This article covers four Rapid7 product lines that do not use the asset metrics of InsightVM or InsightIDR. Metasploit Pro is licensed by a key that fixes the number of users.[2] AppSpider Pro is licensed per app or engine, with each licence key bound to one system’s hardware.[9][8] InsightAppSec is priced per app.[10] InsightCloudSec is priced by the average number of billable cloud resources.[13] All four are Software under Schedule B of the Master Software and Services Agreement. Schedule B limits use to internal business purposes and to the Volume Limitations. Those include applications and billable cloud resources.[14]
Editions
| Product | Editions | How it is sold |
|---|---|---|
| Metasploit | Metasploit Pro, for penetration testers and IT security teams; Metasploit Framework, for developers and security researchers[1] | Pro through sales; Framework a free download[1] |
| AppSpider | AppSpider Pro; AppSpider Enterprise[9] | Per app or engine[9] |
| InsightAppSec | Single offering; dynamic application security testing is also listed in Exposure Command Ultimate[15] | Per app, from $175 per month, billed annually[10] |
| InsightCloudSec | Single offering in resource tiers | Annual tiers by average billable resources[13] |
Metasploit Pro adds several features that the Framework lacks. They include a web interface, smart exploitation, automated credential brute forcing, baseline penetration testing reports, task chains, closed-loop vulnerability validation, phishing campaigns and dynamic payloads to evade anti-virus.[1] Catalog proof: Metasploit Framework is a free download; Metasploit Pro is sold through sales.
Metasploit
Licence key. A Metasploit licence key determines three things: the commercial edition, the number of days left on the licence, and the number of users allowed to use Metasploit at a given time.[2] When the maximum number of users is reached, the New User button is removed. The allowed number is shown next to Product Edition on the Software License page.[3] The legacy End User License Agreement (purchases before 2023-03-01) listed “named individual users of the Software” among its Volume Limitations.[7] See User (Metasploit Pro) and Metasploit license key caps edition, term and number of users.
Commentary: the documentation enforces the cap through the number of user accounts in the instance and does not describe a concurrent-session count. Reconcile Pro entitlements against the user accounts on each installation, not against login counts.
Subscription and legacy perpetual licences. Metasploit is licensed as a subscription. After the subscription expires the application can no longer be run, although accumulated project data stays in the local database.[2] Some older licences are perpetual, but the perpetual licence key expires every year. Without renewal the customer can still run Metasploit, but only the last version released before the key expired.[2] Under the legacy EULA, the Maintenance and Support Term of perpetual software renewed for one year unless notice was given at least 30 days before the anniversary.[7] See Metasploit legacy perpetual license and Metasploit subscriptions stop at expiry; legacy perpetual keys freeze updates.
Activation. Metasploit Pro needs an internet connection for its first activation. After that it can be used offline. Offline activation uses an activation file, and customers for whom online activation is not possible at all are told to contact Support.[2] US embargo restrictions are enforced during activation. Users who cannot activate may still use the open-source Framework, which needs no registration.[6]
Trials. Metasploit is available as a 14-day trial.[2] Rapid7 reviews trial requests from outside the United States or Canada before issuing a key, to check whether the requester is a restricted government end user.[4] The general evaluation rule in the MSSA is thirty days, with one trial per product in any twelve months.[14] Commentary: the product-specific 14-day period is what the key enforces. Catalog proof: Metasploit Pro trials last 14 days and are export-screened outside US and Canada.
Framework licence. Metasploit Framework is provided under the 3-clause BSD licence, with copyright held by Rapid7, Inc. Some third-party components carry their own licences.[5] Commentary: installations of the Framework alone need no Rapid7 entitlement. Software inventories should distinguish a Framework install from a Metasploit Pro install, which adds the licensed commercial interface.[6]
AppSpider Pro
AppSpider Pro is activated with a product key over the internet. Offline systems use a licence key that Rapid7 Support generates from the installation’s reference code.[8] The reference code identifies a system and is generated from its hardware and software. The licence is tied to the system hardware, whether physical or virtual. On a virtual machine, changing the RAM, MAC address or system board forces re-licensing.[8] To move a licence, the customer exports it from the licensed installation against the new system’s reference code. After the export, the original system holds an invalid licence. If AppSpider has already been uninstalled, Rapid7 Support must reset the product key.[8] Rapid7’s feature comparison lists AppSpider Pro and AppSpider Enterprise as licensed per app or engine, with unlimited scans and apps.[9] See Licensed system (AppSpider Pro) and AppSpider Pro licence bound to system hardware, physical or virtual.
