| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Cloud security posture management | Cloud and infrastructure | 4% | 6 of 53 | 6% | 17 | accepted challenger |
| Cloud-native application protection | Cloud and infrastructure | 0% | 52 of 57 | 50% | 2 | under 10 labels · led by Wiz at 46% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 1 | 0 | 0 | 0 | 1 |
| GPT-5.4 mini | 1 | 2 | 0 | 0 | 3 |
| Gemini 3.5 Flash | 0 | 2 | 1 | 1 | 4 |
| Perplexity Sonar | 0 | 1 | 0 | 0 | 1 |
| Grok 4.1 Fast | 0 | 0 | 1 | 0 | 1 |
| Mistral Small | 0 | 1 | 0 | 0 | 1 |
| DeepSeek V4 Flash | 0 | 1 | 1 | 0 | 2 |
| Llama 4 Maverick | 1 | 0 | 0 | 0 | 1 |
| Qwen 3.7 Flash | 0 | 1 | 0 | 1 | 2 |
| Kimi K2 | 0 | 1 | 0 | 0 | 1 |
| GLM 4.7 FlashX | 0 | 1 | 0 | 0 | 1 |
| MiniMax M2.5 | 0 | 1 | 0 | 0 | 1 |
Verbatim evidence the judge attached to positive labels.
“Start with your cloud provider's native CSPM tool (AWS Security Hub or Defender for Cloud) if you have not deployed any posture management” Claude Haiku 4.5 · CSPM · negative prompt · first choice
“AWS Security Hub CSPM is typically the most budget-friendly choice, because it's native and has usage-based pricing” GPT-5.4 mini · CSPM · budget prompt · first choice
“a native tool such as Defender for Cloud's free tier or Security Hub CSPM” Llama 4 Maverick · CSPM · budget prompt · first choice
“Also recommended as a starting point if you have AWS infrastructure, though it may have limited free tier capabilities” MiniMax M2.5 · CSPM · budget prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“Avoid relying exclusively on AWS Security Hub, Azure Defender, or Google Security Command Center as your primary CNAPP.” Qwen 3.7 Flash · CNAPP · negative prompt · hard negative
“Avoid them as your primary CSPM if you operate across multiple cloud providers.” Gemini 3.5 Flash · CSPM · negative prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 45 of the 59 answers that named AWS Security Hub and are not a share of its labels.
172 of the 172 domain citations in answers naming AWS Security Hub came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when AWS Security Hub's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as AWS Security Hub, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at awssecurityhub.com is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.