# Rapid7, Inc. (RPD)

Informational only - not investment advice.

CIK: 0001560327
SIC: 7372 Services-Prepackaged Software
SIC breadcrumb: [Services](/division/I/) > [Business Services](/major-group/73/) > [SIC 7372 Services-Prepackaged Software](/industry/7372/)
Latest 10-K filed: 2026-02-19
SEC page: https://www.sec.gov/edgar/browse/?CIK=1560327
Filing source: https://www.sec.gov/Archives/edgar/data/1560327/000156032726000008/rp-20251231.htm

## At a glance

FY2025 · period end 2025-12-31 · filed 2026-02-19 · accession 0001560327-26-000008 · source: https://data.sec.gov/api/xbrl/companyfacts/CIK0001560327.json

| Metric | Value | FY | Provenance |
| --- | ---: | ---: | --- |
| Revenue | 859,794,000 USD | 2025 | verified |
| Net income | 23,381,000 USD | 2025 | verified |
| Assets | 1,726,464,000 USD | 2025 | verified |
| Free cash flow | 146,228,000 USD | 2025 | computed |
| Net margin | 2.72% | 2025 | computed |
| Operating margin | 1.35% | 2025 | computed |
| Revenue YoY | +1.87% | 2025 | computed |
| ROE | 15.11% | 2025 | computed |

Computed values are grepcent-computed from the verified facts above and may differ from ratios the company itself reports. Free cash flow = operating cash flow − capital expenditures. Net margin = net income ÷ revenue. Operating margin = operating income ÷ revenue. Revenue YoY = FY2025 revenue ÷ FY2024 revenue − 1 (consecutive fiscal years only). ROE = net income ÷ period-end stockholders' equity.

No market price, no rating, no forecast on this site. Not investment advice.

### Peer percentile fingerprint

| Ratio | RPD | Peer median | Percentile | N |
| --- | ---: | ---: | ---: | ---: |
| Net margin | 2.7% | 1.5% | 54 | 122 |
| Operating margin | 1.3% | 1.3% | 50 | 121 |
| Revenue growth | 1.9% | 13.5% | 17 | 124 |
| FCF margin | 17.0% | 19.3% | 43 | 120 |
| ROE | 15.1% | 2.0% | 75 | 112 |
| ROA | 1.4% | 0.9% | 52 | 124 |
| Liabilities / equity | 10.16 | 0.91 | 96 | 113 |
| Current ratio | 1.28 | 1.57 | 37 | 124 |

Percentile = share of the N covered peers reporting that ratio whose value is lower (ties counted half); computed among grepcent-covered companies in SIC industry 7372 Services-Prepackaged Software, not the whole market. A higher percentile means a higher value of the ratio, not a better company. Ratios with fewer than 8 reporting peers are omitted. Latest reported values per company; fiscal periods may differ. Descriptive arithmetic - not a score, rating, or ranking.

## Selected Fundamentals
| Metric | Value | Unit | FY | Filed |
| --- | ---: | --- | ---: | --- |
| Revenue | 859794000 | USD | 2025 | 2026-02-19 |
| Net income | 23381000 | USD | 2025 | 2026-02-19 |
| Assets | 1726464000 | USD | 2025 | 2026-02-19 |

## Financials

Annual standardized facts from SEC companyfacts as of latest extracted filing date 2026-02-19. Source: https://data.sec.gov/api/xbrl/companyfacts/CIK0001560327.json. Derived margins, ratios, and free cash flow are computed from the extracted annual SEC facts.

