Rapid7 ASM AI Usage
Use of AI at Rapid7
Rapid7 has established requirements for Artificial Intelligence (AI) usage across all products and services, including an approval process, data privacy standards, model lifecycle management, and security measures. These requirements were developed in the context of the Trust and Compliance policies already in place. For more information on Rapid7’s stance towards AI TRiSM (Artificial Intelligence Trust, Risk, and Security Management), further reading can be found here.
Compliance and enforcement of these requirements are overseen by Rapid7’s Chief Security Officer, including disciplinary actions for policy violations. Models are trained and fine-tuned in secure environments with restricted access permissions. They are then rigorously evaluated by both AI experts for mathematical accuracy as well as subject matter experts for in context utility and accuracy. This ensures the training process has been successful to reach a desired performance level.
Models are trained and fine-tuned in secure environments with restricted access permissions. They are then rigorously evaluated by both AI experts for mathematical accuracy as well as subject matter experts for in-context utility and accuracy. This ensures the training process has been successful to reach a desired performance level.
Attack Surface Management uses AI in the following function:
AI asset summary: Attack Surface Management leverages Rapid7’s AI framework to deliver an AI-generated summary of asset details. This summary provides a concise overview of an asset’s key information — including its identity, business, operational, and security context — enabling users to quickly assess and act on relevant findings. For more information, see https://docs.rapid7.com/surface-command/#day-3-explore-your-data .