Feel secure about our pricing
We make it expensive to exploit software, not to secure it.
Feel secure about our pricing
We make it expensive to exploit software, not to secure it.
Get started for free with the most popular code scanning engine. Connect your code and start securing your code with just a few clicks.
Authentication via GitHub/GitLab
Choose from Code (SAST), Supply Chain (SCA), or Secrets detection to eliminate noise out of the box, streamline developer workflows, and give security teams full visibility. Built-in AI-powered detection, triage, and remediation.
Award-winning support
Built for impact and scale. Get the same powerful AppSec platform as Teams with additional flexibility to suit Enterprise environments. Plus white glove onboarding, dedicated support, roadmap access, and a team deeply invested in your success.
Frequently Asked Questions (FAQs)
A contributor is someone who made at least one commit to your organization's private repository scanned by Semgrep in the past 90 days. More information regarding the methodology used to define and calculate the number of contributors is available on our usage and billing documentation.
Many of us were security consultants in our previous roles. To inquire about using Semgrep in your consulting work, please contact us.
Yes, and we love startups. To get access to special pricing, please contact us.
If Semgrep runs either locally or fully in your CI pipeline, then no, your source code never leaves your computer or your CI environment. Only meta-data related to Semgrep runs (see docs) are sent to Semgrep's service.
If you opt-in to Semgrep’s AI-powered detection, triage and remediation, part of the file that has a finding in it to for processing by a model. Model vendors are not allowed to use the submitted code for training their models.
If you opt-in to Semgrep Managed Scans, allowing onboarding of repositories and their scanning without the need for per-project provisioning, then Semgrep’s service clones your repository at the beginning of every scan. Once the scan completes, the clone is destroyed and is not persisted anywhere.
Users in the Teams and Enterprise tiers for Semgrep can publish rules to the Semgrep Registry as Private rules that are not visible to others outside their organization. The private rules enable you to hide code-sensitive information or legal requirements that prevent you from using a public registry.
Pro rules are proprietary rules written by our security research team with the goal to provide a set of supported rules with improved coverage (across languages and vulnerability types), leveraging the latest Semgrep features, and providing high-confidence results.
Need something custom?
Ask us about our Enterprise tier, including customized support plans and feature development.