| Metric | 2016 | 2017 | 2018 | 2019 | 2020 | 2021 | 2022 | 2023 | 2024 | 2025 |
| --- | ---: | ---: | ---: | ---: | ---: | ---: | ---: | ---: | ---: | ---: |
| Revenue | 157,437,000 | 200,940,000 | 244,091,000 | 326,947,000 | 411,486,000 | 535,404,000 | 685,083,000 | 777,707,000 | 844,007,000 | 859,794,000 |
| Net income | -49,000,000 | -45,470,000 | -55,545,000 | -53,845,000 | -98,849,000 | -146,334,000 | -124,717,000 | -152,815,000 | 25,526,000 | 23,381,000 |
| Operating income | -49,049,000 | -48,794,000 | -53,038,000 | -45,995,000 | -74,099,000 | -120,065,000 | -111,614,000 | -84,288,000 | 35,035,000 | 11,568,000 |
| Gross profit | 117,712,000 | 144,030,000 | 173,008,000 | 235,801,000 | 289,969,000 | 366,456,000 | 470,734,000 | 545,661,000 | 592,972,000 | 604,754,000 |
| Diluted EPS |  |  |  | -1.10 | -1.94 | -2.65 | -2.13 | -2.52 | 0.40 | 0.36 |
| Operating cash flow | 9,112,000 | 13,286,000 | 6,066,000 | -1,420,000 | 4,887,000 | 53,917,000 | 78,204,000 | 104,278,000 | 171,670,000 | 153,827,000 |
| Capital expenditures | 4,499,000 | 4,824,000 | 12,813,000 | 29,428,000 | 13,802,000 | 9,010,000 | 20,382,000 | 4,366,000 | 3,425,000 | 7,599,000 |
| Assets | 243,303,000 | 311,331,000 | 559,369,000 | 664,913,000 | 913,122,000 | 1,296,011,000 | 1,358,991,000 | 1,505,348,000 | 1,652,034,000 | 1,726,464,000 |
| Liabilities | 201,265,000 | 261,305,000 | 472,050,000 | 581,745,000 | 841,586,000 | 1,422,006,000 | 1,479,065,000 | 1,623,527,000 | 1,634,323,000 | 1,571,734,000 |
| Stockholders' equity | 42,038,000 | 24,153,000 | 87,319,000 | 83,168,000 | 71,536,000 | -125,995,000 | -120,074,000 | -118,179,000 | 17,711,000 | 154,730,000 |
| Cash and cash equivalents | 53,148,000 | 51,562,000 | 99,565,000 | 123,413,000 | 173,617,000 | 164,582,000 | 207,287,000 | 213,629,000 | 334,686,000 | 246,664,000 |
| Free cash flow | 4,613,000 | 8,462,000 | -6,747,000 | -30,848,000 | -8,915,000 | 44,907,000 | 57,822,000 | 99,912,000 | 168,245,000 | 146,228,000 |

### Ratios

ROE and ROA use period-end equity/assets. Liabilities / equity uses total liabilities divided by stockholders' equity. Current ratio uses current assets divided by current liabilities when both are reported.

| Metric | 2016 | 2017 | 2018 | 2019 | 2020 | 2021 | 2022 | 2023 | 2024 | 2025 |
| --- | ---: | ---: | ---: | ---: | ---: | ---: | ---: | ---: | ---: | ---: |
| Net margin | -31.12% | -22.63% | -22.76% | -16.47% | -24.02% | -27.33% | -18.20% | -19.65% | 3.02% | 2.72% |
| Operating margin | -31.15% | -24.28% | -21.73% | -14.07% | -18.01% | -22.43% | -16.29% | -10.84% | 4.15% | 1.35% |
| Return on equity | -116.56% | -188.26% | -63.61% | -64.74% | -138.18% |  |  |  | 144.13% | 15.11% |
| Return on assets | -20.14% | -14.61% | -9.93% | -8.10% | -10.83% | -11.29% | -9.18% | -10.15% | 1.55% | 1.35% |
| Liabilities / equity | 4.79 | 10.82 | 5.41 | 6.99 | 11.76 |  |  |  | 92.28 | 10.16 |
| Current ratio | 0.89 | 0.91 | 1.51 | 1.27 | 1.34 | 0.92 | 0.96 | 1.11 | 1.25 | 1.28 |

## As-reported value updates

2 tracked differences above grepcent's stated thresholds were found between the earliest XBRL-filed value and the value currently on file for the same fiscal period.

