InsightIDR is Rapid7’s cloud SIEM and XDR technology. It is sold as the Incident Command packages, and it is also embedded in Managed Threat Complete, Rapid7’s managed detection and response (MDR) service.[1][2] Both are priced per asset. Rapid7 defines an asset as a host running a workstation or server operating system to which data has been attributed in the last 30 days.[1][2] Incident Command is an annual SaaS subscription.[1] Managed Threat Complete is offered on an annual contract.[2] Managed Threat Complete is governed by the Master Software and Services Agreement together with both Schedule A (Services) and Schedule B (Software).[7]
Editions
Incident Command
Rapid7 describes the Incident Command tiers as subscriptions designed to match security maturity. All of them use asset-based pricing.[1] The following table summarises the package comparison as retrieved on 2026-09-30.[1]
| Capability | Essential | Advanced | Ultimate |
|---|---|---|---|
| SIEM detection, investigation and reporting; CAASM; EASM; SOAR; UBA; Rapid7 Agent; log management; APIs; customer support | Included | Included | Included |
| Agentic AI investigation, AI-assisted alert triage, deception technology | Not included | Included | Included |
| Intelligence Hub | Add-on | Included | Included |
| Ransomware prevention | Add-on | Add-on | Included |
| EDR, NDR, IDS, hosted Velociraptor DFIR | Not included | Not included | Included |
| Log retention | 90 days + add-on | 180 days + add-on | 180 days + add-on |
| Alert and audit retention | 13 months + add-on | 13 months + add-on | 13 months + add-on |
| Deployment and training | Quickstart included in year 1 | Quickstart included in year 1 | Quickstart included in year 1 |
MDR subscriptions are priced separately from Incident Command.[1] See Incident Command.
Managed Threat Complete
The MDR packages are Essential, Advanced and Ultimate.[2]
| Element | Essential | Advanced | Ultimate |
|---|---|---|---|
| 24x7 SOC monitoring, incident and breach response, EDR, NDR, remote containment | Included | Included | Included |
| Third-party security tool SOC support | Add-on | Included | Included |
| Hosted Velociraptor DFIR, ransomware prevention | Add-on | Add-on | Included |
| Breach protection warranty | Not included | Not included | Included |
| Scan configuration and remediation guidance | Limited | Limited | Included |
| Assigned cybersecurity advisor, monthly posture reviews | Not included | Included | Included |
| Full XDR platform access, unlimited InsightVM, unlimited SOAR, unlimited data ingestion, 13 months data retention | Included | Included | Included |
| Managed digital risk protection (phishing, leakage, dark web) | Add-on | Add-on | Add-on |
Each package is custom quoted for the size of the environment.[2] Existing MDR Elite and MDR Essentials customers continue their service and may upgrade.[2] See Managed Threat Complete.
Metrics
Asset (host with data attributed in last 30 days). The Incident Command and MDR FAQs define an asset in the same way. It is a host running a workstation or server operating system to which data has been attributed in the last 30 days. This includes servers, desktops, laptops (physical and virtual) and point-of-sale systems.[1][2] The MDR page frames the same thing commercially: pricing is based on the number of endpoints, servers and networks protected. It does not depend on the volume of data ingested or the number of incidents requiring response.[2]
Monthly data (Fair Use Monthly Data Policy). All Incident Command subscriptions include a Fair Use Monthly Data Policy that scales with asset tiers.[1] The MSSA lists gigabytes among the possible Volume Limitations.[3]
Counting / floors
Asset window (as retrieved 2026-09-30). The 30-day attribution window makes the count a rolling one. A host counts if data has been attributed to it in the last 30 days.[1] Commentary: decommissioned hosts fall out of the count 30 days after their last data. Network devices, SaaS applications and other event sources that are not hosts running a workstation or server operating system do not fall within the asset definition. Their log volume counts against the data policy instead. Catalog proof: Incident Command and MDR assets are OS hosts with data in the last 30 days.
No type weighting. The price does not change by asset type.[1][2] A server and a laptop cost the same.
