Salt Security was named in 5 of the 6 answers we collected, an 83% hit rate, making it the most-recommended product when we asked ChatGPT and Gemini for the best API security software. No other name came close: the next group, Akamai, Gravitee, Postman, Snyk and StackHawk, each landed in exactly 3 of 6 answers (50%).
We ran this on 2026-08-07. We put six buyer questions to two AI assistants, ChatGPT and Gemini, gave each one live web search, and recorded every product they named and every source domain they cited. Six questions, six answers, 25 distinct products named, and this page is only that data with nothing added.
There is an honest finding sitting under the headline: the "best" API security tool depends almost entirely on which of the six questions you ask. Only one product, Salt Security at 5 of 6, held up across phrasings, and even it vanished the moment we asked for free tools.
The shortlist changed with the question
Salt Security topped the general questions but was named in 0 of the answers to "best free API security software." That free question returned a completely different shelf: OWASP ZAP, Akto, Postman, apisec.ai, Fastly's Web Application and API Security, and SoapUI. Four of those, OWASP ZAP, Akto, Fastly's Web Application and API Security, and SoapUI, appeared in that one free question and nowhere else across the six.
The bare "best API security software" question pulled the enterprise shelf instead. Its 8 names were Salt Security, two Cloudflare labels (API Shield and API Gateway), Akamai API Security, Imperva API Security, Cequence Security, 42Crunch and Postman. Cequence Security and both of those Cloudflare labels appeared in that one question and in none of the other five.
"Most affordable API security software" produced yet another mix of 8: Salt Security, Gravitee, AWS WAF, StackHawk, Snyk, 42Crunch, APIsec and Akamai. It shares almost nothing with the free list. "Affordable" returned paid commercial tools, "free" returned open-source and free-tier tools, the only product to appear in both the bare "best" list and the free list was Postman, and the free and affordable lists shared no product at all.
The narrower questions were islands too. "Small teams" was the only question to name Zuplo, the plain "Imperva" label, and Cloudflare Application Security and Performance. "What should I use" was the only one to surface Qualys TotalAppSec. "Recommendations" was the only one to surface Noname Security, and "most affordable" the only one to surface APIsec. In total, 13 of the 25 products we recorded appeared in just one of the six questions.
The takeaway for a marketer is that there is no single "best API security" answer to win. Six phrasings produced six different shelves, and the tool that owns "best" (Salt Security, 5 of 6) is completely absent from "free." You have to know which question your buyer is actually typing.
Where the answers came from
The most-cited source was not a review site and not a rival you would expect: it was accuknox.com, which fed 5 of the 6 answers, while AccuKnox the product was named in 0 of them. Its cited pages are competitor roundups, so it shaped every shelf while sitting off all of them. That is the whole mechanism in one data point: the page that gets cited is not the same thing as the product that gets named.
Community discussion mattered. reddit.com was cited in 4 of the 6 answers, tying for second among all sources, while Quora did not appear a single time. In this category, the user-discussion channel that feeds AI is Reddit, not Quora.
Review directories showed up only in part. G2 was cited in 3 of 6 answers (g2.com), with one extra citation from learn.g2.com, and Gartner in 2 of 6. Capterra did not appear in a single answer. The "get listed everywhere" instinct is half right here: G2 and Gartner fed answers, Capterra fed none.
The insight that matters most to a vendor: your own domain can be the source that names you. StackHawk is the clean case. stackhawk.com was cited in 3 of the 6 answers, and StackHawk the product was named in exactly those same 3 questions ("what should I use," "most affordable," and "recommendations"). Its own published content was the source that put it on the shelf. Gravitee is the same story at larger scale, with gravitee.io the second-most-cited domain overall at 4 of 6 answers and Gravitee named in 3 of them. Publishing reference content is not vanity in this category, it is a direct input to the recommendation.
What it takes to get named
Across all six answers, the source list, not market share, decided who got named. The assistants read roundups (accuknox.com at 5 of 6, cycognito.com and indusface.com at 3 of 6 each), a Reddit thread or two, G2 and Gartner, and a few vendor blogs, then repeated the names they found there. If your product is not on those specific pages, it is not in the answer, no matter your size.
So the work is concrete. Get onto the roundup pages that keep getting cited: accuknox.com fed 5 answers, gravitee.io 4, and cycognito.com, indusface.com, owasp.org and stackhawk.com fed 3 each. Show up in the Reddit threads that surface (4 of 6 answers). Keep a live G2 profile (cited in 3 of 6), since Gartner (2 of 6) is harder to move. And publish your own reference content, because StackHawk (named 3 of 6, all off its own domain) and Gravitee show a vendor page can be the citation that names you.
The full list, counted
| Product | Named in | Share |
|---|---|---|
| Salt Security | 5 of 6 | 83% |
| Akamai | 3 of 6 | 50% |
| Gravitee | 3 of 6 | 50% |
| Postman | 3 of 6 | 50% |
| Snyk | 3 of 6 | 50% |
| StackHawk | 3 of 6 | 50% |
| 42Crunch | 2 of 6 | 33% |
| Akamai API Security | 2 of 6 | 33% |
| apisec.ai | 2 of 6 | 33% |
| AWS WAF | 2 of 6 | 33% |
| Google Apigee Sense | 2 of 6 | 33% |
| Imperva API Security | 2 of 6 | 33% |
This is every product named in at least 2 of the 6 answers; the other 13 products were each named once. Two notes on the counts. Akamai shows up twice, as "Akamai" (3 of 6) and as "Akamai API Security" (2 of 6), and we kept them as separate rows because that is how the assistants wrote them, rather than summing them into a number the data never showed. The same split hit Imperva ("Imperva API Security" at 2 of 6 plus a plain "Imperva" at 1 of 6), APIsec ("apisec.ai" at 2 of 6 and "APIsec" at 1 of 6), and Cloudflare, which was named three different ways, one time each.
Why Glotier is not on this list
Glotier does not sell API security software, so we are correctly absent from all 6 of these answers, and that is the point: if a visibility tool invented its own presence in a category it does not serve, you should not trust its counts.
This measurement is exactly what we run for a customer's own category. The same six buyer questions, the same assistants, the same record of who got named and which pages fed the answer, all pointed at the category you actually sell in. The check is free, needs no account, and takes about a minute.