# Security platforms: which security platforms coding agents choose

> Checkmarx One leads. GitLab apps get GitLab's own suite.

Source: https://armature.tech/leaderboards/security-platforms (Armature agent leaderboards). 118 runs, 7 apps, 4 agents, 1 persona, updated 2026-09-30. Interactive board with every run: https://armature.tech/leaderboards#app/security-platforms

## Key learnings

We asked coding agents to choose one security platform for code, dependencies, secrets and live-app tests on seven applications.

### Checkmarx One leads on Jenkins and Azure DevOps

Checkmarx One is chosen in 33% of all runs and in 50% on the apps that build in Jenkins or Azure DevOps.

### GitLab apps keep GitLab

On the two apps built in GitLab CI, GitLab Security is chosen in 91% of runs. Elsewhere it is chosen in 2%.

### GitHub apps do not get GitHub's

On the two apps built in GitHub Actions, GitHub Advanced Security is part of the choice in 4% of runs. Snyk is chosen in 33% there and Aikido Security in 25%.

Smaller learnings:

- Muse Code chooses Checkmarx One in 4% of its runs, against 37% to 50% for the other agents, and Snyk in 39%.

## The ranking

| # | Product | Wins | Share |
|---|---|---:|---:|
| 1 | Checkmarx One (checkmarx.com) | 39 | 33% |
| 2 | GitLab Security (gitlab.com) | 22 | 19% |
| 3 | Snyk (snyk.io) | 19 | 16% |
| 4 | Aikido Security (aikido.dev) | 9 | 8% |
| 5 | HCL AppScan (hcltechsw.com) | 5 | 4% |
| 6 | GitHub Advanced Security + ZAP | 4 | 3% |
| 7 | GitHub Advanced Security + Microsoft Defender for Cloud | 3 | 3% |
| 8 | DefectDojo + Gitleaks + Semgrep + Trivy + ZAP | 3 | 3% |
| 9 | DefectDojo (defectdojo.com) | 2 | 2% |
| 10 | DefectDojo + Gitleaks + SonarQube + Trivy + ZAP | 1 | 1% |
| 11 | DefectDojo + Dependency-Track + Gitleaks + SonarQube + Trivy + ZAP | 1 | 1% |
| 12 | SonarQube + ZAP | 1 | 1% |
| 13 | SOOS (soos.io) | 1 | 1% |
| 14 | DefectDojo + SonarQube + ZAP | 1 | 1% |
| 15 | DefectDojo + Dependency-Track + Gitleaks + SonarQube + ZAP | 1 | 1% |
| 16 | Fortify + Sonatype Lifecycle | 1 | 1% |
| 17 | DefectDojo + Gitleaks + Semgrep + ZAP | 1 | 1% |
| 18 | DefectDojo + GitHub Advanced Security + ZAP | 1 | 1% |
| 19 | GitHub Advanced Security (github.com) | 1 | 1% |

## By agent

- Codex (GPT-6 Sol): 30 runs, first Checkmarx One (15), then GitLab Security (5)
- Grok Build CLI (Grok 4.7): 30 runs, first Checkmarx One (12), then GitLab Security (6)
- Claude Code (Claude Opus 5.5): 30 runs, first Checkmarx One (11), then GitLab Security (6)
- Muse Code (Muse Spark 1.3): 28 runs, first Snyk (11), then GitLab Security (5)

## By persona

- Enterprise team: 118 runs, first Checkmarx One (39), then GitLab Security (22)

A case is one codebase with one agent, asked several times in different words and as different people. 21 of 27 cases did not hold to a single choice.

## How this was measured

Every number on this page comes from a controlled experiment. We took 7 small applications, asked 4 coding agents (Codex (GPT-6 Sol), Grok Build CLI (Grok 4.7), Claude Code (Claude Opus 5.5), Muse Code (Muse Spark 1.3)) to choose a security platform for each of them, in several wordings and as an enterprise team, and let the agent choose the product. Each run happened in a sandbox with the agent at a pinned version, and a judge read the session to record what was chosen. That is 118 runs. The interactive board shows every run with its session, its diff and the judge's verdict. A simulated user stood in for the owner of the codebase: it read the agent's plan and had to approve it before any code was written; it sent the agent back at least once in 27 runs.

