Argus vs Semgrep
SAST / SCA / secrets platform with an AI triage layer.
Semgrep is a SAST/SCA/secrets platform — bundled scanners across four Git platforms with a Multimodal AI layer that triages findings, autofixes, flags business-logic flaws, and remembers org preferences via Memories. It's the security-scanning leader here, but it isn't a general reasoning-based reviewer: no multi-pass pipeline, architecture graph, or failure-scenario checks, and BYOK is gated to Enterprise.
Last verified against Semgrep’s public docs
- Argus
- Free
- Open source (AGPL-3.0), self-hosted. Bring your own LLM key; no seats, no tiers, no gated features.
- Semgrep
- Free tier, then $30/contributor/mo
- Free (≤10 contributors, ≤10 repos); Teams from $30/contributor/mo per module (Secrets $15); Enterprise custom (on-prem SCM, dedicated infra)
How does Argus compare to Semgrep in features?
| Feature | Argus | Semgrep |
|---|---|---|
| Where Argus is built to lead | ||
| Computed per-PR review contract (auto depth routing) | Yes | No |
| Institutional memory across reviews | Yes | Yes |
| Pattern learning from codebase history | Yes | Yes |
| Failure-scenario checks | Yes | No |
| Architecture & dependency tracing | Yes | No |
| Multi-pass / multi-agent pipeline | Yes | No |
| PR diagram generation (sequence + data flow) | Yes | No |
| Bring your own LLM key | Yes | Yes |
| Self-hosted deployment | Yes | Yes |
| Where Semgrep may lead | ||
| Reviews GitLab / Bitbucket / Azure DevOps | No | Yes |
| Bundled static analysis / SAST | Yes | Yes |
| Generates unit tests | Yes | No |
| IDE extension (VS Code / JetBrains) | No | Yes |
| Jira / Linear ticket creation & checks | No | Yes |
| SOC 2 / ISO 27001 certified | No | Yes |
Argus’s static analysis and test generation are narrower than the checkmarks suggest: staticcheck, ESLint and Semgrep results only guide its LLM reviewer and are never posted on their own, and @argus-eye test (the handle is your GitHub App’s slug; argus-eye is the default) posts a test plan or draft test code as a PR comment; the draft is not committed or run.
Where Semgrep excels
- Bundled proprietary SAST, supply-chain (SCA), and secrets scanning — deterministic plus AI detection
- Reviews GitHub, GitLab, Bitbucket, and Azure DevOps
- Multimodal AI layer (formerly Assistant) adds triage, autofix PRs, and business-logic (IDOR/authz) detection
- Memories learns org-specific remediation preferences from triage feedback, per project and per rule
- BYOK / custom model providers (OpenAI, Bedrock, Azure OpenAI, Gemini, xAI, Anthropic) on Enterprise
- Semgrep Guardian scans AI-generated code as it's written; MCP plugin feeds scans to coding agents
- Self-hosted / on-prem (CLI runs locally; Enterprise adds on-prem SCM + dedicated infrastructure)
- VS Code and JetBrains extensions; Jira ticketing; SOC 2 Type II certified
Where Semgrep falls short
- Not a general LLM code reviewer — no multi-pass review pipeline, diagrams, or architecture graph
- No failure-scenario checks: the AI layer triages and autofixes findings rather than reasoning about a change end-to-end
- AI detection (IDOR/authz) runs on full scans only — not diff-aware PR scans
- BYOK and custom model providers are Enterprise-only, and AI features consume monthly per-seat AI credits
- No test generation, no per-PR review contract
Semgrep currently leads Argus on multi-platform support beyond GitHub, an IDE extension, issue-tracker ticket integration, and SOC 2 compliance. If those matter more to your team than depth-routed review, Semgrep may be the better fit there.
When does Argus fit better than Semgrep?
Semgrep and Argus solve adjacent problems: Semgrep is a static-analysis/security platform with an AI triage/remediation layer (Multimodal); Argus is a general LLM code reviewer. Semgrep leads on SAST/SCA/secrets, platform breadth, IDE, ticketing, and compliance, and now offers BYOK on its Enterprise tier. Argus bundles the Semgrep CLI, but only to steer its LLM review (a pre-pass on changed files, plus a score floor for corroborated findings under Deep Review), and never posts its results on their own; it has no dependency (SCA) scanning, IDE extension, ticketing, or certification. Argus wins on the review itself: a staged review (per-file review plus judge scoring, with four specialist reviewers under opt-in Deep Review), architecture tracing, LLM re-checks of earlier findings, diagrams, the computed review contract, and BYOK without an Enterprise contract. The two can run side by side: Semgrep for deterministic security scanning, Argus for judgment-heavy review.
Semgrep Multimodal filters ~60% of SAST findings as noise on average, with a 96% human-agree rate — docs.semgrep.dev, 2026
Try Argus on your next pull request
Open source (AGPL-3.0). Self-host it with your own GitHub App and LLM key, install your App on a repo, and open a PR.
Self-hosted only: Docker Compose or Fly.io, Postgres with pgvector, a GitHub App and a Clerk app you create, your model keys and an embeddings endpoint.