Rapid7 has taken InsightVM's scanner and wrapped it in Exposure Command — attack surface visibility, cloud and application risk, and third-party enrichment in one console. VulnTrek starts from the opposite end: it owns no scanner, no agent and no attack-surface sensor, and exists purely to adjudicate the findings your existing tools already produce, including Rapid7's.
This is a direct comparison written by the VulnTrek team. We say where Rapid7 has genuine strengths — including the places where they do something we also do, and do it across a wider integration estate — and where we think VulnTrek is the stronger fit. Where we could not confirm a capability from Rapid7's public pages, the table says “Not documented” rather than claiming the capability is absent.
Rapid7 capability statements on this page are drawn from rapid7.com product and solution pages and the Exposure Command documentation, checked on 15 September 2026. Vendor pages change; verify current claims, packaging and licensing with Rapid7 directly before a procurement decision.
At a glance
Core positioning
VulnTrek: Unified Exposure Management & Security Assurance Platform: explainable prioritisation, governed remediation, immutable audit evidence. Vendor-neutral by design.
Rapid7: Command Platform with Exposure Command, positioned as hybrid exposure management — attack surface visibility plus vulnerability, cloud and application risk in one platform.
Scanning and sensors
VulnTrek: None. VulnTrek never scans your estate; it consumes findings from the scanners, agents and services you already run.
Rapid7: First-party detection across the portfolio: the InsightVM scanner and Insight Agent, Surface Command external and internal discovery, cloud security and application testing.
Third-party connectors
VulnTrek: 55+, depth-first — every source normalised to one canonical finding schema, with no first-party sensor to favour.
Rapid7: More than 450 out-of-the-box integrations with security and IT operations tools are documented, including third-party exposure and enrichment sources feeding Exposure Command.
Deduplication and correlation
VulnTrek: Intake-first semantic deduplication: 94% accuracy on a labeled set of 2,000 findings across Nessus, Qualys and Burp, reversible and audited.
Rapid7: Findings from native and third-party sources are aggregated into one asset inventory and risk model with asset enrichment; a published cross-vendor deduplication accuracy figure is not documented.
AI agents
VulnTrek: Netra plus eight named, purpose-scoped agents bound to AEDE stages; every external change needs human approval.
Rapid7: AI-driven insight across the Command Platform and AI-powered remediation guidance within Exposure Command; a published inventory of named, individually scoped agents is not documented.
Risk scoring
VulnTrek: VulnTrek Risk Index (VRI), fully decomposable: CVSS, EPSS, CISA KEV status, graded internet exposure, asset and business context, plus modelled annualised loss expectancy in EUR.
Rapid7: Adversary-aware prioritisation using exploit likelihood, reachability, severity and business context, with a risk score highlighting toxic combinations across the attack surface.
Attack path and reachability analysis
VulnTrek: Graded internet exposure and asset context feed the risk index; VulnTrek does not compute attack paths from its own telemetry because it collects none.
Rapid7: Reachability and toxic-combination analysis across cloud, network and application risk, combining an external attacker view with internal scan data.
Financial risk quantification
VulnTrek: Yes — modelled annualised loss expectancy and breach likelihood in EUR.
Rapid7: Business context is documented as an input to risk scoring; a monetary quantification of exposure in currency terms is not documented on public pages.
OT and ICS coverage
VulnTrek: Safety-aware scoring that respects process criticality, mapped to IEC 62443 and NIST SP 800-82, applied to OT findings from the tools you already run.
Rapid7: Hybrid estate coverage across on-premise, cloud and application assets; safety or process-criticality scoring specific to industrial control systems is not documented.
Remediation execution
VulnTrek: Governed remediation: agents prepare the change, policy governs it, a human approves every external action, and the ledger records it. VulnTrek does not patch systems itself.
Rapid7: Built-in remediation workflows with AI-powered guidance, ticketing and no-code automation, including automated alerting when policy drift occurs.
Compliance evidence
VulnTrek: Pramana Ledger: append-only evidence chain with actor attribution, mapped to ISO 27001, NIS2, DORA, CRA and the EU AI Act. Mappings are presentation-only and never change severity, deadlines or history.
