Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Rapid7 Work in China? Data Residency, Localization & PIPL Cross-Border

Rapid7's Insight platform — now unified under the Command Platform — offers five cloud regions (United States, Canada, Europe, Japan, Australia) and no mainland-China region, so vulnerability findings, asset inventory and InsightIDR log telemetry come to rest offshore: a PIPL cross-border transfer. A compliance-first look at where your security data is allowed to rest.

Does Rapid7 work in China?

Whether Rapid7 works in China is a data-residency question about your security data, not whether its agents can reach the cloud.

Rapid7's Insight platform — now unified under the Command Platform — pulls your most sensitive operational data into one place: InsightVM builds a map of your infrastructure's weaknesses, a full asset inventory and the credentials used for authenticated scans, while InsightIDR ingests logs carrying user identity, IP addresses and endpoint activity. By Rapid7's own trust center it offers "five cloud regions: United States, Canada, Europe, Japan, and Australia" — none in mainland China — so that security data comes to rest offshore. Where it describes people in China it is personal information (some Article 28 sensitive), and storing it abroad is a cross-border transfer PIPL governs; a CIIO or high-volume handler also owes an in-country storage duty an offshore cloud cannot meet. An on-prem console (Nexpose) keeps vulnerability data in-country, but InsightIDR and the unified platform are cloud-only.

This is a risk map, not a verdict — your obligations turn on your entity, data volumes and who your users are. Our China team can map your Rapid7 exposure →

What Rapid7's own documentation says about China

FactPrimary source
No mainland-China region exists to select. Rapid7's trust center states customers of certain Insight platform solutions "can select from five cloud regions: United States, Canada, Europe, Japan, and Australia," and that "we will not move data from the region you select" — none of the five is in mainland China, so the security data comes to rest in the offshore region chosen at provisioning. Rapid7 Trust — Transparency (data regions), retrieved 2026-10-10
The platform's regions map to offshore AWS data centers only. Rapid7's own allowlist documentation maps the Insight platform to AWS us-east-1, us-east-2 and us-west-2 (US-1/2/3), eu-central-1 (Frankfurt), ca-central-1, ap-southeast-2 (Sydney), ap-northeast-1 (Tokyo), and more recently me-central-1 and ap-south-2 — with no mainland-China region. On-prem Collectors and Insight Agents gather data locally but send it to the selected offshore region. Rapid7 Docs — Allowlist Cloud Engine IPs, retrieved 2026-10-10
Offshore storage of China personal information is a PIPL cross-border transfer. Vulnerability findings, asset records and InsightIDR identity, IP and endpoint telemetry about people in China, held in an offshore region, require notice, a separate consent and a transfer mechanism under PIPL Articles 38–40; crossing a volume or sensitivity threshold can trigger a CAC-led security assessment before any of it lawfully leaves. PIPL Articles 38–40 (China) — 21YunBox compliance explainer, retrieved 2026-10-10
A CIIO or high-volume handler owes an in-country storage duty an offshore cloud cannot meet. Mainland personal information and important data must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). Any China-facing console also needs an ICP filing. Cybersecurity Law Art. 39 (formerly 37) & PIPL Art. 40 — 21YunBox explainer, retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a team serving mainland China, the question about Rapid7 was never whether its agents install or whether they reach the cloud — they do, fine. Rapid7’s Insight platform, now unified under the Command Platform, is a security-analytics service that pulls your most sensitive operational data into one place: InsightVM builds a map of your infrastructure’s weaknesses, a full asset inventory, and holds the credentials used for authenticated scans, while InsightIDR ingests logs carrying user identity, IP addresses and endpoint activity. That is the irony a security buyer feels first — the platform you bought to protect the estate becomes an offshore path for a catalogue of its weaknesses and the identities of its people. The platform offers five cloud regions, none in mainland China, so that security data comes to rest abroad. An on-premises lever exists for vulnerability management (Nexpose); detection and response run cloud-only.

