RapidRatings - Enterprise Client Services
RapidRatings has the capability to aggregate supplier financial performance across your organization. Our platform delivers actionable intelligence and can private firms globally. By centralizing this data using a consistent ratings methodology, your business can assess its full third-party exposure, identify areas of concentration risk, and uncover financial strengths and weaknesses.
Features
- Financial Health assessments delivered via SaaS
- Financial Health Ratings and analysis for public and private companies
- Acquire private company financial statements from global suppliers
- Implementation Services to teach and empower your teams
- APIs to facilitate real-time integrations with external systems
Benefits
- Stronger Supplier Financial Risk Management program
- Understand which suppliers are at risk in the current environment
- Aggregate supplier financial performance
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 2 3 3 1 7 1 4 5 8 0 8 4 0 1
Contact
Rapid Ratings International, Inc.
G Cloud 15 Team
Telephone: (646)233-4600
Email: legal@rapidratings.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Community cloud
- Service constraints
- No - standards based web application available on most modern browsers. RapidRatings operate a zero downtime deployment model
- System requirements
- Modern browsers: Chrome, Firefox, Edge
User support
- Email or online ticketing support
- Yes
- Support response times
- Typically within 4 hours, Monday to Friday. We do not operate a support service outside of these hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Support is included in the Services price. RapidRatings offers only one level of support to all clients.
RapidRatings Client Success team is available Monday through Friday from 9:00 AM to 7:00 PM EST. RapidRatings
will accommodate scheduled calls and sessions outside of these hours to help the Customer team successfully
meet its goals.
Incidents can be reported to RapidRatings Client Support team by calling +1 (646) 233-4563 or emailing support@rapidratings.com. For service availability incidents, we encourage Customers to both email and call,
explaining the number of users affected and the urgency of the issue.
The majority of issues are assigned a ""Same Day"" turnaround time which corresponds to half a working day. For all
issues that cannot be resolved in this timeline, RapidRatings Client Support will establish a clear timeline and
ensure that this permits business continuity for Customer.
RapidRatings' Client Support will provide Customer with remote assistance for help using and operating the
Subscription Services in order to provide accurate reports of issues. RapidRatings will ensure that each of its
personnel performing any Support Services are experienced, knowledgeable, and qualified in the use, maintenance,
and support of the Subscription Services. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Online training and user documentation
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Clients may request removal of data at contract termination.
- End-of-contract process
- RapidRatings services should not be treated as the system of record. Generally at the end of the contract, our clients do not need formal data extraction. RapidRatings suspends users from the client's organization and there is no longer access to the service.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- RapidRatings is working toward WCAG 2.2 AA compliance.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Client facing web portal
- Accessibility standards
- None or don’t know
- Description of accessibility
-
RapidRatings is working toward WCAG 2.2 AA
compliance. - Accessibility testing
-
RapidRatings is working toward WCAG 2.2 AA
compliance. - API
- Yes
- What users can and can't do using the API
-
RapidRatings has a number of APIs for our service, each with their own functions and limitations. Please inquire directly.
Our rating API allows users to submit rating requests, submit financials to be rated and return the ratings for their
portfolio of companies.
Limitations: Our APIs do not support user or tenant management - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
-
Our service is deployed on elastic, auto-scaling infrastructure and is configured to not exceed 50% utilisation at load.
Our APIs have in-buit rate limiting to prevent run-away use of resources.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Regular reports
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- It depends upon the data type, but RapidRatings supports most common formats upon request. API requests are also used for export.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.5% availability measured quarterly by cumulative hours downtime per quarter expressed as a percentage of schedule hours availability
- Approach to resilience
- Our primary service is deployed in the US-East region (Virginia) across multiple active-active cloud availability zones (each az is analogous to a physical "data center") . In the event of severe regional level disruption, our service is recoverable within a 24 hour RTO to US-West region, again deployed across multiple active-active availability zones
- Outage reporting
- Our CSM will notify the primary user roles of scheduled or unscheduled service outage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Users authenticate with username and password. For Clients wishing to employ their own authentication policy, we offer SAML2.0 identity federation with just in time provisioning from their own identity provider
- Access restrictions in management interfaces and support channels
- Access is assigned on a least privileged basis. There is no access to client systems or devices. Tenant access is restricted to notified sessions and are fully logged.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- SOC2 Type 2
- Information security policies and processes
-
Information Security RapidRatings has a comprehensive set of policies covering Information Security
- Asset Management
- Business Continuity
- Encryption Standards & Policy
- Mobile device and Teleworking
- Vulnerability management
- Training and development policy
- Change Management
- Data Labelling
- Data Retention
- Incident Management
- Access Control
- Physical Access
- Vendor Risk Management
- Acceptable use policy
Privacy
-Data Protection
- Data Breach policy
Compliance
- Insider Trading Policy
-Speak up policy
- Code of conduct
- Anti-bribery and anti corruption - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Our change management approach allows every line of code changed to be tracked back through release, development, test, business sign off and strategic roadmap item.
All changes are subject peer review, with SAST and DAST techniques employed on every release. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We source comprehensive threat intelligence from a variety of threat sources including Github Enterprise Security, Alertlogic threat manager, Amazon ECR, Microsoft Defender for Cloud and Endpoint. These include threats on software, cloud configuration, device hardening, container deployments, network configurations, cloud SaaS services, user endpoints, and so on.
Vulnerability are triaged as per the table below with a target resolution time in the third value:
Critical Immediate < 2 days
High <1 day < 1 week
Medium <1 week < 1 month
Low < 1 month As resources available - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our service is monitored 24/7 by our Security Operations team operated by AlertLogic. This team will detect and escalate potential threats to our on-call team 24-7 with response times per our vulnerability management policy
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our process covers Detection, Analysis, Containment, Eradication, recovery and post-incident activity phases of an incident, with pro-active communications to affected parties occurring within 24 hours of impact confirmation.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo (Ireland) Ltd
- ISO/IEC 27001 accreditation date
- Wednesday 9 April 2025
- What the ISO/IEC 27001 doesn’t cover
-
The ISMS applies to all those with access to data and information or information systems under Rapid Ratings control, regardless of their
location at the time they are doing this. The development, operation and maintenance of the Rapid Ratings Financial Health Rating (FHR) Saas
product is within scope. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-