All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Semgrep sells static analysis, dependency scanning, and secrets detection to application security teams and the developers whose code it scans, priced per contributor above a free tier capped at ten. It now sells the same scanning to AI coding agents through Guardian, a plugin that blocks malicious packages and hardcoded credentials as an agent writes them. What Semgrep keeps is a catalog its repository puts at more than 20,000 rules, written by its own research team. Nine rival toolmakers forked the free scanning engine as Opengrep after a license change. An independent study on production code raised Semgrep's rate only after the researchers wrote new rules for it. Most defensible for teams that need source-code analysis to stay on their own machines.
| Description | Semgrep unifies static application security testing, software composition analysis, and secrets scanning in one platform, and extends the same scanning to AI coding agents. | [f1] |
|---|---|---|
| Founded | 2017 | [f2] |
| HQ | San Francisco, California, USA | [f3] |
| Funding | $204M total | [f4] |
| Latest funding | Series D, $100M (February 2025), led by Menlo Ventures | [f4] |
| Deployment | SaaS, Self-hosted | [f5] |
| Product | What it does |
|---|---|
| Semgrep | Static analysis platform that scans code regardless of who or what wrote it, with a Guardian mode and Multimodal AI that find and help fix vulnerabilities in AI-generated code as it lands. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Semgrep scans code regardless of who or what wrote it, with a Guardian mode and Multimodal AI that find and help fix vulnerabilities in AI-generated code as it lands. It is mapped to the AI Defense Matrix. [f6]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Semgrep provides static analysis, software composition analysis, and secrets scanning. This conventional security is mapped to the Cyber Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | Semgrep names the application security team and the developers whose code it scans, and outside research quantifies the pain it sells against. Lancaster University researchers testing four scanners on production code with known vulnerabilities found individual detection rates of 11.2 to 26.5 percent, and a separate academic evaluation measured a standalone Semgrep run on the OWASP Benchmark at an F1 score of 0.784 with precision of 0.695. Two non-vendor measurements of the same problem clear the bar here. [s13, s14, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Product pages document cross-file analysis, reachability-aware dependency scanning, and secrets detection that validates a credential inside the customer's own infrastructure, and the scanning engine itself is open source and inspectable. Outside parties work directly on that engine: Lancaster University researchers reconfigured it to reach 44.7 percent detection, an independent preprint uses it as its scanning baseline, and an outside reviewer compares the free and paid editions and records the vendor-funded provenance of Semgrep's benchmark. [s2, s3, s4, s6, s13, s14, s16] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is concrete. Semgrep ships Guardian, a plugin that installs into an AI coding agent and stops malicious packages and hardcoded credentials as the agent writes them, with plugins published on the Claude Code and Cursor marketplaces. What the reviewed record does not carry is a second, independently documented buyer-side signal from the past year. The one analyst marker, a placement in Gartner's October 2025 Magic Quadrant for Application Security Testing, reaches the record through Semgrep's own announcement. [s8, s6, s17] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Drew Dennison, Isaac Evans, and Luke O'Malley founded Semgrep in 2017, and in 2020 the team reignited the open source project that became the product. The community standing behind that work is multiply evidenced: the engine carries 16.4 thousand GitHub stars, the public registry holds more than 3,000 community rules by an outside reviewer's count, and an in-house security research team writes and maintains the 20,000-plus proprietary rules the paid platform ships. [s5, s6, s16] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Semgrep's repository names GitLab, Dropbox, Slack, Figma, Shopify, HashiCorp, Snowflake, and Trail of Bits as users, and an outside reviewer repeats six of those names. Scale is the company's own measurement: SiliconANGLE reported that Semgrep disclosed adoption by hundreds of organizations, and the 2025 Gartner placement reaches the record through Semgrep's press release. Verifiable marketplace motion holds the score here, with Guardian downloadable from the Claude and Cursor marketplaces. [s16, s10, s17, s8] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | SiliconANGLE reported a 100 million dollar Series D led