IT AI Index
Index Vendors › SimpleRisk · September 2026 Edition
3 categories · Ranked

SimpleRisk

36Judge labels
14First choices
2Negative labels
10 of 12Models named it
3Categories
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
15% in GRC for small business buyers
Rank 5 of 77 in the mid-market standing
0 of 12 models made it the first choice on the direct prompt; 0% of its 9 labels there were negative.
By buyer segmentStrongest at small business.
In grc · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named SimpleRisk for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
GRC platformsSecurity operations11%5 of 770%9under 10 labels · led by Vanta at 14%
Compliance automationSecurity operations0%40 of 540%1under 10 labels · led by Drata at 37%
Third-party risk managementSecurity operations0%48 of 720%1under 10 labels · led by UpGuard at 53%

Movement

This is the first edition on this tier, so no move can be computed for SimpleRisk yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated SimpleRisk across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.500000
GPT-5.4 mini00000
Gemini 3.5 Flash01001
Perplexity Sonar10001
Grok 4.1 Fast10001
Mistral Small00000
DeepSeek V4 Flash10001
Llama 4 Maverick10001
Qwen 3.7 Flash01001
Kimi K211002
GLM 4.7 FlashX11002
MiniMax M2.501001

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct3 labels1
Paraphrase3 labels1
Comparative2 labelsNone
Budget-constrained19 labels12
Scale-constrained1 labelNone
Negative8 labels1not counted in share
First choiceAlternativeMentionNegative36 labels in all, every segment counted; 14 of the 15 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“For a genuinely limited budget, SimpleRisk is the standout choice — its core platform is free, open source, with unlimited users” DeepSeek V4 Flash · GRC · budget prompt · first choice
“likely to be one that offers basic GRC capabilities for small teams, such as SimpleRisk, Hyperproof, or LogicGate” Llama 4 Maverick · GRC · budget prompt · first choice
“If you want the single best pick on value, SimpleRisk is a strong default” Perplexity Sonar · GRC · budget prompt · first choice
“For absolute minimal budget: Start with SimpleRisk (free)” Kimi K2 · GRC · budget prompt · first choice

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

No model argued against it.

Named alongside

The products named in the same answers as SimpleRisk, over the 36 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and SimpleRisk was named but was not.
ProductSame answerTook the first choice insteadHead to head
Hyperproof28 of 360Not in the top three
Drata22 of 361Not in the top three
Vanta19 of 364Not in the top three
Sprinto18 of 364Not in the top three
RealCISO15 of 363Not in the top three
Ethicontrol14 of 362Not in the top three
Eramba12 of 361Not in the top three
ServiceNow Integrated Risk Management10 of 360Not in the top three
MetricStream9 of 360Not in the top three
LogicGate8 of 361Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named SimpleRisk. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 34 of the 36 answers that named SimpleRisk and are not a share of its labels.

Domains cited

reddit.com32
brightdefense.com28
spotsaas.com26
realciso.io19
orbiqhq.com16
sourceforge.net14
simplerisk.comYour site13
complyjet.com12
capterra.com9
g2.com9

165 of the 178 domain citations in answers naming SimpleRisk came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as SimpleRisk

What the judge wrote, as written, with how often. The vendor table decides that these count as SimpleRisk; a claim can dispute any of them.
SimpleRisk Core 2
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when SimpleRisk's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as SimpleRisk, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at simplerisk.com is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.

Subscribe to the pack