# Static application security testing for enterprise buyers: what AI models recommend, September 2026

IT AI Recommendation Index, September 2026 Edition. Asked as "SAST tool" and as "static code security scanner", six framings each, to twelve models with search on, on behalf of an enterprise B2B company. Page: https://it-ai-index.com/developer/static-application-security-testing/enterprise/

**Standing:** Checkmarx One leads with 54% of first choices; verdict clear leader. 48 first choices across the direct, paraphrase, budget and scale prompts.

## First-choice share

| # | Product | Share | Negative rate | Labels |
|---|---|---|---|---|
| 1 | Checkmarx One | 54% | 17% | 63 |
| 2 | Veracode | 12% | 24% | 46 |
| 3 | SonarQube | 10% | 29% | 48 |
| 4 | Snyk Code | 8% | 6% | 32 |
| 5 | Semgrep | 2% | 17% | 46 |
| 6 | OpenText Fortify | 2% | 27% | 51 |
| 7 | GitHub Advanced Security | 2% | 17% | 12 |
| 8 | Black Duck Coverity | 0% | 0% | 17 |
| 9 | CodeQL | 0% | 17% | 12 |

## Each model's first choice on the direct prompt

- Claude Haiku 4.5: Checkmarx One, OpenText Fortify, Veracode; alternatives Cycode, Mend SAST
- GPT-5.4 mini: Checkmarx One, Veracode Static Analysis; alternatives GitHub Advanced Security, OpenText Fortify, Snyk Code
- Gemini 3.5 Flash: Checkmarx One, Veracode; alternatives CodeQL, GitHub Advanced Security, Semgrep, Snyk Code
- Perplexity Sonar: Checkmarx One; alternatives GitHub Advanced Security, OpenText Fortify, Semgrep, Veracode
- Grok 4.1 Fast: Checkmarx One; alternatives OpenText Fortify, Snyk Code, Veracode
- Mistral Small: Checkmarx One; alternatives GitLab SAST, OpenText Fortify, SonarQube
- DeepSeek V4 Flash: Checkmarx One; alternatives OpenText Fortify, Semgrep, Snyk Code, SonarQube
- Llama 4 Maverick: Checkmarx One
- Qwen 3.7 Flash: Checkmarx One, Veracode; alternatives Black Duck Coverity, Snyk Code
- Kimi K2: Checkmarx One; alternatives Snyk Code, Veracode
- GLM 4.7 FlashX: Checkmarx One; alternatives Semgrep, Snyk Code, Veracode Static Analysis
- MiniMax M2.5: Checkmarx One, Veracode

## Sources the answers cite

67 of 72 answers came back with a source list, from 12 of 12 models. Sites named in the most answers:

- augmentcode.com: 48 answers, 64 citations
- appsecsanta.com: 36 answers, 52 citations
- aikido.dev: 34 answers, 38 citations
- corgea.com: 31 answers, 34 citations
- zeropath.com: 31 answers, 31 citations
- pixee.ai: 29 answers, 34 citations
- cycode.com: 29 answers, 33 citations
- checkmarx.com: 28 answers, 40 citations

Pages named in the most answers:

- https://augmentcode.com/tools/enterprise-sast-tools-large-teams-field-guide (46 answers)
- https://appsecsanta.com/sast-tools/enterprise-sast-tools (34 answers)
- https://zeropath.com/blog/best-sast-tools (31 answers)
- https://aikido.dev/blog/top-enterprise-sast-tools (29 answers)
- https://corgea.com/learn/best-sast-tools (25 answers)
- https://cycode.com/blog/top-13-enterprise-sast-tools-for-2026 (25 answers)
- https://pixee.ai/blog/best-sast-tools-2026 (24 answers)
- https://ox.security/blog/static-application-security-sast-tools (17 answers)
- https://checkmarx.com/learn/sast/open-source-vs-premium-sast-tools (15 answers)
- https://dev.to/rahulxsingh/i-reviewed-32-sast-tools-the-ones-worth-using-283e (10 answers)

## Warned against

- OpenText Fortify: 14 of 51 labels negative. "Verdict: Avoid unless you have a large dedicated AppSec team, a multi-week rollout plan, and compliance mandates that force its reporting format." (DeepSeek V4 Flash, negative prompt)
- SonarQube: 14 of 48 labels negative. "Why cautious/avoid: High operational overhead for large orgs—requires significant tuning to reduce noise" (Grok 4.1 Fast, negative prompt)
- Veracode: 11 of 46 labels negative. "Avoid for mixed-language, dynamic-language, or microservices-heavy environments where you need source-level evidence and fast feedback." (DeepSeek V4 Flash, negative prompt)
- Checkmarx One: 11 of 63 labels negative. "Avoid for Predictability ... Tools like Checkmarx, Veracode, and Fortify offer powerful enterprise features but lack transparent pricing at scale." (Claude Haiku 4.5, budget prompt)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