by Menlo Ventures that lifted outside funding to 204 million dollars, and shipping is visible in the Guardian launch and the three paid scanning products. No revenue or margin appears in the reviewed sources, so output per dollar stays unconfirmed. The raise is proportional to a company founded in 2017 selling a multi-product platform, which is the honest default rather than capital outrunning results. [s10, s8, s7] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Semgrep sells into application security testing, an established analyst category, and Gartner published a Magic Quadrant for that category in October 2025 that included Semgrep. Independent technology press describes the company as a code-scanning vendor without needing its framing. The placement reaches the record through Semgrep's own press release rather than an independently published report, which is what keeps the score below the top rung. [s17, s11, s16] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Editor, pipeline, and pull-request embedding creates real friction against a platform vendor absorbing this as a feature, and the maintained rule catalog is content a rival would have to accumulate. The friction is not structural. Nine application security toolmakers forked the free engine as Opengrep, which shows the layer that draws developers in is reproducible. Distribution through third-party agent marketplaces is reach rather than lock-in. [s11, s12, s6, s8] |
Semgrep sells to the application security team and to the developers whose code it scans, and it frames the problem as scanner noise that buries the findings worth fixing. The platform unifies static analysis, dependency scanning, and secrets detection so the checks run where developers already work, in editors, pull requests, and build pipelines. The company traces that work back to 2017, when Drew Dennison, Isaac Evans, and Luke O'Malley founded it, and to 2020, when the team reignited the open source project that became the product.
The newer framing is code that AI agents write. Semgrep now sells Guardian, a plugin that installs into an AI coding agent and stops malicious packages, hardcoded credentials, and unsafe patterns at the moment the agent writes them.
Independent research quantifies the pain that vendor pages only assert. Lancaster University researchers testing four scanners on production code with known vulnerabilities found individual detection rates of 11.2 to 26.5 percent, and a separate academic evaluation measured a standalone Semgrep run on the OWASP Benchmark at an F1 score of 0.784. Gartner published a Magic Quadrant for Application Security Testing in October 2025, which is the category Semgrep sells into. [s5, s1, s8, s13, s14, s17]
Semgrep ships a free open-source engine and a paid platform on top of it. Semgrep Community Edition is the open-source program analysis engine, and its own repository warns that in security contexts the free edition misses many true positives because it analyzes within the boundaries of a single function or file. The paid platform adds cross-file analysis, Semgrep Supply Chain for reachability-aware dependency scanning and open-source malware blocking, and Semgrep Secrets, which uses semantic and entropy analysis and validates a credential by calling the service from inside the customer's own infrastructure.
An AI layer sits across the scanners. Semgrep Multimodal pairs deterministic static analysis with AI reasoning, and Semgrep reports that it finds up to 3.5 times more true positives at 19 percent lower cost per true positive than AI alone and cuts the findings a team must triage by 20 percent the day it is switched on. Triage decisions feed back, so the platform learns the organization-specific context that decides whether a finding is exploitable.
Semgrep Guardian carries the same scanning to AI coding agents. It bundles an MCP server, hooks, and skills into a plugin that installs into an agent, and its firewall blocks malicious packages at the network layer before they install.
The outside work in the reviewed record treats Semgrep as a configurable baseline rather than confirming its accuracy claims. Lancaster University researchers reconfigured it to reach 44.7 percent detection, more than combining four scanners. An independent preprint measured a standalone Semgrep run on the OWASP Benchmark at an F1 score of 0.784 and removed 496 of its false positives with an added filter. An outside reviewer records the 72 percent WebGoat result as vendor-funded research on a deliberately vulnerable training application rather than an independent cross-scanner test, and a public CVE for a Semgrep dependency is on record. [s6, s2, s3, s4, s8, s13, s14, s16, s15]
Semgrep competes against larger application security platforms and against a fork of its own engine. Semgrep's site offers a program for teams moving off Checkmarx or Snyk, so the company names the accounts it wants to take.
