Skip to content

Semgrep

Open-source-led static analysis platform for code scanning, supply chain and secrets detection, powering GitLab's SAST engine.

Visit Website ↗ + Add to Compare
67/100Incremental Innovator

Overview

Semgrep is a static application security testing (SAST) platform built around a lightweight, open-source pattern-matching engine that lets security and engineering teams write and share custom code-scanning rules quickly, in a syntax designed to feel like the source code itself. The commercial product extends the open-source core into Semgrep Code (SAST), Semgrep Supply Chain (dependency vulnerabilities) and Semgrep Secrets (hardcoded credential detection).

Founded in 2017 as r2c and rebranded to Semgrep, the San Francisco-based company raised a $100 million Series D in February 2025 led by Menlo Ventures, at a valuation reported around $722 million, bringing total funding to roughly $193 million. Its differentiator is distribution: the open-source Semgrep engine is independently embedded as GitLab’s own SAST analyzer and used directly by engineering teams at companies including Dropbox, Slack, Figma, Shopify, Snowflake and HashiCorp — adoption that exists independent of Semgrep’s own commercial sales efforts.

This open-source-first distribution model, combined with a large community-contributed rule set, differentiates Semgrep from proprietary SAST tools that require direct commercial engagement to gain any adoption at all.

Innovation Matrix Assessment

Innovation Velocity 7/10

Has expanded steadily from a single open-source SAST engine into supply-chain and secrets scanning while maintaining active open-source community development.

Operational Value 7/10

Fast, low-noise custom rule writing helps security and engineering teams actually act on SAST findings rather than drowning in false positives, a common complaint with legacy SAST tools.

Market Momentum 7/10

Independently verified: a $100M Series D (Feb 2025) at roughly a $722M valuation, and genuine independent adoption evidenced by GitLab embedding Semgrep as its own SAST analyzer.

Category Disruption 6/10

Open-source-led distribution with a community-vetted rule ecosystem is a real structural difference from proprietary SAST vendors, though SAST itself remains a mature, crowded category.

Real-World Efficacy 6/10

Adoption by engineering-driven organizations like GitLab, Snowflake and Dropbox is meaningful indirect evidence of real-world usefulness, though no independent detection-rate benchmark against other SAST tools was found.

Enduring Relevance 7/10

Code-level security scanning remains a foundational requirement, and Semgrep's rule-writing approach is well positioned to adapt as languages and frameworks evolve.

Why CISOs Should Care

Reduces SAST false-positive fatigue by letting teams write and share precise, fast custom rules, and provides visibility via GitLab's own SAST integration without a separate procurement step.

What Makes It Different

Open-source core with a community-vetted rule ecosystem that has been independently embedded into other companies' products (notably GitLab), unlike closed proprietary scanners.

The Matrix Verdict

67/100 — INCREMENTAL INNOVATOR

A Meaningful Innovator: Semgrep combines independently verified funding momentum with genuine independent adoption of its open-source engine outside its own commercial channel, a stronger evidence base than most SAST peers, even as the broader category remains mature and competitive.

Editorial Note: Claims vs. Verified Findings

Named customer usage (GitLab, Dropbox, Snowflake, Figma) is drawn from Semgrep's own marketing and GitLab's public integration documentation; no independent scanning-accuracy benchmark was found in this research.

Sources