A 16-month developer marketing and content program run by Infrasity for OX Security. Baseline April 2025. The category basket in this case study is AppSec tooling: SAST, SCA, DAST, SBOM, ASPM, container security, application security testing tools, and vulnerability scanning tools.
| TL;DR | OX Security grew organic traffic from 4,393 to a peak of 20,129 visits a month, and now sits ahead of Snyk, Wiz, Black Duck and Checkmarx on a basket of ten core AppSec category keywords. The lead is clearest on container security, SAST, SCA and application security testing tool queries, where OX holds positions 2 to 5 while Snyk sits at a median of 25. We did it by killing pages instead of adding them, rebuilding the blog into a three-layer cluster, and wiring every ranking page to a product page. Twenty-nine of the fifty highest-volume Google AI Overview citations OX now holds come from pages we wrote. This was not a content-only engagement. AI search visibility and Reddit engagement ran as their own workstreams alongside it. OX now appears in 333 Google AI Overview responses across 65 pages, and one of the Reddit comments we placed is being cited inside an AI Overview as a source. |
What actually changed, in one table
Every number below is pulled from Ahrefs. Nothing is modeled or estimated by us.
| Metric | April 2025 | August 2026 | Change |
|---|---|---|---|
| Organic traffic (monthly) | 4,393 | 8,626 (peak 20,129 in Feb 2026) | +96% steady, +358% at peak |
| Keywords in positions 1 to 3 | 89 | 509 | +472% |
| Keywords in positions 4 to 10 | 309 | 754 | +144% |
| Keywords stuck past position 50 | 604 | 0 | Cleared |
| Total ranking keywords | 2,684 | 1,357 | Cut by half on purpose |
| Visits per ranking keyword | 1.64 | 5.64 | 3.4x |
| Non-branded share of traffic | 72.5% | 78.8% | +6.3 points |
| Own brand share of traffic | 23.1% | 9.9% | Less dependent on brand |
| Blog pages driving traffic | Fragmented | 159 pages, 7.7K visits | Consolidated |
The last row of that table is the one most people miss. We removed more than half of OX's ranking keywords and traffic still doubled. That is the whole strategy in one line.
Who is OX Security and why was this hard?
OX Security is an application security platform. It secures software from AI-generated code all the way through to runtime, with products covering code scanning, cloud posture, agentic pentesting and AI code security.
The market they sell into is one of the most contested in B2B software. Snyk, Wiz, Checkmarx, Black Duck, Veracode, Apiiro, Cycode and Palo Alto Networks all publish aggressively against the same keywords. Several of them have ten times the domain authority and content headcount.
When we came in, OX was doing good technical work and publishing regularly. The problem was not effort. It was structure.
What was actually broken when we started?
We spent the first two weeks auditing every URL on the blog before writing a single word. Four problems came out of that audit.
1. Five pages were fighting each other for the same keyword
OX had five separate live pages targeting SBOM tooling. Four separate pages targeting ASPM. Three targeting software composition analysis. Google had no way to pick a winner, so it picked none of them properly. All five SBOM pages sat between positions 20 and 60.
2. The long tail was dead weight
On 12 April 2025, OX ranked for 2,684 keywords. Of those, 1,133 sat between positions 21 and 50, and another 604 sat past position 51. That is 1,737 keywords, 65% of the entire footprint, generating close to zero clicks. Only 89 keywords sat in the top three.
3. Almost a quarter of traffic was people who already knew the brand
23.1% of organic traffic came from people typing some version of "OX Security". Branded traffic is nice, but it does not create a new pipeline. It just intercepts demand somebody else already generated.
4. There was no path from an article to the product
Someone landing on a SAST explainer had no obvious route to OX Code. Rankings existed in one part of the site, and revenue lived in another, with nothing connecting them.

Ahrefs, 12 April 2025. Organic traffic at the start of the engagement: 4,393.