Tiers and floors. Incident Command and Managed Threat Complete are priced by asset, and the price per asset decreases across asset count tiers. Both FAQs answer yes to whether volume discounts apply above 500 assets.[1][2] No minimum quantity and no tier boundaries are published. Pricing also varies internationally.[1]
Locations. Assets need not be in one location.[1] For Managed Threat Complete, all assets connected to the InsightIDR instance must be in a logically separated environment. Customers with multiple subsidiaries or business units may qualify for Multi-Org service delivery.[2]
Overages (effective 2025-10-24). If the asset count exceeds the Ordering Document, Schedule B invoices the excess at then-current list rates for the applicable tier, prorated for the remainder of the Term.[3] Catalog proof: Excess usage invoiced at then-current list rate for the tier, prorated.
Data and retention
Incident Command does not throttle ingestion. Rapid7 says it works with customers so they can operate within their data limits, and agrees reasonable plans for additional consumption when needed.[1] The data limits for each tier are not published. Customers are asked to contact Rapid7 about them.[1] Within the product, SIEM (InsightIDR) reports current monthly data usage, which equals the size of the logs it stores. It also forecasts the rest of the month from the previous month’s usage.[4] Log retention is 90 days in Essential and 180 days in Advanced and Ultimate, with add-ons for longer periods. Alert and audit retention is 13 months in every package.[1] Managed Threat Complete lists unlimited data ingestion and 13 months of data retention in all packages.[2] Catalog proof: SIEM data covered by a fair-use monthly policy that scales with asset tiers.
Virtualization & partitioning
The asset definition expressly covers virtual as well as physical servers, desktops and laptops. No host-level or hypervisor-level alternative is published, so each virtual machine with an operating system that sends data is an asset.[1] Commentary: non-persistent virtual desktops that reuse host identities are not addressed in the retrieved documents. In such pools the 30-day window can inflate the count, and the question should be settled in the Ordering Document.
Cloud / BYOL
InsightIDR is Cloud-Hosted Software. The Insight Platform SLA covers its hosted portion at 99.95% monthly availability.[6] Cloud workloads count as assets under the same definition as on-premises hosts. No bring-your-own-license mapping applies.[1]
Programs
Software inside Managed Services (effective 2025-10-24). Every Managed Threat Complete subscription includes full access to InsightIDR’s SIEM and XDR technology, including 13 months of searchable logs. It also includes full access to InsightVM.[2] Under Schedule A, Software included in Managed Services is licensed for the Term of the Managed Services only.[3] Commentary: a customer that ends MDR but wants to keep the SIEM or vulnerability management tools needs a separate Incident Command or InsightVM subscription from the day the MDR term ends. Catalog proof: Software included in Managed Services is licensed only for the Managed Services term; Managed Threat Complete includes InsightIDR and InsightVM access.
Limited Breach Protection Warranty (last updated 2026-01-29). A click-through warranty agreement. The Eligible Offering is Managed Threat Complete Ultimate, or a similar offering approved by Rapid7’s underwriter.[5] It reimburses Covered Expenses resulting from a Security Incident in the Protected Environment during a Warranty Period. Covered Expenses are forensic investigation, legal consultation, post-incident notification and public relations costs, pre-approved by Rapid7 and incurred within one year of discovery.[5] The limit depends on the number of Covered Endpoints. A Covered Endpoint is an endpoint that runs the Rapid7 agent on an operating system meeting the documentation prerequisites and fully supported by its manufacturer.[5]
| Covered Endpoints | Limit (USD) |
|---|---|
| 500-4,999 | $100,000 |
| 5,000-10,000 | $500,000 |
| 10,001 and above | $1,000,000 |
Payments for all Security Incidents in a Warranty Period are aggregated against one limit.[5] To be eligible, the customer must:
- hold a valid subscription to the Eligible Offering throughout the Warranty Period;
- keep endpoints in the Measured Security Posture;
- run the most recent agent;
- notify Rapid7 within 72 hours of discovery;
- be in compliance with its Customer Agreement, including payment obligations.[5]
Disputes go to AAA arbitration seated in Delaware.[5] Catalog proof: Breach warranty limit set by number of Covered Endpoints.
Out of scope
- The Rapid7 service descriptions and statements of work that define MDR scope, response actions and service levels.
- Managed Digital Risk Protection, Continuous Red Teaming and attack surface management add-ons, whose metrics are not published.
- Incident Command and Managed Threat Complete prices, data limits per tier and add-on retention prices, which are available only by quote.
- Legacy InsightIDR, MDR Elite and MDR Essentials terms. Purchases before 2023-03-01 fell under the Insight Platform Terms of Service and the Master Service Agreement.