# Shopping-Shape Cross-Section: In 26 of 33 Cases a Vendor Holds a Top-10 AI Citation Slot in Only One Question Shape

> Across 39 published shopping segments of the Machine Relations Index, a vendor-owned domain reaches a top-10 citation slot in its category 33 times; only 7 of those hold across more than one question shape. Huntress leads cybersecurity best-tools answers at 58.7% and is not cited in top-list answers at all.

- Published: 2026-09-18
- URL: https://paralabs.ai/blog/vendor-citation-shopping-question-shape-cross-section
- Tags: ai-visibility, brand-visibility, commerce, measurement, case-study

---

The mechanic measured here is **shape-specific citation**: whether a vendor's own domain earns citation per buyer question shape rather than per brand. Across the 39 published shopping segments of the Machine Relations Index, a vendor-owned domain reaches a top-10 citation slot inside its own category 33 times, across 30 distinct domains. Only 7 of those 33 hold a slot in more than one of the three shopping shapes. Twenty-six hold exactly one and drop out of the other two.

This is a cross-section, not an experiment. It reports what six engines cited over a fixed 125-day window. It makes no claim that any page, placement, schema change, or campaign caused a citation rate, and it does not compare a before to an after. Para Labs publishes it as a measured baseline that a later experiment can move against.

## The measurement

The source is the public view of the [Machine Relations Index](https://machinerelations.ai/index), contract `machine_relations_index_public_view_v2.0`, methodology `mri_score_v2.0`, generated 2026-09-18. The [machine-readable release](https://machinerelations.ai/data/machine-relations-index.json) carries the numbers below.

| Field | Value |
| --- | --- |
| Window | 2026-05-10 to 2026-09-18, 125 days observed |
| Answer runs | 15,782 |
| Citation events | 124,397 |
| Cited source domains | 22,179 |
| Eligible monitored queries | 912 |
| Engines | ChatGPT, Claude, Gemini, Google AI Mode, Google AI Overviews, Perplexity |
| Evidence floor per segment | 10 observed runs across 7 distinct run dates |

A segment is one subject category paired with one buyer question shape. The index tracks 157 segment rows; 151 are collectable and 6 are structurally not collectable. Of the collectable rows, 85 have passed the evidence floor and publish a rate. This cross-section uses only published segments.

Three of the six shapes are shopping and selection shapes: `best_x` (best tools in a category), `top_list` (ranked roundups) and `x_vs_y` (head-to-head comparison). Thirteen categories publish all three, giving 39 published shopping segments. Within each segment every cited domain carries a citation rate — the share of observed answer runs in that segment in which the domain was cited — and a source-role class assigned by the index.

## Only 7 of 33 vendor domains carry across shapes

For each of the 39 segments, the top ten domains by citation rate were taken and filtered to the `vendor_owned` class. The unit counted below is the domain-and-category pair, because the question is whether one brand holds across shapes inside one category. That produced 33 pairs across 30 distinct domains; three domains (`ibm.com`, `paloaltonetworks.com`, `nvidia.com`) appear in two categories each.

| Shapes in which the vendor holds a top-10 slot in its category | Vendor–category pairs |
| --- | --- |
| Exactly one shape | 26 |
| Two or more shapes | 7 |
| Total | 33 |

The seven that carry are `sentinelone.com`, `cynet.com` and `paloaltonetworks.com` in cybersecurity, `therankmasters.com` and `semrush.com` in AI visibility, `experian.com` in consumer finance and `stripe.com` in fintech. No vendor holds a top-ten slot in all three shopping shapes of one category.

## Three named brand sets

The persistence count is an aggregate. The per-brand view is where the size of the gap shows. Positions are within the published segment for that category and shape; `n` is the number of domains cited in that segment.

**Cybersecurity** ([segment leaderboard](https://machinerelations.ai/index/categories/cybersecurity/best_x))

| Vendor domain | best_x | top_list | x_vs_y |
| --- | --- | --- | --- |
| [huntress.com](https://www.huntress.com/) | #1 of 213, 58.7% (44/75) | not cited | #13 of 189, 8.4% (9/107) |
| [sentinelone.com](https://www.sentinelone.com/) | #2 of 213, 36.0% (27/75) | #11 of 264, 10.0% (13/130) | #2 of 189, 25.2% (27/107) |
| cynet.com | #3 of 213, 33.3% (25/75) | #170 of 264, 0.8% (1/130) | #5 of 189, 18.7% (20/107) |
| [crowdstrike.com](https://www.crowdstrike.com/) | #20 of 213, 9.3% (7/75) | #126 of 264, 1.5% (2/130) | #4 of 189, 18.7% (20/107) |
| [paloaltonetworks.com](https://www.paloaltonetworks.com/) | #8 of 213, 20.0% (15/75) | #39 of 264, 5.4% (7/130) | #8 of 189, 14.0% (15/107) |
| [wiz.io](https://www.wiz.io/) | not cited | #9 of 264, 10.8% (14/130) | not cited |

