IT AI Index
September 2026 Edition · The permanent record of this edition. The unqualified address always carries the latest edition.
Index Developer platform SAST › Enterprise September 2026 Edition

Static application security testing for enterprise buyers

Asked as “SAST tool”, and as “static code security scanner”, on behalf of an enterprise B2B company. 48 first choices recorded across the direct, paraphrase, budget and scale prompts, twelve models each.
Standing
Clear leader
54% of first choices, clear leader.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

01The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all twelve models, for an enterprise B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrant
01Checkmarx One54%17%63endorsed leader
02Veracode12%24%46accepted challenger
03SonarQube10%29%48criticized challenger
04Snyk Code8%6%32accepted challenger
05Semgrep2%17%46accepted challenger
06OpenText Fortify2%27%51criticized challenger
07GitHub Advanced Security2%17%12accepted challenger
Show the two products at 0%, ordered by negative rate
09CodeQL0%17%12accepted challenger
08Black Duck Coverity0%0%17accepted challenger
Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its vendor page.

One product takes 54% of first choices here, so the chart would put eight markers in one corner and one at the far edge. The two measurements it plots are columns in the standing above: share, and the negative label rate. Two products carry a negative rate above 25% in this category. Jump to the standing

02What they warned about

Five of twelve models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Mistral Small, Llama 4 Maverick, Qwen 3.7 Flash and MiniMax M2.5 changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
OpenText Fortify
27%
14 of 51 labels negative · 10 of 12 models · 5 hard negative
“**Verdict:** Avoid unless you have a large dedicated AppSec team, a multi-week rollout plan, and compliance mandates that force its reporting format.” DeepSeek V4 Flash, negative prompt
SonarQube
29%
14 of 48 labels negative · 9 of 12 models · 4 hard negative
“**Why cautious/avoid**: High operational overhead for large orgs—requires significant tuning to reduce noise” Grok 4.1 Fast, negative prompt
Veracode
24%
11 of 46 labels negative · 9 of 12 models · 3 hard negative
“Avoid for mixed-language, dynamic-language, or microservices-heavy environments where you need source-level evidence and fast feedback.” DeepSeek V4 Flash, negative prompt
Checkmarx One
17%
11 of 63 labels negative · 8 of 12 models · 3 hard negative
“Avoid for Predictability ... Tools like Checkmarx, Veracode, and Fortify offer powerful enterprise features but lack transparent pricing at scale.” Claude Haiku 4.5, budget prompt

03What they cite

Citations exist only for the models that return a source list: twelve of the twelve in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

67 of 72 answers in this category came back with a source list, from 12 of 12 models: citations where the model returns them, or the search results it consulted. 6 of those lists are Google grounding redirects that name no site and are left out of the counts. 820 links across 155 sites, every framing counted. Ranked by the number of answers carrying the site or page.

vendor site · Augment Code48 answers · 64 citations · 10 models
36 answers · 52 citations · 9 models
vendor site · Aikido34 answers · 38 citations · 10 models
vendor site · Corgea31 answers · 34 citations · 9 models
vendor site · ZeroPath31 answers · 31 citations · 10 models
vendor site · Pixee29 answers · 34 citations · 9 models
vendor site · Cycode29 answers · 33 citations · 10 models
vendor site · Checkmarx28 answers · 40 citations · 11 models
19 answers · 27 citations · 9 models
18 answers · 19 citations · 9 models
vendor site · Safeguard17 answers · 23 citations · 7 models
13 answers · 21 citations · 8 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

