{
 "categories": [
  "devsecops",
  "enterprise"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-10-08",
   "fact": "homepage",
   "note": "Rapid7 presents a commercial cybersecurity platform that includes vulnerability management, exposure management, and managed detection.",
   "source": "https://www.rapid7.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "license",
   "note": "The homepage describes managed and platform cybersecurity services. It does not document a free product tier.",
   "source": "https://www.rapid7.com/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.exists",
   "note": "Rapid7 documents a Bulk Export API that creates exports of policies, vulnerabilities, assets, and remediations.",
   "source": "https://docs.rapid7.com/insightvm/bulk-export-api/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.kinds[0]",
   "note": "Export requests are GraphQL mutations and queries posted to a regional /export/graphql URI.",
   "source": "https://docs.rapid7.com/insightvm/bulk-export-api/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.auth[0]",
   "note": "Every request sends the platform API key in the X-Api-Key header. The key must be an Organization key or a user key created with Platform Administrator permissions.",
   "source": "https://docs.rapid7.com/insightvm/bulk-export-api/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.api.coverage",
   "note": "The opened page covers bulk export of policies, vulnerabilities, assets, and remediations to Parquet. It does not document the rest of the Insight console.",
   "source": "https://docs.rapid7.com/insightvm/bulk-export-api/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.mcp.first_party",
   "note": "The rapid7/rapid7-bulk-export-mcp README describes a Rapid7 MCP server that exports Command Platform data through the Bulk Export API into local DuckDB.",
   "source": "https://github.com/rapid7/rapid7-bulk-export-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.mcp.verdict",
   "note": "The server is published from Rapid7's GitHub repository. The README says support is best effort.",
   "source": "https://github.com/rapid7/rapid7-bulk-export-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.data_access.export[0]",
   "note": "Successful exports return download URLs for Parquet files. URLs last 15 minutes and files are retained for 30 days.",
   "source": "https://docs.rapid7.com/insightvm/bulk-export-api/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Opened https://www.rapid7.com/llms.txt. It is a plain-text index of the Rapid7 website, not the Bulk Export API reference.",
   "source": "https://www.rapid7.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "verdict.scores.api",
   "note": "The GraphQL export is documented and useful for vulnerability and asset data, with an admin key, daily refresh, Parquet files, and short-lived download URLs. That is a production path with material limits, scored 6.",
   "source": "https://docs.rapid7.com/insightvm/bulk-export-api/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "verdict.scores.mcp",
   "note": "The official server queries local copies of bulk exports. Rapid7 calls support best effort, so the path is narrow and unsupported beyond the repository, scored 4.",
   "source": "https://github.com/rapid7/rapid7-bulk-export-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "freshness.watch[0].url",
   "note": "Opened the Bulk Export API page, including GraphQL mutations, X-Api-Key, regions, and Parquet download rules.",
   "source": "https://docs.rapid7.com/insightvm/bulk-export-api/",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "freshness.watch[1].url",
   "note": "Opened the Rapid7 bulk-export MCP README, including the best-effort support statement and the API-key requirement.",
   "source": "https://github.com/rapid7/rapid7-bulk-export-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-08",
   "fact": "freshness.watch[2].url",
   "note": "Opened the Rapid7 website llms.txt index.",
   "source": "https://www.rapid7.com/llms.txt",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-08",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://docs.rapid7.com/insightvm/bulk-export-api/"
   },
   {
    "type": "mcp",
    "url": "https://github.com/rapid7/rapid7-bulk-export-mcp"
   },
   {
    "type": "docs",
    "url": "https://www.rapid7.com/llms.txt"
   }
  ]
 },
 "homepage": "https://www.rapid7.com/",
 "id": "rapid7",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "api-key"
   ],
   "coverage": "partial",
   "docs": "https://docs.rapid7.com/insightvm/bulk-export-api/",
   "exists": true,
   "kinds": [
    "graphql"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "parquet"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. The opened automation surface is the Bulk Export API and a local MCP server that queries those exports.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Rapid7 Command Platform",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "tenable-one"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Rapid7",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 6,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 4,
   "overall": 6,
   "rpa": null
  },
  "summary": "Rapid7 Command Platform vulnerability and asset data is automatable today through the Bulk Export API. This record is that export surface and the Rapid7 MCP server that loads it. It is not Tenable, and it does not cover every Insight module. The API is GraphQL. Calls send the platform API key in the X-Api-Key header. The key must be an Organization key or a user key with Platform Administrator permissions. Regional endpoints include https://us.api.insight.rapid7.com/export/graphql, https://eu.api.insight.rapid7.com/export/graphql, and hosts for Canada, Australia, Japan, and additional United States regions. Mutations create policy, vulnerability, and remediation exports. Results are Parquet files. Download URLs last 15 minutes and can be regenerated for 30 days. Files are retained for 30 days. Data refreshes once a day, and overuse can be throttled. A remediation export date range must be after August 2025, must not be a single day, and must be at most 31 days. Rapid7 publishes github.com/rapid7/rapid7-bulk-export-mcp, which loads those exports into a local DuckDB database for agent queries. The README says support is best effort. A language SDK, a CLI, and connector catalogs were not opened. https://www.rapid7.com/llms.txt is a plain-text index of the marketing site. Computer-use viability is unassessed. The Bulk Export API scores 6 and is the best path. The MCP server scores 4.\n"
 }
}