**Fintech** ([segment leaderboard](https://machinerelations.ai/index/categories/fintech/top_list))

| Vendor domain | best_x | top_list | x_vs_y |
| --- | --- | --- | --- |
| [stripe.com](https://stripe.com/) | #85 of 224, 1.8% (2/108) | #1 of 200, 24.5% (25/102) | #8 of 136, 10.8% (11/102) |
| [airwallex.com](https://www.airwallex.com/) | #1 of 224, 38.9% (42/108) | not cited | #13 of 136, 8.8% (9/102) |
| [adyen.com](https://www.adyen.com/) | not cited | #9 of 200, 11.8% (12/102) | #15 of 136, 7.8% (8/102) |

**AI infrastructure** ([segment leaderboard](https://machinerelations.ai/index/categories/ai-infrastructure/x_vs_y))

| Vendor domain | best_x | top_list | x_vs_y |
| --- | --- | --- | --- |
| [nvidia.com](https://www.nvidia.com/) | #57 of 204, 3.9% (3/77) | #2 of 270, 25.0% (27/108) | not cited |
| [databricks.com](https://www.databricks.com/) | #58 of 204, 3.9% (3/77) | not cited | #2 of 231, 29.6% (32/108) |
| [ibm.com](https://www.ibm.com/) | #114 of 204, 1.3% (1/77) | #92 of 270, 1.8% (2/108) | #3 of 231, 22.2% (24/108) |

Stripe is cited in a quarter of fintech ranked-roundup answers and in under two percent of fintech best-tools answers. Nvidia leads AI-infrastructure roundups and is not cited in any observed AI-infrastructure comparison run. Databricks is the inverse of Nvidia in the same category. These are the same brands, the same category, the same 125 days.

## Engine presence is not the variable

A natural explanation for a missing citation is that the domain is absent from some engines. In this brand set it is not. The index records per-engine presence in the window — which engines cited the domain at least once. Every leader named above was cited by all six.

| Vendor domain | Engines that cited it | Overall citation rate | Confidence | Rank within 823 vendor-owned domains |
| --- | --- | --- | --- | --- |
| ibm.com | 6 of 6 | 1.93% | A | #2 |
| sentinelone.com | 6 of 6 | 1.27% | B | #5 |
| stripe.com | 6 of 6 | 0.98% | B | #7 |
| [hubspot.com](https://www.hubspot.com/) | 6 of 6 | 0.90% | B | #10 |
| nvidia.com | 6 of 6 | 0.89% | B | #11 |
| databricks.com | 6 of 6 | 0.87% | B | #12 |
| crowdstrike.com | 6 of 6 | 0.66% | B | #16 |
| huntress.com | 6 of 6 | 0.60% | C | #19 |
| airwallex.com | 6 of 6 | 0.56% | C | #23 |
| [semrush.com](https://www.semrush.com/) | 6 of 6 | 0.54% | C | #26 |

Huntress is cited by all six engines and holds the top cybersecurity best-tools slot at 58.7%, and its top-list citation count in that category is zero. A brand can be universally reachable and still be shape-specific. That is consistent with how the engine operators describe retrieval: Google documents AI features as drawing on its ordinary crawl and index ([Google Search Central](https://developers.google.com/search/docs/appearance/ai-features)) with product data exposed through structured data or feeds ([Google Search Central](https://developers.google.com/search/docs/appearance/structured-data/product)), Perplexity documents query-time search over live sources ([Perplexity docs](https://docs.perplexity.ai/getting-started/overview)) with domain-level filtering available to callers ([Perplexity docs](https://docs.perplexity.ai/guides/search-domain-filters)), and Anthropic documents a web search tool that retrieves and cites per request ([Anthropic docs](https://docs.anthropic.com/en/docs/agents-and-tools/tool-use/web-search-tool)). Retrieval is per query. The question text is part of the query.

## The class mix shifts through the funnel

Aggregating the same 39 segments by source-role class shows the shape effect above the level of any one brand. Each shape has 13 published segments and therefore 130 top-ten slots.

| Source-role class | best_x | top_list | x_vs_y |
| --- | --- | --- | --- |
| Vendor-owned | 9 (6.9%) | 12 (9.2%) | 19 (14.6%) |
| Editorial publication | 23 (17.7%) | 13 (10.0%) | 14 (10.8%) |
| Community and social | 12 (9.2%) | 11 (8.5%) | 17 (13.1%) |
| Search and media platform | 8 (6.2%) | 7 (5.4%) | 10 (7.7%) |
| Academic and government | 4 (3.1%) | 4 (3.1%) | 5 (3.8%) |
| Market and company database | 3 (2.3%) | 2 (1.5%) | 1 (0.8%) |
| Analyst research | 0 | 4 (3.1%) | 1 (0.8%) |
| Unclassified long tail | 71 (54.6%) | 77 (59.2%) | 63 (48.5%) |

Vendor-owned share of top-ten slots roughly doubles from the best-tools shape to the comparison shape, 6.9% to 14.6%. Editorial share falls by a third, 17.7% to 10.0%. Counting which class holds the single top slot in each segment, editorial publications hold 4.5 of 13 best-tools segments (one segment is a tie, split fractionally) and 0 of 13 comparison segments.

