security. It has agents that identify bugs or lack of security on runtime containers."
"What is valuable about Snyk is its simplicity."
"Snyk allows for scaling across large organizations, accommodating tens of thousands of applications and over 60,000 repositories, making it suitable for wide-scale deployment."
"Snyk is a developer-friendly product."
"The solution's Open Source feature gives us notifications and suggestions regarding how to address vulnerabilities."
"We're loving some of the Kubernetes integration as well. That's really quite cool. It's still in the early days of our use of it, but it looks really exciting. In the Kubernetes world, it's very good at reporting on the areas around the configuration of your platform, rather than the things that you've pulled in. There's some good advice there that allows you to prioritize whether something is important or just worrying. That's very helpful."
"I find SCA to be valuable. It can read your libraries, your license and bring the best way to resolve your problem in the best scenario."
"There are many valuable features. For example, the way the scanning feature works. The integration is cool because I can integrate it and I don't need to wait until the CACD, I can plug it in to our local ID, and there I can do the scanning. That is the part I like best."
"They evolved their maturity because they could find the vulnerabilities before the pipeline runs."
 

Cons

"A couple of modules are missing when compared to other providers, specifically related to some IAM, and the login piece needs improvement."
"Technical support could be better. It could also be easier, more user-friendly, and intuitive. The API keys aren't easy to understand, and the cloud layouts aren't intuitive and user-friendly. We should be able to integrate IM governance and APIs into non-compliant workloads like legacy solutions."
"The login piece needs improvement."
"They didn't have any documentation on how to patch it."
"The tool needs to improve its documentation."
"There are a lot of other solutions in the market, not only providing the features of a CSPM, but also CNAPP."
"Rapid7 InsightCloudSec could be better at showing dashboards for virtual firewalls and appliances. Compared to other solutions like Palo Alto, this area is not as good. So, they should work on improving this for virtual devices."
"It would be great if they can include dynamic, interactive, and run-time scanning features. Checkmarx and Veracode provide dynamic, interactive, and run-time scanning, but Snyk doesn't do that. That's the reason there is more inclination towards Veracode, Checkmarx, or AppScan. These are a few tools available in the market that do all four types of scanning: static, dynamic, interactive, and run-time."
"There are some new features that we would like to see added, e.g., more visibility into library usage for the code. Something along the lines where it's doing the identification of where vulnerabilities are used, etc. This would cause them to stand out in the market as a much different platform."
"I think Snyk should add more of a vulnerability protection feature in the tool since it is an area where it lacks."
"The solution's integration with JFrog Artifactory could be improved."
"It lists projects. So, if you have a number of microservices in an enterprise, then you could have pages of findings. Developers will then spend zero time going through the pages of reports to figure out, "Is there something I need to fix?" While it may make sense to list all the projects and issues in these very long lists for completeness, Snyk could do a better job of bubbling up and grouping items, e.g., a higher level dashboard that draws attention to things that are new, the highest priority things, or things trending in the wrong direction. That would make it a lot easier. They don't quite have that yet in container security."
"We had some issues integrating into our pipeline, however, they were resolved."
"The solution could improve the reports. They have been working on improving the reports but more work could be done."
"They were a couple of issues which happened because Snyk lacked some documentation on the integration side. Snyk is lacking a lot of documentation, and I would like to see them improve this. This is where we struggle a bit. For example, if something breaks, we can't figure out how to fix that issue. It may be a very simple thing, but because we don't have the proper documentation around an issue, it takes us a bit longer."
 

Pricing and Cost Advice

"Companies generally buy this tool because the pricing is not that high."
"We're doing an annual subscription. There are additional expenses, but not within the confines of this platform."
"Cost-wise, it's similar to Veracode, but I don't know the exact cost."
"It's inexpensive and easy to license. It comes in standard package sizing, which is straightforward. This information is publicly found on their website."
"It's good value. That's the primary thing. It's not cheap-cheap, but it's good value."
"Compared to Veracode, Snyk is definitely a cheaper tool."
"On a scale of one to ten, where one is cheap and ten is expensive, I rate the pricing a three. It is a cheap solution."
"Presently, my company uses an open-source version of the solution. The solution's pricing can be considered quite reasonable owing to the features they offer."
"We are using the open-source version for the scans."
"We do have some missing licenses issues, especially with non-SPDX compliant one, but we expect this to be fixed soon"
report
Use our free recommendation engine to learn which Cloud Management solutions are best for your needs.
872,019 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
11%
Insurance Company
9%
Computer Software Company
9%
Retailer
8%
Financial Services Firm
15%
Computer Software Company
12%
Manufacturing Company
10%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise9
Large Enterprise21
 

Questions from the Community

What do you like most about Rapid7 InsightCloudSec?
The tool provides centralized visibility through dashboards and alerts, allowing customers to receive reports on cloud vulnerabilities and security posture. Rapid7 InsightCloudSec provides customer...
What is your experience regarding pricing and costs for Rapid7 InsightCloudSec?
The pricing is good when compared to other leaders. It is cheaper.
What needs improvement with Rapid7 InsightCloudSec?
A couple of modules are missing when compared to other providers, specifically related to some IAM, and the login piece needs improvement.
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What do you like most about Snyk?
The most effective feature in securing project dependencies stems from its ability to highlight security vulnerabilities.
What needs improvement with Snyk?
There are a lot of false positives that need to be identified and separated. The inclusion of AI to remove false positives would be beneficial. So far, I've not seen any AI features to enhance vuln...
 

Also Known As

DivvyCloud
Fugue, Snyk AppRisk
 

Overview

 

Sample Customers

Fannie Mae, 3M, PizzaHut, Spotify, Autodesk, Discovery
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about Rapid7 InsightCloudSec vs. Snyk and other solutions. Updated: October 2025.
872,019 professionals have used our research since 2012.