Guide · AI search

How do application security vendors win demand when developers and CISOs ask AI?

By being the tool an AI answer can describe accurately to two different buyers: the developer who tries it and the security leader who consolidates the stack. Application security demand is rising with exploited vulnerabilities, open source malware and AI-written code. The vendors that win are the ones whose documentation, research and community proof are easy to find and hard to dispute.

The short version

  1. Developers are part of the buying decision: in the 2025 Stack Overflow Developer Survey (opens in a new tab), 48% endorsed or influenced a new technology purchase in the past year, and security or privacy concerns were the top reason to reject a tool.
  2. Those developers already work with AI: 84% use or plan to use AI tools, yet 46% do not trust the accuracy of their output, according to Stack Overflow (opens in a new tab).
  3. Demand is driven by real attacks: Verizon’s 2025 breach report (opens in a new tab) found exploitation of vulnerabilities was the entry point in 20% of breaches, up 34%, and third-party involvement doubled to 30%.
  4. Buyers want fewer tools: in Cycode’s 2025 survey (opens in a new tab) of over 700 security leaders, organizations ran an average of 50 AppSec tools and 88% were willing to consolidate within 12 months.
  5. Winning accounts expand: JFrog (opens in a new tab) reported 97 customers above $1 million in annual recurring revenue and 121% net dollar retention, which it credited partly to demand for software supply chain security.

Who buys application security, and what is a customer worth?

Two groups buy it: developers who adopt tools in their workflow, and security leaders who fund and consolidate them.

Application security covers static code analysis (SAST), dynamic testing (DAST), open source and dependency scanning (SCA), secrets detection, container and pipeline security, and the posture platforms (ASPM) that pull findings together. Gartner’s 1Q26 forecast, as summarized by Louis Columbus (opens in a new tab), sizes the application security subsegment at $8.6 billion in 2025 and $9.9 billion in 2026, growth of 13.0%.

The developer side matters more here than in most security categories. Stack Overflow’s survey of more than 49,000 developers found that 48% had endorsed or influenced a technology purchase in the past year. What turns developers away is telling: security or privacy concerns ranked first, prohibitive pricing second and “availability of better alternatives” third.

Pricing is built around developers too. GitHub (opens in a new tab) sells Secret Protection at $19 and Code Security at $30 per month per active committer, so contract size grows with the engineering team.

The security side controls the budget and wants consolidation. Cycode surveyed over 700 CISOs, AppSec directors and DevSecOps managers in the US, UK and Germany; 50% came from organizations with over 5,000 employees. 67% said managing their array of tools was a significant hurdle, and 61% had begun consolidating. Cycode sells a posture platform, so it has an interest in that finding.

A won customer can be large and long-lived. Snyk crossed $300 million in annual recurring revenue (opens in a new tab), with its static analysis product alone at $100 million. JFrog’s customers above $1 million rose to 97 from 61 a year earlier, and it was named a Leader in Gartner’s first Magic Quadrant for Software Supply Chain Security.

What is pushing companies to buy application security now?

Exploited vulnerabilities, poisoned open source and AI-written code, each documented in 2025–2026 research.

  • Exploits. Verizon analyzed 12,195 confirmed data breaches and found credential abuse (22%) and vulnerability exploitation (20%) were the leading ways in.
  • Open source risk. Black Duck’s 2026 audit (opens in a new tab) of 947 codebases found open source in 98% of them and mean vulnerabilities per codebase up 107%.
  • Malicious packages. Sonatype (opens in a new tab) found 454,648 new malicious packages in 2025, as developers downloaded components 9.8 trillion times.
  • AI-written code. Veracode (opens in a new tab) tested more than 100 AI models on 80 coding tasks; they introduced security flaws in 45% of cases. Veracode, Black Duck and Sonatype all sell application security, so read their figures as vendor research.

These triggers become the questions buyers type, which is where AI search enters.

When does an AppSec buyer meet an AI answer?

Inside the developer’s daily workflow, and increasingly in Google results for software questions; no study isolates AppSec buyers.

The developers who trial scanners already lean on AI for answers. AI tools were in use or planned by 84% of Stack Overflow’s respondents, up from 76% in 2024. Trust is low: 46% said they do not trust the accuracy of AI output, and 35% visited Stack Overflow after running into problems with AI responses. Developers check answers against communities and documentation; Stack Overflow (84%), GitHub (67%) and YouTube (61%) were the community platforms they used most.

