Semgrep, formally r2c, whose tools scan developers' code for vulnerabilities, raised a $53M Series C led by Lightspeed, bringing its total funding to $93M
Ron Miller / TechCrunch :
Context & Ripple Effects
Semgrep's $53M Series C is the middle beat of a steady climb: the company built its commercial SaaS business on top of the open-source Semgrep engine with a $27M Series B in 2021, and this round more than triples total funding to $93M ahead of the $100M Series D it would go on to raise in 2025. The trajectory signals that investors see a durable company forming around open-source-based code scanning rather than a quick flip.
The round lands in a market where the biggest players keep absorbing capability directly: GitHub's acquisition of code-analysis vendor Semmle showed platform owners buying scanning outright, while independent vendors like Legit Security were raising their own rounds within months of this one. That split — build on an open-source core versus sell into or get acquired by a platform — defines the strategic question every player in code security is facing.
First-order effects
- Lightspeed takes a lead position in a code-security vendor at roughly $93M total funding, giving Semgrep the capital to scale sales and product against both independent rivals and platform-bundled alternatives like GitHub's Semmle-derived tooling.
Second-order effects
- Competing code-scanning startups such as Legit Security face a better-funded rival chasing the same developer-first buyer, pressuring them toward differentiation by vertical or acquisition as the natural exit path.
Third-order effects
- If the pattern holds — open-source engines raising successive mega-rounds while platforms acquire analysis vendors — code security consolidates into a few capitalized independents alongside platform-embedded offerings, squeezing out subscale point tools.
The trend: Code-security tooling is consolidating around venture-scaled open-source platforms even as developer-platform owners buy scanning capability outright.