Ahrefs, 12 April 2025. 2,684 keywords ranking, but only 89 in the top three, and 23.1% of all traffic branded.
What did we fix first, before writing anything?
Here's what we did and what you can learn from this.
We consolidated instead of publishing
The instinct in most content programs is to publish more. We did the opposite. We merged competing pages into single definitive pages and 301 redirected the rest.
| Topic | Pages before | Pages after | Where the equity went |
|---|---|---|---|
| SBOM tools | 5 | 1 | /blog/sbom-tools/ |
| ASPM | 4 | 1 | /blog/application-security-posture-management-aspm/ |
| ASPM tools | 2 | 1 | /blog/aspm-tools/ |
| SCA tools | 3 | 1 | /blog/software-composition-analysis-and-sca-tools/ |
| AppSec testing tools | 2 | 1 | /blog/application-security-testing-tools/ |
| Vulnerability assessment | 2 | 1 | /blog/application-vulnerability-assessment/ |
| Application security trends | 2 | 1 | /blog/application-security-trends-in-2026/ |
| SAST vs SCA | 2 | 1 | /blog/sast-vs-sca-2026/ |
Twenty-two competing URLs became eight. Every redirect was mapped, implemented, and verified before the new page went live, so no ranking window was lost in the handover.
We gave every page exactly one job
After consolidation, we mapped every surviving page to one primary keyword and one intent. No page was allowed to target two commercial terms. If two keywords deserved a page each, they got a page each, and they linked to one another instead of competing.
How did we build the content engine?
We ran the program in sprints. Each sprint had a theme, a keyword set validated against Ahrefs search volume, an outline reviewed by the OX team, and a published URL with a date. Five sprints shipped more than forty pages.
| Sprint | Theme | Sample pages shipped |
|---|---|---|
| Sprint 1 | Core testing and vulnerability foundations | Application security testing, AppSec testing tools, Application vulnerability management, SAST tools, SCA tools, Snyk alternatives, Checkmarx alternatives |
| Sprint 2 | Category ownership and comparisons | Veracode alternatives, Apiiro alternatives, SBOM tools, ASPM, ASPM tools, DAST, DAST tools |
| Sprint 3 | Containers and 2026 refresh cycle | Aikido alternatives, AppSec trends 2026, Container security solutions, Container security tools, Container security best practices, SAST vs SCA, Software supply chain risk |
| Sprint 4 | AI security and secure SDLC | AI security tools, AI attacks, AI security for AppSec, SBOM security, Vulnerability scanning tools, Secure SDLC, Cloud native security practices, CI/CD security |
| Sprint 5 | AI governance and runtime | AI application security, Runtime security tools, AI risk management framework, AI code security, AI security testing, Vulnerability prioritisation, Vibe coding security |
The three-layer cluster
Every topic got three pages, not one. A definition page to own the concept, a tools listicle to capture buying intent, and an alternatives page to intercept competitor demand. All three link to each other, and all three link down to a product page.

The structure we repeated across every topic. Definition, listicle, alternatives, then product.
This is not a diagram we drew afterward. It is the reason the sprint sheet is organized into "Content Hub" rows. Every row in that sheet is one branch of this tree.
How we chose what to write about
Keyword selection was volume-weighted, but intent-led. We ran three filters on every candidate:
Buying intent. Does the query imply someone is choosing a tool, not just reading about a concept?
Beatable SERP. Is there a competitor page in the top ten that we can beat on depth, not just length?
Product proximity. Does the page have an obvious link into an OX product page?

Terms that failed the third filter got deprioritized even at high volume. That is why we passed on several 2,000-plus volume generic security terms and went hard at CI/CD security at 19,000, AI security at 4,500, and vulnerability scanning tools at 2,220.
How did we connect the blog to the product?
Rankings that don't touch a product page are a vanity metric. We built two link systems on top of the content, and ran them as a recurring monthly task rather than a one-off.
System one: three contextual sources per target page
Every priority page got a minimum of three inbound contextual links from other blog posts, chosen by topical proximity rather than convenience. The SAST tools page, for example, receives links from the AppSec testing tools page, the SAST vs SCA page and the application security testing page. Thirty target pages times three sources is ninety mapped blog-to-blog links, tracked in a sheet with a done status per month.
System two: every ranking page points at a product
This is the part most content programs skip. We mapped each blog cluster to the OX product it naturally sells, then placed a hyperlink or CTA button on every page in that cluster.
| Product page | Blog pages linking to it | Cluster it sits under |
|---|---|---|
| Application Security Platform | 18 | All hubs, hyperlink and CTA button |
| VibeSec | 18 | AI security, secure SDLC, CI/CD |
| OX Code | 18 | SAST, SCA, DAST, testing |
| OX Cloud | 12 | Containers, ASPM, CI/CD pipeline |
| OX Agentic Pentester | 13 | DAST, vulnerability scanning, assessment |
That is seventy-nine blog-to-product links, plus twelve CTA links pushing readers into the head-to-head comparison pages such as OX vs Snyk, OX vs Checkmarx, OX vs Black Duck and OX vs Aikido.
The same treatment was applied to every listicle and alternatives page, not just the educational hub pages. Nine tool listicles and four alternatives pages each received their own three mapped source links, so the SAST tools, SCA tools, DAST tools, container security tools, SBOM tools, vulnerability scanning tools and runtime security tools pages all sit inside the link graph rather than at the edge of it.
System three: the unglamorous monthly maintenance
Alongside the content, we ran a recurring technical hygiene cycle. In a single month that included 576 image alt tags rewritten, 30 internal links added, five listicles rewritten to match new product messaging, schema markup added, broken links found and fixed, oversized images compressed, nofollow applied to external links, and CTA buttons added to ten comparison and listicle pages.

