CLAIM #66330 · Rapid7 Inc (RPD) · 2026Q1 earnings call · May 5, 2026 · due May 5, 2027
“The team is executing with urgency. The operating discipline is taking hold, and the work we are doing this year sets up share gains we expect to deliver over the medium term.”
Corey Thomas · CEO
In context
“Corey Thomas (Chief Executive Officer): Thank you, Matt, and welcome to everyone joining Rapid7, Inc.'s first quarter 2026 earnings call. Let me start by sharing insights from the influx of conversations we have been having with customers as they navigate the rapidly evolving cyber landscape. CIOs and CISOs are telling us the same thing in different ways. Advances from frontier models have fundamentally accelerated the threat environment and outpaced operating models built to defend against it. Vulnerabilities can now be discovered and exploited autonomously, and attackers are moving at machine speed. This fundamentally rewrites the value equation in security. The premium is no longer on detecting threats faster after they emerge; it shifts to preemptive exposure management, autonomous detection, and remediation at scale, closing the windows attackers exploit before they can be exploited at all. This is precisely the environment that plays to our strengths, and that is why our investments in the AI SOC and preemptive security operations are resonating so strongly with customers. The shift we are enabling from reactive to preemptive, from human scale to machine scale, is not a marketing reframe. It is the only viable path forward for teams that need to anticipate where attackers will move next, prioritize the exposures that actually matter, and respond at the speed of modern attacks. Customers are looking for a partner who can unify their data, apply AI with the right context, drive remediation at scale, and translate all of it into measurable outcomes. That is exactly where we are focused. The core platform we are building across detection and response and exposure management is becoming the foundation customers turn to as they modernize for this new threat reality. By unifying exposure and inspection on the Command platform, and combining AI-driven operations with the depth of expertise that we have built over 25 years, we are giving customers a single, coherent way to reduce risk, disrupt attackers, and build durable cyber resilience. The opportunity in front of us has never been clearer, and our conviction in this strategy has never been higher. Turning to the first quarter, I am pleased to report that Rapid7, Inc. delivered outperformance against all guided metrics. ARR of $832 million and revenue of $210 million were driven by sustained growth in our detection and response business, offset by trends in other parts of our business, particularly our non-core standalone offerings. Non-GAAP operating income of $24 million exceeded our guidance and helped drive strong free cash flow of $33 million. Our quarterly results reflect a greater focus on balancing strategic investment and driving scale in the business. In detection and response, ARR growth of approximately 7% was driven by strength in our MDR business. Our approach to delivering AI-enabled SOC, combined with deep services expertise, continues to receive strong market validation, and this quarter we added a new Fortune 500 customer in a seven-figure ARR deal. In exposure management, we will continue to simplify the migration process of upgrading our large vulnerability management base into the Exposure Command platform. Our approach to a unified AI-driven exposure platform continues to resonate with new and existing customers. In this quarter, a large Fortune 500 customer consolidated on Rapid7 as their exposure platform of choice in a competitive deal cycle. In the quarter, we acquired Kenzo Security, an agentic platform built to run security operations autonomously and at machine speed. This is a direct accelerant to our AI SOC vision. Data mesh shifts customers away from a per-alert investigation model to a system-driven one. Coverage scales with the environment, not headcount. This unlocks two things: a meaningful tailwind for MDR growth and a path to higher contribution margins through software-driven efficiency. Most importantly, Kenzo opens the door to the full MDR market. Rapid7 is evolving into a preemptive, agentic security platform that accelerates the entire SOC, delivered either as a managed service or a self-managed platform. By combining deep MDR expertise with exposure-driven visibility into vulnerabilities and attacker behavior, Rapid7 enables organizations to detect, investigate, and stop threats earlier. We also continue to innovate on our Exposure Command platform, delivering two major capabilities: runtime validation for cloud environments and data security posture management to strengthen proactive exposure reduction across hybrid environments. In plain terms, we no longer just tell customers what their vulnerabilities are. We tell them which ones are actively being exploited in their environment. Runtime validation determines what attackers can actually reach in production, and DSPM maps where