Ledger: /company/RPD/revisions/


## Quarterly

Quarterly standardized facts from SEC companyfacts as of latest extracted filing date 2026-08-10. Source: https://data.sec.gov/api/xbrl/companyfacts/CIK0001560327.json.

Flow metrics use discrete quarter-length periods from 10-Q/10-Q/A filings. Q4 revenue and net income are derived only when annual FY and nine-month YTD facts exist for the same fiscal year; derived Q4 values are labeled. EPS Q4 is not derived.

| Quarter | End date | Revenue | Net income | Diluted EPS | Method |
| --- | --- | ---: | ---: | ---: | --- |
| 2022-Q3 | 2022-09-30 |  |  | -0.49 | reported discrete quarter |
| 2023-Q1 | 2023-03-31 |  |  | -0.43 | reported discrete quarter |
| 2023-Q2 | 2023-06-30 |  |  | -1.10 | reported discrete quarter |
| 2023-Q3 | 2023-09-30 | 198,843,000 | -76,611,000 | -1.25 | reported discrete quarter |
| 2023-Q4 | 2023-12-31 | 205,268,000 | 20,048,000 |  | derived Q4 = FY annual - nine-month YTD |
| 2024-Q1 | 2024-03-31 | 205,101,000 | 2,258,000 | 0.03 | reported discrete quarter |
| 2024-Q2 | 2024-06-30 | 207,991,000 | 8,195,000 | 0.11 | reported discrete quarter |
| 2024-Q3 | 2024-09-30 | 214,654,000 | 16,554,000 | 0.22 | reported discrete quarter |
| 2024-Q4 | 2024-12-31 | 216,261,000 | -1,481,000 |  | derived Q4 = FY annual - nine-month YTD |
| 2025-Q1 | 2025-03-31 | 210,253,000 | 2,105,000 | 0.03 | reported discrete quarter |
| 2025-Q2 | 2025-06-30 | 214,193,000 | 8,338,000 | 0.13 | reported discrete quarter |
| 2025-Q3 | 2025-09-30 | 217,960,000 | 9,809,000 | 0.15 | reported discrete quarter |
| 2025-Q4 | 2025-12-31 | 217,388,000 | 3,129,000 |  | derived Q4 = FY annual - nine-month YTD |
| 2026-Q1 | 2026-03-31 | 209,691,000 | 1,130,000 | 0.02 | reported discrete quarter |
| 2026-Q2 | 2026-06-30 | 210,883,000 | 6,073,000 | 0.09 | reported discrete quarter |

## Filed narrative (10-K & 10-Q)

## Business

Verbatim Item 1 Business section from RPD's latest 10-K: [/company/RPD/business/](/company/RPD/business/).

## Risk Factors

Verbatim Item 1A Risk Factors from RPD's latest 10-K: [/company/RPD/risk-factors/](/company/RPD/risk-factors/).

## Latest quarter (10-Q)

Latest 10-Q source: https://www.sec.gov/Archives/edgar/data/1560327/000156032726000044/rp-20260630.htm

Extracted structurally from real Item 2 body heading to real Item 3/4 boundary. Published MD&A gate trimmed front/tail over-capture.
Confidence: high
Filing date: 2026-08-10
Report date: 2026-06-30

Item 2. Management’s Discussion and Analysis of Financial Condition and Results of Operations.

The following discussion and analysis of our financial condition and results of operations should be read in conjunction with (1) our unaudited condensed consolidated financial statements and related notes appearing elsewhere in this Quarterly Report on Form 10-Q and (2) the audited consolidated financial statements and the related notes and Management’s Discussion and Analysis of Financial Condition and Results of Operations for the fiscal year ended December 31, 2025 included in our Annual Report on Form 10-K, filed with the SEC on February 19, 2026. Forward-looking statements in this review are qualified by the cautionary statement included under the next sub-heading, “Special Note Regarding Forward-Looking Statements”.