Google’s AI answers lean on those same places for software searches. In our Reddit study, 35.4% of AI Overviews for B2B software and technology keywords cited a Reddit thread, one of the two highest rates of eight industries, and r/cybersecurity was among the most-cited communities. In our YouTube study, AI Overviews for B2B software searches cited a YouTube video on 91.0% of searches, far more than any other industry.

AI answers about code are also fallible in ways that matter to this industry. Sonatype analyzed nearly 37,000 dependency upgrades suggested by AI tools and said 28% were hallucinations, recommending versions that do not exist. Developers have reason to double-check; a vendor whose facts are published clearly gives them, and the assistant, something to check against.

Which questions do AppSec buyers ask AI assistants?

Developers ask how and which; security leaders ask what to consolidate and how to prove compliance. We wrote the AppSec prompts in this table to show typical needs; none comes from logged queries.

Asked byNeedIllustrative prompt
DeveloperFit“What is the best SAST tool for a TypeScript and Go monorepo that runs in GitHub Actions?”
DeveloperNoise“Which code scanners have the fewest false positives for Java?”
DeveloperAlternatives“Open source alternatives to Snyk for dependency scanning?”
AppSec leadComparison“Semgrep vs GitHub Code Security vs Checkmarx for a 400-developer team?”
AppSec leadConsolidation“Do we need an ASPM platform if we already have SAST, SCA and container scanning?”
CISOCompliance“Which tools generate SBOMs that will help with the EU Cyber Resilience Act?”
CISOAI code“How do we scan code written by AI coding assistants before it ships?”

Each prompt can set off several searches. Google documents that AI Overviews and AI Mode may use a “query fan-out” technique (opens in a new tab) across subtopics, and OpenAI documents that ChatGPT search rewrites questions (opens in a new tab) “into one or more targeted queries.” For AppSec, we infer those searches will reach language support pages, documentation, benchmarks and community threads, not only vendor home pages.

How does a scanner named in an AI answer become a platform contract?

Through two linked motions: a developer tries the tool, then the security team standardizes on a platform.

  1. Bottom-up trial. A developer asks an assistant which scanner suits their stack, installs a free tier or plugin, and sees results in their own code.
  2. Team purchase. Usage spreads, and the team buys seats; per-committer pricing like GitHub’s ties revenue to how many developers commit code.
  3. Security evaluation. The AppSec lead, facing dozens of tools, runs a comparison of a few platforms. AI answers and the sources they cite shape which ones make that list, we infer.
  4. Platform contract. The winner replaces point tools as part of consolidation.
  5. Expansion. Revenue grows with developers, repositories and modules; JFrog’s 121% net dollar retention shows what expansion looks like at a public vendor.

The AI answer can matter at steps 1 and 3, for different readers. A developer wants to know whether it works with their language and pipeline; a security leader wants coverage, compliance and consolidation. A vendor visible only to one of them, we infer, loses deals at the other step.

Why does an assistant suggest one code scanner over another?

The platforms do not document vendor selection; studies show AI answers draw on communities, video and independent sources.

What Google and OpenAI disclose. Both say their AI answers search the web and link to supporting pages. Neither explains how it picks the SAST, SCA or posture tools it suggests.

Observed in studies. Our Reddit study found Google’s AI cites practitioner communities heavily for software questions. Our YouTube study found the text Google shows for a cited video came from what is said in it: for 97.9% of 616 cited videos with an excerpt, the excerpt was not in the video’s description. A recorded walkthrough of how a scanner handles a real vulnerability is, in other words, readable evidence. In our brand study, coverage on independent sites was the strongest predictor of being recommended that we measured.

Our inference on AppSec trust signals. The evidence developers and AppSec leads trust is mostly public:

  • documentation that states supported languages, frameworks, package managers and pipelines;
  • reproducible accuracy claims, such as published benchmark results or detection examples;
  • vulnerability research and disclosures credited to the vendor’s team;
  • open source projects, rules or plugins that developers already use;
  • analyst placements, such as the 18 companies in Gartner’s software supply chain security report, which The Stack (opens in a new tab) reports named eight leaders;
  • candid discussion in practitioner communities.