Rapid7: Compliance posture enforcement across a hybrid environment, discovering assets missing required controls and alerting on drift; specific EU framework mappings such as NIS2, DORA and the CRA are not documented on public pages.
Application security posture
VulnTrek: Decision coverage without running the scanners — VulnTrek adjudicates AppSec findings but is not a build gate replacement.
Rapid7: Application security testing and infrastructure-as-code scanning are included in the higher Exposure Command tier and feed the same risk model.
Free public threat intelligence
VulnTrek: Yes — daily CISA KEV mirror, EU Vulnerability Database, IT and OT advisories, per-CVE pages and a hosted MCP server, no signup.
Rapid7: Extensive free public research, including long-running open-source security tooling and published vulnerability analyses; a free machine-readable exposure API for non-customers is not documented.
Packaging
VulnTrek: One platform with modules enabled per tenant; the decision layer, history and evidence chain are not tiered away.
Rapid7: Tiered packages — Exposure Command Essentials for attack surface and vulnerability management, Ultimate adding cloud, application security, IaC scanning and least-privilege management.
Primary market focus
VulnTrek: EU-regulated enterprises, converged IT/OT estates, and teams that must defend every exposure decision to an auditor or regulator.
Rapid7: Broad global market across mid-market and enterprise security operations, with a large partner and managed-service ecosystem.
AI governance model
VulnTrek: Published and explicit: agents recommend, policy governs, humans approve every external change, evidence remains. Kill switch, daily caps, allow-listed non-mutating actions, append-only action ledger.
Rapid7: AI-driven insight and AI-powered remediation guidance are documented as product capabilities; a published refusal boundary for AI-initiated actions is not documented.
Where VulnTrek has a genuine advantage
Vendor-neutral adjudication over the tools you already bought
Exposure Command is at its strongest when Rapid7's own telemetry supplies most of your findings — their own wording pairs native detection with third-party enrichment. Most enterprises run several scanners, a cloud security tool, an EASM service and a pentest programme. VulnTrek normalises every one of those to a single canonical finding schema — Rapid7 output included — and adjudicates them with no preference for whose sensor produced them.
Deduplication measured across vendors, and published
Overlap between two scanners from different vendors is where backlogs quietly double. VulnTrek deduplicates at intake with 94% accuracy on a labeled set of 2,000 findings across Nessus, Qualys and Burp, and every merge is reversible and recorded. We publish that number because it is the one that decides whether a mixed-tool estate gets smaller or louder.
EU regulatory evidence as an output, not a report
If you fall under NIS2, DORA, CRA or the EU AI Act, the Pramana Ledger records every prioritisation decision, override, exception and remediation action with actor attribution and timestamp, append-only. Evidence is a continuous chain of custody rather than a compliance dashboard you screenshot before an audit.
Scoring you can take apart in front of a regulator
The VulnTrek Risk Index is fully decomposable: every score exposes the weight of CVSS, EPSS, CISA KEV status, graded internet exposure, asset and business context, and the modelled annualised loss expectancy in EUR. Nothing depends on vendor-proprietary telemetry, so a CISO can defend any prioritisation without the vendor in the room.
Exposure expressed in euros, not just in ranking
Rapid7 documents business context as an input to prioritisation; monetary quantification is not documented on their public pages. VulnTrek models annualised loss expectancy and breach likelihood in EUR, which is the form a board or a risk committee can actually compare against other spending decisions.
OT findings treated as safety decisions
VulnTrek applies safety-aware scoring that respects process criticality and maps controls to IEC 62443 and NIST SP 800-82. Rapid7 covers hybrid estates broadly; industrial safety-specific scoring is not documented. In a converged estate that distinction changes which findings you are allowed to act on during production hours.
A published refusal boundary, not an automation promise
We publish what our agents will never do: no autonomous patching, no firewall or IAM mutation, no unapproved commits, no self-approval, no cross-tenant data use, no inline LLM gateway. The guardrail contract is enforced in code and auditable. Where you must demonstrate AI oversight to an auditor, that documentation is itself the deliverable.
