Vendor hubInfra · APM · Logs · Security · ExperienceTechBag Intel Hub

Rapid7

The leading unified cloud observability platform — metrics, traces, logs, real-user experience and security on ONE platform, with best-in-class correlation (one click: symptom → root cause). Powerful & easy — with an honest guide to the cost. This hub is your complete intel file.

5 intel pages insideUnified observability + cost helpIndia-ready via TechBag

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

The company, at a glance

Founded2010 · New York
ListingNASDAQ: DDOG
Scale~32,700 customers
Revenue~$3.5B (~30% growth)
The edgeBest correlation UX

Quick answer

Rapid7 (NASDAQ: RPD) is a Boston-headquartered security company selling exposure management, SIEM and managed detection and response through one console it calls the Command Platform. Founded in 2000, public since July 2015, it closed FY2025 on $860M of revenue with more than 11,500 customers. Wael Mohamed became chief executive on 1 June 2026, succeeding Corey Thomas, who ran the company for thirteen years and is now executive chairman. Its centre of gravity is the mid-market: Rapid7 is strongest where a security team of three to fifteen people needs vulnerability management, log monitoring and a managed SOC from one vendor, on one agent, under one contract, without hiring a dedicated SIEM engineer. That is a real and underserved position and Rapid7 holds it well — it is genuinely a Leader in the 2025 Gartner Magic Quadrant for Exposure Assessment Platforms and a Leader in the 2025 Frost Radar for MDR. It is not the strongest option at the top end. In the 2025 Gartner MQ for SIEM it is a Challenger, not a Leader — its seventh consecutive year of inclusion, which the company markets heavily, but inclusion is not leadership. For Indian buyers one constraint outranks everything else here: Rapid7's platform runs in the United States, Canada, Europe, Japan and Australia. There is no India data region. CERT-In's 2022 Directions require ICT logs to be retained for 180 days within Indian jurisdiction, so an Indian entity using Rapid7's SIEM or MDR holds its logs offshore and generally needs a parallel in-India log store to close that gap. The 13-month retention comfortably exceeds 180 days in duration; it fails the location test. Settle that before you evaluate a single feature. The Pune Global Capability Centre, opened April 2025, is a real asset for support hours and follow-the-sun SOC delivery — it is not an India data region and does not change the residency answer. Read more ↓ Show less ↑
The portfolio

Five intel pages. One unified observability platform.

The complete Rapid7 platform — every linked card is a full intel page, from infrastructure metrics to the real user experience.

Next-gen SIEMIntel page →

Incident Command

The SIEM formerly sold as InsightIDR, now AI-native.

Rapid7 renamed InsightIDR to Incident Command in July 2025, though the documentation still carries the old name in brackets and most buyers still search for InsightIDR. It is a cloud-delivered SIEM licensed per asset rather than per gigabyte ingested, which makes budgeting unusually predictable — a chatty firewall does not produce a surprise invoice. User behaviour analytics, deception technology and agentic AI investigation workflows sit on top of standard log management. It suits mid-sized teams who want detections that work on day one more than they want a platform they can rebuild.

90–180 days log retention by tierExplore
Vulnerability managementIntel page →

InsightVM

Risk-scored vulnerability management for hybrid estates.

Scans on-premises, cloud and remote assets and scores what it finds on Active Risk, a 0–1000 scale weighted by real exploitation evidence from CISA KEV, Metasploit and Rapid7's own honeypot network. Remediation Projects and SLA goals turn findings into assigned work with deadlines, which is the part most vulnerability tools do badly. Now marketed as the engine inside Exposure Command, but still separately purchasable — and it carries the only published vulnerability-management price Rapid7 offers.

Published from $1.62 per asset/monthExplore
Managed detection & responseIntel page →

Managed Threat Complete

A 24/7 SOC with vulnerability management bundled in.

Rapid7's MDR runs on its own SIEM, staffed around the clock from Boston, Prague and Pune. What makes it distinctive is the bundle: unlimited incident response with no retainer or hour cap, and unlimited InsightVM scanning included in the per-asset price — which no pure-play MDR vendor offers. The published SLAs are contractual rather than marketing: fifteen minutes to begin investigating a critical alert, a phone call within thirty minutes. Three tiers, and the differences between them are narrower than the marketing suggests.

15-minute critical investigation startExplore
Application securityIntel page →

InsightAppSec

Dynamic testing for web applications and APIs.

A DAST scanner that crawls running web applications and APIs and attacks them the way an external tester would, covering the OWASP Top 10 and reporting with attack replay so developers can reproduce a finding rather than argue about it. Priced transparently per application, which is rare in this category and makes it easy to start with the handful of applications that actually face the internet. For Indian buyers it maps directly onto SEBI CSCRF's per-release VAPT expectation.

