Listing Thumbnail

    Insight AppSec - Web Application Security

     Info
    Sold by: Rapid7 
    Deployed on AWS
    InsightAppSec performs black-box security testing to automate identification, triage vulnerabilities, prioritize actions, and remediate application risk.
    4

    Overview

    InsightAppSec is part of Rapid7s security suite, delivering Dynamic Application Security Testing DAST for both mature and growing application security teams. Modern applications are increasingly complex, leveraging JavaScript frameworks like React and Angular to enhance user experience and accelerate development. However, these advancements also introduce security challenges.

    Application security is complex, but using security tools should not be. While security scans often require extensive configuration, InsightAppSec comes with system defaults informed by Rapid7s years of expertise so you can focus on remediating vulnerabilities, not fine-tuning settings. When you need to balance speed and thoroughness, the intuitive Scan Configuration Wizard lets you customize scans to fit your organizations unique needs.

    With Rapid7 InsightAppSec, organizations can:

    Secure the modern web - Automatically assess web apps and APIs with fewer false positives and missed vulnerabilities.

    Collaborate with speed - Fast-track fixes with rich reporting, seamless integrations, and clear insights for compliance and development teams.

    Scale with ease - Manage security assessments across your entire application portfolio, no matter the size.

    Highlights

    • Dynamic Application Security Testing (DAST) - Get actionable, accurate insights with an industry leading attack framework and library.
    • Replay attacks & validate fixes - Speed up remediation and reduce dev team back-and-forth by providing self-service access.
    • Integrate into dev workflows - Better prevent risk early by adding security testing as part of the build pipeline and integrating dev and sec team workflows.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Insight AppSec - Web Application Security

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Insight AppSec
    Price based on 1 application.
    $2,100.00

    AI Insights

     Info

    Dimensions summary

    This contract prices Insight AppSec by application. You buy units, where each unit covers one web application you want to scan for vulnerabilities. Pricing scales with the number of applications in your portfolio: add more units to cover more applications. There is a single billing dimension, so cost tracks directly to how many applications you protect. Cloud scan engines let you run multiple scans at once with no extra charge, and an optional on-premise engine is available for internal or closed-network applications.

    Top-of-mind questions for buyers

    One unit covers one web application you scan for vulnerabilities. Each distinct application in your portfolio uses one unit. To cover more applications, add more units. The count tracks the number of applications you want assessed, not the number of scans you run against them.
    No. You can run multiple scans at once using cloud engines at no extra cost. You can also spin up additional cloud engines to run scans simultaneously without added charges. Cost is driven by the number of application units you buy, not scan volume or engine count.
    Yes. An optional on-premise scan engine lets you assess pre-production and internal apps on closed networks. You download the installer and pair it with your account. Results store in the cloud console alongside cloud scans. Pricing still tracks the number of application units, not where the app is hosted.
    www.rapid7.com
    Helpful?

    Vendor refund policy

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4
    13 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    23%
    69%
    8%
    0%
    0%
    1 AWS reviews
    |
    12 external reviews
    External reviews are from PeerSpot .
    Brandi Lea

    Rapid risk detection has transformed how I uncover hidden vulnerabilities in new applications

    Reviewed on Aug 24, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Rapid7 is onboarding all new applications both built in house and third party acquired, where I run them through a sandbox environment and allow Rapid7 to conduct an initial scan looking for vulnerabilities that might not otherwise be publicly announced. On an ongoing basis, while applications live and survive within the McKesson environment, I use Rapid7 to aggregate data about new vulnerabilities to determine if I have to do any kind of hardening or shelf the application.

    A specific example of how I used Rapid7 during the onboarding process involves a recent scenario with Change Healthcare. I had just purchased or acquired a new practice in the United States that was still using Change Healthcare software, and during the onboarding process of all the applications they have in their environment, I used Rapid7 in the sandbox to figure out if those were still vulnerable to the breach that occurred in twenty twenty four. Almost all of the applications that practice was using were in fact filled with the vulnerabilities that caused the twenty twenty four breach.

    What is most valuable?

    Rapid7 InsightAppSec offers excellent features including a cloud-based platform that allows for detailed breakdowns of information into more digestible bits. The platform is user-friendly with a broad range of tools, although it does require quite a bit of a learning curve. It allows me to aggregate data and put it into presentations to send to executives about the security status across the entire enterprise.