Rapid7's own trust center stating that customers of certain Insight platform solutions can select from five cloud regions — United States, Canada, Europe, Japan, and Australia — with no mainland-China region
Rapid7's own trust center states customers of certain Insight platform solutions "can select from five cloud regions: United States, Canada, Europe, Japan, and Australia" — none in mainland China, so Insight security data comes to rest offshore. Source: rapid7.com/trust — data regions

Rapid7 in China at a glance

What decides it In Rapid7's own terms — and China's law
Where the security data physically rests Rapid7 has no region of its own; your account is pinned to one at provisioning. Its trust center says customers "can select from five cloud regions: United States, Canada, Europe, Japan, and Australia" — none in mainland China — and its allowlist documentation maps these to offshore AWS data centers (us-east-1, us-east-2, us-west-2, eu-central-1 in Frankfurt, ca-central-1, ap-southeast-2 in Sydney, ap-northeast-1 in Tokyo, plus me-central-1 and ap-south-2).
What it ingests, and why residency bites InsightVM concentrates a map of your weaknesses, a full asset inventory and the credentials used for authenticated scans; InsightIDR ingests logs carrying user identity, IP addresses and endpoint and process activity. Where those describe people in China they are personal information under PIPL, and the identity, location and activity fields can fall within Article 28 sensitive personal information — a higher bar of specific purpose, strict necessity and separate consent.
Your mainland users' data in the platform Findings, logs and identifiers generated in China and held in an offshore region are a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). The handler on the hook is you, the operator — not Rapid7, which is the processor you selected the region with.
In-country storage duty A critical information infrastructure operator or high-volume handler owes an in-country storage duty an offshore security cloud cannot meet — mainland personal information and important data must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged.
Is it reachable? Treat reachability as the delivery half, not the question — the agents and collectors connect fine. The lawful lever is to run the security-data layer in-country (Nexpose on-premises where it fits, or a licensed in-country or sovereign-cloud equivalent), and any China-facing surface in front of it — the admin console, the reporting portal — needs an ICP filing tied to a mainland hosting resource (State Council Order No. 292; MIIT Order No. 33).

Where the data actually rests

Rapid7 does not give you a region of your own; it offers a fixed menu, and your account is placed on one of its cloud instances when you provision it. Its trust center is explicit: customers of certain Insight platform solutions “can select from five cloud regions: United States, Canada, Europe, Japan, and Australia,” and, it adds, “we will not move data from the region you select.” Not one of those five is in mainland China. Rapid7’s own allowlist documentation goes a level deeper, mapping the platform to specific AWS data centers — us-east-1, us-east-2 and us-west-2 for the three US instances, eu-central-1 in Frankfurt, ca-central-1 in Canada, ap-southeast-2 in Sydney and ap-northeast-1 in Tokyo, and more recently me-central-1 and ap-south-2 — and even this expanded list has no mainland-China region to select. Whichever you pick, the Insight platform’s findings, asset records and log telemetry come to rest in that offshore region.

The on-premises Collectors and Insight Agents you run inside your network do not change that. They gather data locally, then send it to the cloud instance you were provisioned on — so the collection happens in-country but the resting place is abroad. The one genuine exception is Nexpose, Rapid7’s self-managed, on-premises vulnerability console (the predecessor InsightVM grew out of, still documented and supported): run on mainland infrastructure, it keeps vulnerability data in-country. But Rapid7 is cloud-first now — InsightVM, InsightIDR and the unified Command Platform are managed cloud services with no mainland-China region — so for everything other than a Nexpose deployment, the security data lands offshore by design.

What it ingests is personal information — and that is the irony

Rapid7 earns this scrutiny because of what it concentrates. A vulnerability-management and detection platform is, by construction, a single store of your estate’s most sensitive operational facts: InsightVM holds a classified map of where your systems are weak, a full inventory of your assets, and the scan credentials that unlock authenticated scans; InsightIDR holds a running record of who signed in from which IP address and what they did on which endpoint. The tool you deployed to protect that estate is therefore itself an offshore path for a catalogue of its exploitable weaknesses and the identities of its people — which is precisely the exposure a security buyer cares about most.

It becomes a data-protection matter, not just a trade-secret one, the moment that data describes people in China. User identities, IP addresses, endpoint and process activity, and any names tied to assets or findings are personal information under PIPL once they identify someone; the identity, continuous-activity and location fields InsightIDR ingests can fall within Article 28 sensitive personal information, which carries a higher bar of specific purpose, strict necessity and separate consent. Holding any of it in an offshore region is a cross-border transfer the Personal Information Protection Law governs. And for a critical information infrastructure operator, or a handler whose volumes cross the regulators’ thresholds, personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore security cloud structurally cannot satisfy that duty — the data is, by definition, in the wrong country.

