| Category | Function | Share | Rank | Negative rate | Labels | Quadrant | Since September 2026 |
|---|---|---|---|---|---|---|---|
| Threat intelligence platforms | Security operations | 12% | 2 of 119 | 44% | 54 | criticized challenger | ▲+3Since September 2026: 9% → 11%, +3 points. Inside the 11-point floor: within noise. Read over the models both editions asked. |
| Category | September 2026 | Now | Change | Reading | Rank |
|---|---|---|---|---|---|
| Threat intel | 9% | 11% | ▲+3Since September 2026: 9% → 11%, +3 points. Inside the 11-point floor: within noise. Read over the models both editions asked. | Within noise | Rank 5 → 2 of 119 |
Shares here are read over the models both editions asked, so they can differ by a point or two from the standing above, which counts every model in this edition.
The floor is 11 points of share, measured: how far the models move a leader on their own when the same questions are asked twice with nothing changed. A larger change is movement; a smaller one is noise, and both are shown. Movement is read over the twelve models both editions asked; GPT-6 Luna, Muse Glimmer 30B joined this edition and are in the standing but not yet in the comparison. How the floor is measured · The editions
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 2 | 1 | 0 | 0 | 3 |
| GPT-5.4 mini | 2 | 1 | 0 | 0 | 3 |
| Gemini 3.5 Flash | 1 | 0 | 0 | 4 | 5 |
| Perplexity Sonar | 0 | 0 | 1 | 2 | 3 |
| Grok 4.1 Fast | 1 | 1 | 1 | 2 | 5 |
| Mistral Small | 2 | 0 | 1 | 1 | 4 |
| DeepSeek V4 Flash | 1 | 1 | 0 | 4 | 6 |
| Llama 4 Maverick | 0 | 0 | 0 | 1 | 1 |
| Qwen 3.7 Flash | 2 | 0 | 1 | 1 | 4 |
| Kimi K2 | 1 | 0 | 0 | 4 | 5 |
| GLM 4.7 FlashX | 2 | 0 | 0 | 2 | 4 |
| MiniMax M2.5 | 2 | 0 | 2 | 0 | 4 |
| GPT-6 Luna | 1 | 1 | 1 | 0 | 3 |
| Muse Glimmer 30B | 1 | 0 | 0 | 3 | 4 |
Verbatim evidence the judge attached to positive labels.
“For Comprehensive Coverage: If you need to monitor everything from ransomware forums to geopolitical shifts without hiring more analysts, choose Recorded Future.” Qwen 3.7 Flash · Threat intel · comparative prompt · first choice
“Best For: Enterprises needing comprehensive, real-time, and automated threat intelligence with broad integration capabilities.” Mistral Small · Threat intel · comparative prompt · first choice
“Recorded Future is the best all-around choice due to its balance of automation, integration, and actionable intelligence” Mistral Small · Threat intel · paraphrase prompt · first choice
“Best for: Large enterprises needing massive-scale threat intelligence ... the data-volume benchmark in the industry” DeepSeek V4 Flash · Threat intel · comparative prompt · first choice
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“Verdict: Avoid if you have a limited budget or require high-volume, automated ingestion into many disparate tools without manual tuning.” GLM 4.7 FlashX · Threat intel · negative prompt · hard negative
“one buyer guide flags "standard" TIPs like Recorded Future as something to avoid in some enterprise-fit comparisons” Perplexity Sonar · Threat intel · negative prompt · hard negative
“recommended to avoid if you have a limited budget or need high-volume, automated ingestion across many tools” Mistral Small · Threat intel · negative prompt · hard negative
“Avoid pure enterprise like Recorded Future initially—suited for larger teams due to cost.” Grok 4.1 Fast · Threat intel · paraphrase prompt · hard negative
Citations exist only for the models that return a source list, five of the fourteen in this edition, so these counts come from 165 of the 175 answers that named Recorded Future Intelligence Cloud and are not a share of its labels.
477 of the 532 domain citations in answers naming Recorded Future Intelligence Cloud came from somebody else's page.
Pages are listed as the models cited them.
Search figures are US estimates from DataForSEO, read September 28, 2026; AI search demand is its modeled, directional estimate, not a count of queries to any assistant. The answers are this edition's. Two measurements side by side: neither is read as the cause of the other.
| Kind | Pages | Last 90 days | 2025-10 to 2026-09 | Latest | Categories named |
|---|---|---|---|---|---|
| Blog | 738 | undated | SIEM, SOAR | ||
| Report or ebook | 362 | undated | TPRM | ||
| News or press | 65 | undated | |||
| Case study | 61 | undated | MDR | ||
| Glossary or explainer | 14 | undated | Threat intel | ||
| Conference or event | 7 | undated | |||
| Comparison | 6 | undated | |||
| Webinar or virtual event | 2 | undated | |||
| Template or tool | 1 | undated | |||
| Podcast or video | 1 | undated |
Every page recordedfuture.com exposes, subdomains included. Kind is read from the address and title. The last 90 days, the latest date and the twelve months count pages by when they were published, from the site's feeds, a date in the address, or the page's own publication date, read from up to a hundred of its most recently changed pages; a page that says only when it last changed is counted in its kind but not in when, so the recent counts are a floor, and a kind none of whose pages gives a publication date reads undated. An event counts as online when its address or title says so (webinar, on demand, virtual or online summit); a conference, summit, trade show, expo or roadshow that does not say so is counted as a conference or event, which on a vendor's site is mostly in person. Read September 29, 2026.
An email the morning each edition publishes: where this product moved, where it held, and by how much against the noise floor. One address, confirmed by a click; a stop link in every email.
Already following? Everything you follow, with a stop for each.
What Recorded Future Intelligence Cloud's own pages state, read October 5, 2026: recordedfuture.com/platform, recordedfuture.com/why-recorded-future, recordedfuture.com/threat-intelligence, recordedfuture.com/building-successful-threat-intelligence-program-recorded-future, recordedfuture.com/products/cyber-operations. A claimed page can correct any of them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when Recorded Future Intelligence Cloud's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as Recorded Future Intelligence Cloud, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
A new claim receives the current edition's vendor brief for Recorded Future Intelligence Cloud by email, built from the raw record of the edition. It shows:
Recorded Future Intelligence Cloud is among the products AI models recommend first in Threat intelligence platforms this edition. Each badge says so in the buyer's words, names the edition, and links to the standing. The next edition issues a new badge; this one stays true as a record of October 2026.
Badges read on light and dark pages. Alt text carries the claim, the category, the edition and the index, so it stays a citation where the image does not load.