This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

Rapid7, Inc.
5/5/2026
Good day, everyone. My name is Kahe Alani, and I'll be your conference operator today. At this time, I would like to welcome you to the Q1 2026 Rapid7 earnings call. All lines have been placed on mute to prevent any background noise. After the speaker's remarks, there will be a question and answer session. If you would like to ask a question during this time, and if you have joined via the webinar, please use the raise hand icon, which can be found at the bottom of your webinar application. At this time, I would like to turn the call over to Matt Wells, Vice President of Investor Relations.
Thank you, Operator, and good afternoon, everyone. We appreciate you joining us. Today, we will be discussing Rapid7's first quarter fiscal 2026 financial results. We've distributed our earnings press release over the wire, and it can be accessed on our investor relations website. With me on the call today are Corey Thomas, our CEO, and Rafe Brown, our CFO. As a reminder, all participants are in a listen-only mode, and a question-and-answer session will follow our opening remarks. Before I hand the call over to Corey, I want to note that certain statements made during this conference call may be considered forward-looking under federal securities laws. Such statements are made pursuant to the safe harbor provisions of the Private Securities Litigation Reform Act of 1995 and include our outlook for the second quarter and fiscal year 2026, any assumptions for fiscal periods beyond that period, and our positioning, strategy, business plan, operational improvements, and growth drivers. These forward-looking statements are based on our current expectations and beliefs and information currently available to us. While we believe any forward-looking statements we make are reasonable, actual results could differ materially due to a number of risks and uncertainties, including those contained in our filings with the SEC. Reported results should not be considered as indicative of future performance. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events, or otherwise, except to the extent required by applicable law. Further information on these forward-looking statements and risk factors are included in the filings we make with the SEC, including the section titled Cautionary Language Concerning Forward-Looking Statements in our earnings press release. Additionally, over the course of this call, we'll reference non-GAAP measures to describe our performance. Please review our earnings press release and filings with the SEC for a rationale behind the use of non-GAAP measures and for a full reconciliation of these GAAP to non-GAAP metrics. These documents, in addition to a replay of this call, will be available on the Rapid7 Investor Relations website. And with that, I'd like to turn the call over to Corey.
Thank you, Matt, and welcome to everyone joining Rapid7's first quarter 2026 earnings call. Let me start by sharing insights from the influx of conversations we've been having with customers as they navigate the rapidly evolving cyber landscape. CIOs and CISOs are telling us the same thing in different ways. Advances from frontier models have fundamentally accelerated the threat environment and outpaced operating models built to defend against it. Vulnerabilities can now be discovered and exploited autonomously, and attackers are moving at machine speed. This fundamentally rewrites the value equation in security. The premium is no longer on detecting threats faster after they emerge. It shifts to preemptive exposure management, autonomous detection, and remediation at scale, closing the windows attackers exploit before they can be exploited at all. This is precisely the environment that plays to our strengths. And that's why our investments in the AI SOC and preemptive security operations are resonating so strongly with customers. The shift we're enabling from reactive to preemptive, from human scale to machine scale, is not a marketing reframe. It's the only viable path forward for teams that need to anticipate where attackers will move next, prioritize the exposures that actually matter, and respond at the speed of modern attacks. Customers are looking for a partner who can unify their data, apply AI with the right context, drive remediation and scale, and translate all of it into measurable outcomes. That is exactly where we are focused. The core platform we're building across detection response and exposure management is becoming the foundation customers turn to as they modernize for this new threat reality. By unifying exposure and inspection on the command platform and combining AI-driven operations with the depth of expertise that we've built over 25 years, we're giving customers a single, coherent way to reduce risk, disrupt attackers, and build durable cyber resilience. The opportunity in front of us has never been clearer, and our conviction in this strategy has never been higher. Turning to the first quarter, I am pleased to report that Rapid7 delivered outperformance against all guided metrics. ARR of $832 million and revenue of $210 million were driven by sustained growth in our detection response business, offset by trends in other parts of our business, particularly our non-core standalone offerings. Non-GAAP operating income of $24 million exceeded our guidance and helped drive strong free cash flow of $33 million. Our quarterly results reflect a greater focus on balancing strategic investment and driving scale in the business. In detection response, ARR growth of approximately 7% was driven by strength in MDR business. Our approach to delivering AI-enabled SOC combined with deep services expertise continues to receive strong market validation. In this quarter, we added a new Fortune 500 customer and a seven-figure ARR deal. In exposure management, we'll continue to simplify the migration process of upgrading our large vulnerability management base into the exposure command platform. Our approach to a unified AI-driven exposure platform continues to resonate with new and existing customers. In this quarter, a large Fortune 500 customer consolidated on Rapid7 as their exposure platform of choice in a competitive deal cycle. In the quarter, we acquired Kenzo Security, an agentic platform built to run security operations