IT AI Index
Index Vendors › Trivy · September 2026 Edition
5 categories · Ranked

Trivy

225Judge labels
61First choices
13Negative labels
12 of 12Models named it
5Categories
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
40% in SCA for mid-market buyers
Rank 1 of 49 in the mid-market standingendorsed leader
0 of 12 models made it the first choice on the direct prompt; 3% of its 30 labels there were negative.
By buyer segmentStrongest at mid-market.
In sca · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named Trivy for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Software composition analysisDeveloper platform40%1 of 493%30endorsed leader
Container and Kubernetes securityCloud and infrastructure16%2 of 785%39accepted challenger
Cloud-native application protectionCloud and infrastructure0%15 of 570%6under 10 labels · led by Wiz at 46%
Vulnerability management platformsSecurity operations0%76 of 8050%6under 10 labels · led by Rapid7 InsightVM at 45%
Static application security testingDeveloper platform0%42 of 470%1under 10 labels · led by Semgrep at 47%

Movement

This is the first edition on this tier, so no move can be computed for Trivy yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated Trivy across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.501102
GPT-5.4 mini04015
Gemini 3.5 Flash23308
Perplexity Sonar31127
Grok 4.1 Fast332210
Mistral Small24208
DeepSeek V4 Flash361111
Llama 4 Maverick10203
Qwen 3.7 Flash31206
Kimi K245009
GLM 4.7 FlashX24107
MiniMax M2.531206

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct27 labels5
Paraphrase50 labels18
Comparative39 labels11not counted in share
Budget-constrained61 labels36
Scale-constrained11 labels2
Negative37 labels8not counted in share
First choiceAlternativeMentionNegative225 labels in all, every segment counted; 61 of the 80 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“the open‑source stack of Trivy + Falco + Kubescape (with NeuVector as a full‑life optional addition) provides a credible, complete container security solution” GLM 4.7 FlashX · Container security · budget prompt · first choice
“I would recommend Trivy as the default open-source dependency vulnerability scanner because it gives the broadest practical coverage in one tool” Perplexity Sonar · SCA · paraphrase prompt · first choice
“Trivy (by Aqua Security) stands out as the best software composition analysis (SCA) tool for companies with a limited budget.” Grok 4.1 Fast · SCA · budget prompt · first choice
“the best container security platform is usually Trivy if you want the lowest-cost option, because it is fully open source” Perplexity Sonar · Container security · budget prompt · first choice

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

“Avoid for high-security environments until fully audited; check releases post-v0.69.4 and scan your pipelines.” Grok 4.1 Fast · SCA · negative prompt · hard negative
“Build-time scanners like Trivy, Grype, and Clair can find CVEs and misconfigurations, but they do not detect runtime threats.” Perplexity Sonar · Container security · negative prompt · soft negative
“Trivy and Nuclei are noted as strong specialized tools but with limited enterprise features or centralized management” Perplexity Sonar · Vuln management · negative prompt · soft negative
“provide a strong free foundation but lack enterprise-scale management, support, and advanced enforcement” Grok 4.1 Fast · Container security · comparative prompt · soft negative

Named alongside

The products named in the same answers as Trivy, over the 224 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and Trivy was named but was not.
ProductSame answerTook the first choice insteadHead to head
Falco106 of 2244Not in the top three
Kubescape63 of 2248Not in the top three
Prisma Cloud63 of 2242Not in the top three
Wiz60 of 2241Not in the top three
OWASP Dependency-Check55 of 2247Not in the top three
Snyk52 of 2247Not in the top three
SUSE NeuVector43 of 2242Not in the top three
Sysdig42 of 2243Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named Trivy. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 187 of the 224 answers that named Trivy and are not a share of its labels.

Domains cited

gbhackers.com89
cyberpress.org87
expertinsights.com73
cybersecuritynews.com72
appsecsanta.com70
aikido.dev68
ox.security62
safeguard.sh61
endorlabs.com60
dupple.com47

689 of the 689 domain citations in answers naming Trivy came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as Trivy

What the judge wrote, as written, with how often. The vendor table decides that these count as Trivy; a claim can dispute any of them.
Trivy (by Aqua Security) 5Trivy (Aqua Security) 2Aqua Security's Trivy (open-source scanner) 1Trivy (by Aqua/Falco) 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when Trivy's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as Trivy, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at trivy.dev is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.