The structural pressure is on the open-source flank. Dark Reading reports that the triggering event for the split came on December 13, when Semgrep outlined changes to features of the free edition, and quotes an Opengrep backer saying Semgrep's biggest competitor had become its own open source engine. A consortium of application security companies then launched Opengrep, a fork of the Community Edition, keeping the same LGPL license and stating that it would restore the removed features and create an open source database of rules.
Parity between the fork and the paid platform is not established. An outside reviewer records that Opengrep restored cross-function taint analysis and other features Semgrep had moved behind its paid tier, while Opengrep's own page still lists cross-file analysis and extended language support among the capabilities it will unlock. The cited record shows no reproduction of the 20,000-plus proprietary rules the paid platform ships. [s1, s11, s12, s18, s16, s6]
Semgrep runs a product-led motion seeded by a free engine. The Free Edition costs nothing for up to 10 contributors and signs up directly, the Teams plan starts at 30 dollars per contributor per month, and Enterprise pricing is custom, so the published rate card covers the smaller team and the larger deal is negotiated.
The named-customer record is real and mostly vendor-sourced. Semgrep's repository names GitLab, Dropbox, Slack, Figma, Shopify, HashiCorp, Snowflake, and Trail of Bits as users, and an outside reviewer names Lyft, Dropbox, Snowflake, HashiCorp, Trail of Bits, GitLab, and Figma, six of them repeats of the repository's list. Scale is the company's own measurement, since SiliconANGLE reported that Semgrep disclosed adoption by hundreds of organizations since launch.
Analyst recognition arrived in 2025 and reached the record through Semgrep. The company announced its first placement in Gartner's Magic Quadrant for Application Security Testing, published in October 2025, in its own press release. Distribution now runs through AI coding tools as well, with Guardian downloadable from the Claude and Cursor marketplaces.
Semgrep discloses its funding and not its revenue. SiliconANGLE reported a 100 million dollar Series D led by Menlo Ventures that lifted outside funding to 204 million dollars, and no audited revenue figure appears in the reviewed sources. [s7, s6, s16, s10, s17, s8]
Semgrep's founders built the company from an open-source project into the platform it sells today. Drew Dennison, Isaac Evans, and Luke O'Malley founded Semgrep in 2017, and in 2020 the team reignited development of the open source project sgrep that became the product. Isaac Evans is chief executive.
The engine carries 16.4 thousand GitHub stars, the public registry holds more than 3,000 community rules by an outside reviewer's count, and an in-house security research team writes and maintains the 20,000-plus proprietary rules the paid platform ships.
Investors back the team. Menlo Ventures led the Series D, with Felicis Ventures, Harpoon Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital participating. [s5, s6, s16, s17, s10]
Semgrep publishes an inspectable trust portal, and an intrusion has now tested it. The portal announces a SOC 2 Type II report covering December 2023 through November 2024 and a full-scope whitebox penetration test performed by Include Security. The reviewed sources record no federal authorization and no product-specific mandate, so the assurance eases a procurement review without blocking a funded substitute.
The incident is the kind a code-scanning buyer fears. Semgrep disclosed that the Qilin group released Semgrep scan results of Semgrep's own source code, obtained through a Semgrep API token used to reach a sandbox environment, and says its completed post-incident investigations confirmed the threat actor did not access customer findings or source code and that the integrity of its source code and release processes was not compromised.
