LICENSEWARE

Rapid7 InsightIDR, Incident Command and MDR licensing

This article is about licensing Rapid7 detection and response: InsightIDR (Rapid7 SIEM), the Incident Command packages and the Managed Threat Complete MDR service, including the Limited Breach Protection Warranty. For the platform-wide overview, see Rapid7 licensing. It is not legal advice.

On This Page

InsightIDR is Rapid7’s cloud SIEM and XDR technology. It is sold as the Incident Command packages, and it is also embedded in Managed Threat Complete, Rapid7’s managed detection and response (MDR) service.[1][2] Both are priced per asset. Rapid7 defines an asset as a host running a workstation or server operating system to which data has been attributed in the last 30 days.[1][2] Incident Command is an annual SaaS subscription.[1] Managed Threat Complete is offered on an annual contract.[2] Managed Threat Complete is governed by the Master Software and Services Agreement together with both Schedule A (Services) and Schedule B (Software).[7]

Editions

Incident Command

Rapid7 describes the Incident Command tiers as subscriptions designed to match security maturity. All of them use asset-based pricing.[1] The following table summarises the package comparison as retrieved on 2026-09-30.[1]

Capability Essential Advanced Ultimate 
SIEM detection, investigation and reporting; CAASM; EASM; SOAR; UBA; Rapid7 Agent; log management; APIs; customer support Included Included Included 
Agentic AI investigation, AI-assisted alert triage, deception technology Not included Included Included 
Intelligence Hub Add-on Included Included 
Ransomware prevention Add-on Add-on Included 
EDR, NDR, IDS, hosted Velociraptor DFIR Not included Not included Included 
Log retention 90 days + add-on 180 days + add-on 180 days + add-on 
Alert and audit retention 13 months + add-on 13 months + add-on 13 months + add-on 
Deployment and training Quickstart included in year 1 Quickstart included in year 1 Quickstart included in year 1 

MDR subscriptions are priced separately from Incident Command.[1] See Incident Command.

Managed Threat Complete

The MDR packages are Essential, Advanced and Ultimate.[2]

Element Essential Advanced Ultimate 
24x7 SOC monitoring, incident and breach response, EDR, NDR, remote containment Included Included Included 
Third-party security tool SOC support Add-on Included Included 
Hosted Velociraptor DFIR, ransomware prevention Add-on Add-on Included 
Breach protection warranty Not included Not included Included 
Scan configuration and remediation guidance Limited Limited Included 
Assigned cybersecurity advisor, monthly posture reviews Not included Included Included 
Full XDR platform access, unlimited InsightVM, unlimited SOAR, unlimited data ingestion, 13 months data retention Included Included Included 
Managed digital risk protection (phishing, leakage, dark web) Add-on Add-on Add-on 

Each package is custom quoted for the size of the environment.[2] Existing MDR Elite and MDR Essentials customers continue their service and may upgrade.[2] See Managed Threat Complete.

Metrics

Asset (host with data attributed in last 30 days). The Incident Command and MDR FAQs define an asset in the same way. It is a host running a workstation or server operating system to which data has been attributed in the last 30 days. This includes servers, desktops, laptops (physical and virtual) and point-of-sale systems.[1][2] The MDR page frames the same thing commercially: pricing is based on the number of endpoints, servers and networks protected. It does not depend on the volume of data ingested or the number of incidents requiring response.[2]

Monthly data (Fair Use Monthly Data Policy). All Incident Command subscriptions include a Fair Use Monthly Data Policy that scales with asset tiers.[1] The MSSA lists gigabytes among the possible Volume Limitations.[3]

Counting / floors

Asset window (as retrieved 2026-09-30). The 30-day attribution window makes the count a rolling one. A host counts if data has been attributed to it in the last 30 days.[1] Commentary: decommissioned hosts fall out of the count 30 days after their last data. Network devices, SaaS applications and other event sources that are not hosts running a workstation or server operating system do not fall within the asset definition. Their log volume counts against the data policy instead. Catalog proof: Incident Command and MDR assets are OS hosts with data in the last 30 days.

No type weighting. The price does not change by asset type.[1][2] A server and a laptop cost the same.

Tiers and floors. Incident Command and Managed Threat Complete are priced by asset, and the price per asset decreases across asset count tiers. Both FAQs answer yes to whether volume discounts apply above 500 assets.[1][2] No minimum quantity and no tier boundaries are published. Pricing also varies internationally.[1]

Locations. Assets need not be in one location.[1] For Managed Threat Complete, all assets connected to the InsightIDR instance must be in a logically separated environment. Customers with multiple subsidiaries or business units may qualify for Multi-Org service delivery.[2]

Overages (effective 2025-10-24). If the asset count exceeds the Ordering Document, Schedule B invoices the excess at then-current list rates for the applicable tier, prorated for the remainder of the Term.[3] Catalog proof: Excess usage invoiced at then-current list rate for the tier, prorated.

