Trust
Security & compliance
The vendor hasn’t added security or compliance details yet.
Semgrep is a fast, open-source static analysis tool for finding bugs and security vulnerabilities in code, with support for 30+ languages and integration into CI/CD pipelines for automated security scanning.
Pricing
$0-40 / contributor / month
Founded
2020
Team size
51-200 employees
Headquarters
San Francisco, California
Preview from semgrep.dev
At a glance
Best for
Pricing model
Try before you buy
Integrates with
Semgrep is a lightweight, fast static analysis tool that finds bugs and security vulnerabilities in first-party code. The open-source engine supports over 30 programming languages and uses a pattern-matching syntax that developers can learn in minutes.
Semgrep Cloud (now Semgrep AppSec Platform) extends the open-source engine with a managed rule registry, CI/CD integration, findings management, and supply chain security scanning. The platform enables security teams to write custom rules that enforce organization-specific coding standards and security policies.
The platform's speed and developer-friendly approach has made it popular with both security teams and developers. Semgrep processes code orders of magnitude faster than traditional SAST tools, enabling integration into every pull request without slowing down development workflows.
Structured facts from the vendor to help your security, finance, and procurement reviews move faster.
Trust
The vendor hasn’t added security or compliance details yet.
Pricing
Pricing model: Tiered plans
Free trial: Yes
Free plan: Yes
Contract minimum: Not specified
Procurement
The vendor hasn’t added purchasing & legal details yet.
Fit
Company-size fit has not been specified yet.