
Semgrep Stock
| Valuation | $799.24M1 |
| Valuation Date | Feb 5, 2025 |
| Implied Valuation | n/a |
| Last Price | $10.08 |
| 52-Week High | $10.08 |
| 52-Week Low | $9.00 |
| YTD Return | n/a |
| 1-Year Return | n/a |
| 3-Year Return | n/a |
| Total Funding | $204M2 |
| Latest Round Amount | $100M2 |
| Latest Round | Series D |
| Funding Rounds | 5 |
| IPO Status | Unknown |
| Expected IPO Date | n/a |
| Revenue | n/a |
| Revenue Type | n/a |
| P/S Ratio | n/a |
About Semgrep
Semgrep is an application security company whose software scans source code for vulnerabilities while developers are writing it. Its platform covers static analysis of first-party code (Semgrep Code), open-source dependency and malware scanning (Semgrep Supply Chain) and hardcoded credential detection (Semgrep Secrets), plus a Multimodal layer that pairs those deterministic rules with AI reasoning to cut false positives and a Guardian product that checks AI-generated code inside the IDE. The underlying engine is free and open source as Semgrep Community Edition, covers more than 40 languages and now runs over 100 million scans a year for customers including Figma, Dropbox, Okta and Lyft. Semgrep makes money by selling the hosted AppSec Platform on a per-contributing-developer subscription, starting at $30 per contributor per month on the Teams plan with custom pricing for Enterprise.
Invest in Semgrep
Semgrep is a private company, so you can't purchase it with a regular brokerage account. However, its shares are available on Hiive.
Hiive is a secondary marketplace where accredited investors can buy and sell shares of private, pre-IPO companies. Invest in the world's most exciting startups before they go public.
Invest on HiiveStock Analysis may be compensated for user sign-ups through Hiive links. Hiive is not affiliated with Stock Analysis. Securities offered by Hiive Markets Limited, member of FINRA/SIPC.
Related Companies
News
Semgrep and Replit Expand Integration to Keep Pace With AI-Generated Code at Scale
SAN FRANCISCO--(BUSINESS WIRE)--Semgrep, a leading code security company, today announced a deepened partnership with Replit to bring automated, real-time security analysis directly into the AI-native...
Semgrep Agentic Workflows Automates AppSec Capabilities
Semgrep launched Agentic Workflows in public beta, combining AI reasoning with deterministic program analysis to detect business logic flaws, broken authorization, and other complex vulnerability clas...
It's Not npm-ver Yet: npm Worm ChainDrop Hits 400 Packages Including jaredwray, ServiceTitan, Ornikar, Qlik and NebulaJS
Semgrep's security research team documents ChainDrop, a self-spreading npm worm that compromised roughly 400 packages across several maintainer accounts. The post lists indicators of compromise and th...
Introducing Semgrep Agentic Workflows: Automate Deep Vulnerability Hunting at Scale
Semgrep launched Agentic Workflows, which lets security teams build and deploy pipelines that combine static analysis with AI agents. The product targets deeper vulnerability hunting than rule-based s...
Introducing Semgrep Guardian: Security for AI-Generated Code
Semgrep launched Guardian, a product that scans and fixes AI-generated code inside the IDE as an agent writes it. It ships as an official Cursor and Claude Code partner integration and works with GitH...
Announcing Pyro Caml: A Continuous Profiler for OCaml
Semgrep open-sourced Pyro Caml, a continuous profiler for OCaml, the language its analysis engine is written in. The company built it to find performance regressions in long-running scans.
Semgrep Hires Veteran Engineering Leader Cathy Polinsky as Co-CTO and VP of Engineering to Secure the Era of AI-Generated Code
Semgrep hired Cathy Polinsky, previously an engineering leader at Yahoo, Salesforce, Stitch Fix, Shopify and DataGrail, as Co-CTO and VP of Engineering. The release says Semgrep runs more than 100 mil...
Attackers Are Still Coming for Security Companies. Here's Where We Stand.
Semgrep reviews the TeamPCP supply chain campaign that reached Trivy, Checkmarx Docker images, VS Code extensions and the Bitwarden CLI. The company also describes the internal incident response it ra...
Semgrep chosen to be part of OpenAI's Trusted Access for Cyber Program
OpenAI selected Semgrep as one of four initial recipients of its Cybersecurity Grant Program under Trusted Access for Cyber. The program commits $10 million in API credits and gives participants early...
Mythos & Semgrep
CEO Isaac Evans sets out how Semgrep positions its platform against Anthropic's Mythos model, which the company frames as a probabilistic pentest rather than a replacement for deterministic static ana...
OpenAI names Semgrep among initial Trusted Access for Cyber recipients
OpenAI selected Semgrep as one of four initial Cybersecurity Grant Program recipients, giving the AppSec platform access to frontier models including GPT-5.4-Cyber for software supply chain defense.
Semgrep Supply Chain extends reachability coverage to Rust
Semgrep added Rust to the languages for which Semgrep Supply Chain performs reachability analysis. The feature filters dependency vulnerabilities down to those actually reachable from application code...
Semgrep Launches Multimodal for Detection, Triage, and Remediation
Semgrep announced Multimodal in March 2026, combining AI reasoning with rule-based analysis and reporting up to 8x more true positives with 50% less noise versus foundation models alone.
Attackers Can't Have All the Advantage: Introducing Semgrep Multimodal
Semgrep launched Multimodal, which pairs AI reasoning with its rule-based engine for detection, triage and remediation. The company says it finds up to 8x more true positives with 50% fewer false posi...
Introducing Semgrep Custom Workflows
Semgrep introduced Custom Workflows, letting security teams script their own automation on top of the AppSec Platform. It underpins the Agentic Workflows product released later in the year.
Semgrep Autofix public beta
Semgrep opened Autofix to public beta, generating remediation guidance and fix suggestions directly in pull requests. It also flags breaking changes introduced by dependency upgrades.
Semgrep x Cursor: Introducing Cursor Plugins
Semgrep shipped a one-click plugin for Cursor and Claude Code that scans code as AI agents generate it. The integration runs Semgrep's engine locally through hooks and an MCP server.
Cortex and Semgrep partner to strengthen application security
Cortex and Semgrep integrated security findings into developer portals so teams can track vulnerability management and policy compliance through Cortex Scorecards and Initiatives.
Semgrep Recognized in the 2025 Gartner Magic Quadrant for Application Security Testing
Semgrep was named in Gartner's Magic Quadrant for Application Security Testing for the first time, positioned as a Niche Player. CEO Isaac Evans said the hybrid static analysis and AI approach filters...
Semgrep Announces $100M Series D Funding to Advance AI-Powered Code Security
Semgrep raised a $100 million Series D led by Menlo Ventures with participation from Felicis, Harpoon Ventures, Lightspeed, Redpoint and Sequoia. The company said the round brought its total funding t...
Code security startup Semgrep reels in $100M from investors
SiliconANGLE covers Semgrep's $100 million Series D and how the company plans to spend it on AI and program analysis hiring plus go-to-market expansion. It puts total outside funding at $204 million.
Semgrep, a code & supply chain security search engine, raises Series C
Semgrep announced a $53 million Series C led by Lightspeed Venture Partners with Felicis, Redpoint and Sequoia participating. The post is also where the company confirmed its rename from r2c.