Special Note Regarding Forward-Looking Statements

This Quarterly Report on Form 10-Q, including the sections entitled “Risk Factors,” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” contains forward-looking statements that involve risks and uncertainties, as well as assumptions that, if they never materialize or prove incorrect, could cause our results to differ materially from those expressed or implied by such forward-looking statements. Statements that are not purely historical are forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. Forward-looking statements are often identified by the use of words such as, but not limited to, “anticipate,” “believe,” “can,” “continue,” “could,” “estimate,” “expect,” “intend,” “may,” “plan,” “project,” “seek,” “should,” “target,” “will,” “would” and similar expressions or variations intended to identify forward-looking statements. These forward-looking statements include, but are not limited to, statements concerning the following:

• our ability to continue to add new customers, maintain existing customers and sell new products and professional services to new and existing customers;

• uncertain impacts that prolonged economic uncertainty may have on our business, strategy, operating results, financial condition and cash flows, as well as changes in overall level of software spending and volatility in the global economy;

• the effects of increased competition as well as innovations by new and existing competitors in our market;

• our ability to effectively restructure our business in alignment with our strategic priorities;

• our ability to adapt to technological change and effectively enhance, integrate, innovate and scale our solutions and platform capabilities, including our Command Platform;

• our ability to capitalize on customer demand for consolidated security platforms and vendor consolidation trends, including our ability to deliver an integrated, open security operations platform;

• our ability to deliver, scale and operate managed services (including managed detection and response (“MDR”) and related offerings, including with respect to service quality, staffing, operating efficiency, and the integration of technology and expertise;

• our ability to effectively manage or sustain our growth and to sustain profitability;

• our ability to diversify our sources of revenue;

• potential acquisitions and our ability to successfully integrate acquired businesses, technologies and personnel, including the realization of anticipated benefits from such acquisitions;

• our expected use of proceeds from future issuances of equity or convertible debt securities;

• our ability to maintain, or strengthen awareness of, our brand;

• perceived or actual security, integrity, reliability, quality or compatibility problems with our solutions, including problems related to systems, unscheduled downtime, outages or security breaches in our customers;

• statements regarding future revenue, hiring plans, expenses, capital expenditures, capital requirements and stock performance;

• our ability to meet publicly announced guidance or other expectations about our business, key metrics and future operating results;

• our ability to maintain an adequate annualized recurring revenue growth;

• our ability to attract and retain qualified employees and key personnel and further expand our overall headcount;

• our ability to grow, both domestically and internationally;

• our ability to stay abreast of new or modified laws and regulations that currently apply or become applicable to our business both in the United States and internationally;

• our ability to maintain, protect and enhance our intellectual property;

26

• the outcomes of our initiatives that use artificial intelligence (“AI”), including the development, integration and effectiveness of AI-driven and autonomous (“agentic”) security capabilities within our solutions;

• the evolving threat landscape, including the increasing sophistication and frequency of cyberattacks, including those leveraging AI;

• costs associated with defending intellectual property infringement and other claims; and

• the future trading prices of our common stock and the impact of securities analysts’ reports on these prices.

These statements represent the beliefs and assumptions of our management based on information currently available to us. Such forward-looking statements are subject to risks, uncertainties and other important factors that could cause actual results and the timing of certain events to differ materially from future results expressed or implied by such forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to, those identified above, and those discussed in the section titled “Risk Factors” included under Part II, Item 1A. Furthermore, such forward-looking statements speak only as of the date of this report. Except as required by law, we undertake no obligation to update any forward-looking statements to reflect events or circumstances that occur after the date of this report.

As used in this report, the terms “Rapid7,” the “company,” “we,” “us,” and “our” mean Rapid7, Inc. and its subsidiaries unless the context indicates otherwise.