None of that is exciting. All of it compounds.
How did OX end up inside Google's AI Overviews?
This was the outcome we did not fully price in when we started, and it turned out to be the most valuable one.
As of August 2026, OX Security is cited as a source inside Google AI Overviews for a large set of commercial AppSec queries. We pulled the fifty highest-volume AI Overview citations OX currently holds and traced each one back to the page that earned it.

That panel is the whole AI visibility picture in one frame. OX is pulled into 333 Google AI Overview responses across 65 distinct pages, and it is not limited to Google: 170 responses across 69 pages in Google AI Mode, 23 across 13 pages in Perplexity, 8 in Gemini, 7 in ChatGPT and 4 in Copilot.
The pattern that matters is the page count. Sixty-five pages earning citations means this is a structural result from the cluster, not one lucky article.
| What the AI Overview data shows | 29 of the top 50 AI Overview citations OX holds come from pages Infrasity wrote. 22 of those 29 come from tools listicles specifically, not definition pages. OX is cited in position 1 inside the AI Overview for web application security testing tools (1,300 searches a month), security testing tools for web application (1,300), software composition analysis sca tools (880), SBOM tools (320), and app security testing tools (260). |
Why listicles win in AI Overviews
An AI Overview needs to name options. A definition page explains a concept, which the model can already do on its own, so there is nothing to cite. A well-structured listicle hands the model a ready-made set of named tools with differentiators attached, which is exactly the shape of the answer the overview is trying to produce.
Once we saw that pattern in the Sprint 1 data, we deliberately over-indexed on listicles from Sprint 2 onward. Sixteen of the forty-plus pages we shipped are tools listicles or alternatives pages.
Not only that, but the blog we wrote is still ranking even after a year:


The pages doing the work
| Page | AI Overview citations in top 50 | Best position |
|---|---|---|
| /blog/application-security-testing-tools/ | 12 | 1 |
| /blog/static-application-security-sast-tools/ | 4 | 5 |
| /blog/software-composition-analysis-and-sca-tools/ | 4 | 1 |
| /blog/dynamic-application-security-testing-dast/ | 3 | 8 |
| /blog/application-security-testing/ | 2 | 19 |
| /blog/sbom-tools/ | 1 | 1 |
| /blog/vulnerability-scanning-tools/ | 1 | 7 |
| /blog/checkmarx-alternatives/ | 1 | 3 |
| /blog/application-vulnerability-assessment/ | 1 | 15 |
What did Reddit add on top?
Search results for tool comparison queries increasingly include Reddit threads. On the ten core category keywords we track for OX, reddit.com ranks in the top ten on five of them, including position 3 for SAST tools and position 4 for vulnerability scanning tools.
That means for a meaningful share of buying queries, a Reddit thread is competing with the vendor's own page, and AI Overviews are reading that thread as a source. So we ran a Reddit engagement program alongside the content: genuine, technically credible participation in AppSec threads where OX was a legitimate answer to the question being asked.
One of those comments is now being surfaced as a source in an AI Overview, which means OX gets represented in the answer twice: once through its own page and once through the community thread sitting next to it.
What were the results?
Rankings

Positions 1 to 3 grew 5.7x while the dead long tail was cleared entirely.
The shape of that chart is the whole point. In April 2025, the ranking profile was bottom-heavy: 1,737 keywords sat past position 20. By August 2026, that number is 94, and nothing at all sits past position 50. The footprint got smaller and far more valuable.

