If you are looking for a Rapid7 InsightVM alternative, or a Nexpose alternative that runs on your own servers, check one condition first: SITEY is not a like-for-like replacement for the Rapid7 scan engine. For vulnerability scanning it works with a scanner you run. It launches scans directly in Nessus and OpenVAS, and it imports results from 16 scanner families, Nexpose among them. What SITEY adds is everything after the scan: deduplication, AI triage, a fix script written for the specific host, an approval gate, and a retest before the finding is closed. Below: what that costs next to InsightVM, where Rapid7 is still the better choice, and what SITEY does not do.
The condition to check first: you bring the scanner
With InsightVM, scanning is part of what you buy. With SITEY, it is not. If you leave Rapid7 entirely, you need Nessus or OpenVAS for SITEY to launch scans itself, or another supported tool whose reports you upload. If you keep Nexpose as your scanner, SITEY sits on top of it and imports its exports. SITEY’s price does not include a scanner license, so choosing Nessus means a separate purchase from Tenable.
Every finding lands in one schema with one severity scale, whichever of these tools produced it. Details are on the scanner integrations module.
InsightVM pricing next to SITEY, including where SITEY costs more
Rapid7 lists InsightVM on AWS Marketplace, in a listing sold as SaaS, with a public price for up to 128 assets. SITEY publishes two fixed prices. Here they are side by side.
| SITEY | Rapid7 InsightVM | |
|---|---|---|
| Published price | 599 USD per month, cancel anytime (7,188 USD over 12 months), or 5,999 USD once for a lifetime license. Each license has an IP quota, see the pricing page | 3,840 USD for 12 months, “Up to 128 Assets” |
| Larger estates | Same fixed price. No per-asset fee and no scan quota, but each license has an IP quota, see the pricing page | Priced through a Private Offer rather than a public list price |
| Scanning in the price | No scanner license included. Launches Nessus and OpenVAS scans; imports results from 16 scanner families | Unlimited scan engines and templates included |
| Where the console runs | Your own Linux server, with your own PostgreSQL database | Up to 3 Consoles included in the listing |
| Contract terms | Monthly, or lifetime with the first year of updates and the engine feed included | 12-month term listed; 24 and 36-month contracts are discounted |
Read the first row carefully. At 128 assets, InsightVM is cheaper. SITEY’s monthly plan costs 3,348 USD more per year, close to twice as much, and the lifetime license costs 2,159 USD more than one InsightVM year. The real gap is wider, because the Rapid7 figure includes scanning and the SITEY figure does not. AI usage is also extra: you bring your own AI provider key and pay that provider directly. Check the IP quota on the pricing page against your estate before you compare.
At 128 assets, InsightVM is the cheaper option. SITEY’s case is a fixed price at larger scale, not a smaller bill at small scale.
Above 128 assets, the InsightVM listing moves to a Private Offer, so there is no public number to compare against and your cost depends on negotiation. SITEY’s price does not change with asset count, up to the license’s IP quota. The other difference is what the money buys: SITEY writes a remediation script for the specific host, holds it for approval, has the agent apply it, and retests. Multi-year comparisons are not clean either way: Rapid7 discounts longer terms, and SITEY’s lifetime price covers updates and the engine feed for the first year only. For a wider view, see our vulnerability management pricing comparison and the pricing page.
Where Rapid7 still wins
For some teams, InsightVM or Nexpose remains the better fit.
The InsightVM Marketplace listing bundles unlimited scan engines and templates with up to 3 Consoles. With SITEY, scanning is a second product you license, deploy and maintain.
Rapid7 published guidance (February 2024) that InsightVM’s credentialed scanning aligns with PCI DSS 4.0 requirement 11.3.1.2 and can help you meet it. SITEY is not the scanner here: authenticated scans come from the tool you pair it with. SITEY can help you produce evidence that findings were triaged, fixed and retested.
Scanner, templates and consoles come from one vendor on one term, with discounts for 24 and 36-month commitments. SITEY plus a scanner means two vendors and two renewals.
SITEY is built by SITEY Bilisim, a small company at Giresun Teknopark in Turkiye, founded by a security researcher active since 2014 (CVE-2021-40960, CVE-2022-3792). We hold no ISO 27001 or SOC 2 certification. If procurement requires a large, long-established vendor, that counts against us.
Nexpose (on-prem) alternative
Rapid7’s Nexpose page presents the product as an “On-Premise Vulnerability Scanner” and shows no price. We found no end-of-life notice for Nexpose itself, only notices for specific operating systems and integrations, so this is not a “Nexpose is going away” pitch. Teams look for an on-prem Nexpose replacement for control: they want the console and the findings on servers they own.
SITEY installs on your own Linux server (Ubuntu 22.04 or 24.04, Debian 12, RHEL or Rocky 9) and stores every finding in your own PostgreSQL database. There is no Windows server install and no hosted version. Agents run on your Windows and Linux endpoints, apply approved fix scripts, and report results and inventory. More on the on-premise vulnerability management page.
- Keep Nexpose, add SITEY on top
Run scans in Nexpose as today and upload its report exports to SITEY. The findings then go through triage, remediation and approval like any other source.
- Move scanning to Nessus or OpenVAS
If you want SITEY to launch scans and rescans itself, these are the two scanners it controls directly. Earlier Nexpose findings can still come in through import.
SITEY imports Nexpose findings from an uploaded report file. It does not pull findings from a Nexpose console and cannot launch a Nexpose rescan. Rescan-based retest runs through Nessus and OpenVAS, and for OpenVAS the retest judges the rescan at scan level rather than finding by finding. Run one of your own Nexpose exports through a pilot import first and check that hosts, CVEs and severities come across as you expect.