Published at $175 per app/monthExplore

Surface Command

Platform & engine

Attack surface management — ships inside every Exposure Command tier

Metasploit

Platform & engine

The framework is free and open source; only Metasploit Pro is commercial

InsightCloudSec

Platform & engine

CNAPP — a Forrester Contender; we would point you at Wiz instead

Rapid7 sells across 4 of the categories TechBag carries in security. The SIEM & log management guide shows how the category splits and which part is yours. →

The thesis

Why “one agent, one contract, priced per asset” is the whole story

Most security platforms are assembled from acquisitions and priced on the thing you cannot control — how much data you generate. Rapid7 bet the company on the opposite: one agent feeding vulnerability, endpoint and log data, metered per monitored asset rather than per gigabyte ingested— so a chatty firewall never produces a surprise invoice, and a three-person security team can run vulnerability management, a SIEM and a managed SOC under a single contract. That is a genuinely underserved position and Rapid7 holds it well. The honest corollary is that the same design decisions cap the ceiling: this is a strong mid-market platform, not a top-end specialist, and the pages below say exactly where that stops being the right trade.

01
The Command Platform

The Command Platform is the wrapper, not a product

Rapid7 sells Incident Command, Exposure Command and Surface Command as named products under one console called the Command Platform. In practice the platform is a shared identity, a shared agent and a shared asset inventory rather than a single SKU. This matters commercially: Rapid7's sales motion pushes multi-product platform commitments with bundle discounts, so ask explicitly for standalone pricing if you only want one component.

02
One agent serves

One agent serves several products

The Rapid7 Agent, formerly the Insight Agent, feeds vulnerability assessment, endpoint detection and log collection from a single installation on Windows, Linux and macOS. For a small team, deploying one agent instead of three is a genuine operational saving. The limit is real though: the agent performs local checks only and cannot run remote or unauthenticated network checks, so scan engines remain necessary for full coverage.

03
Collectors and sensors

Collectors and sensors sit on your network

An on-premises Collector aggregates event sources and forwards them to the cloud, sized at roughly 600 endpoints per CPU core, so four cores handles about 2,400 agents. The optional Insight Network Sensor is passive, taps a SPAN or mirror port and runs a Suricata detection engine. Neither runs on ARM, so Graviton instances are out. Budget for this infrastructure — it is not included in the licence.

04
Priced per asset

Priced per asset, not per gigabyte

Rapid7 meters its SIEM and MDR by monitored asset rather than by data volume. For teams burned by ingestion-based SIEM billing this is the single most attractive thing about the platform, because a noisy log source does not produce a surprise invoice. Be aware that packaged marketplace SKUs do carry monthly data allowances, so confirm what happens on overage before signing.

05
Open source feeds

Open source feeds the commercial products

Rapid7 stewards Metasploit, acquired in 2009, and Velociraptor, the open-source DFIR tool acquired in 2021, and runs Project Sonar internet-wide scanning and the AttackerKB vulnerability community. These are not marketing ornaments — exploit evidence from Metasploit and AttackerKB feeds directly into the Active Risk score that prioritises your vulnerabilities. It is a real technical asset and a credible reason to trust the prioritisation.

Start with Infrastructure Monitoring (the core) — then add APM, Logs, Cloud Security and Digital Experience, all correlated on one platform. (And manage the cost — TechBag’s key value.)

The trophy wall

Peer & market recognition

Every claim on this hub traces to one of these public signals.

Leader

2025 Gartner MQ for Exposure Assessment

Exposure Command evaluated, November 2025

Leader

2025 Frost Radar for MDR

Assessed against a field of 120 vendors

Leader

2025 IDC MarketScape Exposure Management

Worldwide vendor assessment

Gartner Peer Insights

MDR

4.6 out of 5 across 315 reviews

Challenger

2025 Gartner MQ for SIEM

Seventh year included — but not a Leader

Strong Performer

Forrester Wave for Unified VM

2025 wave, not top tier

Recognition

SCAP validated and USGCB certified by NIST

InsightVM policy assessment

ISO 27001

SOC 2 Type II, IRAP, FedRAMP

FedRAMP covers InsightGovCloud only

By the numbers

The company in six figures

11,500+
Customers worldwide
Rapid7 FY2025 results
$860M
FY2025 revenue
Rapid7 FY2025 results
15 min
SLA to begin a critical investigation
MDR scope of service
180 days
Log retention, Advanced and Ultimate SIEM tiers
Rapid7 SIEM packages
1000
Top of the Active Risk vulnerability scale
InsightVM documentation
13 months
Alert and audit retention, all SIEM tiers
Rapid7 SIEM packages

See the platform, hear the pitch

Rapid7 (official)·Overview

Rapid7 Command Platform Capabilities

The platform, presented by Rapid7.