Read the unclassified row as a denominator artifact and not as a finding. The index leaves 18,623 of 22,179 domains unclassified, so that class takes about half of every top-ten regardless of shape. The comparison that carries meaning is between classified classes and between shapes within one class.

## Authority does not decide the segment

Within a single category and shape, ordering does not follow brand size. In cybersecurity best-tools answers, huntress.com is cited in 58.7% of observed runs and crowdstrike.com in 9.3% — the same 75 runs, the same seven run dates. Both are cited by all six engines. Whatever separates them in that segment is not reach and is not company scale.

A related caution applies to the source-role labels themselves. The index classifies domains by what the domain is, and vendor-operated media properties sit inside the editorial class in several categories. Read the class as measured and check who operates a domain before treating it as third-party.

## What a brand-side operator can take from this

Three things follow from the cross-section, and none of them is a causal claim.

1. **A single visibility number hides the failure.** Huntress at 0.60% overall and #19 among vendor-owned domains looks unremarkable, and it leads its category's best-tools segment. Aggregate rates and per-segment rates answer different questions.
2. **Measure per shape before changing anything.** The same brand can be first and absent in one category. A baseline that does not separate best-tools, roundup and comparison answers cannot detect a shape-specific gap and cannot show that one closed.
3. **The seven carriers are the hypothesis worth testing.** Twenty-six of 33 vendor–category pairs hold one shape. Whether the seven that hold two or more share a source-layer property — comparison pages, specification tables, per-competitor documentation — is a testable question, and this release is the frozen baseline to test it against.

## Limits

This is one release. Segments below the evidence floor publish no rate, so "not cited" in a table above means zero cited runs in a published segment, not a claim about a brand's visibility outside the index. The index runs the market's buyer questions, not queries about any one brand, so it cannot report whether a specific brand's own pages are performing. Citation rate is not traffic, ranking, or revenue. Nothing here establishes that a source-side change moves a segment; that requires a paired design with a frozen baseline, and the release identifier above is what a later read must be compared against.

## FAQ

**What is a question shape?**
A buyer intent pattern the index groups queries into. The three shopping shapes are best tools in a category (`best_x`), ranked roundups (`top_list`) and head-to-head comparisons (`x_vs_y`). The index also tracks how buyers choose, is-it-worth-it and problem-first shapes.

**Does "not cited" mean the brand is invisible?**
No. It means the domain had zero cited runs in that published segment during the window. The brand may be cited in other segments, other categories, or in queries the index does not monitor.

**Why do vendor-owned domains do better in comparison answers?**
The cross-section reports the pattern, not the cause. Vendor-owned share of top-ten slots rises from 6.9% in best-tools answers to 14.6% in comparison answers. A plausible mechanism is that head-to-head questions pull toward primary specification sources, but that is a hypothesis this design cannot test.

**How many engines does this cover?**
Six: ChatGPT, Claude, Gemini, Google AI Mode, Google AI Overviews and Perplexity, across 15,782 answer runs in the window.

**Can I reproduce these numbers?**
Yes. The release is public. Filter `domains[].mri_score_v2.strata[]` to `status: "published"` and to the three shopping shapes, rank within each category-and-shape segment by `citation_rate`, and join `source_role` from the domain record.

## Machine-readable related links

- Primary concept: [Ai Visibility](https://paralabs.ai/blog)
- Related concept: [Brand Visibility](https://paralabs.ai/blog)
- Related concept: [Commerce](https://paralabs.ai/blog)
- Related concept: [Measurement](https://paralabs.ai/blog)
- Supporting research: [Product-Variant Attribution Protocol for AI Shopping Answers](https://paralabs.ai/blog/product-variant-attribution-ai-shopping-answer-protocol)
- Supporting research: [Locale and currency consistency protocol for AI shopping answers](https://paralabs.ai/blog/locale-currency-consistency-ai-shopping-answer-protocol)
- Supporting research: [Why AI Visibility Scores Differ Between Tools](https://paralabs.ai/blog/why-ai-visibility-scores-differ-between-tools)
- Research index: [Para Labs research index](https://paralabs.ai/blog)
- Machine manifest: [Para Labs machine manifest](https://paralabs.ai/machine-manifest.json)
