| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Third-party risk management | Security operations | 2% | 6 of 72 | 21% | 29 | accepted challenger |
| Attack surface management | Security operations | 0% | 55 of 104 | 0% | 1 | under 10 labels · led by Intruder at 59% |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 1 | 1 | 0 | 2 |
| GPT-5.4 mini | 0 | 0 | 0 | 0 | 0 |
| Gemini 3.5 Flash | 1 | 2 | 0 | 1 | 4 |
| Perplexity Sonar | 0 | 0 | 1 | 1 | 2 |
| Grok 4.1 Fast | 0 | 3 | 1 | 1 | 5 |
| Mistral Small | 0 | 2 | 0 | 0 | 2 |
| DeepSeek V4 Flash | 0 | 1 | 0 | 2 | 3 |
| Llama 4 Maverick | 0 | 0 | 1 | 0 | 1 |
| Qwen 3.7 Flash | 0 | 2 | 1 | 1 | 4 |
| Kimi K2 | 0 | 1 | 1 | 0 | 2 |
| GLM 4.7 FlashX | 0 | 2 | 1 | 0 | 3 |
| MiniMax M2.5 | 0 | 1 | 1 | 0 | 2 |
Verbatim evidence the judge attached to positive labels.
“If your budget is exactly $0: Sign up for the free tiers of SecurityScorecard or UpGuard” Gemini 3.5 Flash · TPRM · budget prompt · first choice
“For pure speed and scale: Start with SecurityScorecard or Bitsight for their outside-in visibility.” Qwen 3.7 Flash · TPRM · comparative prompt · alternative
“Focus on Closing Big Enterprise Deals | SecurityScorecard (To prove compliance to prospects)” Qwen 3.7 Flash · ASM · paraphrase prompt · alternative
“SecurityScorecard – Ratings-first, great for external monitoring, often paired with other tools.” GLM 4.7 FlashX · TPRM · scale prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“Most enterprise platforms (SecurityScorecard, Bitsight, Black Kite, Panorays, ProcessUnity, Prevalent) are quote-only, so budgets can balloon” DeepSeek V4 Flash · TPRM · budget prompt · soft negative
“Platforms with known alert fatigue or false-positive concerns such as SecurityScorecard and Bitsight” Perplexity Sonar · TPRM · negative prompt · soft negative
“Quote-based pricing (e.g., SecurityScorecard) can surprise; small orgs report it's "very expensive"” Grok 4.1 Fast · TPRM · negative prompt · soft negative
“SecurityScorecard used *without* a workflow engine ... Do not use these as your *only* tool” Qwen 3.7 Flash · TPRM · negative prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 94 of the 112 answers that named SecurityScorecard and are not a share of its labels.
425 of the 425 domain citations in answers naming SecurityScorecard came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when SecurityScorecard's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as SecurityScorecard, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at security.org is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.