Overview

Rapid7 is a global leader in AI-powered managed cybersecurity operations, trusted to advance organizations’ cyber resilience. Open and extensible, the Rapid7 Command Platform integrates security data, enriching it with AI, threat intelligence, and 25 years of expertise and innovation to reduce risk and disrupt attackers. As a recognized leader in preemptive managed detection and response (MDR), Rapid7 unifies exposure and detection to transform the cybersecurity operations of customers worldwide. In today's rapidly evolving IT environment, customers are encountering escalating challenges due to the widening spectrum of attackers and techniques, including the proliferation of cyberattacks leveraging AI. We empower security professionals to manage a modern attack surface through our AI-driven technology, research, and broad, strategic expertise. Rapid7’s comprehensive security solutions, including our MDR services, next-gen security information and event management ("SIEM"), and exposure management help our global customers unify exposure management with threat detection and response to prioritize and reduce material risk, and eliminate threats with greater speed, precision, and consistency.

We believe that Rapid7 is poised to expand the capabilities of today's SecOps teams through our integrated, open data security operations platform which is powered by our AI-assisted workflows to AI-driven, machine-speed security operations. Rapid7 enables the Security Operations Center (“SOC”) to understand their fragmented attack surface through an attacker's perspective, thereby allowing them to proactively reduce exposures and better detect and respond to threats. Enriched by years of industry-leading risk research and managed services expertise, our integrated platform replaces reactive security with a preemptive, risk-aware approach that reduces attack surfaces and enables faster, more confident response through contextually rich insights and deep operational visibility.

In recent years, security leaders have increasingly prioritized consolidating fragmented point products into unified security operations platforms to improve visibility, operational efficiency, and risk outcomes. In 2022, Gartner reported that approximately 75% of organizations were pursuing security vendor consolidation as part of their SecOps strategies. This shift reflects mounting challenges associated with managing expanding attack surfaces, disconnected exposure data, escalating alert volume, and the need to continuously prioritize and respond to risk across complex environments. As a result, customers are seeking platforms that unify exposure management with threat detection and response, enabling them to identify where they are most vulnerable, anticipate how attackers may exploit those exposures, and respond with speed and precision. At the same time, customers are increasingly relying on MDR and adjacent managed services to deliver continuous expertise, higher-fidelity detection, and faster response outcomes that extend and augment internal SOC teams. In this context, organizations are prioritizing open, integrated security operations platforms that pair technology with expertise to deliver risk-aware detection and response across on-premise, cloud, identity, and external attack surfaces. We have been an active participant in advancing this shift toward consolidated SecOps by innovating across our open platform architecture, strengthening our exposure management and AI SOC capabilities, and expanding our managed services portfolio. As we continue to execute on our SecOps consolidation strategy, we are advancing innovation across our core platform capabilities and managed services to accelerate customer value and deliver a frictionless, integrated security operations experience.

As the threat landscape continues to grow in complexity, customers are demonstrating demand for integrated expertise to support them in effectively managing their security technologies. The convergence of these key trends – security consolidation, AI SOC capabilities, integrated cloud security, and expertise driven outcomes – forms the foundation of what our customers require for the modern SOC. Our focus is to be the leading provider of integrated, AI-driven security solutions infused with

27

human expertise for the modern SOC by providing risk-aware detection and response that outpaces attackers and strengthens security program maturity.

We market and sell our products and professional services to organizations of all sizes globally, including mid-market businesses, enterprises, non-profits, educational institutions and government agencies. Our customers span a wide variety of industries such as technology, energy, financial services, healthcare and life sciences, manufacturing, media and entertainment, retail, education, real estate, transportation, government and professional services. As of June 30, 2026, we had over 11,500 customers in 149 countries, including 34% of the Fortune 100. Our revenue was not concentrated with any individual customer and no customer represented more than 1% of our revenue for the three and six months ended June 30, 2026 and 2025.

