Measured · 2026-08-07

Who ChatGPT and Gemini recommend for API security software

We put 6 buyer questions about API security software to ChatGPT and Gemini. One tool tied at the top, each named in 5 of 6 answers, and none in all six. Here is the full list, the pages the answers were built from, and what it means whether or not your product is on it.

Answers read
6
Products named
25
Top source
accuknox.com

Salt Security was named in 5 of the 6 answers we collected, an 83% hit rate, making it the most-recommended product when we asked ChatGPT and Gemini for the best API security software. No other name came close: the next group, Akamai, Gravitee, Postman, Snyk and StackHawk, each landed in exactly 3 of 6 answers (50%).

We ran this on 2026-08-07. We put six buyer questions to two AI assistants, ChatGPT and Gemini, gave each one live web search, and recorded every product they named and every source domain they cited. Six questions, six answers, 25 distinct products named, and this page is only that data with nothing added.

There is an honest finding sitting under the headline: the "best" API security tool depends almost entirely on which of the six questions you ask. Only one product, Salt Security at 5 of 6, held up across phrasings, and even it vanished the moment we asked for free tools.

The shortlist changed with the question

Salt Security topped the general questions but was named in 0 of the answers to "best free API security software." That free question returned a completely different shelf: OWASP ZAP, Akto, Postman, apisec.ai, Fastly's Web Application and API Security, and SoapUI. Four of those, OWASP ZAP, Akto, Fastly's Web Application and API Security, and SoapUI, appeared in that one free question and nowhere else across the six.

The bare "best API security software" question pulled the enterprise shelf instead. Its 8 names were Salt Security, two Cloudflare labels (API Shield and API Gateway), Akamai API Security, Imperva API Security, Cequence Security, 42Crunch and Postman. Cequence Security and both of those Cloudflare labels appeared in that one question and in none of the other five.

"Most affordable API security software" produced yet another mix of 8: Salt Security, Gravitee, AWS WAF, StackHawk, Snyk, 42Crunch, APIsec and Akamai. It shares almost nothing with the free list. "Affordable" returned paid commercial tools, "free" returned open-source and free-tier tools, the only product to appear in both the bare "best" list and the free list was Postman, and the free and affordable lists shared no product at all.

The narrower questions were islands too. "Small teams" was the only question to name Zuplo, the plain "Imperva" label, and Cloudflare Application Security and Performance. "What should I use" was the only one to surface Qualys TotalAppSec. "Recommendations" was the only one to surface Noname Security, and "most affordable" the only one to surface APIsec. In total, 13 of the 25 products we recorded appeared in just one of the six questions.

The takeaway for a marketer is that there is no single "best API security" answer to win. Six phrasings produced six different shelves, and the tool that owns "best" (Salt Security, 5 of 6) is completely absent from "free." You have to know which question your buyer is actually typing.

Where the answers came from

The most-cited source was not a review site and not a rival you would expect: it was accuknox.com, which fed 5 of the 6 answers, while AccuKnox the product was named in 0 of them. Its cited pages are competitor roundups, so it shaped every shelf while sitting off all of them. That is the whole mechanism in one data point: the page that gets cited is not the same thing as the product that gets named.

Community discussion mattered. reddit.com was cited in 4 of the 6 answers, tying for second among all sources, while Quora did not appear a single time. In this category, the user-discussion channel that feeds AI is Reddit, not Quora.

Review directories showed up only in part. G2 was cited in 3 of 6 answers (g2.com), with one extra citation from learn.g2.com, and Gartner in 2 of 6. Capterra did not appear in a single answer. The "get listed everywhere" instinct is half right here: G2 and Gartner fed answers, Capterra fed none.

The insight that matters most to a vendor: your own domain can be the source that names you. StackHawk is the clean case. stackhawk.com was cited in 3 of the 6 answers, and StackHawk the product was named in exactly those same 3 questions ("what should I use," "most affordable," and "recommendations"). Its own published content was the source that put it on the shelf. Gravitee is the same story at larger scale, with gravitee.io the second-most-cited domain overall at 4 of 6 answers and Gravitee named in 3 of them. Publishing reference content is not vanity in this category, it is a direct input to the recommendation.

What it takes to get named

Across all six answers, the source list, not market share, decided who got named. The assistants read roundups (accuknox.com at 5 of 6, cycognito.com and indusface.com at 3 of 6 each), a Reddit thread or two, G2 and Gartner, and a few vendor blogs, then repeated the names they found there. If your product is not on those specific pages, it is not in the answer, no matter your size.

So the work is concrete. Get onto the roundup pages that keep getting cited: accuknox.com fed 5 answers, gravitee.io 4, and cycognito.com, indusface.com, owasp.org and stackhawk.com fed 3 each. Show up in the Reddit threads that surface (4 of 6 answers). Keep a live G2 profile (cited in 3 of 6), since Gartner (2 of 6) is harder to move. And publish your own reference content, because StackHawk (named 3 of 6, all off its own domain) and Gravitee show a vendor page can be the citation that names you.