    My favorite aspect of the user-friendly interface of Rapid7 is the primary cloud-based dashboard, which I find most useful. I love that even inside a browser, the intuitive help options are available for figuring out what things are, whether it's hovering over a particular option for insights or using right-click features that offer tools and tips on managing the vulnerabilities when found. The interface is very clean, not overly convoluted or difficult to navigate, which I do enjoy.

    Rapid7 has positively impacted my organization by allowing me to discover vulnerabilities, both publicly known and zero-day, much faster and efficiently than I ever did in the past, ultimately saving the company a lot of money in compliance issues, fines, and possibly even lawsuits. The number of vulnerabilities I am discovering has improved by almost thirty seven percent in the last two years alone. Remediation especially has increased significantly because I am finding these vulnerabilities faster, and Rapid7 provides tips on how to remediate or harden against them, whether through hardening options or upgrading to better versions, which does save the company money.

    What needs improvement?

    While Rapid7 InsightAppSec is getting better with each update or version, it needs to enhance its zero-day detection for anomalous things without relying on third-party solutions like Vericode. Having that capability in-house would be a much better feature, and a couple of menu options might need cleaning up on the cloud platform.

    Integration with ServiceNow and One Trust as a GRC platform would be beneficial and would be significantly valuable to many enterprises, especially in McKesson.

    For how long have I used the solution?

    I have been using Rapid7 for application vulnerability assessments and management for about a year and a half as I was recently put on the team using it.

    What do I think about the stability of the solution?

    I consider Rapid7 to be a very stable platform. Thanks to continuous updates and the transparency from the company, I have not encountered any real issues with it.

    What do I think about the scalability of the solution?

    Rapid7 InsightAppSec is very scalable and caters to both small and large enterprise solutions. I was able to deploy it globally in less than three months across fourteen different countries and over fifty thousand endpoints and employees.

    How are customer service and support?

    Customer support for Rapid7 is superb. Whenever I have confusion or issues, a quick email or phone call resolves the issue within fifteen minutes, and I have never had a problem getting the right answers.

    The transparency of Rapid7 in terms of gaining visibility into detections and investigations is wonderful, and the support I receive from the company has also been outstanding. During massive audits or when things are flagged that might become problematic in the future, I have had nothing but astounding support and transparency regarding the findings produced by Rapid7.

    Which solution did I use previously and why did I switch?

    I was part of the team long enough to see only the end of the previous solution, which revolved around RSA's Archer platforms, but I did not use it extensively.

    How was the initial setup?

    In my experience on the incident recovery team, though it has been less than six months, the tools provided by Rapid7 allow me to rapidly collect all necessary data, pulling everything from drives and RAM, and coalesce that into a report that helps me break down exactly what happened, when it happened, and who did it. I am taking advantage of the expanded ecosystem telemetry support, which has significantly improved my visibility and efficiency in correlation. It allows me to generate reports on the spot for executives, senior managers, and vice presidents, speeding up remediation techniques considerably.

    What about the implementation team?

    I unfortunately did not have the opportunity to attend discussions about pricing, setup costs, or licensing for Rapid7, so I do not have enough authority to comment on that.

    What was our ROI?

    Speaking from an information security officer's point of view about the return on investment, Rapid7 does not necessarily reduce the number of staff as I already operate lean. However, it does reduce the issues my company faces regarding compliance, laws, and potential lawsuits, which probably saves a significant amount of money, not to mention the time I save by fixing things faster, identifying issues quicker, and remediating them even more efficiently, ultimately freeing me up to conduct other tasks like forensic investigations or rebuilding the enterprise.

    Which other solutions did I evaluate?

    I am not sure if my team evaluated other options before choosing Rapid7. I imagine they might have, but I was not part of that decision-making group.

    What other advice do I have?

    If you are looking for a solution that will help identify vulnerabilities and provide remediation tips for hardening your infrastructure, I think Rapid7 does an excellent job. While I do not know the specifics of licensing costs, I imagine it is significantly less costly than a federal lawsuit.