Recent Developments

Restructuring Plan

In June 2026, we executed a limited restructuring activity designed to improve operational efficiencies and better align our workforce with current business needs. The restructuring included a reduction of our workforce primarily within our sales and marketing departments and, to a lesser degree, within our general and administrative business support departments. The restructuring activities are expected to be substantially completed by the end of the third

[Excerpt truncated for page length; source filing is linked above.]

## Latest 10-K MD&A (excerpt)

Latest 10-K Item 7 source: https://www.sec.gov/Archives/edgar/data/1560327/000156032726000008/rp-20251231.htm
Complete FY 2025 MD&A: /company/RPD/mda/fy2025/

Extracted structurally from real Item 7 body heading to real Item 7A/8 boundary. Published MD&A gate trimmed front/tail over-capture.
Confidence: high
Filing date: 2026-02-19
Report date: 2025-12-31

Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations.

The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and related notes appearing elsewhere in this Annual Report on Form 10-K. In addition to historical financial information, the following discussion contains forward-looking statements that reflect our plans, estimates and beliefs. Our actual results could differ materially from those contained in or implied by any forward-looking statements. Factors that could cause or contribute to these differences include those under “Risk Factors” included in Part I, Item 1A or in other parts of this Annual Report on Form 10-K.

Overview

Rapid7 is a global cybersecurity software and service provider on a mission to create a safer digital world by making cybersecurity simpler and more accessible. For more than twenty years, Rapid7 has partnered with enterprises across the globe representing a diverse range of industries to improve the efficacy and productivity of their security operations (“SecOps”). In today's rapidly evolving IT environment, customers are encountering escalating challenges due to the widening spectrum of attackers and techniques, including the proliferation of cyberattacks leveraging AI and targeted automation. We empower security professionals to manage a modern attack surface through our trusted AI infused technology, leading-edge research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help our global customers unite exposure management with threat detection and response to reduce attack surfaces and eliminate threats with speed and precision.

Our Command Platform is anchored on our cloud security, security information and event management (“SIEM”), advanced detection and response, and vulnerability management offerings. Rapid7 enables the Security Operations Center (“SOC”) to understand their fragmented attack surface with attacker perspective, allowing them to proactively secure their attack surface and better detect and respond to threats. Enriched by years of managed services expertise, our integrated security operations platform enables SecOps teams to move away from a reactive approach, reduce their attack surface, and enhance response efficiency with a deep contextual understanding of their environment.

In the past few years, we have observed the industry undergoing a customer-driven shift to consolidated security platforms. As part of this transition, customers are moving away from cloud security as a specialized function towards cloud security as an integrated capability for SecOps teams. We view this as a demand driver for integrated SecOps, and believe that we have an opportunity to be a leader in delivering integrated risk and threat management across on-premise, cloud, and external attack surfaces. As we have shifted our strategic focus to SecOps consolidation, we are focused on continuing to drive innovation

38

Table of Contents

across our core products and capabilities to accelerate customer value and provide a frictionless and integrated cloud security experience.

As the threat landscape continues to grow in complexity, customers are demonstrating demand for integrated expertise to support them in effectively managing their security technologies. The convergence of these key trends – security consolidation, integrated cloud security, and expertise driven outcomes – are the foundation of what our customers require for the modern SOC. Our focus is to be the leading provider of integrated security operations solutions by providing exposure and threat management that leverages our ability to give customers command of their attack surface.

We market and sell our products and professional services to organizations of all sizes globally, including mid-market businesses, enterprises, non-profits, educational institutions and government agencies. Our customers span a wide variety of industries such as technology, energy, financial services, healthcare and life sciences, manufacturing, media and entertainment, retail, education, real estate, transportation, government and professional services. As of December 31, 2025, we had over 11,500 customers in 150 countries, including 36% of the Fortune 100. Our revenue was not concentrated with any individual customer and no customer represented more than 1% of our revenue for the years ended December 31, 2025, 2024 or 2023.

