LICENSEWARE

Rapid7 licensing

This article is an overview of how Rapid7 licenses the Command Platform, its Insight products, Metasploit and its managed services. Deeper articles cover the Master Software and Services Agreement, InsightVM, Nexpose and Exposure Command, InsightIDR, Incident Command and MDR, and Metasploit, AppSpider, InsightAppSec and InsightCloudSec. It is not legal advice.

On This Page

Rapid7 licensing is the set of terms under which Rapid7 sells its security software and services: the Command Platform products for exposure management and detection and response, the Insight family (InsightVM, InsightIDR, InsightAppSec, InsightCloudSec), the on-premises products Nexpose, Metasploit and AppSpider, and managed services such as Managed Threat Complete. Unless a customer has a signed agreement, all current offerings are governed by one Master Software and Services Agreement (MSSA). It has two schedules: Schedule A for professional and managed services and Schedule B for software. A schedule applies only to the extent the relevant offering is purchased.[2] The contracting entity is Rapid7 LLC for customers in the United States and Rapid7 International Limited elsewhere.[1]

Software is licensed for a Term set in the Ordering Document. It may be used solely for the customer’s internal business purposes and within the Volume Limitations.[1] The MSSA defines Volume Limitations as the capacity indicated on the Ordering Document or Documentation. This includes unique assets, applications, number of scans, number of billable cloud resources, gigabytes or workflows, as applicable.[1] The metric is therefore product-specific, and the product documentation defines how each one is counted. Purchases made before 24 October 2025 remain under archived terms. Purchases made before 1 March 2023 remain under older product-specific agreements.[3] Catalog proof: Terms depend on purchase date: 2025-10-24 and 2023-03-01 cut-overs.

Editions

Rapid7 now sells most capabilities as platform packages. Several individual Insight products still carry public starting prices.[4]

Offering What it contains (vendor description) How it is priced 
Exposure Command Essentials InsightVM vulnerability management with attack surface management[5] By quote; “flexible coverage based on the asset types you use”[5] 
Exposure Command Ultimate Essentials plus cloud and application security, including multi-cloud visibility and dynamic application security testing[19] By quote 
InsightVM Vulnerability risk management; now part of Exposure Command, and still available[5] From $1.62 per asset per month, for 500 assets[4] 
Nexpose On-premise vulnerability scanner[20] By quote; licensed for unique assessed assets[21] 
Incident Command Essential, Advanced, Ultimate Next-Gen SIEM (InsightIDR) packages[7] Annual SaaS subscription, per asset[7] 
Managed Threat Complete Essential, Advanced, Ultimate 24x7 MDR with InsightIDR and InsightVM access[8] Custom quote by number of assets[8] 
InsightAppSec Dynamic application security testing[9] From $175 per app per month, billed annually[9] 
InsightCloudSec Cloud security[4] Annual tiers by average billable resources, from $66,000 per year[10] 
Metasploit Pro Edition for penetration testers and IT security teams[22] Subscription licence key; number of users set by the key[11] 

Nexpose follows the same asset counting rules as InsightVM. This is covered in Rapid7 InsightVM, Nexpose and Exposure Command licensing. The public price points are recorded as catalog SKUs, for example InsightVM - starting price per asset and the eight InsightCloudSec resource tiers. Rapid7 publishes no part numbers. Every plan on the pricing page includes unlimited user accounts, single sign-on, 24/7 technical support and a customer-success team. Premium support is sold separately.[4]

Metrics

Rapid7 term Catalog row Where it applies What Rapid7 says 
Unique assessed asset Asset (unique assessed asset) InsightVM, Nexpose, Exposure Command vulnerability management Licensed for unique assessed assets; an asset is assessed when its assessment data is stored in the Security Console.[6] 
Asset (host with recent data) Asset (host with data attributed in last 30 days) InsightIDR / Incident Command, Managed Threat Complete Hosts running a workstation or server operating system to which data has been attributed in the last 30 days.[7] 
App App (InsightAppSec) InsightAppSec Priced per app.[9] 
Billable resource Billable resource (InsightCloudSec) InsightCloudSec Average number of billable resources monitored across the cloud environment.[10] 
Developer license Developer license (InsightCloudSec) InsightCloudSec One named-user seat to develop custom filters, actions and integrations.[10] 
User User (Metasploit Pro) Metasploit Pro The licence key sets the number of users allowed to use Metasploit at a given time.[11] 
Gigabytes Monthly data (Fair Use Monthly Data Policy) Incident Command A Fair Use Monthly Data Policy that scales with asset tiers.[7] 
Covered Endpoint Covered Endpoint (Breach Protection Warranty) Breach protection warranty on Managed Threat Complete Ultimate An endpoint with the Rapid7 agent and a supported operating system; sets the warranty limit, not the fee.[12] 