    I find Rapid7's AI capabilities and governance to be very malleable, which is valuable to a lot of my teams. I can also lock it down and harden it, which I find very useful. The AI integration tool has been very helpful for simulations and for identifying the dependencies that software requires to operate correctly and the vulnerabilities in those dependencies.

    The accuracy and reliability of Rapid7 output are decent for an AI platform, but it does require double-checking the sources of information to ensure that the output is not misleading.

    I find the risk-aware detection features in Rapid7 extremely valuable. The fact that Rapid7 includes this on all platforms, whether on-prem or cloud or hybrid, offers great insight into what to look for, especially as it pertains to software in the healthcare industry, while also allowing me to widen the scope to a global level if needed.

    Currently, I am not utilizing the AI-assisted risk-aware investigation workflows as they are not enabled yet. This is pending an AI review board's approval to ensure usefulness and security. I gave this product a rating of nine out of ten.

    SohailHyder

    Unlimited scheduled scans have supported compliance goals but reporting customization still needs work

    Reviewed on Feb 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I usually recommend this solution for financial institutions. Banks and financial institutions need this solution mostly because they have to follow stringent compliance advisory requirements, so they must have this solution.

    What is most valuable?

    My team is working with this product because we are a service provider and have provided this service to our customers. From that perspective, I cannot go into detail on the feature sets if you are interested in knowing that. However, as far as I know, we are providing the service, and customers are satisfied with it because we are getting renewals.

    Customers use the product for scanning purposes and do not want to be restricted with respect to the number of scans they perform. The scanning can be scheduled daily, weekly, monthly, or whenever the need arises. This is a good feature that customers are getting.

    What needs improvement?

    Customers sometimes experience issues with performance. One thing that I recall is that most customers often want to have reporting as per their customized dashboard. This needs to be improved because although we guide them and let them know what they have to learn, some customers want to have some respect to their local environment. Some customers need help, support, or improvements in that platform if we can customize the reporting.

    For how long have I used the solution?

    I have been dealing with this solution for more than three to four years now.

    How are customer service and support?

    Regarding the pricing of Rapid7 InsightAppSec, I think it is reasonable because if a product is performing well, customers are happy to go with it even if it costs a little bit more. I have not received any complaints or issues regarding high price, so I would say it is acceptable.

    I would rate the technical support by Rapid7 from one to ten at about seven.

    Regarding the response time, I have to check with my respective team if they have any issues regarding that, but it has not been escalated. This means they are satisfied and are getting the response when the need arises for opening tickets or requesting support. The technical team responds, and sometimes we do that on behalf of our customers, so we get the response.

    What other advice do I have?

    I have not heard any complaints.

    I do not have any recommendations because customers were initially worried about the number of scans they used to perform, and now it has been enhanced or it will sometimes go to a maximum of unlimited number of scans they can do. This supports them, and I think that is acceptable. There is no such big issue here.

    I do not think we always go with Rapid7 InsightAppSec in our basket to any customer. Even if someone is not using it, we pitch the same product to them as well. This is how we work and operate.

    I would rate this review seven out of ten.

    Shritam Bhowmick

    Provides reliable applications security but needs better integration options

    Reviewed on Jun 13, 2025
    Review from a verified AWS customer

    What is our primary use case?

    Our main use case for Rapid7 InsightAppSec is to perform internal assessment of applications and external facing applications. We have a cloud engine plus on-premises engine, and we have been leveraging both to conduct our internal app sec and external web application security scanning.

    There are some areas for improvements regarding false positives. The integration capabilities are limited, as options for integrations with other tools such as SNOW, Jira, or other integration tools have been lacking in Rapid7 InsightAppSec. Rapid7 has InsightConnect for automation, but it has not been readily available to us. We would appreciate the ability to integrate with other tools, which is currently lacking in the Rapid7 InsightAppSec platform.

    We heavily rely on this platform to do our security work. We also use Security Scorecard, which is another vendor providing external security intelligence and external web application monitoring. We would appreciate if Rapid7 InsightAppSec could leverage its inbuilt functionalities and possibly integrate our own written tools.

    From the strong points, it provides very good scan coverage and has excellent cloud-based engine scanning capabilities. It has a user-friendly interface, though it can be glitchy sometimes. The platform currently does not support AI-driven capabilities. They have recently released AI integrations to detect LLM-based attacks, but it is not leveraging LLMs; it's merely detecting LLM attack scenarios.