Semgrep's default keeps source code where the customer already holds it. Semgrep analyzes code locally or in the build environment and does not upload it by default, and its pricing page states that opting into AI-powered detection, triage, and remediation sends the part of the file containing a finding to a model for processing, with model vendors barred from training on the submitted code. [s9, s6, s7]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Snyk | competes with | Contests the same developer-first code-security buyer. Semgrep's site offers a program for teams switching off Snyk. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Checkmarx | competes with | Established application-security-testing vendor selling into the same category. Semgrep's site offers a program for teams switching off Checkmarx. | |
| GitHub | adjacent | Developer platform whose CodeQL an outside reviewer names as one of the closest substitutes to Semgrep for teams comparing rule-driven static analysis. | |
| Opengrep | competes with | Fork of Semgrep's Community Edition launched after Semgrep changed its open-source rule license, contesting the free-engine developers who feed Semgrep's paid funnel. | |
| Orca Security | competes with | Named by Dark Reading and InfoQ as one of the application security companies backing the Opengrep fork of Semgrep's engine. | |
| Endor Labs | competes with | Named by Dark Reading as one of the application security toolmakers that banded together to fork Semgrep's engine. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Aikido Security | competes with | Named by Dark Reading as one of the application security toolmakers that banded together to fork Semgrep's engine. | |
| SonarQube | competes with | Named by an outside reviewer as a substitute chosen when quality gates and pull-request workflows matter more than security depth. |
Add analyzed competitors to compare them side by side with Semgrep.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Semgrep is durable on a hard program-analysis problem and on the rule catalog behind its paid platform, and thin elsewhere. Nine application security toolmakers forked its free edition, and they now pool OCaml developers and fund a full-time team to advance their copy. The catalog of more than 20,000 rules Semgrep's research team writes and maintains stays with the company, apart from the community rules its registry lists. Leaving the platform costs the work of re-integrating editors, pipelines, and pull-request checks, and the cited record does not size that migration. It fits best where a team must keep source-code analysis on its own machines.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Semgrep sells software the customer's own team installs, configures, and runs, from the open-source engine to the paid platform. The scanning findings, the AI triage decisions, and the remediation suggestions that appear in pull requests are automated output of that software, and the customer's own developers decide what to merge. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Editor, pipeline, and pull-request integration plus custom rules and accumulated triage context create real friction to replace. The rule language is not a lock, because the engine is open source, the syntax mirrors the code a team already writes, and the Opengrep fork says it will be backward compatible with it. The cited record documents no mechanism beyond that integration work and does not size the migration. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The trust portal publishes a SOC 2 Type II report and a full-scope third-party penetration test, which ease a procurement review and which a funded competitor obtains through ordinary enterprise preparation. The reviewed sources identify no federal authorization, no product-carried mandate, and no retained liability that would block a substitution. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Semgrep's engine traces data flow across files and functions, scores dependency reachability, and validates live credentials, which is program-analysis work rather than integration. The vendors who forked the free engine describe pooling OCaml development power and funding a full-time developer team to advance it, and Lancaster University researchers had to author new rules before the tool reached 44.7 percent detection. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | Semgrep publishes per-contributor rates and a Free Edition that costs nothing for up to 10 contributors and signs up directly, so adoption starts with developer choice rather than a procurement review. Enterprise pricing is custom and the named users include large engineering organizations, so the buyer band spans self-serve teams as well as gated enterprises rather than the regulated buyer alone. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Semgrep is application-layer tooling that scans and gates code across the development pipeline. No customer traffic runs through it, and removing it stops the scanning rather than an application. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | Semgrep retains a curated rule catalog rather than only shipping public content. Its repository states the platform works out of the box with more than 20,000 proprietary rules across static analysis, dependency scanning, and secrets, written and maintained by its own security research team, and the pricing page repeats that Pro rules are proprietary. The public registry holds a separate set of about 3,000 community rules, so the paid catalog is not shown to be public. A funded rival could accumulate comparable coverage with time and effort, which is this rung's own standard. |
Semgrep sells to the application security team and to the developers whose code it scans, and its free tier extends that down to a single team. The Free Edition covers up to 10 contributors with authentication through GitHub or GitLab, so a team adopts without a sales conversation.