Our Business Model

We offer our products through a variety of delivery models to meet the needs of our diverse customer base, including:

•Cloud-based subscriptions, which provide our software capabilities to our customers through cloud access and on a subscription basis. Our Incident Command, Exposure Command, and Threat Command products are offered as cloud-based subscriptions, with an option for a one or multi-year term.

•Managed services, through which we operate our products and provide our capabilities on behalf of our customers. Our Managed Vulnerability Management, Managed Detection and Response, and Managed Application Security products are offered on a managed service basis, pursuant to one or multi-year agreements.

•Licensed on-premise software consists of term licenses. When licensed on-premise software is purchased, maintenance and support and content subscriptions, as applicable, are bundled with the license for the term period. Our Nexpose and Metasploit products are offered through term software licenses with an option for one or multi-year terms. Our maintenance and support provides our customers with telephone and web-based support and ongoing bug fixes and repairs during the term of the maintenance and support agreement, and our customers who purchase our Nexpose and Metasploit products also purchase content subscriptions, which provide them with real-time access to the latest vulnerabilities and exploits.

Additionally, we offer our products through our consolidation offerings, which unify our products and services to our customers in a single package. Our Threat Complete and Cloud Risk Complete packages are offered as cloud based subscriptions, with an option for a one or multi-year term. Our Managed Threat Complete Offering is offered on a managed service basis, generally pursuant to one or multi-year agreements.

For the years ended December 31, 2025, 2024 and 2023, recurring revenue, defined as revenue from term software licenses, content subscriptions, managed services, cloud-based subscriptions and maintenance and support, was 96%, 96%, and 95% respectively, of total revenue.

Immaterial Correction of an Error

During the fourth quarter of 2024, we identified an immaterial error related to stock-based compensation expense associated with certain restricted stock units (“RSUs”) and performance stock units (“PSUs”) granted during fiscal years 2023 and 2024 attributable to an improper valuation of the underlying awards, resulting in an understatement of stock-based compensation expense in 2023 and 2024. In accordance with Staff Accounting Bulletin (“SAB”) No. 99, Materiality, and SAB No. 108, Considering the Effects of Prior Year Misstatements when Quantifying Misstatements in Current Year Financial Statements, we evaluated the errors and determined the related impacts were not material to our consolidated financial statements for the prior periods when they occurred, but that correcting the cumulative errors in the period detected would have been material to our results of operations for that period. Accordingly, we revised previously reported comparative financial information presented herein for such immaterial errors. Refer to Note 19, Immaterial Correction of an Error, in the notes to our consolidated financial statements for further information.

39

Table of Contents

Components of Results of Operations

Revenue

We generate revenue primarily from selling products and professional services through a variety of delivery models to meet the needs of our diverse customer base.

Product Subscriptions

We generate product subscriptions revenue from the sale of (1) cloud-based subscriptions, (2) managed services offerings, which utilize our products and (3) software licenses with related maintenance and support and content subscription, as applicable. Software license revenue consists of revenues from term licenses. When software licenses are purchased, maintenance and support and content subscription, as applicable, are bundled with the license for the term period.

Professional Services

We generate professional service revenue from the sale of deployment and training services related to our products, incident response services and security advisory services.

Cost of Revenue

Our total cost of revenue consists of the costs of product subscriptions and professional services, as noted below. In addition, cost of revenue includes overhead costs for depreciation, facilities, IT, information security, and recruiting. Our IT overhead costs include IT personnel compensation costs and costs associated with our IT infrastructure. All overhead costs are allocated based on relative headcount.

Cost of Product Subscriptions

Cost of product subscriptions consists of personnel and related costs for our content, support, managed service and cloud operations teams, including salaries and other payroll related costs, bonuses, stock-based compensation and allocated overhead costs. Also included in cost of product subscriptions are software license fees, cloud computing costs and internet connectivity expenses directly related to delivering our products, amortization of contract fulfillment costs, as well as amortization of certain intangible assets including internally developed software.