autonomously and at machine speed. This is a direct accelerant to our AI stock vision. Kenjo's data mesh shifts customers away from a per alert investigation model to a system-driven one. Coverage scales with the environment, not headcount. This unlocks two things, a meaningful tailwind for MDR growth and a path to higher contribution margins through software-driven efficiency. Most importantly, Kenzo opens the door to the full MDR market. Rapid7 is evolving into a preemptive agentic security platform that accelerates the entire SOC, delivered either as a managed service or a self-managed platform. By combining deep MDR expertise with exposure-driven visibility into vulnerabilities and attacker behavior, Rapid7 enables organizations to detect, investigate, and stop threats earlier. We also continue to innovate on our exposure command platform, delivering two major capabilities, runtime validation for cloud environments and data security posture management to strengthen proactive exposure reduction across hybrid environments. In plain terms, we no longer just tell customers what their vulnerabilities are. We tell them which ones are actively being exploited in their environment. Runtime validation determines what attackers can actually reach in production. And DSPM maps where the high-value data lives and who has access to it. Together, they collapse the noise and surface to the small set of exposures that actually matter. These steps accelerate the playbook we shared with you in February. Strategically investing in our AI-enabled SOC to deliver preemptive security infrastructure, while also deploying expert talent towards high-value customer engagements that AI cannot replicate. Turning to customer wins in the quarter. Rapid7 continues to be the partner of choice for global organizations securing complex on-prem, cloud, and hybrid environments. The go-to-market changes Allen, our chief commercial officer, put in place at the start of the year are beginning to bear fruit. We are running a sharper, more focused organization, and productivity has improved. While it's still early, the operating discipline we're committed to in February is beginning to take hold, and we believe that as an organization, we can continue to drive efficiencies over the middle term. In this quarter alone, a Fortune 500 mining company with global operations selected Rapid7 as its MDR provider of choice in a seven-figure deal. This was a long, competitive sales cycle in which our SIEM and detection response capabilities stood out to their security leaders. Rapid7's history managing cloud, hybrid, and on-prem environments and strong technical knowledge helped cement this decision. After years of only covering a portion of its environment, a global Fortune 500 aviation manufacturer expanded with Rapid7 as their preferred global exposure management provider in a large six-figure deal. The capabilities of our command platform combined with our in-house technical talent were resonant points during the expansion process. And lastly, a leading health services provider selected Rapid7 as their MBR provider of choice in a large six-figure deal. Previously, subsidiaries of the organization used disparate tools and lacked unified coverage. Rapid7's ability to address challenges at a regional and local level, in addition to a unified coverage across ecosystems, stood out to security leaders at the organization. Now, before I pass the call to Rafe, I want to dive deeper into implications of the unprecedented shift front-tier models bring to the security landscape. And I want to be clear that this market shift is a long-term tailwind for us, not a threat. Vulnerability discovery has been accelerating and commoditizing for years, driven by advances in AI coding and reasoning, and frontier models like Anthropix's Mythos and Google's Big Sleep have made that trajectory undeniable. Mythos surfaced more than 2,000 previously unknown vulnerabilities in seven weeks. That is a new baseline. But here's the part of the stories that headlines miss. Mythos commoditized vulnerability identification. finding bugs in code. It does not commoditize the operational reality of managing those vulnerabilities across complex enterprise environments. It does not commoditize detection and response. It does not commoditize exposure management. If anything, it makes it all the more essential because the volume and velocity of findings every enterprise has to act on is about to increase dramatically. The value is migrating in three directions, and RAPID-7 is at the intersection of each trend. First, remediation at scale. The command platform provides the granular visibility and tracking required to manage thousands of filings across hybrid environments. Combined with our SOAR capabilities and Kenzo's agentic AI, we are moving from traditional patch management towards AI-native remediation, identifying flaws and deploying fixes autonomously. Second, detection response. A faster discovery cycle on the attacker side means a faster response cycle on the defender side. Kinzo accelerates our MDR service from AI-assisted workflows to autonomous machine speed investigation. Detection is no longer the bottleneck. It becomes a precursor to near instantaneous response. And third, preemptive exposure management. Our March releases of runtime validation and data security posture management move exposure command from continuous assessment to continuous validation, telling customers which exposures are actually exploitable in their environment against their sensitive data, given their identity surface. This is the shift the market is describing. It is the shift that Rapid7 has been building toward. More vulnerabilities found means more demand for operational platform that turns findings into outcomes. To close, this is the moment of real change in our industry. We have the data foundation. We now have a step change AI capability accelerated by Kenzo. And we have the expertise customers do not get from a model alone. The team is executing with urgency. The operating discipline is taking hold, and the work we're doing this year sets up share gains we expect to deliver over the medium term. With that, I'd like to pass the call to Rafe to discuss Q1 results in more detail and our updated 2026 guidance. Rafe, over to you.
You're reading a preview of the RPD Q1 2026 earnings call.
Free account.