The free-to-paid funnel defines the segment more than any single named buyer. An outside reviewer describes the Community Edition as a free open-source engine limited to single-file analysis, and the AppSec Platform as the tier that adds cross-file analysis, dependency scanning, and secrets detection. The Free Edition sits between them, listing cross-file analysis with Pro rules while stopping at 10 contributors.
The newer segment is the team shipping AI-written code. Guardian installs into an AI coding agent and enforces the same rules there, which keeps the buyer inside the engineering organization rather than a separately cultivated market.
Semgrep's claimed advantage is pairing deterministic static analysis with AI reasoning rather than choosing one. Semgrep Multimodal uses rule-based analysis for classic flaws such as cross-site scripting and injection and AI models for business-logic vulnerabilities, and Semgrep reports 3.5 times more true positives at 19 percent lower cost per true positive than AI alone.
The scanning footprint spans the three established testing categories. Semgrep Code does cross-file analysis, Semgrep Supply Chain does reachability-aware dependency scanning and blocks open-source malware, and Semgrep Secrets uses semantic and entropy analysis and validates a credential inside the customer's own infrastructure, so one engine covers static analysis, composition analysis, and secrets.
The durable assets are the engine and the rule corpus, both Semgrep's own. The separate AI layer depends on outside model providers. The trust portal records that Semgrep Assistant added Amazon Web Services Bedrock as a model provider, and the pricing page states that opting into AI features sends the part of a file containing a finding to a model for processing.
Semgrep runs a product-led motion seeded by a free engine. The Community Edition and the Free Edition let teams adopt before they buy, and the engine carries 16.4 thousand GitHub stars.
The commercial proof is broad for this market and mostly vendor-sourced. Semgrep's repository names GitLab, Dropbox, Slack, Figma, Shopify, HashiCorp, Snowflake, and Trail of Bits as users, an outside reviewer repeats six of those names, and SiliconANGLE reported that Semgrep disclosed adoption by hundreds of organizations since launch. Semgrep announced its first placement in Gartner's Magic Quadrant for Application Security Testing itself, in a press release.
The company also competes for installed accounts directly. Semgrep's site offers a program for teams moving off Checkmarx or Snyk, and its repository lists Claude Code and Cursor plugins on those tools' official marketplaces, which puts the product where developers choose their agent tooling.
Semgrep publishes its rates, which is a positioning choice in this cluster. The Teams plan starts at 30 dollars per contributor per month, with Secrets at 15 dollars, while the Checkmarx page directs buyers to a custom quote and the Black Duck page to a no-obligation quote request.
The charged unit tells the buyer what Semgrep thinks it sells. A contributor is someone who made at least one commit to a scanned private repository in the past 90 days, so the meter tracks active developers rather than seats, assets, or scan volume.
Self-service stops at the free tier. The Free Edition costs nothing for up to 10 contributors and signs up directly, while Enterprise pricing is listed as custom, so the published rate covers the smaller team and the larger deal is negotiated.
Semgrep delivers software the customer runs, with a default that keeps source code in place. The engine analyzes code locally or in the build environment and does not upload it by default, so a team runs Semgrep in its own pipeline without sending source to a vendor cloud. The pricing page repeats that source code never leaves the machine or the CI environment when Semgrep runs locally or fully in CI.
The platform meets developers inside the tools they already use. Findings surface in editors and pull requests, and Guardian bundles an MCP server, hooks, and skills into an AI coding agent so a scan fires on every file write.
The AI features change what leaves the environment. Semgrep's pricing page states that opting into AI-powered detection, triage, and remediation sends the part of the file that has a finding in it to a model for processing, and that model vendors may not train on the submitted code.
Semgrep publishes an inspectable trust portal, and an intrusion has tested it. The portal announces a SOC 2 Type II report covering December 2023 through November 2024 and a full-scope whitebox penetration test performed by Include Security.