Cost of Professional Services

Cost of professional services consists of personnel and related costs for our professional services team, including salaries and other payroll related costs, bonuses, stock-based compensation, costs of contracted third-party vendors, travel and entertainment expenses and allocated overhead costs.

We expect our cost of revenue to increase on an absolute dollar basis as we continue to grow our revenue over time.

Gross Margin

Gross margin, or gross profit as a percentage of revenue, has been and will continue to be affected by a variety of factors, including the average sales price of our products and services, transaction volume growth, the mix of revenue between software licenses, cloud-based subscriptions, managed services and professional services and changes in cloud computing costs.

We expect our gross margins to fluctuate over time depending on the factors described above.

Operating Expenses

Operating expenses consist of research and development, sales and marketing, general and administrative expenses, impairment of long-lived assets, and restructuring costs. Operating expenses include overhead costs for depreciation, facilities, IT, information security and recruiting. Our IT overhead costs include IT personnel compensation costs and costs associated with our IT infrastructure. All overhead costs are allocated based on relative headcount. In the near term, we expect our operating expenses to increase as a percentage of revenue as we prioritize investments to drive growth.

Research and Development Expense

Research and development expense consists of personnel costs for our research and development team, including salaries and other payroll related costs, bonuses and stock-based compensation. Additional expenses include third-party infrastructure costs,

40

Table of Contents

travel and entertainment, consulting and professional fees for third-party development resources as well as allocated overhead costs.

Sales and Marketing Expense

Sales and marketing expense consists of personnel costs for our sales and marketing team, including salaries and other payroll re

[Excerpt truncated for page length; the complete text is on the linked full-MD&A page.]

Read the full FY 2025 MD&A: /company/RPD/mda/fy2025/
All MD&A years: /company/RPD/mda/


## MD&A history

Prior-year 10-K MD&A spans are extracted from SEC filings with the same bounded parser used for the latest filing. Each year's full verbatim text is on its own sub-page.

- [FY 2024 MD&A](/company/RPD/mda/fy2024/): filed 2025-02-28; accession 0001560327-25-000021 (https://www.sec.gov/Archives/edgar/data/1560327/000156032725000021/rp-20241231.htm)
- [FY 2023 MD&A](/company/RPD/mda/fy2023/): filed 2024-02-26; accession 0001560327-24-000021 (https://www.sec.gov/Archives/edgar/data/1560327/000156032724000021/rp-20231231.htm)
- [FY 2022 MD&A](/company/RPD/mda/fy2022/): filed 2023-02-24; accession 0001560327-23-000016 (https://www.sec.gov/Archives/edgar/data/1560327/000156032723000016/rp-20221231.htm)
- [FY 2021 MD&A](/company/RPD/mda/fy2021/): filed 2022-02-24; accession 0001560327-22-000026 (https://www.sec.gov/Archives/edgar/data/1560327/000156032722000026/rp-20211231.htm)




## Macro cross-references

Indicators mapped to this company's SIC classification (industry 7372 Services-Prepackaged Software) by grepcent's deterministic macro-sector crosswalk. A navigational mapping, not a statistical or causal claim.

- [PAYEMS](/indicator/PAYEMS/): All Employees, Total Nonfarm
- [CES0500000003](/indicator/CES0500000003/): Average Hourly Earnings of All Employees, Total Private
- [DGS10](/indicator/DGS10/): Market Yield on U.S. Treasury Securities at 10-Year Constant Maturity

Macro-to-micro threads including this sector: [US labor market](/thread/us-labor-market/), [Growth & output](/thread/growth-output/), [Government finances](/thread/government-finances/), [Sector employment](/thread/sector-employment/).

All macro indicators: /indicators/


## For LLMs & downloads

Markdown twin: /company/RPD.md · JSON record: /company/RPD.json · verified financials: /company/RPD/financials.json / /company/RPD/financials.csv · machine TOC for the whole site: /llms.txt
