Burp Suite is the one product ChatGPT and Gemini named most for application security testing software, landing in 4 of the 6 buyer answers we measured on 2026-08-07. No other tool in the category came close to that reach.
We put six buyer questions to ChatGPT and Gemini, gave each question one live web search, and recorded every product named and every source cited. Three tools tied for second at 3 of 6 answers each, a 50% hit rate: Checkmarx, OWASP ZAP, and SonarQube. So four names, Burp Suite plus those three, carried most of the category's visibility.
Below that tier the drop is steep. Invicti, Snyk, and "ZAP by Checkmarx" each appeared in 2 of 6 answers, or 33%. Everything else, eight separate products, showed up exactly once, 1 of 6, or 17%: AppScan, Checkmarx SAST, Contrast, GitGuardian, OpenText Application Security, OWASP PurpleTeam, StackHawk, and Veracode. Fifteen distinct product names came up across the six answers in total.
Two brands were counted under more than one label, and we kept them split rather than invent a merged number the data does not show. Checkmarx appears as both "Checkmarx" (3 of 6) and "Checkmarx SAST" (1 of 6). The open-source ZAP scanner appears as both "OWASP ZAP" (3 of 6) and "ZAP by Checkmarx" (2 of 6): the assistants used two names for the same scanner. Added together they would look larger, but each label stays its own row in the table below.
How the shortlist changed with the question
The most useful thing in this data is how far the shortlist moved when the question changed. The six questions read almost the same in plain English, yet 8 of the 15 products appeared in only one of the six answers, so more than half the names hung on a single phrasing.
The bare "best application security testing software" question returned 5 names: Burp Suite, Checkmarx, AppScan, Invicti, and "ZAP by Checkmarx." AppScan surfaced here and in none of the other five answers.
"Best free" collapsed the list to just 2 names, Snyk and GitGuardian, and shared nothing with the "best" answer. GitGuardian appeared only in the free answer. Burp Suite, the overall leader at 4 of 6, was absent from the free question entirely, which is the clearest sign that "free" is a different race.
"Most affordable" returned a third mix of 5 names: OWASP ZAP, Veracode, Burp Suite, SonarQube, and Checkmarx. Veracode showed up only in the affordable answer and nowhere else across the six.
"For small teams" was the sole appearance of OpenText Application Security, named alongside Checkmarx, SonarQube, and OWASP ZAP. "What should I use" was the sole appearance of OWASP PurpleTeam, named next to Burp Suite and "ZAP by Checkmarx." Each of those products lived in exactly 1 of 6 answers.
The broad "recommendations" question was the widest single answer at 8 names, and it was the only place Checkmarx SAST, StackHawk, and Contrast came up. Change the modifier, change the shortlist: "free" and "best" produced almost no overlap, and a vendor watching only the bare category term would miss the free, affordable, and small-team answers where a different set of names wins.
The source map
The answers lean on a small set of pages, and they are not the pages most vendors watch. Two domains fed all six answers: reddit.com (6 of 6) and ox.security (6 of 6). Community discussion and one security vendor's roundup sat behind every single answer.
Right behind them, cycode.com and owasp.org each fed 5 of 6 answers, and gartner.com, quora.com, and Carnegie Mellon's Software Engineering Institute (sei.cmu.edu) each fed 4 of 6. So the backbone is community threads (Reddit and Quora), security-vendor roundups (ox.security, cycode.com), the OWASP project site, one analyst (Gartner), and one academic institute.
The classic software review directories did not appear at all. G2 was cited 0 times. Capterra was cited 0 times. Whatever star ratings or review volume a vendor has built on those platforms did nothing to earn a mention in these six answers.
Here is the insight worth the whole page for a vendor: your own domain can be the source that gets you named. opentext.com was cited in the "small teams" answer, and OpenText Application Security was named in that same answer, 1 of 6. The page the assistant read was the vendor's own, and the vendor's product came straight out of it.
The pattern repeats more loosely with Contrast. contrastsecurity.com was cited once, in the "what should I use" answer, and Contrast was named once, in the "recommendations" answer that pulled from Reddit, Quora, Gartner, and OWASP. So Contrast got in both when it fed a page and when the community repeated its name. Owning the source is one road in; being what the community says is the other.
What it takes to get named here
The takeaway is blunt, and it is not about market share. The named set is decided by the source list, not by revenue or install base. Burp Suite leads at 4 of 6 because Reddit threads, OWASP pages, and the ox.security roundup keep naming it, not because a scoreboard ranked it first.
So the work for a vendor is unglamorous: be present in the exact pages these answers read, the 6-of-6 and 5-of-6 sources. That means the Reddit conversations, the OWASP ecosystem, and the roundup posts on ox.security and cycode.com. A slot in a roundup an assistant reads for 5 of 6 answers is worth more here than any directory profile, because the directories scored 0.
And because 8 of the 15 names rode in on a single question, the edges are open. Only Snyk and GitGuardian held the "free" answer. "Affordable" was loose enough that Veracode took a place with 1 of 6. A vendor with a real free tier or a low price has a specific, winnable answer to aim at instead of the whole category at once.
Where Glotier fits
Glotier does not sell application security testing, so we are correctly absent from all 6 of these answers. We would not expect our name in a list where we do not belong, and we are not going to pretend we belong in it.
This page, though, is the exact thing we run for a customer's own category. We take the six buyer questions a real shopper would type, ask ChatGPT and Gemini, and hand back the same counts you just read: who got named, in how many of 6 answers, and which pages fed each one. The check is free, needs no account, and takes about a minute.
The full list, counted
| Product | Named in | Share |
|---|---|---|
| Burp Suite | 4 of 6 | 67% |
| Checkmarx | 3 of 6 | 50% |
| OWASP ZAP | 3 of 6 | 50% |
| SonarQube | 3 of 6 | 50% |
| Invicti | 2 of 6 | 33% |
| Snyk | 2 of 6 | 33% |
| ZAP by Checkmarx | 2 of 6 | 33% |
| AppScan | 1 of 6 | 17% |
| Checkmarx SAST | 1 of 6 | 17% |