IT AI Index
Index Vendors › ZenGRC · September 2026 Edition
1 category · Ranked

ZenGRC

34Judge labels
7First choices
6Negative labels
10 of 12Models named it
1Category
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
7% in GRC for mid-market buyers
Rank 6 of 77 in the mid-market standingaccepted challenger
3 of 12 models made it the first choice on the direct prompt; 7% of its 14 labels there were negative.
By buyer segmentRead the same way at every buyer size.
In grc · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named ZenGRC for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
GRC platformsSecurity operations7%6 of 777%14accepted challenger

Movement

This is the first edition on this tier, so no move can be computed for ZenGRC yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated ZenGRC across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.500000
GPT-5.4 mini00000
Gemini 3.5 Flash00000
Perplexity Sonar00000
Grok 4.1 Fast01102
Mistral Small00202
DeepSeek V4 Flash02002
Llama 4 Maverick00000
Qwen 3.7 Flash00011
Kimi K221003
GLM 4.7 FlashX12003
MiniMax M2.510001

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct6 labels3
Paraphrase4 labelsNone
Comparative5 labelsNone
Budget-constrained6 labels3
Scale-constrained5 labels1
Negative8 labels3not counted in share
First choiceAlternativeMentionNegative34 labels in all, every segment counted; 7 of the 10 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“I'd recommend starting with LogicGate Risk Cloud or ZenGRC. ... ZenGRC offers better multi-framework mapping capabilities” MiniMax M2.5 · GRC · direct prompt · first choice
“or ZenGRC for multi-framework compliance — both offer the right balance of capability” Kimi K2 · GRC · direct prompt · first choice
“Shortlist 2-3 vendors in the mid-market tier (LogicGate, Hyperproof, AuditBoard, ZenGRC)” Kimi K2 · GRC · scale prompt · first choice
“LogicGate or ZenGRC are typically the best starting points” GLM 4.7 FlashX · GRC · direct prompt · first choice

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

“Cons: User interface can feel dated; implementation can be slower.” Qwen 3.7 Flash · GRC · paraphrase prompt · soft negative

Named alongside

The products named in the same answers as ZenGRC, over the 34 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and ZenGRC was named but was not.
ProductSame answerTook the first choice insteadHead to head
ServiceNow Integrated Risk Management23 of 341Not in the top three
MetricStream21 of 341Not in the top three
Hyperproof20 of 343Not in the top three
Vanta20 of 343Not in the top three
Archer19 of 340Not in the top three
Drata18 of 341Not in the top three
OneTrust18 of 340Not in the top three
AuditBoard17 of 341Not in the top three
LogicGate13 of 341Not in the top three
Secureframe11 of 340Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named ZenGRC. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 30 of the 34 answers that named ZenGRC and are not a share of its labels.

Domains cited

zengrc.comYour site14
expertinsights.com13
initiarisk.com12
orbiqhq.com12
riskwatch.com11
comchart.com9
complyjet.com9
reddit.com9
saltycloud.com9
apono.io8

Ninety-two of the 106 domain citations in answers naming ZenGRC came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as ZenGRC

What the judge wrote, as written, with how often. The vendor table decides that these count as ZenGRC; a claim can dispute any of them.
Reciprocity 1ZenGRC (Reciprocity) 1ZenGRC (Riskonnect) 1ZenGRC (by Reciprocity) 1ZenGRC by RiskOptics 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when ZenGRC's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as ZenGRC, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at zengrc.com is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.