CISO Tribune

Company record · security vendor

Semgrep

What the company sells

Semgrep sells static analysis software that scans source code for security issues, along with tools for open-source dependency and secrets scanning and an AI-assisted layer for detection and remediation. It is headquartered in San Francisco and was founded in 2017. The company is privately held and raised a $100 million Series D funding round in February 2025.

Headquarters
San Francisco, United States
Founded
2017
Ownership
Privately held

Products and services

  • Semgrep Code

    Scans source code to find and fix the security issues that matter, using static analysis.

  • Semgrep Supply Chain

    Fixes vulnerabilities in open-source dependencies and blocks malicious packages.

  • Semgrep Secrets

    Finds and fixes hardcoded secrets in code using semantic analysis.

  • Semgrep Assistant

    Combines rule-based analysis with AI reasoning to detect, triage, and help remediate findings.

Sources

  1. SemgrepUndated page, accessed September 27, 2026 · Tier A: the company, a regulator or a filing
  2. SemgrepUndated page, accessed September 27, 2026 · Tier A: the company, a regulator or a filing
  3. Semgrep via PR NewswirePublished February 5, 2025 · Tier A: the company, a regulator or a filing
  4. Craft.coUndated page, accessed September 27, 2026 · Tier C

Recorded September 27, 2026 from the sources above. Descriptions are in our own words; we do not rank or recommend vendors, and no vendor pays to be listed or to change what we write. Disclosure: until the publisher confirms it has no business relationship with this company, treat one as possible (how the network works). Spot a factual error? Request a correction.

Security leadership

CISO Tribune has not yet recorded who holds the top security seat at Semgrep. We add a seat only from a verified source; if you have one, send it to the desk.