    What is most valuable?

    The centralized dashboard feature is very important in Rapid7 InsightAppSec. As part of the red teaming, while vulnerability management is not the only thing I do, it's crucial to see the statistics. If one engine is failing, I would mobilize my internal team to address it properly. It's super important to analyze critical issues, running scans, their effectiveness, and accessible metrics; these details are easily available in the centralized dashboard.

    The flexibility in deployment options, including cloud native and on-prem, is very helpful for our infrastructure. We have Rapid7 AppSec installers, and when we attempt to leverage this platform for internal application scanning, the cloud engine cannot interact with our internal applications. This is why we need to depend on our own servers to install those installers from Rapid7 and use the on-premises feature.

    We are leveraging the reporting feature of Rapid7 InsightAppSec, and the reporting functionality is excellent. The only issue occurs when using the user interface and exporting files, as it sometimes doesn't work. The issue stems from browser settings where cookies interfere with the user interface. A support technician confirmed they are working on improving this aspect, as browsers' built-in capabilities interfere with their ability to import or export files. The reports themselves are accurate and very good, except where many entries may be false positives.

    What needs improvement?

    There are areas for improvements regarding false positives. Integration capabilities are lacking, as options for integrations with other tools such as SNOW, Jira, or other integration tools are not sufficient in Rapid7 InsightAppSec.

    The user interface sometimes has glitches, which may prevent appropriate results during navigation, and even when we get appropriate results, it can be impossible to export them to CSV records or download files.

    Regarding scalability, Rapid7 InsightAppSec is not a scalable solution for our industry due to limited integration capabilities. Rapid7 relies on another tool called InsightConnect, which requires additional investment, detracting from scalability.

    Another area that needs improvement is the integration of AI capabilities into the platform. Both Rapid7 InsightAppSec and InsightVM need to advance in that area.

    In terms of behavioral and pattern recognition, identifying complex attacks such as SQL, blind SQL, JSON, and LDAP injections often results in 94% false positives. This necessitates improvement in their behavioral-based analytics feature.

    What do I think about the stability of the solution?

    Regarding stability, there are no complaints as it works as it should, but the issue of false positives is significant. Stability is fine, but we have to question the false positives. If those false positives were eliminated, it would be good; however, stability in general is not a concern for us.

    What do I think about the scalability of the solution?

    Rapid7 InsightAppSec is not a scalable solution for our industry. Scalability will always factor in terms of integration possibilities. To scale something, you will always need the ability to integrate with other tools. At the moment, the integration capabilities are not very good, which is disappointing. Rapid7 tends to rely on another tool called InsightConnect for which you must spend more money, which detracts from scalability. If I had to rate scalability on a scale of one to ten, I would give it a four or five.

    How are customer service and support?

    I have a very good impression of Rapid7's technical support. They have provided excellent technical support, and they are responsive. However, they seem to struggle with their own methods of handling tickets. We have support both on call and for any issues that arise, and it is always timely. What I would suggest is that while the technicians understand the problems and accept them, they do not adequately integrate feedback into their products. Hundreds of feedback items have been submitted over the past three years without notable improvements being integrated or implemented, which is disappointing. Otherwise, the technical support itself is satisfactory.

    How would you rate customer service and support?

    How was the initial setup?

    The initial setup for Rapid7 InsightAppSec is very straightforward, and the installations have been seamless. That is why I have been recommending it; there were no errors or technical difficulties in the process. Anyone can easily set it up, provided they have appropriate and powerful servers. It truly boils down to your own infrastructure if you can deploy it correctly.

    For us, it took approximately 40 minutes to deploy. We did not use an integrator, reseller, or consultant for deployment because the documentation was so apt that we managed to set it up ourselves. Although we had various kinds of consultants available, we didn't need to leverage them since we had the knowledge to install it, and it was super easy.

    What other advice do I have?

    The behavior-based analytics feature in Rapid7 InsightAppSec has not been leveraged. From what I believe, it does not come out of the box within the Rapid7 InsightAppSec. The behavioral aspect appeared to focus on scanning, where blind SQL injections were mostly false positives that required manual tests to confirm.

