Join us at Minneapolis API Security Summit 2025!
Join us at Minneapolis API Security Summit 2025!
Join us at Minneapolis API Security Summit 2025!
Join us at Minneapolis API Security Summit 2025!
Join us at Minneapolis API Security Summit 2025!
Join us at Minneapolis API Security Summit 2025!
Close
Privacy settings
We use cookies and similar technologies that are necessary to run the website. Additional cookies are only used with your consent. You can consent to our use of cookies by clicking on Agree. For more information on which data is collected and how it is shared with our partners please read our privacy and cookie policy: Cookie policy, Privacy policy
We use cookies to access, analyse and store information such as the characteristics of your device as well as certain personal data (IP addresses, navigation usage, geolocation data or unique identifiers). The processing of your data serves various purposes: Analytics cookies allow us to analyse our performance to offer you a better online experience and evaluate the efficiency of our campaigns. Personalisation cookies give you access to a customised experience of our website with usage-based offers and support. Finally, Advertising cookies are placed by third-party companies processing your data to create audiences lists to deliver targeted ads on social media and the internet. You may freely give, refuse or withdraw your consent at any time using the link provided at the bottom of each page.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Case study

Rappi Case Study

How one of the largest tech companies in LATAM solved the pressing challenge of discovering and protecting APIs.

Thanks for filling out the form!
The resource link will open in the new tab. If its not, please follow this link
Oops! Something went wrong while submitting the form.
Rappi Case Study

Fastest growing e-commerce delivery network in South/Latin America

Rappi was founded in 2015 by three Colombian entrepreneurs. Rappi's customers can "order almost anything they want with a super app concept that will deliver it to them in 30 minutes in exchange for a buck." The company generates revenue by taking a % from each retail transaction.

Rappi entered Y-Combinator's Winter 2016 batch, generating additional investment & raised another $200 million in funding in 2018. SoftBank became a major stakeholder in Rappi in April, 2019 with a $1 billion dollar investment.

Today, if you want to get anything from lunch to a new phone or even cash, it probably will be Rappi who will do it for you. Rappi's defining characteristics is the broad range of products and services available for delivery. The mobile app lets users order groceries, food or drugstore medications, but also send money (cash) to someone, or have a courier withdraw money from their bank account from an ATM and get it delivered to them, also, the couriers can offer transport personal belongings (such as house keys, wallets, purses and more). Couriers even walk customers' dogs.

  • Industry: Ecommerce
  • 2000 APIs: Mix of exposed and internal. Non-stop releases with CI/CD for
    thousands microservices
  • Product: End-to-end API Security. API Threat Prevention. API Security Testing. API Discovery.
  • Previous solutions: API Gateway + Imperva SecureSphere WAF
  • Infrastructure: AWS + Multiple regions + Auto-Scaling
  • Infrastructure as a Code approach (IaaC) to manage API Security
  • Heavy load with spikes that require autoscaling
  • Integrations: with Slack and DevSec tools

Wallarm advantages for Rappi

  • Protection for REST and SOAP APIs
  • API Discovery
  • API Security Testing
  • CI/CD ready. Infrastructure as a Code.
    Bitbucket + sync up configuration
    Push changes in live infrastructure
  • Readiness for the multi-cloud
    Autoscaling: 1-2 minutes
    Centralized way of management
  • Modern UI, navigation & reports
  • Integration with DevOps (SIEM) tools

We have a lot of trouble moving Imperva SecureSphere to the cloud. It just can’t scale to the extent that Rappi has. And it’s not ready for our infrastructure as a code approach - Gustavo Ogawa. Head of DevSecOps at Rappi

Trusted by the world’s most innovative companies:

15 min

To unboard and view secutity results
“I needed cloud security tooling that could get me visibility fast. Wallarm answers all my visibility needs within minutes — across multiple clouds.”
Miro Logo

500K

per year in const savings
“With Wallarm, we've been able to scale API protection to the scale we need and manage with our infrastructure as a code approach.”
Rappi Logo

100%

visibility into multi-cloud environments
“With Wallarm, we've been able to scale API protection to the scale we need and manage with our infrastructure as a code approach.”
Dropbox Logo
Panasonic Logo
Victoria's Secret Logo
Miro Logo
Gannet Logo
Dropbox Logo
Rappi Logo
Wargaming Logo
Semrush Logo
Tipalti Logo
UZ Leuven Logo

Ready to protect your APIs?

Wallarm helps you develop fast and stay secure.