What happens to a finding once it reaches SITEY
SITEY’s work is the stretch between the scan result and a proven fix, organized as an eight-phase pipeline across 28 modules.
- Discovery and scanning
Launch a Nessus or OpenVAS scan from SITEY, or upload a report from any of the 16 supported scanner families.
- Collection and deduplication
Findings are normalized into one schema. A repeat finding raises a re-detection count instead of opening a second ticket.
- AI validation
AI triage estimates a false-positive probability for each finding, using CVSS, EPSS and CISA KEV. The reasoning is stored, and an analyst can reverse the verdict.
- Risk scoring
Each finding gets a priority score, so the queue is ordered by priority rather than by CVSS alone.
- Assignment
Each finding becomes a task. SITEY suggests an owner based on workload and role, and a person confirms it.
- AI remediation planning
AI remediation writes a bash or PowerShell script for the specific host the finding was reported on.
- Approval-gated patching
An approval gate with 4 autonomy levels and 18 risk-classified AI actions holds high-impact changes until a person approves them. The agent then applies the script and reports the result.
- Retest and closure
A retest re-runs the scan before the finding is closed, rather than trusting a script’s exit code. SITEY launches that rescan in Nessus or OpenVAS only; for OpenVAS the verdict is made at scan level rather than finding by finding, and SITEY does not rescan findings imported from other scanners, Nexpose included.
What SITEY does not do
SITEY is not SaaS: you install it on your own Linux server, and installing and operating it needs a technical person on your side. Each license has an IP quota, see the pricing page. It is not air-gapped: your server connects to siteyvm.com for license activation and validation and for the engine feed, and neither connection carries scan data. The AI features need your own key for an OpenAI-compatible endpoint, the finding text and host context go to that endpoint, and the AI cost is not included in SITEY’s price. It includes no scanner license and does not replace Rapid7’s scan engines. It does not launch Nexpose rescans, so it cannot retest Nexpose findings by itself.
Who should switch, and who should stay
You want scanning and consoles from one vendor, your estate fits the published InsightVM price, your PCI program is built around Rapid7’s authenticated scans, or no one in-house can run a Linux server.
You own Nessus or OpenVAS or are prepared to, you want the console and findings on your own server, you want a fixed price rather than a negotiated one as the estate grows, and your bottleneck is closing findings rather than finding them.
Outbound connections, what we hold and how we handle flaws in our own code are covered on the security page.
Frequently asked questions
Is SITEY a drop-in replacement for Rapid7 InsightVM?
No. InsightVM includes its own scan engines; SITEY works with a scanner you run. It launches scans directly in Nessus and OpenVAS and imports results from 16 scanner families, including Nexpose. If you replace InsightVM with SITEY, plan for a scanner as well.
Can I keep Nexpose and add SITEY on top?
Yes. SITEY imports Nexpose report exports by file upload, then triages and remediates those findings like any other source. It does not pull findings from the Nexpose console and cannot launch a Nexpose rescan, so run a pilot import with one of your own exports before you commit.
Does SITEY work air-gapped? What data leaves my network?
SITEY is not air-gapped. Your server connects to siteyvm.com for license activation and validation and for the engine feed; neither carries scan data. Optional outbound calls go to the OpenAI-compatible AI endpoint you choose (it receives finding text and host context; you can pick an endpoint you host yourself or turn AI off), and to NVD, CISA KEV, FIRST EPSS, MSRC and the Microsoft Update Catalog.
Is SITEY cheaper than InsightVM?
Not at 128 assets. InsightVM is listed at 3,840 USD for 12 months at that size, while SITEY’s monthly plan comes to 7,188 USD a year and the lifetime license is 5,999 USD, before a scanner or AI usage. SITEY’s price stays fixed as the estate grows, up to the license’s IP quota (see the pricing page), where InsightVM moves to a Private Offer.
Will SITEY’s AI change my servers without approval?
High-impact changes are held at an approval gate until a person approves them. The gate has 4 autonomy levels, set per policy, and classifies 18 AI actions by risk. After approval, the agent applies the script and reports the result. For findings from Nessus or OpenVAS, a retest re-runs the scan before the finding is closed.
Sources
- Rapid7 InsightVM, AWS Marketplace SaaS listing: 3,840 USD for 12 months, “Up to 128 Assets”; “unlimited scan engines and templates, up to 3 Consoles”; discounted 24 and 36-month contracts; Private Offer for larger scale. https://aws.amazon.com/marketplace/pp/prodview-iytoknlkgcesm, accessed 24 September 2026.
- Rapid7 Nexpose product page: “On-Premise Vulnerability Scanner”, no price shown; no end-of-life notice found for the product itself. https://www.rapid7.com/products/nexpose/, accessed 24 September 2026.
- Rapid7 blog, 20 February 2024: InsightVM credentialed scanning and PCI DSS 4.0 requirement 11.3.1.2. https://www.rapid7.com/blog/post/2024/02/20/explanation-of-new-authenticated-scanning-pci-dss-requirement-11-3-1-2-in-pci-dss-v4-0-and-how-insightvm-can-help-meet-the-requirement/, accessed 24 September 2026.
Rapid7, InsightVM and Nexpose are trademarks of Rapid7, Inc. Nessus and Tenable are trademarks of Tenable, Inc. Other product names are trademarks of their respective owners. SITEY is not affiliated with or endorsed by Rapid7 or Tenable.