Rapid7 licensing is the set of terms under which Rapid7 sells its security software and services: the Command Platform products for exposure management and detection and response, the Insight family (InsightVM, InsightIDR, InsightAppSec, InsightCloudSec), the on-premises products Nexpose, Metasploit and AppSpider, and managed services such as Managed Threat Complete. Unless a customer has a signed agreement, all current offerings are governed by one Master Software and Services Agreement (MSSA). It has two schedules: Schedule A for professional and managed services and Schedule B for software. A schedule applies only to the extent the relevant offering is purchased.[2] The contracting entity is Rapid7 LLC for customers in the United States and Rapid7 International Limited elsewhere.[1]
Software is licensed for a Term set in the Ordering Document. It may be used solely for the customer’s internal business purposes and within the Volume Limitations.[1] The MSSA defines Volume Limitations as the capacity indicated on the Ordering Document or Documentation. This includes unique assets, applications, number of scans, number of billable cloud resources, gigabytes or workflows, as applicable.[1] The metric is therefore product-specific, and the product documentation defines how each one is counted. Purchases made before 24 October 2025 remain under archived terms. Purchases made before 1 March 2023 remain under older product-specific agreements.[3] Catalog proof: Terms depend on purchase date: 2025-10-24 and 2023-03-01 cut-overs.
Editions
Rapid7 now sells most capabilities as platform packages. Several individual Insight products still carry public starting prices.[4]
| Offering | What it contains (vendor description) | How it is priced |
|---|---|---|
| Exposure Command Essentials | InsightVM vulnerability management with attack surface management[5] | By quote; “flexible coverage based on the asset types you use”[5] |
| Exposure Command Ultimate | Essentials plus cloud and application security, including multi-cloud visibility and dynamic application security testing[19] | By quote |
| InsightVM | Vulnerability risk management; now part of Exposure Command, and still available[5] | From $1.62 per asset per month, for 500 assets[4] |
| Nexpose | On-premise vulnerability scanner[20] | By quote; licensed for unique assessed assets[21] |
| Incident Command Essential, Advanced, Ultimate | Next-Gen SIEM (InsightIDR) packages[7] | Annual SaaS subscription, per asset[7] |
| Managed Threat Complete Essential, Advanced, Ultimate | 24x7 MDR with InsightIDR and InsightVM access[8] | Custom quote by number of assets[8] |
| InsightAppSec | Dynamic application security testing[9] | From $175 per app per month, billed annually[9] |
| InsightCloudSec | Cloud security[4] | Annual tiers by average billable resources, from $66,000 per year[10] |
| Metasploit Pro | Edition for penetration testers and IT security teams[22] | Subscription licence key; number of users set by the key[11] |
Nexpose follows the same asset counting rules as InsightVM. This is covered in Rapid7 InsightVM, Nexpose and Exposure Command licensing. The public price points are recorded as catalog SKUs, for example InsightVM - starting price per asset and the eight InsightCloudSec resource tiers. Rapid7 publishes no part numbers. Every plan on the pricing page includes unlimited user accounts, single sign-on, 24/7 technical support and a customer-success team. Premium support is sold separately.[4]
Metrics
| Rapid7 term | Catalog row | Where it applies | What Rapid7 says |
|---|---|---|---|
| Unique assessed asset | Asset (unique assessed asset) | InsightVM, Nexpose, Exposure Command vulnerability management | Licensed for unique assessed assets; an asset is assessed when its assessment data is stored in the Security Console.[6] |
| Asset (host with recent data) | Asset (host with data attributed in last 30 days) | InsightIDR / Incident Command, Managed Threat Complete | Hosts running a workstation or server operating system to which data has been attributed in the last 30 days.[7] |
| App | App (InsightAppSec) | InsightAppSec | Priced per app.[9] |
| Billable resource | Billable resource (InsightCloudSec) | InsightCloudSec | Average number of billable resources monitored across the cloud environment.[10] |
| Developer license | Developer license (InsightCloudSec) | InsightCloudSec | One named-user seat to develop custom filters, actions and integrations.[10] |
| User | User (Metasploit Pro) | Metasploit Pro | The licence key sets the number of users allowed to use Metasploit at a given time.[11] |
| Gigabytes | Monthly data (Fair Use Monthly Data Policy) | Incident Command | A Fair Use Monthly Data Policy that scales with asset tiers.[7] |
| Covered Endpoint | Covered Endpoint (Breach Protection Warranty) | Breach protection warranty on Managed Threat Complete Ultimate | An endpoint with the Rapid7 agent and a supported operating system; sets the warranty limit, not the fee.[12] |
The two asset metrics are not interchangeable. The vulnerability management asset is counted when assessment results are stored. The detection and response asset is counted when a host has sent data in the last 30 days. The same laptop can therefore be counted in one product and not in the other.
Counting / floors
Quantity in the Ordering Document (effective 2025-10-24). The Ordering Document identifies the offering, the Volume Limitations, the overage options, the Term, the tiers and the price.[1] Catalog proof: Volume Limitations are the capacities on the Ordering Document or Documentation.
Overages (effective 2025-10-24). Rapid7 first gives a reasonable notification period. Excess usage is then invoiced at Rapid7’s then-current list rates for the applicable Volume Limitation tier, prorated for the rest of the Term.[1] The archived terms for purchases before 2025-10-24 offered a choice for Cloud-Hosted Software. A customer could pay a True-Up for the excess, or True-Forward by moving to the next tier for the remainder of the Term.[15] Catalog proof: Excess usage invoiced at then-current list rate for the tier, prorated; Legacy terms offered True-Forward to the next tier for cloud overages.