Ahrefs, 5 August 2026. 1,357 keywords, 509 in the top three, none past position 50.
Traffic

Baseline, peak and current run rate.
Traffic peaked at 20,129 visits in February 2026, a 358% increase on the April 2025 baseline. The current run rate of 8,626 is roughly double where OX started, on a keyword footprint half the size. We are showing you both numbers rather than only the peak, because the honest version of this chart is more useful to you than the flattering one.

Ahrefs, 25 February 2026. Peak organic traffic of 20,129.

Ahrefs, 22 July 2026. Stabilized at 8,626, roughly double the starting point.
Traffic quality

Branded dependence more than halved. Category demand now carries the blog.
Own brand traffic fell from 23.1% to 9.9% of the total while overall traffic doubled. In absolute terms, non-branded traffic went from 3,186 to 6,039 visits. OX is now being found by people who didn't know the company existed, which is the only kind of traffic that builds a pipeline.
Competitive position

DataForSEO SERP visibility across ten core AppSec category keywords, August 2026.
This is the number we would put on a slide if we could only keep one. Across ten core category keywords, OX Security now has a higher SERP visibility rating than Snyk, Wiz, Black Duck, Checkmarx, Cycode, Palo Alto Networks, Apiiro and Mend. OX ranks on nine of the ten. Its median position is 5. Snyk's median position on the same ten is 25.
| Keyword | OX position | Snyk | Checkmarx | Black Duck |
|---|---|---|---|---|
| container security solutions | 2 | 33 | 13 | 1 |
| container security tools | 4 | 10 | 2 | 15 |
| software composition analysis tools | 5 | 25 | 31 | 2 |
| sast tools | 5 | 15 | 7 | 10 |
| dast tools | 5 | 4 | 7 | 13 |
| sbom tools | 11 | 37 | 16 | Not ranking |
| application security testing tools | 11 | 25 | Not ranking | 10 |
| vulnerability scanning tools | 13 | 52 | Not ranking | Not ranking |
Which pages are doing the work

Ahrefs top pages, August 2026. 159 blog pages driving 7.7K visits.
| Page | Monthly traffic | Share of blog traffic |
|---|---|---|
| /blog/cloud-native-security-practices/ | 1,193 | 15.6% |
| /blog/software-composition-analysis-and-sca-tools/ | 853 | 11.1% |
| /blog/application-security-testing-tools/ | 519 | 6.8% |
| /blog/application-vulnerability-management/ | 498 | 6.5% |
| /blog/container-security-tools-2026/ | 317 | 4.1% |
| /blog/understanding-and-mitigating-software-supply-chain-risk/ | 244 | 3.2% |
Six pages carry 47.3% of all blog traffic, and five of the six are pages from our sprint plan. The top page, cloud native security practices, went from not existing to 1,193 visits a month.
For context on value: DataForSEO puts the paid equivalent cost of OX's current organic footprint at roughly $124,000 a month. That is what it would cost to buy this traffic through Google Ads.
What can you take from this and run tomorrow?
Four things came out of this program that transfer to almost any technical category. All four are backed by the data above.
1. Track visits per ranking keyword, not keyword count
Most reporting celebrates keyword growth. That is backward. Divide organic sessions by ranking keywords, and you get a yield number. OX went from 1.64 to 5.64, a 3.4x improvement, while the keyword count halved. If your yield is under 2, you have a consolidation problem, not a publishing problem.
2. Merging pages beats publishing new ones on contested terms
Five SBOM pages ranking between positions 20 and 60 became one page cited in position 1 inside Google's AI Overview for SBOM tools. Four ASPM pages became one page ranking at position 8 for a 1,900-volume head term. If you have more than one live page on a topic and none of them are in the top ten, the answer is rarely a sixth page.
3. Listicles are the currency of AI Overviews
22 of the 29 AI Overview citations we earned for OX come from tools listicles, not definition content. An overview needs named options with differentiators. Give the model a table it can lift, and you get cited. Give it a definition, and it writes its own.
This is exactly what app.infrasity.com reveals.

4. Every ranking page needs a product link, engineered not improvised
We placed seventy-nine deliberate links from blog pages to OX product pages, mapped cluster by cluster, with the anchor text and link format decided in advance. Rankings without that layer are just traffic. Rankings with it are a distribution system.
Work with the team that built OX
Everything described above was delivered by Infrasity. If you want the same program, these are the exact services OX used.
For the full program: audit, consolidation, sprint planning, writing, publishing, and reporting. https://www.infrasity.com/contact
For more case studies: https://www.infrasity.com/case-studies





