InsightVM is Rapid7’s vulnerability risk management product. Nexpose is its on-premise vulnerability scanner.[1][9] Both are licensed by the number of unique assets whose vulnerability or policy assessment data is stored in the Security Console.[4][5] Rapid7 now presents InsightVM as the vulnerability management technology within Exposure Command. Exposure Command Essentials combines InsightVM with attack surface management. Exposure Command Ultimate adds cloud and application security.[1] Both products are Software under Schedule B of the Master Software and Services Agreement. InsightVM combines Rapid7-hosted components with components deployed on premises, while Nexpose is deployed on premises. Schedule B therefore applies its rules for both Cloud-Hosted and Distributed Software.[7]
Editions
| Offering | Contents (vendor description) | Commercial notes |
|---|---|---|
| InsightVM | Vulnerability scanning with scan engines or agents, risk prioritisation and remediation guidance[12] | Starts at $1.62 per asset per month for 500 assets[3]; still available, now part of Exposure Command[1] |
| Nexpose | On-premise scanner with Real Risk Score, Adaptive Security, policy assessment and remediation reporting[9] | By quote |
| Exposure Command Essentials | InsightVM plus attack surface management; hybrid scanning, agent visibility, risk-based prioritisation and remediation workflows[2] | By quote; demo-led[1] |
| Exposure Command Ultimate | Essentials plus multi-cloud and container assessment, IaC scanning, cloud threat detection and dynamic application security testing[2] | By quote |
| Managed Threat Complete | MDR service that includes full access to InsightVM[8] | Priced per MDR asset, not per InsightVM asset |
The public price point is recorded as InsightVM - starting price per asset. Commentary: $1.62 per asset per month for 500 assets works out to about $9,720 a year, before any discount. Existing InsightVM customers are told to take changes to their contract, timeline or deployment to their Rapid7 account team.[1] Customers who need hands-on access, an on-premise deployment or a smaller evaluation can still start an InsightVM trial.[12] See Exposure Command and InsightVM is sold as part of Exposure Command packages.
Metrics
Asset (unique assessed asset). InsightVM is licensed for unique assessed assets. An asset is assessed when its vulnerability or policy assessment data is stored in the Security Console.[4] Assets assessed by agents count toward the same total.[4] The contract term for this capacity is “unique assets”, one of the Volume Limitations in the MSSA.[7] The Nexpose documentation uses identical wording.[5]
Scan Engine (Max. Scan Engines) and hosted engine assets. The Security Console licence records several capacities alongside the asset maximum. Max. Scan Engines is the number of internal Scan Engines the customer may use. Max. Assets to Scan is the number of assets it may scan with internal engines. Max. Assets to Scan w/ Hosted Engine is the number it may scan with a Rapid7-hosted engine.[6]
Counting / floors
Assessed, not discovered (as retrieved 2026-09-30). The licence limits the number of assets that can be assessed and stored. It does not limit the number of assets that can be discovered on the network.[4] Commentary: discovery scans and asset inventory imports do not consume licences. The first vulnerability or policy result stored for an asset does. Catalog proof: InsightVM and Nexpose licence unique assessed assets, not discovered assets.
Correlation. Uniqueness is decided by correlation heuristics on UUIDs, hostnames, MAC addresses and IP addresses. A UUID match always correlates. Non-matching UUIDs do not prevent correlation if other attributes match.[4] Correlated assets are counted once, so an asset assessed by both an agent and a credentialed scan is not double-counted.[4] Commentary: assets that fail to correlate, for example unauthenticated scan results for agent-managed hosts, do count twice. Rapid7 points subscribers to its guidance on correlating agent assets with unauthenticated scans.[4] Catalog proof: Correlated assets counted once across agent and scan.
Thresholds and enforcement. The Security Console notifies users at three thresholds.[4]
| Usage of licensed maximum | What the console does |
|---|---|
| Above 90% | Orange notification |
| Above 100% | Red notification; temporary flexibility to scan above the limit |
| Above 110% | Red banner that cannot be dismissed; further scans may trigger automatic enforcement |
| Enforcement | New scan data is not retained and cannot be recovered later; ends when the count is back within the licence |
To avoid enforcement, the documentation says to clean up duplicate or stale assets, or to contact the customer success team to increase the licence.[4] Catalog proof: Above 110% of licensed assets new scan data may not be retained.
Contractual overage (effective 2025-10-24). Enforcement in the product is separate from the contract. Under Schedule B, excess usage is invoiced after a Notice Period at then-current list rates for the applicable tier, prorated for the rest of the Term.[7] Distributed Software may track or enforce its Volume Limitations. Rapid7 may also ask, no more than once every six months, for a signed certification of compliant use.[7] Catalog proof: Excess usage invoiced at then-current list rate for the tier, prorated; Distributed Software may enforce limits; signed usage certification at most every six months.
