# Rapid7: how AI models rank it, September 2026

IT AI Recommendation Index, September 2026 Edition. Named in 32 judge labels across 7 categories by 11 of 12 models. Page: https://it-ai-index.com/vendors/rapid7/

## Standing by category

| Category | Share | Rank | Negative rate | Labels |
|---|---|---|---|---|
| Vulnerability management platforms | 0% | 34 | 38% | 13 |
| Penetration testing as a service | 0% | 24 | 25% | 8 |
| Attack surface management | 0% | 16 | 0% | 7 |
| Cloud security posture management | 0% | 30 | 0% | 1 |
| Data loss prevention | 0% | 61 | 0% | 1 |
| Endpoint protection | 0% | 87 | 100% | 1 |
| Extended detection and response | 0% | 54 | 100% | 1 |

## What the models said for it

- "Rapid7 masters the PTaaS model by providing expert consultation through a cloud-based approach that combines expert-led testing with live results" (Claude Haiku 4.5, PTaaS)
- "the top vulnerability management platforms are Tenable, Qualys, and Rapid7" (Qwen 3.7 Flash, Vuln management)
- "If budget is a key constraint: Rapid7 offers strong value and is purpose-built for mid-market needs." (MiniMax M2.5, CSPM)
- "Offers modular exposure management and is suitable for those with a limited budget" (Mistral Small, ASM)

## And against it

- "Missed 30+ attacks (93-94% protection); limited enterprise scalability." (Grok 4.1 Fast, Endpoint protection)
- "InsightVM requires "Security Consoles" and "Scan Engines" that can be notoriously resource-intensive." (Gemini 3.5 Flash, Vuln management)
- "Higher cost (often $20k‑$50k+ per engagement); less suited for continuous/subscription models" (GLM 4.7 FlashX, PTaaS)
- "its reporting interface and discovery features are often criticized for being less intuitive" (Qwen 3.7 Flash, Vuln management)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