The incident is the kind a code-scanning buyer fears. Semgrep disclosed that the Qilin group released Semgrep scan results of Semgrep's own source code, obtained through a Semgrep API token used to reach a sandbox environment, and says its completed post-incident investigations confirmed the threat actor did not access customer findings or source code and that the integrity of its source code and release processes was not compromised.
A SOC 2 report and a third-party penetration test ease a procurement review without blocking a funded rival. The reviewed sources identify no federal authorization and no product-specific mandate, so a cautious buyer weighs the local-analysis default, the published reports, and the handling of the breach together.
Semgrep positions itself as the unified code-security platform built on an engine it gives away. The paid platform layers Code, Supply Chain, and Secrets over the open-source Community Edition, and the secrets page states that all products draw on the same underlying Pro and open-source engines, so a buyer consolidates three scanning categories instead of stitching point products together.
Outward, the platform reaches developers through the tools they already run. It integrates with editors, pipelines, and pull requests, it lets teams write rules in a pattern syntax that mirrors source code, and Guardian brings that scanning into AI coding agents through the Claude Code and Cursor marketplaces.
The structural tension is that the entry point is forkable. A consortium of application security companies launched Opengrep as a fork of the Community Edition after Semgrep changed the license on its open-source rules, and an outside reviewer records that the fork restored cross-function taint analysis and other features Semgrep had moved behind its paid tier. The cited record shows no reproduction of the 20,000-plus proprietary rules.
Semgrep's founders built the company from an open-source project into the platform it sells today. Drew Dennison, Isaac Evans, and Luke O'Malley founded Semgrep in 2017, and in 2020 the team reignited development of the open source project sgrep that became the product. Isaac Evans is chief executive.
The engine carries 16.4 thousand GitHub stars, the public registry holds more than 3,000 community rules by an outside reviewer's count, and an in-house security research team writes and maintains the 20,000-plus proprietary rules the paid platform ships.
Investors back the team. Menlo Ventures led the 100 million dollar Series D, with Felicis Ventures, Harpoon Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital participating.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Semgrep: homepage | official | 2026-08-28 |
| f2 | Semgrep About page | official | 2026-06-14 |
| f3 | Semgrep Wikipedia entry | research | 2026-06-14 |
| f4 | SiliconANGLE: Code security startup Semgrep reels in $100M from investors | press | 2026-06-27 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-09 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f7 | Semgrep platform | official | 2026-06-14 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Semgrep homepage (platform positioning, product list, vendor-reported metrics) “Catch, flag, and fix real vulnerabilities before they ship, powered by security that learns as you build. Unify SAST, SCA, and secrets scanning into one platform built for today’s software era.” | official | 2026-08-28 |
| s2 | Semgrep Code product page (Multimodal detection and vendor-reported accuracy figures) “Semgrep Multimodal finds up to 3.5x more true positives at 19% lower cost per true positive compared to using AI alone.” | official | 2026-08-28 |
| s3 | Semgrep Supply Chain product page (reachability analysis, malware blocking) “Reduce noise with codebase-aware reachability.” | official | 2026-08-28 |
| s4 | Semgrep Secrets product page (semantic and entropy analysis, local validation) “Go beyond regex: leverage Semantic Analysis, entropy analysis, and validation to accurately detect and fix secrets.” | official | 2026-08-28 |
| s5 | Semgrep About page (founders, 2017 founding, named users) “Founded by Drew Dennison, Isaac Evans, and Luke O’Malley in 2017, the company’s mission has been to profoundly improve software security from day 1.” | official | 2026-08-28 |
