Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightCloudSec vs Spacelift comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 17, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightCloudSec
Ranking in Cloud Management
14th
Average Rating
7.8
Reviews Sentiment
6.3
Number of Reviews
13
Ranking in other categories
Cloud Security Posture Management (CSPM) (15th), Cloud-Native Application Protection Platforms (CNAPP) (10th), AI Observability (6th)
Spacelift
Ranking in Cloud Management
17th
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
5
Ranking in other categories
AI Software Development (18th)
 

Mindshare comparison

As of March 2026, in the Cloud Management category, the mindshare of Rapid7 InsightCloudSec is 0.9%, up from 0.4% compared to the previous year. The mindshare of Spacelift is 1.4%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Management Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightCloudSec0.9%
Spacelift1.4%
Other97.7%
Cloud Management
 

Featured Reviews

Arun Babu - PeerSpot reviewer
SOC analyst at a media company with 1,001-5,000 employees
Daily endpoint monitoring has improved investigations and saved time but detection rules still need tuning
It is important to note that Rapid7 InsightCloudSec's features are not 100% precise, but I find about 70% of the time it is satisfactory. I would like to suggest that you improve it to be more precise, ideally making it 100% if possible. Some cases in Rapid7 InsightCloudSec indicate that the log is not enough, as they mostly just generate alerts, and the synchronization between data connectors is often problematic, particularly in terms of not being in sync always, especially between the AD and Rapid7 alerts, which generates numerous false positives. Additionally, the traditional rules should be updated, as this is a main point worth mentioning since we spend a lot of time fine-tuning these traditional rules. I suggest improving the legacy detection rules. If there are any authentication cases, such as impossible travel activity where a user has their SharePoint hosted in a different location, Rapid7 can often trigger alerts, creating confusion as we cannot fine-tune it properly. Another issue is with honeypot access. We sometimes lack necessary logs because Defender's advanced threat protection scanning gets detected as honeypot activity by Rapid7, leading to annoying and noisy alerts that we need to constantly close. If you can improve the traditional detection rules to reflect current detection rules, it would make it significantly easier for us to manage, as we constantly need to check legacy rules to update or possibly turn them off. Updating the legacy rules should be a priority.
Sudheer Kumar Jamjam - PeerSpot reviewer
Technical Lead Cloud DevOps Engineer at Deloitte
Everything can be visibly managed, scheduling and state management features are pretty good
We've integrated it with source control management tools like GitLab and Bitbucket. The scheduling and state management features are pretty good using Spacelift. It integrates with tools like Terraform and Kubernetes for policies, but we haven't worked on the compliance part. Spacelift streamlines collaboration among our development and operations teams. We use it for CI/CD as well. It can handle automation strategies. Whenever you put your YAML files and integrate them with Spacelift, it will scan the code and show where you need to make changes.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The best features Rapid7 InsightCloudSec offers include more automation remediation, compliance reporting for auditing, improvement on multi-cloud governance, and cost visibility, which really stand out to me."
"After implementing Rapid7 InsightCloudSec, we increased our CIS benchmark score from 48 to around 88 after addressing missing patches on some VM instances, indicating a significant positive impact."
"I find the security frameworks and security tools valuable, as they are good in the infrastructure of the code security and are also good at threat protection."
"I find the security frameworks and security tools valuable. I think they're good in the infrastructure of the code security. They are also good at threat protection."
"The fastest scanning is the best feature Rapid7 InsightCloudSec offers, helping me respond to threats quickly in my daily operations."
"The tool provides centralized visibility through dashboards and alerts, allowing customers to receive reports on cloud vulnerabilities and security posture. Rapid7 InsightCloudSec provides customers with a robust understanding of cloud security."
"ICSE is cheaper compared to other tools and has a pleasant user experience with good support."
"Rapid7 InsightCloudSec has helped us save thirty percent time in our log retrievals, and it completely changed log searching, making it really fast when we search for logs, with no prior knowledge required."
"A valuable feature of Spacelift is that you can attach labels, and it is a modernized tool for infrastructure deployments. It is pull request-based, and you can see all the Terraform plan and apply logs on the pull request itself, which is not available across any other CI/CD tools."
"Knowing the HashiCorp Configuration Language (HCL) makes it easier to use without issues."
"I appreciate that I just have to connect to my AWS account with my credentials, and Spacelift handles the rest."
"Spacelift is like an extension of Terraform, where everything can be visibly managed."
"One key feature is the Spacelift policies, which we can attach to deployments to ensure compliance with our standards."
 