Running it on a no-China-region cloud doesn’t meet the residency duty — and what does

The honest summary is narrow and important: nothing about Rapid7 is “blocked,” and you do not have to abandon it. The exposure is not the software; it is a managed deployment that parks the mainland’s weakness-map, asset inventory and identity telemetry outside the mainland. Fix where the data rests and the exposure closes.

The lawful lever is to keep the security-data layer in-country. For vulnerability management that can mean the self-managed, on-premises console (Nexpose) on mainland infrastructure, so findings and asset data never leave. For InsightIDR and the unified Command Platform — which are cloud-only and offer no mainland-China region — the lever is a lawful in-country or licensed sovereign-cloud equivalent that keeps the log and endpoint telemetry on mainland soil, not a managed instance abroad. Pointing a mainland collector at the offshore cloud region is not localization and does not meet the storage duty; standing up a lawful in-country equivalent is. Where a minimized subset of data may lawfully cross the border, you keep that transfer consented and backed by a transfer mechanism — and crossing a volume or sensitivity threshold can trigger a CAC-led data-export security assessment first. Any China-facing surface in front of the platform earns its own ICP filing.

This is a risk map, not a verdict. Whether you owe in-country storage, a transfer mechanism, a separate consent, an ICP filing, or some combination turns on your entity, your data volumes, how much of what the platform ingests is personal or sensitive, and who your users are — and it is worth settling with counsel before you decide where a single mainland finding or log line comes to rest.

The lawful path — map, localize, deliver

You do not have to drop Rapid7 to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a platform you already run, a partner that sits alongside your stack, not a competitor to it. There are three moves, and they fit together.

Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization (CII) obligations against your actual entity, your data volumes, and whose personal information the platform ingests — the identities in your logs, the people behind your assets, the weakness map and scan credentials — so the exposure is written down before anything is moved.

Localize. Because the risk is where the security data rests, we run that layer in-country — the self-managed console on mainland infrastructure where the product allows, or a licensed in-country or sovereign-cloud equivalent for the cloud-only pieces — so the findings, asset inventory and identity telemetry China requires to stay on mainland soil do. Localize means a lawful in-country deployment, never a connection back to an offshore endpoint; only the minimized, lawfully transferable subset ever crosses.

Deliver. For any China-facing surface in front of the platform — the admin console, the reporting portal your mainland operators hit — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.

The goal is plain: your Rapid7 deployment runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Rapid7 have a data center in mainland China?
No. Rapid7's trust center lists five cloud regions — United States, Canada, Europe, Japan and Australia — and its allowlist docs map them to AWS regions including Frankfurt, Sydney and Tokyo, plus Middle East and India; none is in mainland China. Your account is pinned to one offshore region at provisioning, and that is where the vulnerability findings, asset inventory and InsightIDR telemetry come to rest.
Is sending Rapid7 Insight data out of China a cross-border transfer under PIPL?
Where that data includes personal information of people in China — the user identities, IP addresses and endpoint activity InsightIDR ingests, or names tied to assets and findings — yes. Storing it in an offshore region is a cross-border transfer requiring notice, separate consent and a transfer mechanism (PIPL Articles 38–40), and a CIIO or high-volume handler owes in-country storage (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37). Settle the specifics with counsel.
Can I run Rapid7 on-premises in China to keep the data in-country?
Partly. Nexpose, Rapid7's on-prem vulnerability console, is residency-flexible and can run on mainland infrastructure, but InsightVM, InsightIDR and the unified Command Platform are cloud-first or cloud-only, and their on-prem Collectors and Insight Agents ship data to the offshore region you selected. The lawful lever is to run the security-data layer in-country — on-prem where the product allows, or a licensed in-country or sovereign-cloud equivalent — and deliver any China-facing console over ICP-filed infrastructure, not point a mainland collector back at the offshore endpoint.

ARTICLES RELATED TO RAPID7

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.