| s6 | Semgrep GitHub repository (Community Edition engine, Pro rules, local analysis) “The Semgrep AppSec Platform works out-of-the-box with 20000+ proprietary rules across SAST, SCA, and secrets.” | official | 2026-08-28 |
| s7 | Semgrep pricing page (tiers, contributor definition, AI data-handling FAQ) “A contributor is someone who made at least one commit to your organization's private repository scanned by Semgrep in the past 90 days.” | official | 2026-08-28 |
| s8 | Semgrep Guardian product page (plugin for AI coding agents) “Coding agents install malicious packages, hardcode secrets, and write vulnerable patterns. Guardian stops each one at generation time, so your developers ship AI-written code without shipping the risk.” | official | 2026-08-28 |
| s9 | Semgrep Trust Portal (SOC 2 Type II, third-party pentest, Qilin incident updates) “Semgrep Inc. is thrilled to announce our latest SOC 2 Type II report (covering December 1, 2023 - November 30, 2024) and our latest full-scope, whitebox penetration test (performed by Include Security).” | official | 2026-08-28 |
| s10 | SiliconANGLE: Code security startup Semgrep reels in $100M from investors “Menlo Ventures led the Series D investment.” | press | 2026-08-28 |
| s11 | Dark Reading: Code-Scanning Tool's License at Heart of Security Breakup “The triggering event for the open source split came on Dec. 13, when Semgrep outlined changes it had made to seemingly small — but nevertheless important — features.” | press | 2026-08-28 |
| s12 | InfoQ: Opengrep Forks Semgrep to Liberate Rulesets After License Change “A consortium of software companies, including JIT and Orca Security , has launched Opengrep , a fork of Semgrep 's open-source software, in response to licensing changes for rules provided in the OSS version.” | press | 2026-08-28 |
| s13 | ACM Digital Library: EASE 2024 paper on improving SAST tool performance with Semgrep “Our results show that the vulnerability detection rates of individual tools range from 11.2% to 26.5%, but combining these four tools can detect 38.8% of vulnerabilities.” | research | 2026-08-28 |
| s14 | arXiv: QASecClaw preprint using Semgrep as its SAST baseline “QASecClaw correctly reclassified 496 false positives as true negatives, while only misclassifying 40 true positives as false negatives.” | research | 2026-08-28 |
| s15 | NVD: CVE-2023-32758 record for a ReDoS in a Semgrep dependency “giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs.” | other | 2026-08-28 |
| s16 | AppSec Santa: review of Semgrep Community Edition and the paid platform “In a benchmark Semgrep commissioned from Doyensec, Semgrep Code detected 72% of WebGoat vulnerabilities vs 48% for CE — vendor-funded research on a deliberately vulnerable training app, not an independent cross-scanner test.” | press | 2026-08-28 |
| s17 | PR Newswire: Semgrep announcement of its 2025 Gartner Magic Quadrant recognition “today announced it has been recognized in the 2025 Gartner® Magic Quadrant™ for Application Security Testing 1 for the first time.” | press | 2026-08-28 |
| s18 | Opengrep: project page for the Semgrep Community Edition fork “An improved engine enabling more powerful analyses, Opengrep will unlock previously pro-only capabilities , including inter-procedural analysis (cross-function), cross-file analysis, windows support, extended language support , and more.” | official | 2026-08-28 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Semgrep homepage (platform positioning, product list, vendor-reported metrics) “Catch, flag, and fix real vulnerabilities before they ship, powered by security that learns as you build. Unify SAST, SCA, and secrets scanning into one platform built for today’s software era.” | official | 2026-08-28 |
| s2 | Semgrep Code product page (Multimodal detection and vendor-reported accuracy figures) “Semgrep Multimodal finds up to 3.5x more true positives at 19% lower cost per true positive compared to using AI alone.” | official | 2026-08-28 |
| s3 | Semgrep Supply Chain product page (reachability analysis, malware blocking) “Reduce noise with codebase-aware reachability.” | official | 2026-08-28 |