04How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ModelDirect“What is the best SAST tool for an enterprise B2B company?”Paraphrase“Which static code security scanner would you recommend to a large B2B company with thousands of employees?”Comparative“What are the top enterprise-grade SAST tools and how do they differ?”Budget-constrained“What is the best SAST tool for a large company that needs predictable total cost across thousands of users?”Scale-constrained“We are a 5,000 person company with SSO, SOC 2 and procurement review requirements evaluating a SAST tool. What should we look at?”Negative“Which SAST tools should a large enterprise avoid or be cautious about?”
Claude Haiku 4.5Checkmarx One, OpenText Fortify, Veracode
Two alternativesCycode, Mend SAST
no first choiceChangedno first choice
Seven alternativesCheckmarx One, CodeQL, Corgea, OpenText Fortify, Semgrep, Snyk Code, Veracode
Snyk Code, ZeroPath
One alternativeSemgrep
against: Checkmarx One, OpenText Fortify, Veracode
no first choiceagainst: Checkmarx One, OpenText Fortify
GPT-5.4 miniCheckmarx One, Veracode Static Analysis
Three alternativesGitHub Advanced Security, OpenText Fortify, Snyk Code
Checkmarx OneChanged
Two alternativesCodeQL/GitHub Advanced Security, OpenText Fortify
against: Semgrep
Checkmarx One
Six alternativesCodeQL, GitHub Advanced Security, OpenText Fortify, Snyk Code, SonarQube, Veracode Static Analysis
SonarQube
One alternativeCheckmarx Fusion / Checkmarx One
no first choicenothing named
Gemini 3.5 FlashCheckmarx One, Veracode
Four alternativesCodeQL, GitHub Advanced Security, Semgrep, Snyk Code
Snyk CodeChanged
Four alternativesCheckmarx One, GitHub Advanced Security (GHAS) with CodeQL, Semgrep, Veracode
no first choiceSonarQube
Three alternativesCheckmarx One, OpenText Fortify, Veracode
against: GitHub Advanced Security, Semgrep, Snyk
no first choiceagainst: Bandit, Brakeman, ESLint-security, HCL AppScan, OpenText Fortify, SonarQube, Veracode, gosec
Perplexity SonarCheckmarx One
Four alternativesGitHub Advanced Security, OpenText Fortify, Semgrep, Veracode
against: Aikido Security, Corgea
Checkmarx OneHeld
Four alternativesGitHub Advanced Security with CodeQL, OpenText Fortify, Semgrep, Veracode
no first choiceagainst: OpenText Fortify, Snyk Code, SonarQubeCheckmarx One
Two alternativesGraphNode, SonarQube
no first choiceagainst: Bandit, Brakeman, CodeQL, Semgrep, SonarQube
Grok 4.1 FastCheckmarx One
Three alternativesOpenText Fortify, Snyk Code, Veracode
Checkmarx OneHeld
Three alternativesOpenText Fortify, SonarQube, Veracode
Checkmarx One
Four alternativesBlack Duck Coverity, OpenText Fortify, SonarQube, Veracode Static Analysis
against: Semgrep
SonarQube
Three alternativesCheckmarx One, OpenText Fortify, Veracode
against: Snyk
Checkmarx Oneagainst: Checkmarx One, CodeQL, OpenText Fortify, Semgrep, SonarQube, Veracode
Mistral SmallCheckmarx One
Three alternativesGitLab SAST, OpenText Fortify, SonarQube
SonarQubeChanged
Four alternativesCheckmarx One, CodeQL, Semgrep, Veracode
Checkmarx One, Veracode Static Analysis
Four alternativesBlack Duck Coverity, Cycode, OpenText Fortify, SonarQube
Semgrep, Snyk Code
One alternativeZeroPath
against: Checkmarx One, GitHub Advanced Security, OpenText Fortify, SonarQube
no first choiceagainst: Bandit, Checkmarx One, OpenText Fortify, Veracode
DeepSeek V4 FlashCheckmarx One
Five alternativesOpenText Fortify, Semgrep, Snyk Code, SonarQube, Veracode
Checkmarx OneHeld
Four alternativesGitHub Advanced Security / CodeQL, OpenText Fortify, Semgrep, Veracode
Checkmarx One
Six alternativesBlack Duck Coverity, GitHub Advanced Security / CodeQL, Semgrep, Snyk Code, SonarQube, Veracode Static Analysis
against: OpenText Fortify
Checkmarx One
Three alternativesBlack Duck Coverity, OpenText Fortify, Veracode
against: Semgrep, Snyk, SonarQube
no first choiceagainst: Bandit, Brakeman, Checkmarx One, OWASP Dependency-Check, OpenText Fortify, SonarQube, Veracode
Llama 4 MaverickCheckmarx Oneno first choiceChangedno first choiceno first choiceno first choiceagainst: Checkmarx One, OpenText Fortify, Semgrep, Snyk Code, SonarQube, Veracode
Qwen 3.7 FlashCheckmarx One, Veracode
Two alternativesBlack Duck Coverity, Snyk Code
against: SonarQube
Checkmarx OneChanged
Three alternativesGitHub Advanced Security, OpenText Fortify, SonarQube
Checkmarx One
Five alternativesBlack Duck Coverity, OpenText Fortify, Semgrep, Snyk Code, Veracode
GitHub Advanced Security
Four alternativesCheckmarx One, Semgrep, Snyk Code, SonarQube
Checkmarx One, Contrast, SonarQube, Veracodeagainst: Checkmarx One, OpenText Fortify, SonarQube
Kimi K2Checkmarx One
Two alternativesSnyk Code, Veracode
against: SonarQube
Checkmarx OneHeld
Four alternativesOpenText Fortify, Semgrep, SonarQube, Veracode
Checkmarx One
Four alternativesBlack Duck Coverity, OpenText Fortify, SonarQube, Veracode Static Analysis
Checkmarx One
Two alternativesSemgrep, SonarQube
against: OpenText Fortify, Snyk, Veracode
Checkmarx One, Veracode
Three alternativesSemgrep, Snyk, SonarQube
against: Bandit, Basic SAST in GitLab/GitHub, Brakeman, HCL AppScan, OpenText Fortify, SonarQube, SpotBugs, Veracode, gosec
GLM 4.7 FlashXCheckmarx One
Three alternativesSemgrep, Snyk Code, Veracode Static Analysis
Checkmarx OneHeld
Four alternativesGitHub Advanced Security / CodeQL, OpenText Fortify, SonarQube, Veracode
Checkmarx One
Four alternativesBlack Duck Coverity, OpenText Fortify, SonarQube, Veracode Static Analysis
Snyk Code
One alternativeSemgrep
against: Checkmarx One, SonarQube, Veracode
no first choiceagainst: Checkmarx One, OpenText Fortify, SonarQube, Veracode
MiniMax M2.5Checkmarx One, VeracodeCheckmarx OneChanged
Three alternativesGitHub Advanced Security, OpenText Fortify, Veracode
no first choice
Eleven alternativesAikido Security, Black Duck Coverity, Checkmarx One, Corgea, GitHub Advanced Security / CodeQL, OpenText Fortify, Perforce Klocwork, Semgrep, Snyk Code, Veracode, ZeroPath
Offensive360
One alternativeStaticCodeAudit
against: Checkmarx One, Semgrep, Snyk, Veracode
no first choicenothing named
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

