AI Security Has Six Buyer Questions and Six Different Source Lists
Across the six buyer-question leaderboards the Machine Relations Index publishes for AI Security & Privacy, 39 of the 45 domains that reach a top ten reach exactly one of them. The six that carry across are YouTube, arXiv, Reddit, Medium, LinkedIn and one data-governance vendor.
If you sell AI security or data privacy software, there is no list.
Across the six buyer-question leaderboards the Machine Relations Index publishes for AI Security & Privacy, 45 distinct domains reach a top ten. Thirty-nine of them reach exactly one. The six that carry across more than one question are YouTube, arXiv, Reddit, Medium, LinkedIn and a single data-governance vendor.
The practical version: a placement programme aimed at one of your buyer's questions buys you presence in roughly one sixth of the surface where that buyer is actually being answered.
What the release publishes
Release mri_score_v2.0+2026-09-25+04fcb7fb8f29 covers the observation window 2026-05-10 through 2026-09-25 across six answer engines. A segment is one subject category paired with one buyer question shape, and it publishes a ranked leaderboard only after clearing an evidence floor of at least 10 observed answer runs across at least 7 distinct observation dates.
AI Security & Privacy publishes all six buyer shapes. Each has its own denominator, and every rate below is the share of that segment's observed runs in which at least one observed answer cited the domain.
| Buyer question | Observed runs | Run dates | Cited domains observed |
|---|---|---|---|
| Best tools | 136 | 7 | 275 |
| How buyers choose | 130 | 7 | 305 |
| Is it worth it | 130 | 7 | 330 |
| Problem-first research | 106 | 7 | 272 |
| Top lists | 106 | 7 | 313 |
| Comparisons | 114 | 7 | 263 |
The six top tens
| Rank | Best tools | How buyers choose | Is it worth it |
|---|---|---|---|
| 1 | arXiv 38.24% | Teramind 26.15% | Witness.ai 21.54% |
| 2 | Medium 27.21% | Aona.ai 21.54% | Veeam.com 20.00% |
| 3 | Getmaxim.ai 22.79% | YouTube 16.92% | YouTube 18.46% |
| 4 | YouTube 21.32% | arXiv 16.15% | Cloudflare 16.15% |
| 5 | Galileo.ai 19.12% | Philterd.ai 16.15% | Radware.com 16.15% |
| 6 | Futureagi.com 18.38% | Cyberhaven.com 13.85% | OvalEdge 14.62% |
| 7 | Reddit 16.91% | Forcepoint.com 13.85% | Reddit 12.31% |
| 8 | Dev.to 16.18% | Microsoft.com 13.85% | Akamai.com 10.77% |
| 9 | Amazon.com 13.97% | Dope.security 13.08% | Hydrox.ai 10.77% |
| 10 | Generalanalysis.com 13.24% | Nightfall.ai 13.08% | LinkedIn 10.77% |
| Rank | Problem-first research | Top lists | Comparisons |
|---|---|---|---|
| 1 | YouTube 18.87% | OvalEdge 39.62% | arXiv 47.37% |
| 2 | arXiv 16.98% | Osano 28.30% | Medium 24.56% |
| 3 | Iguazio.com 16.04% | Ketch 26.42% | Apxml.com 21.05% |
| 4 | Reddit 15.09% | Transcend 21.70% | YouTube 19.30% |
| 5 | Medium 12.26% | arXiv 20.75% | Milvus.io 17.54% |
| 6 | TechRadar 12.26% | Usercentrics 19.81% | Bluedot.org 16.67% |
| 7 | Conferbot.com 11.32% | Sprinto 17.92% | Oneuptime.com 13.16% |
| 8 | LinkedIn 11.32% | Enzuzo.com 16.04% | Ibm.com 11.40% |
| 9 | TechTarget 11.32% | Reddit 16.04% | Palo Alto Networks 11.40% |
| 10 | Aembit.io 10.38% | Matomo.org 15.09% | Substack.com 11.40% |
Read the columns sideways
Forty-five distinct domains hold those sixty slots. Thirty-nine of them hold exactly one.