Rapid7 (official)·Demo

Overview Video: InsightVM

Vulnerability management in the console.

Rapid7 (official)·MDR

Rapid7 Managed Detection & Response (MDR)

What the managed service actually does.

The market maps

Where Rapid7 sits — the grids

Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.

Grid 01 · The portfolio

Rapid7 Across Its Platform

Each dot is a Rapid7 product: competitive position vs category momentum.

Emerging betsCrown jewelsSteady nicheAnchor strengths
InsightVMRapid7

The strongest product in the portfolio.

Grid 02 · The industry

The Unification × Breadth Map

Deployment flexibility and cost control vs the field — and where the Leaders still go deeper.

Niche monitoringBroad + unifiedPoint playersBroad but disjointed
Rapid7Rapid7

One agent, one contract, mid-market fit.

Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Track 01 · Beginner guides

New to this? Learn it properly.

Zero-jargon starting points, in reading order. Each links into the deep education on the product page.

Interactive · 30 seconds

Where should you start with Rapid7?

Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.

1. What is the gap you are trying to close?

2. How big is your security team?

3. Does an Indian regulator or contract bind where your logs sit?

The acronym decoder

Every term on these pages, in one place
Command Platform
Rapid7's unified console and shared data layer, under which Incident Command, Exposure Command and Surface Command are sold.
Incident Command
Rapid7's SIEM, renamed from InsightIDR in July 2025. Detects, investigates and responds across logs, endpoints and users.
InsightVM
Rapid7's vulnerability management product; scans assets, scores risk and tracks remediation to a deadline.
Active Risk
Rapid7's 0–1000 vulnerability score, weighting real-world exploitation evidence above theoretical CVSS severity. Replaced Real Risk in January 2026.
Rapid7 Agent
The single endpoint agent, formerly Insight Agent, feeding vulnerability, endpoint and log data to the platform.
Collector
An on-premises virtual machine that aggregates log sources and forwards them to Rapid7's cloud.
LEQL
Log Entry Query Language — Rapid7's search syntax for the SIEM, using select, where and groupby clauses.
Deception technology
Decoy honeypots, honey users, honey files and honey credentials that raise a high-confidence alert when an intruder touches them.
Managed Threat Complete
The commercial name for Rapid7's MDR bundle: managed SOC plus InsightVM plus automation.
Surface Command
Attack surface management; combines external attack surface discovery with internal asset inventory.
Metasploit
The open-source penetration testing framework Rapid7 has stewarded since 2009; also sold commercially as Metasploit Pro.
CERT-In Directions
India's 2022 cyber rules requiring six-hour incident reporting and 180 days of ICT logs retained within Indian jurisdiction.
Track 02 · Buying guides

Buy it like you’ve done this before

The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.

01

Settle the data residency question first

Before any demo, confirm where your logs and scan data will live. Rapid7 has no India region. If CERT-In's 180-day in-India log rule binds you, decide now whether you will run a parallel in-India log store or choose a different vendor. This single answer can end the evaluation, and it is far cheaper to establish now than during an audit.

02

Count your assets honestly

Rapid7 prices per asset, defined as a host with a workstation or server operating system that reported data in the last thirty days. Count servers, workstations, laptops and cloud instances. Undercounting produces a quote you cannot honour; overcounting costs you money for three years.

03

Decide standalone or platform

Rapid7's sales motion pushes Exposure Command and Managed Threat Complete bundles. Ask explicitly for standalone InsightVM or Incident Command pricing alongside the bundle quote. Sometimes the bundle is genuinely cheaper than the parts; sometimes you are buying three products to use one.

04

Run a proof of concept on real assets

Insist on scanning a representative slice of your actual estate, including your noisiest servers and your network appliances. Scan duration, false-positive volume and console resource use only reveal themselves at your scale. A curated demo environment tells you nothing useful.

05

Size the infrastructure you must supply

InsightVM needs a Security Console you host, and the hardware is not trivial — twelve cores, 64 GB RAM and 2 TB storage at twenty thousand assets. The SIEM needs Collectors. Add this capital and operational cost to the licence before comparing against a fully cloud-hosted competitor.

06

Negotiate the renewal, not just year one

Rapid7 states around three percent annual uplift; customers commonly report seven to ten percent at renewal. Fix the uplift contractually for the full term, and agree what happens if your asset count grows. Buy through TechBag and we hold that conversation with the vendor on your behalf, in INR.

