Rapid7 InsightVM is an on-premises vulnerability management platform for network scanning, authenticated vulnerability detection and compliance assessment, available as part of Exposure Command with quote-based pricing.
Listing updated . Checked by MSP Software .
Rapid7 InsightVM is a vulnerability management and scanning platform from Rapid7 for mid-market and enterprise MSPs to scan networks for vulnerabilities, misconfigurations and policy violations. The platform runs network-based scanning from distributed Scan Engines and supports authenticated scanning to detect missing patches and security misconfigurations on systems. InsightVM organises discovered assets into dynamic or static groups and uses risk scoring to prioritise remediation based on threat exposure and exploitability.
The platform supports compliance frameworks including CIS policy compliance, PCI and other standards, generating customizable reports from built-in templates or SQL queries. InsightVM deploys as an on-premises solution with a web-based Security Console for management and distributed Scan Engines for scanning infrastructure. This on-premises model appeals to MSPs serving clients with data residency requirements or those uncomfortable hosting vulnerability data in shared cloud infrastructure. The platform includes scheduled recurring scans, asset tagging for fine-grained risk adjustment, and multi-tenant capabilities for managing multiple client environments from a single console.
Rapid7 offers a RESTful API and pre-built integrations with platforms including ServiceNow, Splunk, AWS and Microsoft Defender for Cloud, enabling automation of remediation workflows. Pricing is not published on Rapid7's site; instead, InsightVM is available through tiered Exposure Command packages with quote-based pricing depending on asset count and feature tier. Essentials includes vulnerability management and attack surface scanning, while Ultimate adds cloud and application security findings. Contact Rapid7 sales for pricing based on your asset count and requirements. Rapid7 is based in Boston, USA.
InsightVM stands out for its on-premises deployment model and detailed compliance reporting, making it suitable for MSPs serving regulated industries or clients with data residency requirements. The platform is mature and well-established within Rapid7's product suite. Weakness is that pricing is not published, requiring a vendor conversation before evaluation; many MSPs prefer transparent pricing. Consider how the vulnerability scanning tier pricing compares to alternatives like Qualys VMDR or Tenable Vulnerability Management. Confirm the on-premises architecture meets your infrastructure needs and that your PSA or ticketing system integrates via API.
| Feature | Supported | Note |
|---|---|---|
| Network vulnerability scanning | yes | Distributed Scan Engines perform extensive network probing for vulnerabilities and policy violations |
| Authenticated scanning | yes | Supports authenticated scanning to detect missing patches and security misconfigurations |
| Missing patch detection | yes | Identifies missing patches through authenticated system scanning |
| Compliance framework mapping | yes | Includes CIS policy compliance, PCI and other compliance framework mappings with policy manager |
| Risk scoring | yes | Uses risk scoring to prioritise remediation based on threat exposure and exploitability |
| Dark web monitoring | unknown | Not confirmed in available vendor documentation |
| External attack surface scanning | no | External attack surface is available through separate Exposure Command Essentials package, not core to InsightVM scanning |
| PSA integration for remediation tickets | yes | RESTful API available; pre-built integrations include ServiceNow and broader ticketing platforms |
| Scheduled recurring scans | yes | Supports scheduled recurring scans with scan templates |
| Client-facing reports | yes | Customizable reports using built-in templates and SQL query exports; multi-tenant for client visibility |
| Multi-tenant console | yes | Multi-tenant capabilities for MSPs managing multiple client environments |
| Automated evidence collection | unknown | Not explicitly confirmed in available vendor documentation |
Rapid7 InsightVM pricing is not publicly listed. Instead, it is available through Rapid7 Exposure Command tiered packages with quote-based pricing that typically depends on the number of assets scanned and the feature tier selected. Contact Rapid7 sales to receive a price quote based on your asset count and required capabilities.
Rapid7 InsightVM operates as an on-premises deployment with a web-based Security Console for management and distributed Scan Engines for scanning infrastructure. This makes it suitable for MSPs serving clients with data residency requirements or those preferring not to host vulnerability data in a cloud environment.
Yes, Rapid7 InsightVM offers a RESTful API and pre-built integrations with platforms including ServiceNow and Splunk. Integration with your specific PSA or ticketing system would depend on API availability and whether your platform is listed in Rapid7's current integrations. Contact Rapid7 to confirm compatibility with your specific tools.
Rapid7 InsightVM supports compliance framework mapping including CIS policy compliance, PCI and other standards. The platform includes a Policy Manager for configuration assessment and compliance verification, and generates customizable compliance reports using built-in templates. MSPs can export SQL query results for custom reporting needs, making it suitable for clients with specific compliance documentation requirements for audits.
Yes, Rapid7 offers a free trial of InsightVM. Since InsightVM pricing is quote-based and delivered through Exposure Command packages rather than published per-asset rates, trials are available for evaluation. Contact Rapid7 sales directly to discuss trial options and requirements for your organisation, particularly if you want to evaluate scanning performance against your existing asset inventory.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review