The carry-over set is small and almost entirely general-purpose infrastructure. YouTube reaches five of the six top tens. arXiv reaches five. Reddit reaches four, Medium three, LinkedIn two. Exactly one domain with a stake in this category — the data-governance vendor OvalEdge — appears in more than one, at first place in Top lists and sixth in Is it worth it.
Every other category-native source is a single-question source. Teramind leads How buyers choose and holds a slot in no other top ten. Osano, Ketch, Transcend, Usercentrics, Sprinto and Enzuzo — the consent and privacy-management set — take six of the ten Top lists slots and hold no slot in the other five. Witness.ai, Veeam, Cloudflare, Radware and Akamai hold the Is it worth it answer and hold no slot in How buyers choose.
The shape of the question is also changing what kind of source wins. arXiv takes 47.37% of Comparisons runs, the highest single rate in the category: when a buyer asks whether one AI security approach beats another, the engines reach for papers. Top lists is a vendor-page market almost end to end. How buyers choose is led by operator and vendor surfaces, with Medium the first editorial publication on that leaderboard, in thirteenth place.
The cross-category version of this — that the domain holding first place changes with the question — was published in this brief on 2026-09-19. What the AI Security & Privacy segments add is that it is not only the top slot that moves. The whole reachable set moves.
What this changes about the budget
Three decisions follow, and none of them is "make a list".
Pick the question before the placement. A source that wins Top lists in this category is very unlikely to be the source that wins How buyers choose. Decide which stage of your buyer's research you are trying to be present at, then work the sources that stage actually uses. Spreading one budget across six lists spends it six times at one sixth the strength.
Treat the five platforms as the only portable surface. YouTube, arXiv, Reddit, Medium and LinkedIn are the places where presence earned for one question carries to another. They are also the surfaces most security marketing programmes do not staff. A technical paper, a maintained community presence and a genuine explainer video library are load-bearing in this category in a way a single trade-press placement is not.
Stop reading one leaderboard as your market. The per-question leaderboards are public and free to read, domain by domain, at the Index. Reading your own domain's segment standings tells you which of the six questions you are already present at — a different and more useful number than a single visibility score.
What this measurement does not say
These rates are floors, not ceilings. Two Google surfaces had collection gaps inside this window: Google AI Overviews recorded no citations from 2026-08-15 to 2026-09-24, and Google AI Mode recorded none from 2026-09-14 to 2026-09-24. ChatGPT, Claude, Gemini and Perplexity collected throughout. A domain those two surfaces would have cited during their blind days is measured low here, and every rate above should be read as at least that much. The comparison across the six questions still holds, because the same window and the same gaps apply to all six segments equally.
The Index measures which sources answer engines cite when the market's buying questions are asked. It does not measure whether a placement caused a citation, and no figure here should be read that way. Source-role labels are annotations rather than ranking inputs, and they cover part of the index; that is why several leaders above are listed as other observed sources rather than as vendors or publications.
This is also one category on one release. The segments are measured over roughly a hundred answer runs each across seven observation dates. That clears the Index's evidence floor and it is enough to see structure. It is not enough to read a two-point rate difference as a ranking change.
Why this is a Machine Relations problem
AI security buyers are asking several distinct questions, and the standards work around the category — the NIST AI Risk Management Framework and the OWASP Top 10 for LLM Applications among it — is training them to ask more. Each question assembles its own evidence set, and the engines rebuild that set from whatever is legible and retrievable at the moment of the answer.
That is Machine Relations: making a brand legible, retrievable and credible inside AI-driven discovery, measured per question rather than per campaign. AuthorityTech is the practice that applies it, earning the third-party evidence and the entity structure that put a brand inside those answers. The Index is the neutral instrument. The work is deciding which of your buyer's six questions is worth being the answer to first.