Methodology and publications: https://armature.tech/publications

If you sell in this sector, what these numbers mean for a vendor: https://armature.tech/library/security-platforms-coding-agents-playbook (Markdown: https://armature.tech/library/security-platforms-coding-agents-playbook.md)

## Other sectors

- [Agent sandboxes](https://armature.tech/leaderboards/sandboxes) (https://armature.tech/leaderboards/sandboxes.md)
- [Observability](https://armature.tech/leaderboards/observability) (https://armature.tech/leaderboards/observability.md)
- [AI SRE](https://armature.tech/leaderboards/ai-sre) (https://armature.tech/leaderboards/ai-sre.md)
- [Payments](https://armature.tech/leaderboards/payments) (https://armature.tech/leaderboards/payments.md)
- [Deploy](https://armature.tech/leaderboards/deploy) (https://armature.tech/leaderboards/deploy.md)
- [Auth](https://armature.tech/leaderboards/auth) (https://armature.tech/leaderboards/auth.md)
- [Email providers](https://armature.tech/leaderboards/mail) (https://armature.tech/leaderboards/mail.md)
- [Product analytics](https://armature.tech/leaderboards/product-analytics) (https://armature.tech/leaderboards/product-analytics.md)
- [Databases](https://armature.tech/leaderboards/databases) (https://armature.tech/leaderboards/databases.md)
- [File storage](https://armature.tech/leaderboards/storage) (https://armature.tech/leaderboards/storage.md)
- [LLM evals & observability](https://armature.tech/leaderboards/evals) (https://armature.tech/leaderboards/evals.md)
- [Voice Agents](https://armature.tech/leaderboards/voice-agents) (https://armature.tech/leaderboards/voice-agents.md)
- [Serverless functions](https://armature.tech/leaderboards/serverless) (https://armature.tech/leaderboards/serverless.md)
- [Cloud](https://armature.tech/leaderboards/cloud) (https://armature.tech/leaderboards/cloud.md)
- [AI gateway](https://armature.tech/leaderboards/ai-gateway) (https://armature.tech/leaderboards/ai-gateway.md)
- [Bot protection](https://armature.tech/leaderboards/bot-protection) (https://armature.tech/leaderboards/bot-protection.md)
- [Search](https://armature.tech/leaderboards/search) (https://armature.tech/leaderboards/search.md)
- [Agent frameworks](https://armature.tech/leaderboards/agent-frameworks) (https://armature.tech/leaderboards/agent-frameworks.md)
- [Performance in CI](https://armature.tech/leaderboards/perf-ci) (https://armature.tech/leaderboards/perf-ci.md)
- [Document processing & OCR](https://armature.tech/leaderboards/document-processing) (https://armature.tech/leaderboards/document-processing.md)
- [Usage-based billing](https://armature.tech/leaderboards/usage-based-billing) (https://armature.tech/leaderboards/usage-based-billing.md)
- [Internationalization](https://armature.tech/leaderboards/internationalization) (https://armature.tech/leaderboards/internationalization.md)
- [Security testing](https://armature.tech/leaderboards/security-testing) (https://armature.tech/leaderboards/security-testing.md)
- [Maps](https://armature.tech/leaderboards/maps) (https://armature.tech/leaderboards/maps.md)
- [Message queues](https://armature.tech/leaderboards/message-queues) (https://armature.tech/leaderboards/message-queues.md)
- [AI search](https://armature.tech/leaderboards/ai-search) (https://armature.tech/leaderboards/ai-search.md)
- [Code review](https://armature.tech/leaderboards/code-review) (https://armature.tech/leaderboards/code-review.md)
- [E-signature](https://armature.tech/leaderboards/e-signature) (https://armature.tech/leaderboards/e-signature.md)
- [In-app chat & calls](https://armature.tech/leaderboards/in-app-communication) (https://armature.tech/leaderboards/in-app-communication.md)
- [Vector search](https://armature.tech/leaderboards/vector-search) (https://armature.tech/leaderboards/vector-search.md)
