Does Google offer a qualifying DevSecOps platform?
Gartner says yes. It has even placed Google in the Magic Quadrant dedicated to this market segment. This is the fourth edition… but the first to include security in its title—and in the list of mandatory criteria. Specifically, vendors had to demonstrate the ability to orchestrate features such as code analysis, threat modeling, and API protection.
Google appeared in the first edition (2023). It subsequently vanished from the roster, due to not having a platform-level offering. Gartner believes things have changed. Not drastically, though: we’re more of a “collection of tools” that aren’t specifically built for DevSecOps and are combined without a global product strategy.
In this context, Google sits among the “niche players.” It sits alongside, in this quadrant, Buildkite, CircleCI, CloudBees, JetBrains, and Octopus, all of which were already there last year. OpenText is a new entrant. IBM and HCLSoftware are classified, for their part, as “visionaries.”
DevSecOps Platform: 13 Vendors, 4 “Leaders”
According to the Magic Quadrant terminology, “visionaries” are suppliers positioned in the lower half of the execution axis… and in the upper half of the vision axis. The former reflects the ability to meet demand (customer experience, pricing, product/service quality…). The latter reflects the strategies (sales, innovation, industry and geographic deployment…). Vendors placed in the opposite quadrant are described as “challengers.” Those well positioned on both axes are “leaders.” Those at the far end are “niche players.”
The picture on the execution axis:
| Rank | Vendor | Year-over-year |
| 1 | Atlassian | = |
| 2 | Harness | = |
| 3 | GitLab | = |
| 4 | Microsoft | = |
| 5 | HCLSoftware | new entrant |
| 6 | Buildkite | + 1 |
| 7 | CloudBees | + 1 |
| 8 | IBM | new entrant |
| 9 | Octopus | – 3 |
| 10 | new entrant | |
| 11 | JetBrains | – 2 |
| 12 | CircleCI | -2 |
| 13 | OpenText | new entrant |
On the “vision” axis:
| Rank | Vendor | Year-over-year |
| 1 | Harness | + 1 |
| 2 | Microsoft | + 3 |
| 3 | GitLab | = |
| 4 | Atlassian | – 3 |
| 5 | IBM | new entrant |
| 6 | HCLSoftware | new entrant |
| 7 | CloudBees | = |
| 8 | new entrant | |
| 9 | OpenText | new entrant |
| 10 | Buildkite | – 4 |
| 11 | JetBrains | – 1 |
| 12 | CircleCI | – 4 |
| 13 | Octopus | – 4 |
The four “leaders” from last year remain in place:
- Atlassian (advances on execution, slips on vision)
- GitLab (advances on execution, stable on vision)
- Harness (advances on both axes)
- Microsoft (advances on both axes)
Atlassian Ends the On-Prem Option
Gartner praises the SLA levels and security of Atlassian’s SaaS offering, as well as data residency options. It also highlights the platform’s unification, the way AI is embedded within it, and its ability to meet the needs of different stakeholders across the SDLC.
Although technically unified, the platform isn’t commercially unified—there is no single SKU—except for the largest customers. Atlassian also offers fewer native security modules than the other “leaders.” It is also the only one without a viable on-site option, according to Gartner. Behind this stance lies last year’s announcement of the sunsetting of the Datacenter range in 2029, with exceptions for Align and Bitbucket.
GitLab, a Restructuring that Leaves Traces
At GitLab, SaaS and on-prem are functionally on par, including the AI components. Its SLAs have been strengthened, matching or surpassing those of the competition. Overall, it offers, natively, most of the capabilities one would expect from a DevSecOps platform, Gartner notes.
Unlike Atlassian, GitLab lacks a holistic footprint across the SDLC beyond the software engineering domain. Its indirect business yields modest results in the Asia-Pacific region, and the AI-driven restructuring announced recently has not won universal buy-in from all employees.
Harness, Not at the Level of Competition on SLAs
Harness manages to integrate open-source solutions effectively, as well as the companies it has acquired. Gartner commends its value proposition around security, MLOps, and agentic AI. It also approves of the platform’s modular sales approach.
Geographic differences in the services and support offered by its partners prove uneven. The SLAs do not reach the level of the competition, whether in availability or response times. Harness’s marketing also remains fairly detached from the C-suite population.
On GitHub, Microsoft Prioritizes AI at the Core of Functionality
Beyond its global footprint (sales, support, R&D, datacenters…) and more broadly the viability of its business, Microsoft has built a vast ecosystem around its offering. Gartner regards it as functionally rich, while noting the integrative bridges with other DevSecOps solutions. It also applauds the way AI is integrated there.
This focus on AI tends to slow the pace of innovation on GitHub’s core functionality. In parallel, the transition from a centralized model to consumption-based billing complicates cost management. And the Azure DevOps offering remains on the catalog, necessitating an assessment of complementarity and/or overlap with GitHub.
* Cloud Build, Cloud Deploy, Artifact Registry, Gemini Code Assist, Gemini Cloud Assist, Security Command Center, Secret Manager, Google Cloud Observability, Gemini Enterprise