Semgrep is an open-source static analysis tool and AI-powered SAST platform that enables developers to write and enforce custom code security rules. It finds bugs, vulnerabilities, and code anti-patterns across 30+ programming languages and integrates into CI/CD pipelines.

    Category

    Security

    Subcategory

    Vulnerability Scanning

    // ACCESS METHODS

    Web AppAPICLI

    // COMPLIANCE

    SOC2ISO27001GDPRHIPAA

    ● certified · ○ not verified

    // DATA STORAGE

    Region

    Trains on Data

    Self-hostable

    Yes

    // PRICING DETAIL

    Free Tier

    Semgrep OSS free forever; Semgrep Community free tier

    Paid Plans

    Team from $40/developer/month, Enterprise pricing available

    API Cost

    Not available yet
    >> OPEN TOOL

    // MORE IN VULNERABILITY SCANNING

    C
    CodeQL
    Free
    SecurityVulnerability Scanning
    #code-analysis#security#vulnerability-detection
    G
    GitGuardian
    Freemium
    SecurityVulnerability Scanning
    #secrets detection#credential scanning#code security
    V
    Veracode
    Paid
    SecurityVulnerability Scanning
    #application security#sast#dast

    // USE CASES

    Custom code security rulesVulnerability detection at scaleCode quality enforcementSecurity policy as codeMulti-language codebase scanning