The two asset metrics are not interchangeable. The vulnerability management asset is counted when assessment results are stored. The detection and response asset is counted when a host has sent data in the last 30 days. The same laptop can therefore be counted in one product and not in the other.

Counting / floors

Quantity in the Ordering Document (effective 2025-10-24). The Ordering Document identifies the offering, the Volume Limitations, the overage options, the Term, the tiers and the price.[1] Catalog proof: Volume Limitations are the capacities on the Ordering Document or Documentation.

Overages (effective 2025-10-24). Rapid7 first gives a reasonable notification period. Excess usage is then invoiced at Rapid7’s then-current list rates for the applicable Volume Limitation tier, prorated for the rest of the Term.[1] The archived terms for purchases before 2025-10-24 offered a choice for Cloud-Hosted Software. A customer could pay a True-Up for the excess, or True-Forward by moving to the next tier for the remainder of the Term.[15] Catalog proof: Excess usage invoiced at then-current list rate for the tier, prorated; Legacy terms offered True-Forward to the next tier for cloud overages.

In-product enforcement. The InsightVM and Nexpose Security Console warns at 90%, 100% and 110% of the licensed asset maximum. It allows temporary flexibility above 100%. Above 110%, new scan data may not be retained.[6] Metasploit Pro removes the New User button once the licensed number of users is reached.[11] Catalog proof: Above 110% of licensed assets new scan data may not be retained; Metasploit license key caps edition, term and number of users.

Floors. None of the retrieved documents sets a minimum purchase quantity. The InsightVM starting price is expressed “for 500 assets”.[4] The lowest InsightCloudSec tier covers 251 to 500 resources.[10] Incident Command and Managed Threat Complete per-asset prices decrease across asset count tiers.[7][8]

Virtualization & partitioning

Rapid7 does not license by processor, core or host, and publishes no partitioning policy. For InsightVM and Nexpose, each assessed virtual machine is an asset. Each AWS or Azure instance counts until it is terminated. A container host counts as one asset however many containers it runs.[6] The Incident Command and MDR asset definition includes physical and virtual servers, desktops and laptops.[7] Catalog proof: AWS and Azure instances count until terminated; container hosts count once.

Cloud / BYOL

Most Rapid7 products are Cloud-Hosted Software. The MSSA defines this as subscription applications hosted by Rapid7. Distributed Software, by contrast, is deployed in the customer’s on-premises environment.[1] No bring-your-own-license mapping applies to the hosted services. Distributed components such as Security Consoles and scan engines run under the same subscription and Volume Limitations wherever the customer installs them. InsightCloudSec is itself priced on the customer’s cloud estate, by averaging billable compute, database, cache and search instances.[10]

Programs

Contract terms

The main MSSA provisions are summarised here, all effective for purchases from 2025-10-24. Rapid7 Master Software and Services Agreement covers them in depth.

Audits and compliance

The current MSSA has no clause allowing Rapid7 to inspect a customer’s records or premises. Instead, Distributed Software may track and enforce its Volume Limitations itself. On written request, no more than once every six months, the customer must provide a signed certification of compliant use.[1] The legacy End User License Agreement, which covers Nexpose, Metasploit and AppSpider bought before 2023-03-01, went further. Rapid7 could review the customer’s records, deployment and use on at least ten days’ notice, at the customer’s facilities.[14] Catalog proof: Distributed Software may enforce limits; signed usage certification at most every six months; Legacy EULA allowed Rapid7 to review records and deployment on ten days notice.