Who can see the count. Only global administrators can see the full licence limit, the usage bar and the licence details. Non-admin users see the overall and discovered asset counts for the assets they can access, along with the threshold notifications.[4]
Floors. No minimum quantity is published. The public starting price is expressed “for 500 assets”.[3]
Virtualization & partitioning
Rapid7 publishes no host-based, processor-based or hypervisor-based alternative. Each assessed virtual machine is an asset. The documentation does, however, set out three cases for elastic estates.[4]
- AWS and Azure. Each instance or virtual machine counts as one asset until it is terminated. Rapid7’s discovery connections detect decommissioned instances and remove them from the licence count immediately, so stale cloud assets do not count against the limit.
- Containers. Each container host counts as one asset, however many containers it runs. Per-image assessments, and the data they use, do not affect the licence count.
- Other virtualization. On-premises virtual machines are not covered by an automatic removal rule. Commentary: stale virtual machines stay in the count until they are deleted from the console or aged out by the customer’s own retention settings.
Catalog proof: AWS and Azure instances count until terminated; container hosts count once.
Cloud / BYOL
InsightVM combines components Rapid7 hosts with components the customer deploys: scan engines and agents across on-prem and cloud-hosted infrastructure[12], managed from a Security Console.[6] The MSSA grants use of the Software within the Volume Limitations wherever it is deployed. It publishes no separate rule for installing Distributed Software in a public cloud.[7] In the Exposure Command packages, cloud resources are assessed by the cloud security component of Exposure Command Ultimate. That component covers AWS, Azure, GCP and Kubernetes, and extends to Oracle Cloud Infrastructure and Alibaba Cloud.[2] See Rapid7 Metasploit, AppSpider, InsightAppSec and InsightCloudSec licensing for how InsightCloudSec counts billable resources.
Licence activation and entitlement records
A Security Console is activated with a licence key from Rapid7, a string of 16 numbers and letters in four hyphen-separated groups. A console without internet access uses a .lic licence file instead, which lists the licensed features and scanning capacities.[6] The licence details show the licence status, the expiration date, the scan engine and asset maxima, and whether SCADA scanning, discovery scanning, PCI reporting and policy scanning are enabled. An active licence is needed to run scans and create reports.[6] On the Command Platform, the Subscription Management view lists each InsightVM or Nexpose subscription with its expiry and entitlements, together with Console Management.[10] Catalog proof: Security Console licence sets expiry, scan engines, asset maxima and features; Command Platform Subscription Management lists purchased entitlements and expiry.
Programs and legacy editions
- Managed Threat Complete. Every MDR subscription includes full access to InsightVM. Rapid7 runs internal and external exposure scans, and the customer can build its own projects and integrations.[8] This licence lasts only as long as the managed service.[7] Catalog proof: Managed Threat Complete includes InsightIDR and InsightVM access.
- Nexpose MSSP and Consultant (legacy). Under the End User License Agreement for purchases before 2023-03-01, Nexpose MSSP Edition and Nexpose Consultant licences could scan third-party assets whose owners had authorised the scan.[11] The same EULA gave Rapid7 a right to review records and deployment on ten days’ notice.[11] Current terms prohibit service bureau use.[7] Catalog proof: Legacy Nexpose MSSP and Consultant editions could scan authorised third-party assets; Legacy EULA allowed Rapid7 to review records and deployment on ten days notice.
Worked example
Commentary, illustrative only. A customer has 2,000 licensed InsightVM assets. It runs agents on 1,500 laptops and servers and credentialed scans on 700 servers, 400 of which also run the agent. It also holds 300 AWS instances, 120 of which were terminated during the quarter.
- Agents and scans together cover 1,500 + 700 - 400 = 1,800 hosts, provided the agent and scan records correlate.
- The 180 running AWS instances add 180, because terminated instances drop out through the discovery connection. That gives 1,980 assessed assets, or 99% of the licence.
- If 400 overlapping servers fail to correlate because scans are unauthenticated, the count rises to 2,380, or 119%. The console would then show the 110% banner, and new scan data could be withheld.
- The contractual exposure is the excess, invoiced at list rate for the relevant tier and prorated. The remedy is either to fix correlation and delete duplicates, or to buy up.
Out of scope
- Surface Command licensing and the metric of the Exposure Command attack surface component. Neither is published.
- Managed Vulnerability Management services, which are governed by Schedule A and a statement of work.
- Metasploit integration with InsightVM, covered in the Metasploit article.
- End-of-life dates for individual InsightVM integrations.