InsightAppSec
Price and inclusions (as retrieved 2026-09-30). InsightAppSec starts at $175 per app per month, billed annually, in US dollars. International prices vary. The price includes cloud and on-premises scan engines, unlimited and concurrent scanning, the Universal Translator, 95+ attack types, scan schedules and blackout periods, and dashboards and interactive reporting.[10] Catalog SKU: InsightAppSec - starting price per app.
What an app is. An app groups one or more targets so that scans are tuned consistently, results collected in one place and improvements tracked over time. A web application must be added to an app, with its URLs, before it can be scanned. Wildcards such as *.mysite.com can cover several subdomains.[11] Deleting an app permanently deletes its scan configurations and vulnerabilities.[11] The feature comparison gives InsightAppSec a per-app licensing model with unlimited scans.[9] See App (InsightAppSec) and InsightAppSec priced per app; an app groups target URLs.
Commentary: the retrieved documents do not say how many URLs or subdomains one licensed app may contain. A wildcard target can technically place several applications in one app, so the Ordering Document’s definition of an application decides the count.
InsightCloudSec
Metric. InsightCloudSec is priced on the average number of billable resources monitored across the cloud environment.[13] Billable resources are:
- compute instances;
- database instances;
- cache instances;
- search instances;
- active IAM roles, on an opt-in basis;
- Kubernetes nodes, on an opt-in basis.[13]
The average is calculated over the trailing month of each quarter, which Rapid7 says avoids volatility from short-term bursts. Contracts are annual, invoiced annually, with quarterly reconciliation.[13] See Billable resource (InsightCloudSec) and InsightCloudSec billable resources averaged over the trailing month of each quarter.
Tiers (as retrieved 2026-09-30). The following table shows Rapid7’s published annual pricing.[13]
| Resource tier | Range | Annual price (USD) | Catalog SKU |
|---|---|---|---|
| 500 | 251-500 | $66,000 | 500 tier |
| 750 | 501-750 | $93,000 | 750 tier |
| 1,000 | 751-1,000 | $120,000 | 1,000 tier |
| 2,000 | 1,001-2,000 | $222,000 | 2,000 tier |
| 3,000 | 2,001-3,000 | $318,000 | 3,000 tier |
| 5,000 | 3,001-5,000 | $438,000 | 5,000 tier |
| 10,000 | 5,001-10,000 | $784,000 | 10,000 tier |
| 15,000 | 10,001-15,000 | $1,043,000 | 15,000 tier |
| 20,000+ | Negotiated |
The marketing pricing page gives a different entry point: $5,775 per month for up to 500 instances.[12] Commentary: that equals $69,300 a year, against $66,000 in the documentation tier table. The two pages are undated, so the quote decides which applies.
Inclusions and developer licences. Customers may deploy self-hosted, managed self-hosted or full SaaS at no additional cost. Enterprise Support is included.[13] There is no limit on users, clouds and cloud accounts, or on Insights, Bots and Integrations.[13] The one per-user element is the developer licence. Each provides one named-user seat for developing custom filters, actions and integrations. One is included, and additional licences cost $6,000 per licence per year.[13] See Developer license (InsightCloudSec), InsightCloudSec - additional developer license and InsightCloudSec includes unlimited users and clouds; developer seats are named users.
Worked example. Commentary, illustrative only. A customer runs 400 compute instances for two months of a quarter, then scales to 700 in the trailing month. The quarterly measurement uses the trailing month’s average of about 700, which sits in the 750 tier ($93,000 a year). If the customer had bought the 500 tier, the quarterly reconciliation would show the excess. Schedule B then invoices it at the then-current list rate for the applicable tier, prorated.[14] Opting in IAM roles or Kubernetes nodes adds them to the count.
Out of scope
- Metasploit Pro prices, which are not published.
- AppSpider Enterprise deployment and licence terms beyond the feature comparison.
- The cloud security component of Exposure Command Ultimate. Rapid7 does not publish whether it uses the InsightCloudSec billable resource metric.
- tCell and DivvyCloud, legacy products named in archived terms.