| s4 | Semgrep Secrets product page (semantic and entropy analysis, local validation) “Go beyond regex: leverage Semantic Analysis, entropy analysis, and validation to accurately detect and fix secrets.” | official | 2026-08-28 |
| s5 | Semgrep About page (founders, 2017 founding, named users) “Founded by Drew Dennison, Isaac Evans, and Luke O’Malley in 2017, the company’s mission has been to profoundly improve software security from day 1.” | official | 2026-08-28 |
| s6 | Semgrep GitHub repository (Community Edition engine, Pro rules, local analysis) “The Semgrep AppSec Platform works out-of-the-box with 20000+ proprietary rules across SAST, SCA, and secrets.” | official | 2026-08-28 |
| s7 | Semgrep pricing page (tiers, contributor definition, AI data-handling FAQ) “A contributor is someone who made at least one commit to your organization's private repository scanned by Semgrep in the past 90 days.” | official | 2026-08-28 |
| s8 | Semgrep Guardian product page (plugin for AI coding agents) “Coding agents install malicious packages, hardcode secrets, and write vulnerable patterns. Guardian stops each one at generation time, so your developers ship AI-written code without shipping the risk.” | official | 2026-08-28 |
| s9 | Semgrep Trust Portal (SOC 2 Type II, third-party pentest, Qilin incident updates) “Semgrep Inc. is thrilled to announce our latest SOC 2 Type II report (covering December 1, 2023 - November 30, 2024) and our latest full-scope, whitebox penetration test (performed by Include Security).” | official | 2026-08-28 |
| s10 | SiliconANGLE: Code security startup Semgrep reels in $100M from investors “Menlo Ventures led the Series D investment.” | press | 2026-08-28 |
| s11 | Dark Reading: Code-Scanning Tool's License at Heart of Security Breakup “The triggering event for the open source split came on Dec. 13, when Semgrep outlined changes it had made to seemingly small — but nevertheless important — features.” | press | 2026-08-28 |
| s12 | InfoQ: Opengrep Forks Semgrep to Liberate Rulesets After License Change “A consortium of software companies, including JIT and Orca Security , has launched Opengrep , a fork of Semgrep 's open-source software, in response to licensing changes for rules provided in the OSS version.” | press | 2026-08-28 |
| s13 | ACM Digital Library: EASE 2024 paper on improving SAST tool performance with Semgrep “Our results show that the vulnerability detection rates of individual tools range from 11.2% to 26.5%, but combining these four tools can detect 38.8% of vulnerabilities.” | research | 2026-08-28 |
| s14 | arXiv: QASecClaw preprint using Semgrep as its SAST baseline “QASecClaw correctly reclassified 496 false positives as true negatives, while only misclassifying 40 true positives as false negatives.” | research | 2026-08-28 |
| s15 | NVD: CVE-2023-32758 record for a ReDoS in a Semgrep dependency “giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs.” | other | 2026-08-28 |
| s16 | AppSec Santa: review of Semgrep Community Edition and the paid platform “In a benchmark Semgrep commissioned from Doyensec, Semgrep Code detected 72% of WebGoat vulnerabilities vs 48% for CE — vendor-funded research on a deliberately vulnerable training app, not an independent cross-scanner test.” | press | 2026-08-28 |
| s17 | PR Newswire: Semgrep announcement of its 2025 Gartner Magic Quadrant recognition “today announced it has been recognized in the 2025 Gartner® Magic Quadrant™ for Application Security Testing 1 for the first time.” | press | 2026-08-28 |
| s18 | Opengrep: project page for the Semgrep Community Edition fork “An improved engine enabling more powerful analyses, Opengrep will unlock previously pro-only capabilities , including inter-procedural analysis (cross-function), cross-file analysis, windows support, extended language support , and more.” | official | 2026-08-28 |
| s19 | Checkmarx: Checkmarx One packaging and quote-request page “Pick the modules that match your attack surface. Get a custom quote in minutes.” | official | 2026-08-28 |
| s20 | Black Duck: Black Duck SCA pricing enquiry page “Get a no-obligation quote , customized to your needs.” | official | 2026-08-28 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.