All categories

Compliance automation

Security and complianceAugust 2026 edition

Which questions do you win vs lose?

Get your brand’s prompt-level results

Recommendation share

How often each brand is named, across unbranded questions and all five engines

BRANDS

SHAREShare of answers naming this brand, averaged across the five engines

ChatGPTChatGPTShare of ChatGPT answers that name this brand
ClaudeClaudeShare of Claude answers that name this brand
GeminiGeminiShare of Gemini answers that name this brand
PerplexityPerplexityShare of Perplexity answers that name this brand
Google AI OverviewsGoogle AI OverviewsShare of Google AI Overviews answers that name this brand
Vanta
71.3
97.2
90.7
65.7
71.3
Drata
69.4
91.7
84.3
47.2
60.2
Sprinto
26.9
80.6
49.1
26.9
46.3
4
Secureframe
37.0
67.6
41.7
12.0
25.9
5
Hyperproof
29.6
39.8
27.8
8.3
29.6
6
AuditBoard
27.8
40.7
40.7
2.8
19.4
7
Thoropass
18.5
41.7
34.3
6.5
14.8
8
Scytale
0.9
39.8
2.8
8.3
12.0
How we measurePowered by daydream

Every question changed this edition. The previous editions asked a set we wrote for the category; this one asks questions derived from what buyers actually searched or posted, so a month-over-month figure would compare two different questions and read as movement. Comparison returns next edition, when there are two mined runs to set against each other.

Framing sensitivity

The same question asked at each company size

Share of answers naming the brand

SMB50-person startupENTERPRISE1,000-person companyHyperproof1.7%70.6%Secureframe68.9%19.4%Sprinto70.0%20.6%Drata89.4%77.8%AuditBoard10.0%55.0%Vanta94.4%81.7%Thoropass44.4%12.8%Scytale12.8%13.9%

BRANDS

SMBShare of answers naming this brand when the question is asked at this company size50-person startup

ENTERPRISEShare of answers naming this brand when the question is asked at this company size1,000-person company

SPREADThe gap between the highest and lowest column in this row, in percentage points

Hyperproof
1.7%
70.6%
68.9%
Secureframe
68.9%
19.4%
49.4%
Sprinto
70.0%
20.6%
49.4%
AuditBoard
10.0%
55.0%
45.0%
Thoropass
44.4%
12.8%
31.7%
Vanta
94.4%
81.7%
12.8%
Drata
89.4%
77.8%
11.7%
Scytale
12.8%
13.9%
1.1%
How we measurePowered by daydream

Model divergence

The engines that name a brand least and most often, and the gap between them

BRANDS

LOWEST ENGINEThe engine that names this brand least often, and its share

HIGHEST ENGINEThe engine that names this brand most often, and its share

SPREADThe gap between the highest and lowest column in this row, in percentage points

Secureframe
12.0PerplexityPerplexity
67.6ClaudeClaude
55.6
Sprinto
26.9ChatGPTChatGPT
80.6ClaudeClaude
53.7
Drata
47.2PerplexityPerplexity
91.7ClaudeClaude
44.4
Scytale
0.9ChatGPTChatGPT
39.8ClaudeClaude
38.9
AuditBoard
2.8PerplexityPerplexity
40.7ClaudeClaude
38.0
Thoropass
6.5PerplexityPerplexity
41.7ClaudeClaude
35.2
Hyperproof
8.3PerplexityPerplexity
39.8ClaudeClaude
31.5
Vanta
65.7PerplexityPerplexity
97.2ClaudeClaude
31.5
How we measurePowered by daydream

Citation trail

The sites the engines linked to when they answered

SOURCES

REACHShare of all answers that cited this source at least once% of all answers

LINKSEvery link to this source, counted across all answerstotal

DEPTHLinks to this source per answer that cited itlinks/answer

vanta.com
413
1.3
soc2auditors.org
866
2.9
sprinto.com
438
1.7
complyjet.com
337
1.5
drata.com
284
1.5
strac.io
190
1.2
secureleap.tech
385
2.5
optro.ai
117
1.1
reddit.com
109
1.1
getsecureslate.com
125
1.3
scytale.ai
94
1.0
scrut.io
86
1.0
thesectorpost.com
120
1.5
cavanex.com
157
2.0
orbiqhq.com
131
1.8
riskwatch.com
99
1.4
hyperproof.io
79
1.1
secureframe.com
58
1.1
episki.com
94
1.8
v-comply.com
55
1.1
How we measurePowered by daydream

More in Security and compliance

Which questions do you win vs lose?

Get your brand’s prompt-level results

How we measure this3 of 12 questions published

We write a fixed set of category questions, none of which names a brand, and count how often each brand comes up. A brand is present in an answer only when one of its names literally appears in the text, because a string match cannot hallucinate.

Every question starts from one somebody already asked. Some come from search demand, where the figure is how many people typed that phrasing in a month. The rest come from a public forum post, and we link to the page it was written on. We rewrite each one into a plain question, because a search string is a fragment and a forum post is written the way people type, and neither is a fair thing to ask an engine. We change the wording and never the subject, and the original is published beside every question we disclose. The set is frozen before a single answer is collected, so every engine and every edition is asked exactly the same thing.

12questions scored
3buyer framings each
36prompts run
5engines

The 3 we publish, of 12

Chosen to span both where the questions come from and how they are shaped, so the sample describes the battery rather than one corner of it. That is 25% of the questions the ranking comes from.

  • What is the best GDPR compliance softwareas asked: best gdpr compliance software40/mocategoryawareness
  • What is the best healthcare compliance softwareas asked: best healthcare compliance software50/mocategoryawareness
  • What is the best SOC 2 compliance softwareas asked: best soc 2 compliance software90/mocategoryawareness

Each is asked 3 ways

  • for a 50-person startup pursuing its first SOC 250-person startup
  • for a 1,000-person company managing multiple frameworks1,000-person company
  • at the lowest costCheapest option

Why the rest stays private

A published battery invites brands to write pages against the exact wording, at which point a score moves without the brand’s actual standing moving and the measurement stops describing anything. Benchmark suites keep a held-out set for the same reason. The method is public so it can be judged, a quarter of the questions are public so it can be checked, and the rest stays private so the numbers stay worth checking.

What the numbers are, and aren’t

  • The August 2026 edition is one dated run, not a rolling average.
  • Share is averaged across the engines rather than pooled, so an engine that returned fewer answers cannot look like a brand losing ground.
  • A move is marked only when a two-proportion test puts it outside what the sample size can explain. A few points between neighbouring brands is a tie.
  • Rankings reflect how often AI engines name a brand. They are not endorsements by daydream.
  • 16 further questions name competitors directly. None of them feeds the ranking, because a question that already names the contenders cannot measure who gets recommended. They do count towards the citation trail, which is measured over every answer we collected rather than the unbranded ones alone.