Data and retention

Incident Command does not throttle ingestion. Rapid7 says it works with customers so they can operate within their data limits, and agrees reasonable plans for additional consumption when needed.[1] The data limits for each tier are not published. Customers are asked to contact Rapid7 about them.[1] Within the product, SIEM (InsightIDR) reports current monthly data usage, which equals the size of the logs it stores. It also forecasts the rest of the month from the previous month’s usage.[4] Log retention is 90 days in Essential and 180 days in Advanced and Ultimate, with add-ons for longer periods. Alert and audit retention is 13 months in every package.[1] Managed Threat Complete lists unlimited data ingestion and 13 months of data retention in all packages.[2] Catalog proof: SIEM data covered by a fair-use monthly policy that scales with asset tiers.

Virtualization & partitioning

The asset definition expressly covers virtual as well as physical servers, desktops and laptops. No host-level or hypervisor-level alternative is published, so each virtual machine with an operating system that sends data is an asset.[1] Commentary: non-persistent virtual desktops that reuse host identities are not addressed in the retrieved documents. In such pools the 30-day window can inflate the count, and the question should be settled in the Ordering Document.

Cloud / BYOL

InsightIDR is Cloud-Hosted Software. The Insight Platform SLA covers its hosted portion at 99.95% monthly availability.[6] Cloud workloads count as assets under the same definition as on-premises hosts. No bring-your-own-license mapping applies.[1]

Programs

Software inside Managed Services (effective 2025-10-24). Every Managed Threat Complete subscription includes full access to InsightIDR’s SIEM and XDR technology, including 13 months of searchable logs. It also includes full access to InsightVM.[2] Under Schedule A, Software included in Managed Services is licensed for the Term of the Managed Services only.[3] Commentary: a customer that ends MDR but wants to keep the SIEM or vulnerability management tools needs a separate Incident Command or InsightVM subscription from the day the MDR term ends. Catalog proof: Software included in Managed Services is licensed only for the Managed Services term; Managed Threat Complete includes InsightIDR and InsightVM access.

Limited Breach Protection Warranty (last updated 2026-01-29). A click-through warranty agreement. The Eligible Offering is Managed Threat Complete Ultimate, or a similar offering approved by Rapid7’s underwriter.[5] It reimburses Covered Expenses resulting from a Security Incident in the Protected Environment during a Warranty Period. Covered Expenses are forensic investigation, legal consultation, post-incident notification and public relations costs, pre-approved by Rapid7 and incurred within one year of discovery.[5] The limit depends on the number of Covered Endpoints. A Covered Endpoint is an endpoint that runs the Rapid7 agent on an operating system meeting the documentation prerequisites and fully supported by its manufacturer.[5]

Covered Endpoints Limit (USD) 
500-4,999 $100,000 
5,000-10,000 $500,000 
10,001 and above $1,000,000 

Payments for all Security Incidents in a Warranty Period are aggregated against one limit.[5] To be eligible, the customer must:

  • hold a valid subscription to the Eligible Offering throughout the Warranty Period;
  • keep endpoints in the Measured Security Posture;
  • run the most recent agent;
  • notify Rapid7 within 72 hours of discovery;
  • be in compliance with its Customer Agreement, including payment obligations.[5]

Disputes go to AAA arbitration seated in Delaware.[5] Catalog proof: Breach warranty limit set by number of Covered Endpoints.

Out of scope

  • The Rapid7 service descriptions and statements of work that define MDR scope, response actions and service levels.
  • Managed Digital Risk Protection, Continuous Red Teaming and attack surface management add-ons, whose metrics are not published.
  • Incident Command and Managed Threat Complete prices, data limits per tier and add-on retention prices, which are available only by quote.
  • Legacy InsightIDR, MDR Elite and MDR Essentials terms. Purchases before 2023-03-01 fell under the Insight Platform Terms of Service and the Master Service Agreement.

References

  1. Compare SIEM Packages - Incident CommandPackage table and pricing FAQ; the former InsightIDR pricing URL redirects here. Undated.Retrieved 2026-09-30.
  2. Rapid7 MDR PackagesManaged Threat Complete package table and pricing FAQ. Undated.Retrieved 2026-09-30.
  3. Master Software and Services Agreement - Rapid7Schedule A Managed Services; Schedule B Software. Last updated October 2025.Effective 2025-10-24. Retrieved 2026-09-30.
  4. Monthly Data Usage - InsightIDR documentationCurrent and forecast data usage. Undated.Retrieved 2026-09-30.
  5. Rapid7 Limited Breach Protection Warranty AgreementLast updated 2026-01-29.Effective 2026-01-29. Retrieved 2026-09-30.
  6. Rapid7 Insight Platform Service Level AgreementHosted InsightIDR availability. Undated.Retrieved 2026-09-30.
  7. Customers and Partners - Rapid7Purchase schedule comparison. Undated.Retrieved 2026-09-30.

See also

Catalog Rows Cited

3Programs3Metrics6Rules

Esc