Semgrep logo

    Semgrep

    Freemium
    https://semgrep.dev
    >> OPEN TOOL

    Semgrep is an open-source static analysis tool and AI-powered SAST platform that enables developers to write and enforce custom code security rules. It finds bugs, vulnerabilities, and code anti-patterns across 30+ programming languages and integrates into CI/CD pipelines.

    Category

    Security

    Subcategory

    Vulnerability Scanning

    Free Tier

    Semgrep OSS free forever; Semgrep Community free tier

    Paid Plans

    Team from $40/developer/month, Enterprise pricing available

    API Cost

    Not available yet

    Web AppAPICLI

    Semgrep Trust & Security Report

    Certifications, AI-training posture, and security controls, with sourced proof.

    VIEW
    SOC 2 Type IIGDPR (posture)

    Verified against Semgrep's own trust and security pages. See the full report for sourced proof →

    Region

    Primary servers located in the United States per the Privacy Notice; a 'Data Transfer Impact Assessment' document is published on the trust portal for EU customers, but no explicit EU/other-region hosting option is documented publicly.

    Trains on Data

    No

    Self-hostable

    Yes

    Custom code security rulesVulnerability detection at scaleCode quality enforcementSecurity policy as codeMulti-language codebase scanning

    // MORE IN VULNERABILITY SCANNING

    CodeQL logoCodeQL
    Free
    SecurityVulnerability ScanningVerified
    #code-analysis#security
    GitGuardian logoGitGuardian
    Freemium
    SecurityVulnerability ScanningVerified
    #secrets detection#credential scanning
    Veracode logoVeracode
    Paid
    SecurityVulnerability ScanningVerified
    #application security#sast