    The pricing for Rapid7 is very expensive. We are paying $14 per asset for Rapid7 InsightVM and have 6,000 assets, which amounts to approximately $29,000. We've compared this with other tools such as Burp Suite's DAS platform, QualysGuard, and HP Fortify. Despite having E5 and E3 licenses that offer free access to Microsoft's Vulnerability Management dashboard, our significant investments in Rapid7 prevent us from switching.

    I would recommend Rapid7 InsightAppSec if you have a stable industry, not a hybrid one that relies on too many technologies. If you use different stacks in your technology, Rapid7 might not be the tool for you. It can be very efficient if you have a similar stack, such as a Linux environment or Windows environment, which is very specific to this profiling.

    On a scale of one to ten, I rate this solution a seven.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    SonNguyen3

    Benefit from accurate vulnerability detection and user-friendly reports for application security testing

    Reviewed on Apr 10, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I use Rapid7 InsightAppSec for dynamic application security testing. My main focus is on the quality of detection, specifically detecting vulnerabilities correctly. I also use it to provide neat reports, which my security team can use for validation. These reports are user-friendly, allowing us to open them and click 'validate' to check if the validation is accurate.

    What is most valuable?

    Rapid7 InsightAppSec is a good product for dynamic application security testing. It provides neat reports that include validation actions, and it helps to generate web application firewall rules for web applications. Additionally, the attack replay function is beneficial for security testing applications.

    What needs improvement?

    Currently, I do not see any specific areas for improvement except for possibly lowering the price.

    For how long have I used the solution?

    I have been working with Rapid7 InsightAppSec for six years.

    What do I think about the stability of the solution?

    I would rate the stability of Rapid7 InsightAppSec between eight or nine out of ten. It is a stable solution.

    What do I think about the scalability of the solution?

    Scalability is quite easy with Rapid7 InsightAppSec. It's easy to expand and accommodate more users or applications.

    How are customer service and support?

    The technical support from Rapid7 is not bad, but the response time can be quite slow sometimes. I would rate it a seven out of ten.

    How was the initial setup?

    The initial setup is quite simple because it is cloud-based, which makes onboarding applications on-premise not so complicated.

    What's my experience with pricing, setup cost, and licensing?

    The price could potentially be lower for users.

    Which other solutions did I evaluate?

    In the Vietnamese market for now, I could compare Rapid7 InsightAppSec to solutions from Microsoft, specifically Web Inspect.

    What other advice do I have?

    I have an idea for additional functions, but maybe in the future. I would recommend Rapid7 InsightAppSec because it offers some valuable features for customers, and I see the value it provides. My overall final rating for the product would be eight or nine out of ten.
    reviewer2677461

    Robust technical support and effective vulnerability remediation enhance security operations

    Reviewed on Mar 20, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Our primary use case for Rapid7 InsightAppSec is to scan for vulnerabilities on our APIs and UIs. We provide this service while being based at a client location, where we look after the Rapid7 InsightAppSec tool for them.

    What is most valuable?

    The most valuable feature of Rapid7 InsightAppSec is the remediation part, which we use the most. This aspect of the tool helps in addressing vulnerabilities effectively, making it one of the most utilized features in our operations.

    What needs improvement?

    There is room for improvement in Rapid7 InsightAppSec by giving clients the ability for extra columns on reports and enabling the extraction of remediation reports into a CSV format. Currently, the PDF format is cumbersome to go through when dealing with thousands of pages.

    For how long have I used the solution?

    I have approximately two years of experience working with this tool.

    What do I think about the stability of the solution?

    On a scale from one to ten, I would rate the stability of the solution at nine.

    What do I think about the scalability of the solution?

    On a scale from one to ten, the scalability of this solution is rated a nine.

    How are customer service and support?

    I would rate the technical support from Rapid7 a ten, indicating high-quality support.

    How was the initial setup?

    The initial setup of this tool is straightforward.

    What's my experience with pricing, setup cost, and licensing?

    The price of this solution is fair.

    What other advice do I have?

    Based on my experience, I would recommend Rapid7 InsightAppSec to other people. It's a fantastic solution when it works up to your capabilities. I would rate this tool overall at eight on a scale from one to ten.
    View all reviews