The licensing cheat-sheet

ProductLicensing modelHow you enterBest for
InsightVMPublished from $1.62 per asset/month at 500 assetsannual termannual term
InsightAppSecPublished at $175 per application/monthPublished at $175 per application/monthPublished at $175 per application/month
Incident CommandQuote-only, per monitored assetnot per GB ingestednot per GB ingested
Managed Threat CompleteQuote-only; buyer-reported ~$15–22 per asset/month, 500-asset minimumQuote-only; buyer-reported ~$15–22 per asset/month, 500-asset minimumQuote-only; buyer-reported ~$15–22 per asset/month, 500-asset minimum

Quote-only, metered on monitored users plus sources plus modules rather than gigabytes ingested — so the number that decides your bill is your identity count. The cost that surprises is your engineers’ time, not the licence. The compounds across modules. TechBag scopes the tier you actually need AND prices your engineers’ time honestly (Elastic bills USD; GST added).

Five pitfalls that cost buyers quarters

1

Assuming 13-month retention satisfies CERT-In

Rapid7 retains alert and audit data for thirteen months, which comfortably exceeds CERT-In's 180-day requirement in duration. It fails on location. The Directions require logs to be maintained within Indian jurisdiction, and Rapid7's nearest region is Tokyo. Teams discover this during an audit rather than during procurement, which is the expensive time to discover it. Ask the question in writing, early.

2

Buying the SIEM expecting deep customisation

Gartner's own 2025 caution is that Rapid7 lacks advanced analytics such as supervised machine learning and custom deep-learning models. Reviewers report that reports group by only one field at a time, and there is a default cap of 200 custom detection rules. If your detection engineers want to build sophisticated correlation logic, evaluate Splunk or Sentinel instead — we sell both.

3

Deploying agents only and calling it coverage

The Rapid7 Agent performs local checks exclusively. It cannot perform remote or unauthenticated network checks, which means exposed services, TLS misconfigurations and network appliances go unassessed. An agent-only rollout looks complete on the dashboard and leaves a genuine hole. Plan for scan engines alongside agents, and budget the time to configure credentials properly.

4

Missing the Active Risk score migration

Rapid7 retired Real Risk, Temporal, TemporalPlus, Weighted and PCI ASV 2.0 scoring on 21 January 2026, leaving Active Risk as the practical option. Historical scores cannot be recalculated, so your trend data has a discontinuity at the switch. If you are presenting risk reduction to a board or a regulator, be ready to explain the step change.

5

Expecting MDR to contain more than it does

Rapid7's Active Response contains exactly two things: it quarantines endpoints and disables users. Nothing else. Its incident response is remote-only, with no on-site attendance, and the Rapid7 Agent is still required even when a third-party EDR performs containment — assets without it are excluded from threat hunts and from investigations entirely.

The evaluation kit

The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:

Skip the homework entirely

Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.

Book a discovery call →
FAQ

Questions buyers ask about Rapid7

Rapid7 is an American cybersecurity company, listed on NASDAQ as RPD, founded in Boston in 2000 and public since July 2015. It reported $860M of revenue for FY2025 and serves more than 11,500 customers. Wael Mohamed became chief executive on 1 June 2026, succeeding Corey Thomas, who led the company for thirteen years and now serves as executive chairman. The portfolio divides cleanly into three jobs. The first is finding your weaknesses: InsightVM scans assets for vulnerabilities and scores them, Surface Command discovers what you own and what is exposed to the internet, and Exposure Command bundles those together. The second is catching attacks: Incident Command — the SIEM renamed from InsightIDR in July 2025 — collects logs and endpoint telemetry and raises detections, while Threat Command monitors external digital risk. The third is doing the work for you: Managed Threat Complete is a 24/7 managed SOC built on Rapid7's own tooling. Around this sits an unusually credible open-source estate. Rapid7 has stewarded Metasploit, the penetration testing framework, since 2009, and acquired Velociraptor, an open-source digital forensics tool, in 2021. It runs Project Sonar, which scans the public internet, and AttackerKB, a community vulnerability assessment project. These feed the commercial products directly: exploit evidence from Metasploit and AttackerKB is one of the inputs to the Active Risk score that decides which of your vulnerabilities get fixed first. The honest summary of Rapid7's market position is that it is a strong mid-market platform rather than a top-end specialist. It is a Leader in exposure assessment and in MDR by analyst assessment, and a Challenger rather than a Leader in SIEM. If you are a 200 to 5,000 endpoint organisation with a small security team, that combination is often exactly right. If you are a large bank with a dedicated detection engineering function, you will likely find the SIEM constraining.

Ready to shortlist Rapid7?

Open any of the five intel pages for the deep dive, or let a TechBag advisor build the case with you — module scoping, realistic cost estimation and active COST MANAGEMENT, honest comparisons, deployment, GST invoicing and support included.

Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.