The leading unified cloud observability platform — metrics, traces, logs, real-user experience and security on ONE platform, with best-in-class correlation (one click: symptom → root cause). Powerful & easy — with an honest guide to the cost. This hub is your complete intel file.
Buy through TechBag
Same software. Better outcome — at a lower cost.
The company, at a glance
Quick answer
The complete Rapid7 platform — every linked card is a full intel page, from infrastructure metrics to the real user experience.
The SIEM formerly sold as InsightIDR, now AI-native.
Rapid7 renamed InsightIDR to Incident Command in July 2025, though the documentation still carries the old name in brackets and most buyers still search for InsightIDR. It is a cloud-delivered SIEM licensed per asset rather than per gigabyte ingested, which makes budgeting unusually predictable — a chatty firewall does not produce a surprise invoice. User behaviour analytics, deception technology and agentic AI investigation workflows sit on top of standard log management. It suits mid-sized teams who want detections that work on day one more than they want a platform they can rebuild.
Risk-scored vulnerability management for hybrid estates.
Scans on-premises, cloud and remote assets and scores what it finds on Active Risk, a 0–1000 scale weighted by real exploitation evidence from CISA KEV, Metasploit and Rapid7's own honeypot network. Remediation Projects and SLA goals turn findings into assigned work with deadlines, which is the part most vulnerability tools do badly. Now marketed as the engine inside Exposure Command, but still separately purchasable — and it carries the only published vulnerability-management price Rapid7 offers.
A 24/7 SOC with vulnerability management bundled in.
Rapid7's MDR runs on its own SIEM, staffed around the clock from Boston, Prague and Pune. What makes it distinctive is the bundle: unlimited incident response with no retainer or hour cap, and unlimited InsightVM scanning included in the per-asset price — which no pure-play MDR vendor offers. The published SLAs are contractual rather than marketing: fifteen minutes to begin investigating a critical alert, a phone call within thirty minutes. Three tiers, and the differences between them are narrower than the marketing suggests.
Dynamic testing for web applications and APIs.
A DAST scanner that crawls running web applications and APIs and attacks them the way an external tester would, covering the OWASP Top 10 and reporting with attack replay so developers can reproduce a finding rather than argue about it. Priced transparently per application, which is rare in this category and makes it easy to start with the handful of applications that actually face the internet. For Indian buyers it maps directly onto SEBI CSCRF's per-release VAPT expectation.
Attack surface management — ships inside every Exposure Command tier
The framework is free and open source; only Metasploit Pro is commercial
CNAPP — a Forrester Contender; we would point you at Wiz instead
Rapid7 sells across 4 of the categories TechBag carries in security. The SIEM & log management guide shows how the category splits and which part is yours. →
Most security platforms are assembled from acquisitions and priced on the thing you cannot control — how much data you generate. Rapid7 bet the company on the opposite: one agent feeding vulnerability, endpoint and log data, metered per monitored asset rather than per gigabyte ingested— so a chatty firewall never produces a surprise invoice, and a three-person security team can run vulnerability management, a SIEM and a managed SOC under a single contract. That is a genuinely underserved position and Rapid7 holds it well. The honest corollary is that the same design decisions cap the ceiling: this is a strong mid-market platform, not a top-end specialist, and the pages below say exactly where that stops being the right trade.
Rapid7 sells Incident Command, Exposure Command and Surface Command as named products under one console called the Command Platform. In practice the platform is a shared identity, a shared agent and a shared asset inventory rather than a single SKU. This matters commercially: Rapid7's sales motion pushes multi-product platform commitments with bundle discounts, so ask explicitly for standalone pricing if you only want one component.
The Rapid7 Agent, formerly the Insight Agent, feeds vulnerability assessment, endpoint detection and log collection from a single installation on Windows, Linux and macOS. For a small team, deploying one agent instead of three is a genuine operational saving. The limit is real though: the agent performs local checks only and cannot run remote or unauthenticated network checks, so scan engines remain necessary for full coverage.
