Semgrep
Open-source static analysis engine with a commercial AppSec Platform adding cross-file analysis and an AI assistant for triage.
Visit Website [↗][ Facts ]
- Category
- Security
- Open source
- Yes (LGPL-2.1 (CE engine); AppSec Platform proprietary)
- Pricing
- Free for up to 10 contributors; Teams from $30/contributor/mo per product (Code SAST; Secrets $15) with 20 AI credits/dev/mo; Enterprise custom with 50 AI credits/dev/mo source
- Self-hosted
- Yes — full stack — CE engine (LGPL-2.1) runs fully local or in your CI; the AppSec Platform and Assistant are SaaS-only.
- Platforms
- github, gitlab, bitbucket, azure-devops
- Model control
- Assistant uses OpenAI with Amazon Bedrock fallback; custom AI model provider available on Enterprise
- Last verified
- 2026-08-11
[ Against the 9 Standards ]
Based on public documentation as of 2026-08-11. ✓ documented · ~ partial · ✗ not offered · ? unknown. Methodology on the about page.
Cross-file, cross-function dataflow in the Pro engine; Assistant memories add project context; no ticket context.
Fully rule-centric: custom rules, registry, and policy modes (Monitor/Comment/Block) control PR noise.
CLI, IDE extension, and pre-commit locally; policy-managed PR/MR comments in CI.
Assistant Memories store triage decisions and per-project instructions; the core engine does not learn.
LGPL engine is free to run; Assistant is credit-metered on vendor models, custom provider Enterprise-only.
Assistant autofix posts suggested code changes in PR/MR comments; coverage varies by rule and language.
Platform dashboards track findings, fix rates, and remediation times; no dev-cycle ROI attribution.
[ In Our Coverage ]
Evaluating Semgrep?
Run it through the two-week trial protocol before you commit.