Semgrep vs Lory: Static Analysis vs a Human-Signed AI Pentester | Lorikeet Security Skip to main content
Back to Blog
Vendor Comparison

Semgrep vs Lory: Static Analysis vs a Human-Signed AI Pentester

Lorikeet Security · September 7, 2026 · 9 min read
Disclosure: This is written by Lorikeet Security. The Semgrep column reflects Semgrep's public product, pricing, and whitepaper material as of this writing. We'd rather say this up front than pretend otherwise: Semgrep and Lory are not really substitutes for each other, and a comparison that treats them as head-to-head rivals would be misleading. Read on for why, and where each one actually earns its place.

The One-Line Difference

Semgrep is a static analysis platform - it reads your source code and flags patterns that could be a vulnerability, in seconds, on every commit.

Lory is an AI pentester - it attacks a running system (or reviews a repo as one engagement among several) and proves what's actually exploitable, with a human signing every finding.

Semgrep's own reachability documentation is candid about the boundary: a static scanner can find a vulnerable-looking pattern, but it can't always tell you whether that pattern is reachable and exploitable at runtime without dynamic testing. That's the whole reason a category like AI pentesting exists alongside SAST rather than instead of it.


At a Glance

DimensionSemgrepLory by Lorikeet
CategoryStatic application security testing (SAST) + SCA + secretsAI-driven penetration testing, human-signed
What it testsSource code, on every commit or CI runA running system, or a repo as one engagement type among several
SpeedSub-minute scans, results in the pull requestHours to days per engagement, depending on depth
Proves exploitabilityReachability analysis narrows it; doesn't confirm at runtimeYes, reproduced with request/response and the chain it unlocks
Human reviewAI-assisted triage (Semgrep Multimodal), not a named pentesterA named Lorikeet Security pentester signs every finding
Scope modelEvery connected repo, continuouslyA declared target and rules of engagement, enforced as an allowlist
Asset coverageSource code onlyWeb, API, mobile, network, cloud, and source code
PricingFree tier; $35/contributor/month (Team); custom (Enterprise)Prepaid credits, itemised quote within 24 hours, no seats
RecognitionNamed in the 2025 Gartner Magic Quadrant for ASTNot published
Recurring coverageContinuous, on every commitWeekly, biweekly, monthly, quarterly, or yearly, queued and started automatically

These Solve Different Problems

Worth stating plainly rather than forcing a false rivalry:


Where Lory Differentiates

Honest Weak Spots for Lory Semgrep is dramatically faster and cheaper for the specific job of continuous code scanning - sub-minute results on every commit for $35/contributor/month, versus a scoped, queued Lory engagement. Its cross-file dataflow and reachability analysis are purpose-built and mature; Lory's source review is one engagement type among several rather than a dedicated multi-year SAST product. And Semgrep's Gartner Magic Quadrant recognition is a market-maturity signal we can't match with a comparable claim.

Picking Between Them

Semgrep may fit if...
  • You want a security gate on every pull request, in seconds, before code ships
  • Your primary risk surface is what's visible in source: known-bad patterns, vulnerable dependencies, leaked secrets
  • You want per-contributor pricing that scales with your engineering team
Lory may fit if...
  • You need proof of exploitability, not a flagged pattern, for a customer, auditor, or board
  • Your risk surface includes a running application, network, or cloud environment - not just source
  • You want a named human accountable for every finding that reaches you
  • You want a scheduled, recurring engagement across your whole estate under one credit balance

Most security-mature teams run both, and that's the honest recommendation: Semgrep in CI catching what's visible in the code on every commit, Lory for the signed, cross-surface engagement that proves what's actually exploitable once it's live.

See What a Signed Engagement Actually Proves

Book a scoping call and we'll show you the difference between a flagged pattern and a reproduced exploit chain - and how a named pentester signs off before anything reaches your report.

Book a Consultation
-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.