No scanner lock-in and no agent to roll out
Because VulnTrek assesses nothing, changing scanner does not change your platform and there is no endpoint agent to deploy or maintain. You can replace a scanner, add a second for coverage, or run a pentest supplier alongside both, and the decision layer, history and evidence chain stay intact.
The decision layer is not tiered away
Rapid7 splits attack surface, cloud, application security and least-privilege capabilities across Essentials and Ultimate packages. VulnTrek enables modules per tenant, but prioritisation, governed remediation and the evidence ledger are the platform itself rather than an upgrade path.
Free threat intelligence with no funnel attached
We mirror CISA KEV, the EU Vulnerability Database and IT/OT vendor advisories daily, and publish per-CVE exploit context plus a hosted MCP server with no signup, no API key and no rate-limited trial.
Frequently Asked Questions
Does VulnTrek replace Rapid7?
No. VulnTrek runs no scanners, no agent and no attack surface discovery, so it cannot replace Exposure Command or InsightVM. The two sit at different layers: Rapid7 finds exposures and drives remediation workflow, VulnTrek decides which findings matter across every source you have and records why. Most VulnTrek customers keep their scanners, Rapid7 included, and connect them.
Can VulnTrek ingest Rapid7 or InsightVM findings?
Yes. InsightVM output is one of the sources VulnTrek normalises to its canonical finding schema, alongside other scanners, cloud security tools, EASM services and pentest reports, so a Rapid7 finding and a finding from another vendor about the same weakness on the same asset collapse into one adjudicated decision.
How does Rapid7's adversary-aware prioritisation compare with the VulnTrek Risk Index?
Rapid7 prioritises using exploit likelihood, reachability, severity and business context, with reachability derived from their own internal and external telemetry — something we cannot do, because we collect none. The VulnTrek Risk Index is fully decomposable instead: every score exposes the weight of CVSS, EPSS, CISA KEV status, graded internet exposure, asset and business context, plus modelled annualised loss expectancy in EUR, and can be reproduced and challenged without our involvement.
Rapid7 documents 450+ integrations and VulnTrek has 55+. Why should I consider the smaller number?
Because the two counts measure different things. Rapid7's number covers security and IT operations tooling across a broad platform. Ours counts finding sources normalised into one canonical schema with deduplication, provenance and evidence attached to each one. If your requirement is a long tail of ITOps systems already wired up, Rapid7 covers more ground. If it is defensible adjudication across the finding sources you actually run, depth matters more than breadth.
Which platform is better for NIS2, DORA and CRA evidence?
VulnTrek. The Pramana Ledger provides an append-only evidence chain with control mapping to NIS2, DORA, CRA, the EU AI Act and ISO 27001, and records every decision, override, exception and remediation action with actor attribution. Rapid7 documents compliance posture enforcement and drift alerting across hybrid environments, but specific EU framework mappings are not documented on their public pages.
Which platform is better for OT and ICS environments?
It depends which half of the problem you have. Rapid7 covers hybrid estates spanning on-premise, cloud and application assets. VulnTrek applies safety-aware scoring that respects process criticality, aligned to IEC 62443 and NIST SP 800-82, to OT findings from whichever tools produce them — but it does not discover OT assets. In a converged estate the two are complementary rather than competing.
Rapid7 offers AI-powered remediation guidance. How is VulnTrek's governed agentic AI different?
The difference is the boundary, not the intelligence. VulnTrek's agents are purpose-scoped, their actions are allow-listed and non-mutating, and every external change requires a named human approval that lands in an append-only ledger — with a kill switch, daily caps and a published refusal boundary. We never patch systems, mutate firewall or IAM configuration, commit code or self-approve. Rapid7 documents AI-driven insight and AI-powered remediation guidance; a published refusal boundary for AI-initiated actions is not documented.
How can I try VulnTrek?
Onboarding is founder-led and typically takes two to three weeks from first conversation to a working tenant — start at the contact page. You can also use the free threat intelligence surfaces immediately, with no signup: the live threat intelligence explorer, the per-CVE exploit pages and the hosted MCP server.