05The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Seventy-two rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 14:02yes1410 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 11:32no03 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-09-17 11:50yes1228 s
Direct recommendationPerplexity Sonarsonar2026-09-17 10:09yes187 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 10:21yes3116 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-09-17 13:21yes56 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 10:37yes919 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 13:48yes53 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 09:34yes525 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-09-17 10:39yes926 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 10:40yes679 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 14:03yes524 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 10:51no05 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 13:10yes35 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-09-17 11:59yes925 s
ParaphrasePerplexity Sonarsonar2026-09-17 14:12yes205 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 14:13yes3119 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-09-17 10:37yes55 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-09-17 13:35yes1634 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 12:49yes53 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 11:56yes1566 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-09-17 10:47yes1930 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:56yes1426 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 10:41yes932 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 11:53yes910 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 12:46yes710 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:09yes2135 s
ComparativePerplexity Sonarsonar2026-09-17 11:03yes2013 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 14:15yes2617 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-09-17 10:14yes58 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 12:22yes1520 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 11:32yes52 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 09:31yes530 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-09-17 11:20yes10122 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:48yes2994 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 11:09yes518 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 10:17yes1210 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 12:32yes37 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:12yes2228 s
Budget constrainedPerplexity Sonarsonar2026-09-17 10:48yes195 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 12:03yes3419 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-09-17 09:43yes58 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 12:27yes1622 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 09:59yes53 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 12:36yes530 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-09-17 14:07yes921 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 12:45yes2879 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 09:55yes1581 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 12:20yes1614 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 09:30no08 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-09-17 11:48yes629 s
Scale constrainedPerplexity Sonarsonar2026-09-17 10:48yes1710 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 11:42yes1210 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-09-17 14:12no010 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 10:50yes2227 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 10:14yes53 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 11:20no040 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-09-17 13:44yes2155 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:36yes20175 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 13:17yes524 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 11:47yes188 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 11:03yes38 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:07yes1829 s
Negative framingPerplexity Sonarsonar2026-09-17 14:14yes208 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 13:51yes2116 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-09-17 14:01yes56 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 11:54yes2745 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 13:30yes53 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 10:17yes1792 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-09-17 12:38yes2647 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 12:47yes2254 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 10:44yes731 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

Category-scoped readings
Aikido read as Aikido Security
Checkmarx read as Checkmarx One
GitLab Ultimate read as GitLab SAST
GitLab Ultimate (with SAST built-in) read as GitLab SAST
Unresolved, counted raw
Basic SAST in GitLab/GitHub (without Advanced Security)
Checkmarx Fusion / Checkmarx One
DerScanner
ESLint-security
GitHub Advanced Security (GHAS) with CodeQL
GitHub Advanced Security / GitLab Security
GitHub Advanced Security with CodeQL
GraphNode
Offensive360
StaticCodeAudit
Discontinued, still offered
No shut-down product was recommended here.
← Source controlData warehouses →