In-product enforcement. The InsightVM and Nexpose Security Console warns at 90%, 100% and 110% of the licensed asset maximum. It allows temporary flexibility above 100%. Above 110%, new scan data may not be retained.[6] Metasploit Pro removes the New User button once the licensed number of users is reached.[11] Catalog proof: Above 110% of licensed assets new scan data may not be retained; Metasploit license key caps edition, term and number of users.
Floors. None of the retrieved documents sets a minimum purchase quantity. The InsightVM starting price is expressed “for 500 assets”.[4] The lowest InsightCloudSec tier covers 251 to 500 resources.[10] Incident Command and Managed Threat Complete per-asset prices decrease across asset count tiers.[7][8]
Virtualization & partitioning
Rapid7 does not license by processor, core or host, and publishes no partitioning policy. For InsightVM and Nexpose, each assessed virtual machine is an asset. Each AWS or Azure instance counts until it is terminated. A container host counts as one asset however many containers it runs.[6] The Incident Command and MDR asset definition includes physical and virtual servers, desktops and laptops.[7] Catalog proof: AWS and Azure instances count until terminated; container hosts count once.
Cloud / BYOL
Most Rapid7 products are Cloud-Hosted Software. The MSSA defines this as subscription applications hosted by Rapid7. Distributed Software, by contrast, is deployed in the customer’s on-premises environment.[1] No bring-your-own-license mapping applies to the hosted services. Distributed components such as Security Consoles and scan engines run under the same subscription and Volume Limitations wherever the customer installs them. InsightCloudSec is itself priced on the customer’s cloud estate, by averaging billable compute, database, cache and search instances.[10]
Programs
- Exposure Command. InsightVM is part of Exposure Command Essentials. Exposure Command Ultimate adds cloud and application security context.[5] See Rapid7 InsightVM, Nexpose and Exposure Command licensing.
- Incident Command. Three SIEM packages with asset-based pricing and a Fair Use Monthly Data Policy.[7]
- Managed Threat Complete. Rapid7’s MDR offering, sold in three packages. Every subscription includes full access to InsightVM and InsightIDR.[8] See Rapid7 InsightIDR, Incident Command and MDR licensing.
- Limited Breach Protection Warranty (last updated 2026-01-29). Reimbursement of covered incident expenses for Managed Threat Complete Ultimate customers. The limit runs from $100,000 to $1,000,000 depending on the number of Covered Endpoints.[12]
- Evaluation and trial licenses. Evaluations run for thirty days by default, with one per product in any twelve-month period.[1] Metasploit Pro trials last 14 days.[11]
- PACT Partner Program. A partner specialization for service providers, with a multi-tenanted platform to serve many customers.[16]
- Insight Platform SLA and Customer Support. The SLA commits to 99.95% monthly availability, with service credits applied only to renewals or purchases.[13] Support is given under the Customer Support Guidebook.[17]
Contract terms
The main MSSA provisions are summarised here, all effective for purchases from 2025-10-24. Rapid7 Master Software and Services Agreement covers them in depth.
- Renewal. Terms renew automatically for the same period unless either party gives notice at least 30 days before the end. For a renewal term, Rapid7 may change rates on 60 days’ written notice.[1] Catalog proof: Terms auto-renew for the same period unless 30 days notice; 60 days notice of rate changes.
- Refunds and early termination. Fees are non-refundable and non-cancellable. A customer that terminates before the fixed term ends remains liable for fees for the full term.[1] Catalog proof: No refund on early termination; fees due for the full fixed term.
- Affiliates and transfer. Controlled Affiliates may use the Offerings, and the customer is liable for them. Assignment needs Rapid7’s advance written consent.[1] Catalog proof: Affiliates may use the Offerings; customer liable for them; Assignment requires Rapid7 advance written consent.
- Restrictions. Resale, sublicensing, timesharing and service bureau use are prohibited. So is using the Software for competitive analysis.[1] Catalog proof: No resale, sublicensing, timesharing or service bureau use.
- Managed services. Software included in Managed Services is licensed for the Term of the Managed Services only.[1] Catalog proof: Software included in Managed Services is licensed only for the Managed Services term.
Audits and compliance
The current MSSA has no clause allowing Rapid7 to inspect a customer’s records or premises. Instead, Distributed Software may track and enforce its Volume Limitations itself. On written request, no more than once every six months, the customer must provide a signed certification of compliant use.[1] The legacy End User License Agreement, which covers Nexpose, Metasploit and AppSpider bought before 2023-03-01, went further. Rapid7 could review the customer’s records, deployment and use on at least ten days’ notice, at the customer’s facilities.[14] Catalog proof: Distributed Software may enforce limits; signed usage certification at most every six months; Legacy EULA allowed Rapid7 to review records and deployment on ten days notice.
For an effective license position, the vendor-side entitlement record is the Command Platform’s Subscription Management view. It lists each purchased subscription with its expiry, main entitlements and status.[18] Consumption comes from the licence usage bars in each product. Commentary: in the retrieved documents, the only monetary consequence of over-deployment is the overage invoice at list rates, and nothing suggests any penalty beyond it. The practical exposure is therefore the gap between contracted and list price for the excess tier, plus proration.
Out of scope
- Signed enterprise agreements, public-sector contract vehicles, reseller terms and cloud marketplace private offers, none of which were retrievable.
- Prices for Exposure Command, Incident Command, Managed Threat Complete, Nexpose, Metasploit Pro and professional services, which Rapid7 sells by quote.
- Threat Command, Intelligence Hub, Vector Command, Cloud Risk Complete, InsightConnect and InsightOps. They are named in the terms and the SLA but have no published metric in the retrieved documents.
- Metasploit Framework, which is free open-source software. See Rapid7 Metasploit, AppSpider, InsightAppSec and InsightCloudSec licensing.
- The Data Processing Addendum and privacy terms, which do not affect licence counting.