The full list, counted

ProductNamed inShare
Salt Security5 of 683%
Akamai3 of 650%
Gravitee3 of 650%
Postman3 of 650%
Snyk3 of 650%
StackHawk3 of 650%
42Crunch2 of 633%
Akamai API Security2 of 633%
apisec.ai2 of 633%
AWS WAF2 of 633%
Google Apigee Sense2 of 633%
Imperva API Security2 of 633%

This is every product named in at least 2 of the 6 answers; the other 13 products were each named once. Two notes on the counts. Akamai shows up twice, as "Akamai" (3 of 6) and as "Akamai API Security" (2 of 6), and we kept them as separate rows because that is how the assistants wrote them, rather than summing them into a number the data never showed. The same split hit Imperva ("Imperva API Security" at 2 of 6 plus a plain "Imperva" at 1 of 6), APIsec ("apisec.ai" at 2 of 6 and "APIsec" at 1 of 6), and Cloudflare, which was named three different ways, one time each.

Why Glotier is not on this list

Glotier does not sell API security software, so we are correctly absent from all 6 of these answers, and that is the point: if a visibility tool invented its own presence in a category it does not serve, you should not trust its counts.

This measurement is exactly what we run for a customer's own category. The same six buyer questions, the same assistants, the same record of who got named and which pages fed the answer, all pointed at the category you actually sell in. The check is free, needs no account, and takes about a minute.

The questions we asked

One live web search per question, put to serper+or:chatgpt,gemini on 2026-08-07. 6 of 6 came back with an answer we could read. Whether a product was named is decided by looking for it in the answer text, not by asking a model for its opinion.

  1. best api security software
  2. best api security software for small teams
  3. what api security software should I use
  4. best free api security software
  5. most affordable api security software
  6. api security software recommendations

Questions people ask

Which API security software does AI recommend most?
Salt Security. It was named in 5 of the 6 answers we collected from ChatGPT and Gemini (83%), more than any other product. The next group, Akamai, Gravitee, Postman, Snyk and StackHawk, each appeared in 3 of 6 answers (50%).
What free API security tools do ChatGPT and Gemini suggest?
When we asked specifically for 'best free API security software,' the answer named OWASP ZAP, Akto, Postman, apisec.ai, Fastly's Web Application and API Security, and SoapUI. Four of those (OWASP ZAP, Akto, Fastly's, and SoapUI) appeared only in the free question. Salt Security, the overall leader at 5 of 6, was named in 0 of the free answers.
Do ChatGPT and Gemini rely on G2 or Capterra for API security recommendations?
G2 yes, Capterra no. g2.com was cited in 3 of the 6 answers, with one extra citation from learn.g2.com, and Gartner in 2 of 6. Capterra did not appear in a single answer. The single most-cited source was actually accuknox.com, a competitor roundup site, at 5 of 6.
How does an API security vendor get named by AI assistants?
Be present in the pages the assistants cite, because the source list, not market share, decides who is named. StackHawk is the clearest example: stackhawk.com was cited in 3 of 6 answers and StackHawk was named in exactly those same 3. Roundups like accuknox.com (5 of 6) and Reddit threads (4 of 6) were the other main inputs.
Does the recommended shortlist change with how you phrase the question?
Heavily. Six phrasings produced six different shelves, and 13 of the 25 products we recorded appeared in only one question each. Only Salt Security was named across most phrasings (5 of 6), and even it dropped to 0 in the free question. The 'best free' and 'most affordable' lists shared no product between them.

Do you sell in API security software? Find out whether you are in that list.

Paste your domain and watch the same run happen for your own buyer questions: which of the three assistants names you, who gets named instead, and the exact pages those answers were built from. Free, no card, no account for the first check.

Show my visibility

For reference, Salt Security was named in 5 of the 6 answers we read.

Start with Solo

Get Glotier Solo

Everything on this page is one measurement, taken by hand, on one day. Solo runs it for your product every day and writes the work it points to.

  • The Citation Agent: which of your pages an assistant can actually cite, and the fix for each
  • A paragraph-quality read of your pages: what an assistant can lift whole, and where a claim is missing its source
  • An X agent and a Reddit agent: the live threads worth answering in your category, with a reply drafted for each
  • A daily check, and an article written from what it measured that day, ready to publish
  • The same buyer questions re-asked every day, with every source page behind each answer

Track 3 products and up to 150 buyer questions across ChatGPT, Gemini and Perplexity. $39/month.

Cancel any time. Not for you? Email us within 7 days of a charge and we refund it in full. Refund policy

Not ready to pay? The check is free, with no card and no account. Run it on your own product.