An on-premises Collector aggregates event sources and forwards them to the cloud, sized at roughly 600 endpoints per CPU core, so four cores handles about 2,400 agents. The optional Insight Network Sensor is passive, taps a SPAN or mirror port and runs a Suricata detection engine. Neither runs on ARM, so Graviton instances are out. Budget for this infrastructure — it is not included in the licence.
Rapid7 meters its SIEM and MDR by monitored asset rather than by data volume. For teams burned by ingestion-based SIEM billing this is the single most attractive thing about the platform, because a noisy log source does not produce a surprise invoice. Be aware that packaged marketplace SKUs do carry monthly data allowances, so confirm what happens on overage before signing.
Rapid7 stewards Metasploit, acquired in 2009, and Velociraptor, the open-source DFIR tool acquired in 2021, and runs Project Sonar internet-wide scanning and the AttackerKB vulnerability community. These are not marketing ornaments — exploit evidence from Metasploit and AttackerKB feeds directly into the Active Risk score that prioritises your vulnerabilities. It is a real technical asset and a credible reason to trust the prioritisation.
Start with Infrastructure Monitoring (the core) — then add APM, Logs, Cloud Security and Digital Experience, all correlated on one platform. (And manage the cost — TechBag’s key value.)
Every claim on this hub traces to one of these public signals.
Exposure Command evaluated, November 2025
Assessed against a field of 120 vendors
Worldwide vendor assessment
4.6 out of 5 across 315 reviews
Seventh year included — but not a Leader
2025 wave, not top tier
InsightVM policy assessment
FedRAMP covers InsightGovCloud only
The platform, presented by Rapid7.
Vulnerability management in the console.
What the managed service actually does.
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is a Rapid7 product: competitive position vs category momentum.
The strongest product in the portfolio.
Deployment flexibility and cost control vs the field — and where the Leaders still go deeper.
One agent, one contract, mid-market fit.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What is the gap you are trying to close?
2. How big is your security team?
3. Does an Indian regulator or contract bind where your logs sit?
A plain map of the Command Platform, which products are real SKUs, and which names are marketing wrappers.
Read →Why the SIEM changed name in July 2025, and why the documentation still shows both names.
Read →What counts as an asset, why per-asset beats per-gigabyte for predictable budgets, and where overage still bites.
Read →Why the absence of an India data region matters for the 180-day in-India log rule, and what buyers do about it.
Read →When the standalone vulnerability product is enough, and when the bundle genuinely earns its price.
Read →An honest cost comparison for an Indian mid-market team, including what MDR does not cover.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
Before any demo, confirm where your logs and scan data will live. Rapid7 has no India region. If CERT-In's 180-day in-India log rule binds you, decide now whether you will run a parallel in-India log store or choose a different vendor. This single answer can end the evaluation, and it is far cheaper to establish now than during an audit.
Rapid7 prices per asset, defined as a host with a workstation or server operating system that reported data in the last thirty days. Count servers, workstations, laptops and cloud instances. Undercounting produces a quote you cannot honour; overcounting costs you money for three years.
Rapid7's sales motion pushes Exposure Command and Managed Threat Complete bundles. Ask explicitly for standalone InsightVM or Incident Command pricing alongside the bundle quote. Sometimes the bundle is genuinely cheaper than the parts; sometimes you are buying three products to use one.
Insist on scanning a representative slice of your actual estate, including your noisiest servers and your network appliances. Scan duration, false-positive volume and console resource use only reveal themselves at your scale. A curated demo environment tells you nothing useful.
InsightVM needs a Security Console you host, and the hardware is not trivial — twelve cores, 64 GB RAM and 2 TB storage at twenty thousand assets. The SIEM needs Collectors. Add this capital and operational cost to the licence before comparing against a fully cloud-hosted competitor.