the high-value data lives and who has access to it. Together, they collapse the noise and surface the small set of exposures that actually matter. These steps accelerate the playbook we shared with you in February: strategically investing in our AI-enabled SOC to deliver preemptive security infrastructure while also deploying expert talent towards high-value customer engagements that AI cannot replicate. Turning to customer wins in the quarter, Rapid7 continues to be the partner of choice for global organizations securing complex on-prem, cloud, and hybrid environments. The go-to-market changes Alan, our Chief Commercial Officer, put in place at the start of the year are beginning to bear fruit. We are running a sharper, more focused organization, and productivity has improved. While it is still early, the operating discipline we committed to in February is beginning to take hold, and we believe that as an organization we can continue to drive efficiencies over the middle term. In this quarter alone, a Fortune 500 mining company with global operations selected Rapid7 as its MDR provider of choice in a seven-figure deal. This was a long, competitive sales cycle in which our SIEM and detection and response capabilities stood out to their security leaders. Rapid7's history managing cloud, hybrid, and on-prem environments and strong technical knowledge helped cement this decision. After years of only covering a portion of its environment, a global Fortune 500 aviation manufacturer expanded with Rapid7 as their preferred global exposure management provider in a large six-figure deal. Capabilities of our Command platform combined with our in-house technical talent were resonant points during the expansion process. And lastly, a leading health services provider selected Rapid7 as their MDR provider of choice in a large six-figure deal. Previously, subsidiaries of the organization used disparate tools and lacked unified coverage. Rapid7's ability to address challenges at a regional and local level, in addition to unified coverage across ecosystems, stood out to security leaders at the organization. Now, before I pass the call to Rafe, I want to dive deeper into the implications that the unprecedented shift to frontier models brings to the security landscape. I want to be clear that this market shift is a long-term tailwind for us, not a threat. Vulnerability discovery has been accelerating and commoditizing for years, driven by advances in AI coding and reasoning, and frontier models like Anthropic’s Methos and Google’s Big Sleep have made that trajectory undeniable. Methos surfaced more than 2,000 previously unknown vulnerabilities in seven weeks. That is a new baseline. But here is the part of the story that headlines miss. Methos commoditized vulnerability identification—finding bugs in code. It does not commoditize the operational reality of managing those vulnerabilities across complex enterprise environments. It does not commoditize detection and response. It does not commoditize exposure management. If anything, it makes it all the more essential because the volume and velocity of findings every enterprise has to act on is about to increase dramatically. The value is migrating in three directions, and Rapid7 is at the intersection of each trend. First, remediation at scale. The Command platform provides the granular visibility and tracking required to manage thousands of findings across hybrid environments. Combined with our SOAR capabilities and Kenzo’s agentic AI, we are moving from traditional patch management towards AI-native remediation—identifying flaws and deploying fixes autonomously. Second, detection and response. A faster discovery cycle on the attacker side means a faster response cycle on the defender side. Kenzo accelerates our MDR service from AI-assisted workflows to autonomous, machine-speed investigation. Detection is no longer the bottleneck; it becomes a precursor to near-instantaneous response. And third, preemptive exposure management. Our March releases of runtime validation and data security posture management move Exposure Command from continuous assessment to continuous validation, telling customers which exposures are actually exploitable in their environment against their sensitive data, given their identity surface. This is the shift the market is describing, and it is the shift that Rapid7 has been building toward. More vulnerabilities found means more demand for an operational platform that turns findings into outcomes. To close, this is a moment of real change in our industry. We have the data foundation. We now have a step-change AI capability accelerated by Kenzo. And we have the expertise customers do not get from a model alone. The team is executing with urgency. The operating discipline is taking hold, and the work we are doing this year sets up share gains we expect to deliver over the medium term. With that, I would like to pass the call to Rafe to discuss Q1 results in more detail and our updated 2026 guidance. Rafe, over to you.”
Verify independently
SEC filings for RPD ↗ · Claim quote is verbatim from the 2026Q1 earnings call.