For an effective license position, the vendor-side entitlement record is the Command Platform’s Subscription Management view. It lists each purchased subscription with its expiry, main entitlements and status.[18] Consumption comes from the licence usage bars in each product. Commentary: in the retrieved documents, the only monetary consequence of over-deployment is the overage invoice at list rates, and nothing suggests any penalty beyond it. The practical exposure is therefore the gap between contracted and list price for the excess tier, plus proration.

Out of scope

  • Signed enterprise agreements, public-sector contract vehicles, reseller terms and cloud marketplace private offers, none of which were retrievable.
  • Prices for Exposure Command, Incident Command, Managed Threat Complete, Nexpose, Metasploit Pro and professional services, which Rapid7 sells by quote.
  • Threat Command, Intelligence Hub, Vector Command, Cloud Risk Complete, InsightConnect and InsightOps. They are named in the terms and the SLA but have no published metric in the retrieved documents.
  • Metasploit Framework, which is free open-source software. See Rapid7 Metasploit, AppSpider, InsightAppSec and InsightCloudSec licensing.
  • The Data Processing Addendum and privacy terms, which do not affect licence counting.

References

  1. Master Software and Services Agreement - Rapid7Agreement §§1-9, Schedule A (Services), Schedule B (Software). Last updated October 2025.Effective 2025-10-24. Retrieved 2026-09-30.
  2. Customers and Partners - Rapid7Terms index and purchase schedule comparison; archived terms apply to purchases before 2025-10-24. Undated.Retrieved 2026-09-30.
  3. Customers and Partners - archived termsTerms for purchases before 2025-10-24 and before 2023-03-01. Undated.Retrieved 2026-09-30.
  4. Rapid7 PricingStarting prices for InsightVM, InsightAppSec and InsightCloudSec; plan inclusions. Undated.Retrieved 2026-09-30.
  5. InsightVM is now part of Exposure CommandProduct page and FAQ. Undated.Retrieved 2026-09-30.
  6. Live Licensing - InsightVM documentationAsset counting and licence enforcement. Undated.Retrieved 2026-09-30.
  7. Compare SIEM Packages - Incident CommandPackage comparison and pricing FAQ. Undated.Retrieved 2026-09-30.
  8. Rapid7 MDR PackagesManaged Threat Complete packages and pricing FAQ. Undated.Retrieved 2026-09-30.
  9. InsightAppSec PricingPer-app starting price. Undated.Retrieved 2026-09-30.
  10. InsightCloudSec Pricing Model and TiersBillable resources, tier table, developer licences, contract terms. Undated.Retrieved 2026-09-30.
  11. Managing License Keys - Metasploit documentationLicence key contents, subscription and legacy perpetual licences, trial. Undated.Retrieved 2026-09-30.
  12. Rapid7 Limited Breach Protection Warranty AgreementLast updated 2026-01-29.Effective 2026-01-29. Retrieved 2026-09-30.
  13. Rapid7 Insight Platform Service Level Agreement99.95% availability and service credits. Undated.Retrieved 2026-09-30.
  14. Rapid7 End User License Agreement (purchases before 2023-03-01)Legacy EULA for Nexpose, Metasploit and AppSpider. Last updated April 2021.Retrieved 2026-09-30.
  15. Rapid7 General Terms and Conditions - Schedules A and B (purchases before 2025-10-24)Archived terms with True-Up and True-Forward. Undated.Retrieved 2026-09-30.
  16. PACT Partner Program for Service ProvidersService provider partner programme. Undated.Retrieved 2026-09-30.
  17. Rapid7 Customer Support GuidebookSupport policy referenced by Schedule B §10. Undated.Retrieved 2026-09-30.
  18. Subscription Management - Command Platform documentationSubscription and entitlement view for administrators. Undated.Retrieved 2026-09-30.
  19. Hybrid Exposure Management - Exposure CommandExposure Command Essentials and Ultimate capabilities. Undated.Retrieved 2026-09-30.
  20. On-Premise Vulnerability Scanner - NexposeNexpose product page. Undated.Retrieved 2026-09-30.
  21. Live Licensing - Nexpose documentationNexpose asset counting. Undated.Retrieved 2026-09-30.
  22. Metasploit editionsMetasploit Pro and Framework comparison. Undated.Retrieved 2026-09-30.

See also

Catalog Rows Cited

15Rules2SKUs8Metrics8Programs

Esc