Rapid7 states around three percent annual uplift; customers commonly report seven to ten percent at renewal. Fix the uplift contractually for the full term, and agree what happens if your asset count grows. Buy through TechBag and we hold that conversation with the vendor on your behalf, in INR.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| InsightVM | Published from $1.62 per asset/month at 500 assets | annual term | annual term |
| InsightAppSec | Published at $175 per application/month | Published at $175 per application/month | Published at $175 per application/month |
| Incident Command | Quote-only, per monitored asset | not per GB ingested | not per GB ingested |
| Managed Threat Complete | Quote-only; buyer-reported ~$15–22 per asset/month, 500-asset minimum | Quote-only; buyer-reported ~$15–22 per asset/month, 500-asset minimum | Quote-only; buyer-reported ~$15–22 per asset/month, 500-asset minimum |
Quote-only, metered on monitored users plus sources plus modules rather than gigabytes ingested — so the number that decides your bill is your identity count. The cost that surprises is your engineers’ time, not the licence. The compounds across modules. TechBag scopes the tier you actually need AND prices your engineers’ time honestly (Elastic bills USD; GST added).
Rapid7 retains alert and audit data for thirteen months, which comfortably exceeds CERT-In's 180-day requirement in duration. It fails on location. The Directions require logs to be maintained within Indian jurisdiction, and Rapid7's nearest region is Tokyo. Teams discover this during an audit rather than during procurement, which is the expensive time to discover it. Ask the question in writing, early.
Gartner's own 2025 caution is that Rapid7 lacks advanced analytics such as supervised machine learning and custom deep-learning models. Reviewers report that reports group by only one field at a time, and there is a default cap of 200 custom detection rules. If your detection engineers want to build sophisticated correlation logic, evaluate Splunk or Sentinel instead — we sell both.
The Rapid7 Agent performs local checks exclusively. It cannot perform remote or unauthenticated network checks, which means exposed services, TLS misconfigurations and network appliances go unassessed. An agent-only rollout looks complete on the dashboard and leaves a genuine hole. Plan for scan engines alongside agents, and budget the time to configure credentials properly.
Rapid7 retired Real Risk, Temporal, TemporalPlus, Weighted and PCI ASV 2.0 scoring on 21 January 2026, leaving Active Risk as the practical option. Historical scores cannot be recalculated, so your trend data has a discontinuity at the switch. If you are presenting risk reduction to a board or a regulator, be ready to explain the step change.
Rapid7's Active Response contains exactly two things: it quarantines endpoints and disables users. Nothing else. Its incident response is remote-only, with no on-site attendance, and the Rapid7 Agent is still required even when a third-party EDR performs containment — assets without it are excluded from threat hunts and from investigations entirely.
The flagship intel page carries an 8-question vendor checklist and an automation-savings calculator:
Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Six trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*Directionally consistent with public analyst forecasts; verify exact figures before relying on them. SOC automation is the fastest line — which is what Nova is aimed at.
Standalone vulnerability scanning is being repackaged into broader exposure platforms adding attack surface discovery and attack path analysis.
What it means for you
Rapid7 now describes InsightVM as the technology powering Exposure Command, and Gartner has created a whole Magic Quadrant for the category.
Rapid7 has built agentic investigation workflows from its own SOC playbooks, and AI-assisted triage now sits in its Advanced and Ultimate tiers.
What it means for you
The claimed benefit is analyst hours returned rather than better detection. Treat vendor accuracy statistics as unaudited.
CERT-In log localisation, RBI outsourcing rules and the DPDP Act increasingly decide Indian deals before features are compared.
What it means for you
Vendors without an India region lose regulated buyers outright, and several global platforms are opening Indian regions in response.
Building a 24/7 SOC requires roughly eight to ten analysts for round-the-clock cover, which is out of reach for most mid-market Indian firms.
What it means for you
RBI and SEBI both expect continuous monitoring, pushing regulated buyers toward managed services.
Ingestion-based billing has made SIEM budgets unpredictable for a decade.
What it means for you
Rapid7 meters by monitored asset instead, and buyers increasingly shortlist on the pricing model before the feature list. Expect competitors to offer flat-rate options in response.
Mid-sized Indian teams are cutting vendor counts, favouring one platform with adequate coverage over four best-of-breed tools they cannot staff.
What it means for you
This is the trend Rapid7 is built for, and its clearest competitive advantage against point-solution specialists.
Open any of the five intel pages for the deep dive, or let a TechBag advisor build the case with you — module scoping, realistic cost estimation and active COST MANAGEMENT, honest comparisons, deployment, GST invoicing and support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.