![]()
Semgrep, a leading code security company, announces Semgrep Agentic Workflows, a set of pre-built security detection pipelines that uncover business logic flaws, broken authorization and other vulnerabilities classes that both traditional scanners and AI-only tools routinely miss. Covering a broad range of vulnerability classes, Agentic Workflows combines AI reasoning with deterministic program analysis to help security teams find critical issues without adding more noise to their alert queues.
“Attackers are already using AI to find complex exploit chains in minutes,” said Isaac Evans, CEO and co-founder of Semgrep. “To defend enterprise codebases at scale, AppSec teams need security tools operating with that same reasoning and sophistication. Agentic Workflows gives defenders that analytical power out of the box, without the burden of building the AI system themselves.”
AI Has Escalated the Security Equation
The influx of AI-generated code has increased codebase volumes by an order of magnitude, stretching security teams further than ever before. At the same time, attackers are leveraging advanced AI capabilities to discover and exploit complex vulnerabilities with unprecedented speed and sophistication.
Traditional static analysis tools lack the context to catch complex business logic flaws, while relying on AI models alone to detect vulnerabilities creates new noise through false positives or inconsistent findings. To keep pace, AppSec teams cannot rely on traditional tools or human-led review. They need security tools operating with the same level of sophistication, reasoning, and depth that attackers are using, evaluating difficult security questions without burdening developers with noise.
Security Research That Runs Like Software
Agentic Workflows uses deterministic program analysis to narrow the code under review and establish the context surrounding a potential issue. AI reasoning is then applied where understanding application behavior or business logic can reveal vulnerabilities that pattern matching alone may not detect.
Pre-built Agentic Workflows currently address more than 10 vulnerability classes, including insecure direct object references, business logic flaws and other risks within the OWASP Top 10. The same pipeline can move a potential issue through validation and remediation while preserving visibility into how the result was produced.
In Semgrep benchmarking, combining AI reasoning with program analysis identified 3.5 times more true positives at a 19% lower cost per true positive than AI alone.
Built for AppSec Teams to Adapt
Because Agentic Workflows run on Semgrep’s proven infrastructure, AppSec teams can deploy them across large repository fleets from day one, moving from proof-of-concept to production without having to build, scale, or maintain the operational system themselves. Organizations with codebase-specific requirements can also adapt pre-built Agentic Workflows or build Custom Agentic Workflows from Semgrep’s analysis tools, AI models, and internal integrations. Semgrep manages execution across repositories, so teams extend capability without taking on infrastructure responsibility.
Availability
Semgrep Agentic Workflows is available in open beta to existing customers and new users.
For more information or to join the beta, visit the Semgrep Agentic Workflows product page.
About Semgrep
Semgrep provides code security tools for developers and application security teams. The company helps organizations identify and remediate vulnerabilities across proprietary code, open source dependencies and secrets while supporting the speed of modern software development. Companies including Snowflake, Figma, Lyft and Dropbox use Semgrep to protect their code. Semgrep is backed by Felicis Ventures, Lightspeed Venture Partners, Menlo Ventures, Redpoint Ventures and Sequoia Capital.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260729986005/en/
Media gallery