A reasonable expectation is that vendors with more of this in public view give both developers and assistants more to cite. No study has tested it for AppSec.

What does an AppSec vendor lose when assistants name rivals instead?

Missed trials, which never show up in a pipeline report, and missed consolidation decisions, which last for years.

  • Developers drop tools fast. “Availability of better alternatives” is the third-ranked reason developers reject a technology. If an assistant names a rival for a developer’s stack, the trial you never got is invisible.
  • Consolidation shrinks the field. With organizations running an average of 50 tools and 88% willing to consolidate, each consolidation decision removes vendors, and the ones not on the shortlist are the first to go, we infer.
  • Wrong facts cost trials. If an assistant says you do not support a language you do support, developers may never test you. Our guide to fixing wrong brand information in AI answers shows how to trace and correct a claim like that.

No study has put a dollar figure on these losses.

How does GEO work for an application security company?

It puts your language coverage and detection proof where developers and assistants can check them; nobody can promise a mention.

  1. Documentation as a public asset. Keep language, framework and integration support on crawlable, current pages. This is the first thing developers and assistants check.
  2. Clear category language. Say plainly whether you are SAST, SCA, DAST, ASPM, supply chain security or a platform, and use the same words everywhere.
  3. Proof developers can reproduce. Publish detection examples, benchmark methods and false positive data, with enough detail to test.
  4. Original research. Vulnerability and malware research earns coverage in security media and developer communities, which assistants can cite. More on that in how brands build authority for AI search.
  5. Video with spoken explanation. Short walkthroughs of real findings, with captions, give Google’s AI something to quote.
  6. Honest community presence. Answer questions in developer and security communities as identified staff; planted posts backfire, as we explain in legitimate GEO versus manipulation.
  7. Comparison and alternatives pages. Fair comparisons help buyers, though third-party sources carry more weight; see whether comparison pages help B2B citations.
  8. Measurement for both buyers. Track developer and security-leader questions separately, across assistants and over repeated runs.

For the general security buying picture, see cybersecurity software and AI search; for self-serve and seat-based revenue, see B2B SaaS and AI search.

What is still unmeasured about AI answers and AppSec purchases?

No one has measured how AppSec buyers use assistants, or whether being named lifts trials or platform wins.

  • No AppSec buyer study. Stack Overflow covers developers in general, not AppSec purchases.
  • Vendor research dominates. Most threat figures come from companies that sell AppSec tools; their methods differ.
  • Selection is opaque. No platform publishes how it chooses which tools to name, and answers change between runs.
  • No study ties visibility to scanner revenue. The broader evidence is weighed in does AI visibility drive business results.

How can an AppSec vendor tell whether AI answers bring it trials and platform deals?

Test what assistants tell developers and security leaders about your tool, using the questions each one actually asks.

Write two question sets: one for developers (stack fit, accuracy, setup, alternatives) and one for security leaders (consolidation, compliance, AI-written code). Put every question to ChatGPT, Gemini, Perplexity, Copilot and Google’s AI more than once, since the scanners named shift between runs. Note whether your tool appears, how its language support and false positive rate are described, and which pages are cited. Gaps usually point to thin documentation, missing research or little community presence.

For an outside view, talk to us about an AppSec visibility audit. It shows where AI answers send developers and AppSec leaders instead of you, and which gaps most likely cost you free-tier installs, seat expansion and consolidation wins. The generative engine optimization service page explains how we then build the documentation, detection proof and research coverage that developers and security leaders each check.

Frequently asked questions

Do developers trust AI recommendations for security tools?

Not fully: 46% of developers in Stack Overflow’s 2025 survey said they do not trust the accuracy of AI output, so they check documentation and communities.

Should AppSec vendors target developers or CISOs in AI search?

Both. Developers influence purchases (48% did last year), while security leaders decide consolidation. Their questions differ, so track them separately.

Does publishing on YouTube help AppSec visibility in Google’s AI?

Possibly. In our study, Google’s AI cited a YouTube video on 91.0% of B2B software searches, quoting what was said in the video.

Does an analyst report placement matter for AI answers?

Untested, but it is public, citable proof. Gartner’s first software supply chain security report covered 18 companies.

Sources

Free strategy call

Some questions are easier to answer about your own business.

Bring the one that matters most. On a free 30-minute call we’ll take a first look at it and send you a short written read afterward.