IT AI Index
Index Vendors › SecurityScorecard · September 2026 Edition
2 categories · Ranked

SecurityScorecard

112Judge labels
2First choices
32Negative labels
12 of 12Models named it
2Categories
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
2% in TPRM for enterprise buyers
Rank 6 of 72 in the mid-market standingaccepted challenger
0 of 12 models made it the first choice on the direct prompt; 21% of its 29 labels there were negative.
By buyer segmentRead the same way at every buyer size.
In tprm · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named SecurityScorecard for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Third-party risk managementSecurity operations2%6 of 7221%29accepted challenger
Attack surface managementSecurity operations0%55 of 1040%1under 10 labels · led by Intruder at 59%

Movement

This is the first edition on this tier, so no move can be computed for SecurityScorecard yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated SecurityScorecard across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.501102
GPT-5.4 mini00000
Gemini 3.5 Flash12014
Perplexity Sonar00112
Grok 4.1 Fast03115
Mistral Small02002
DeepSeek V4 Flash01023
Llama 4 Maverick00101
Qwen 3.7 Flash02114
Kimi K201102
GLM 4.7 FlashX02103
MiniMax M2.501102

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct17 labelsNone
Paraphrase15 labelsNone
Comparative34 labels1not counted in share
Budget-constrained15 labels1
Scale-constrained9 labels1
Negative22 labelsNone
First choiceAlternativeMentionNegative112 labels in all, every segment counted; 2 of the 3 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“If your budget is exactly $0: Sign up for the free tiers of SecurityScorecard or UpGuard” Gemini 3.5 Flash · TPRM · budget prompt · first choice
“For pure speed and scale: Start with SecurityScorecard or Bitsight for their outside-in visibility.” Qwen 3.7 Flash · TPRM · comparative prompt · alternative
“Focus on Closing Big Enterprise Deals | SecurityScorecard (To prove compliance to prospects)” Qwen 3.7 Flash · ASM · paraphrase prompt · alternative
“SecurityScorecard – Ratings-first, great for external monitoring, often paired with other tools.” GLM 4.7 FlashX · TPRM · scale prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

“Most enterprise platforms (SecurityScorecard, Bitsight, Black Kite, Panorays, ProcessUnity, Prevalent) are quote-only, so budgets can balloon” DeepSeek V4 Flash · TPRM · budget prompt · soft negative
“Platforms with known alert fatigue or false-positive concerns such as SecurityScorecard and Bitsight” Perplexity Sonar · TPRM · negative prompt · soft negative
“Quote-based pricing (e.g., SecurityScorecard) can surprise; small orgs report it's "very expensive"” Grok 4.1 Fast · TPRM · negative prompt · soft negative
“SecurityScorecard used *without* a workflow engine ... Do not use these as your *only* tool” Qwen 3.7 Flash · TPRM · negative prompt · soft negative

Named alongside

The products named in the same answers as SecurityScorecard, over the 112 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and SecurityScorecard was named but was not.
ProductSame answerTook the first choice insteadHead to head
Bitsight93 of 1127Not in the top three
UpGuard82 of 11235Not in the top three
OneTrust Third-Party Risk Management79 of 1125Not in the top three
ProcessUnity62 of 11212Not in the top three
Prevalent58 of 1122Not in the top three
Vanta55 of 1127Not in the top three
Panorays48 of 1122Not in the top three
Archer35 of 1120Not in the top three
Venminder29 of 1124Not in the top three
Riskonnect24 of 1121Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named SecurityScorecard. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 94 of the 112 answers that named SecurityScorecard and are not a share of its labels.

Names read as SecurityScorecard

What the judge wrote, as written, with how often. The vendor table decides that these count as SecurityScorecard; a claim can dispute any of them.
SecurityScorecard (Free Tier) 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when SecurityScorecard's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as SecurityScorecard, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at security.org is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.

Subscribe to the pack