Cons

"Some cases in Rapid7 InsightCloudSec indicate that the log is not enough, as they mostly just generate alerts, and the synchronization between data connectors is often problematic, particularly in terms of not being in sync always, especially between the AD and Rapid7 alerts, which generates numerous false positives."
"I would say that because Rapid7 InsightCloudSec does not have automatic patching capabilities, it provides recommendations, but it does not execute anything from within Rapid7 InsightCloudSec."
"There are a lot of other solutions in the market, not only providing the features of a CSPM, but also CNAPP."
"For a first-time user who starts using Rapid7 InsightCloudSec, it is somewhat complicated to navigate through the UI and search for logs or vulnerabilities, so this is one aspect that could be improved."
"I'm not impressed with their support right now. Their support model is not really good."
"The platform could be improved with more customizable dashboards and reporting."
"Technical support could be better. It could also be easier, more user-friendly, and intuitive. The API keys aren't easy to understand, and the cloud layouts aren't intuitive and user-friendly. We should be able to integrate IM governance and APIs into non-compliant workloads like legacy solutions."
"Rapid7 InsightCloudSec could be better at showing dashboards for virtual firewalls and appliances. Compared to other solutions like Palo Alto, this area is not as good. So, they should work on improving this for virtual devices."
"In the free version, there's no straightforward way to be notified once a deployment is finished."
"If you are a small enterprise organization, below 500 people, I would not recommend it."
"Spacelift currently lacks features that can help with complex type deployments and coordination for major deployments."
"Synchronization can be difficult when using older and newer versions with Kubernetes and HashiCorp."
"The self-hosted version does not have a lot of features compared to the SaaS version, such as cloud integrations for Azure and GCP."
 

Pricing and Cost Advice

"Companies generally buy this tool because the pricing is not that high."
"We're doing an annual subscription. There are additional expenses, but not within the confines of this platform."
"It is a bit expensive product."
report
Use our free recommendation engine to learn which Cloud Management solutions are best for your needs.
885,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Insurance Company
10%
Manufacturing Company
9%
Comms Service Provider
8%
Financial Services Firm
8%
Financial Services Firm
11%
Manufacturing Company
11%
Educational Organization
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise5
Large Enterprise8
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Rapid7 InsightCloudSec?
The pricing, setup cost, and licensing for Rapid7 InsightCloudSec are reasonable, and since our organization is growing, I have observed that the more numbers you have, the less costly the product ...
What needs improvement with Rapid7 InsightCloudSec?
I would say that because Rapid7 InsightCloudSec does not have automatic patching capabilities, it provides recommendations, but it does not execute anything from within Rapid7 InsightCloudSec. It h...
What is your primary use case for Rapid7 InsightCloudSec?
In my role, my main use case for Rapid7 InsightCloudSec is for vulnerability management, where I scan my machines to see zero-day vulnerabilities and receive remediation tactics recommended by Rapi...
What is your experience regarding pricing and costs for Spacelift?
I've never checked the pricing because I enjoy using it for free. Besides the notification feature, I haven't needed any paid features.
What needs improvement with Spacelift?
There are a few areas for improvement. For instance, getting notification webhooks is not easy. In the free version, there's no straightforward way to be notified once a deployment is finished. Spa...
What is your primary use case for Spacelift?
I use Spacelift to deploy my applications, particularly AWS applications and infrastructure to my personal AWS account.
 

Also Known As

DivvyCloud
No data available
 

Overview

 

Sample Customers

Fannie Mae, 3M, PizzaHut, Spotify, Autodesk, Discovery
Information Not Available
Find out what your peers are saying about Rapid7 InsightCloudSec vs. Spacelift and other solutions. Updated: March 2026.
885,311 professionals have used our research since 2012.