No more typing reviews! Try our Samantha, our new voice AI agent.

Semgrep vs SentinelOne Singularity Cloud Security comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.8
Users reported improved ROI with Semgrep due to time savings, better code quality, reduced labor, and early vulnerability detection.
Sentiment score
5.7
SentinelOne Singularity Cloud significantly boosts efficacy by automating security, reducing costs, and enhancing productivity with faster incident response.
We have saved time by automating code analysis processes, which has reduced the number of employees needed for manual reviews.
DevOps SRO Specialist at a manufacturing company with 201-500 employees
This can be translated to being able to do the same amount of work with less technicians.
SecOps Engineer at a real estate/law firm with 501-1,000 employees
Tasks that previously took days are completed in significantly less time.
DevOps Engineer at Exponential Craft
After implementing SentinelOne, it takes about five to seven minutes.
Cloud engineer at a construction company with 5,001-10,000 employees
With SentinelOne Singularity Cloud Security, we reduce investigation time to about 80%.
Cybersecurity And Information Governance Head at Aeren
SentinelOne Singularity Cloud Security has helped reduce the time required for threat investigation and response by providing automated detection, detailed context, and centralized visibility.
it support at a outsourcing company with 51-200 employees
 

Customer Service

Sentiment score
6.6
Semgrep's comprehensive documentation and active community reduce the need for direct customer support, despite occasional communication issues.
Sentiment score
7.5
Feedback for SentinelOne Singularity Cloud Security is mixed, with praise for expertise but some complaints about responsiveness and knowledge.
When I created custom rules, I had some doubts, and the documentation was very helpful, simple, and easy to understand.
Senior Software Engineer 2 at Porch
Their documentation and community are very active, so most of the time when problems occur, I get a solution.
Security Researcher at a tech vendor with 10,001+ employees
Customer support and services for Semgrep are very reliable and good.
Angular developer at Flourish software
Having a reliable team ready and willing to assist with any issues is essential.
Director, DevOps at Relay Network
Throughout the migration, they remained available for several hours without complaint, providing assistance at every step.
Mobile Application Developer at a retailer with 1-10 employees
In my experience, I have never encountered a junior person or someone without knowledge coming into support from SentinelOne.
Senior Technical Engineer at Safezone Secure Solutions Private Limited
 

Scalability Issues

Sentiment score
8.3
Semgrep efficiently manages small and large projects, integrating well in microservices, though some prefer other tools for enterprises.
Sentiment score
7.8
SentinelOne Singularity Cloud Security is praised for its scalability, seamless integration, and efficient management, supporting diverse environments.
I was able to control it from 10 repositories or 10 services to thousands of repositories in a couple of minutes very simply.
Cloud & Application Security at Sixt SE
This is an open-source tool, so it absolutely does the job, but if you were to implement a tool such as this in an enterprise, this would probably not be scalable.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
Semgrep makes it easy to integrate and grow within any environment without concern for crashes.
DevOps Engineer at Exponential Craft
The SentinelOne Singularity Cloud exhibits high scalability.
Security Analyst at Intersistemi Italia s.p.a.
We've automated in our MDM so any device that we start in our MDM automatically installs SentinelOne.
IT Support Specialist at a non-tech company with 201-500 employees
It is scalable. I would rate it a ten out of ten for scalability.
Sr security engineer at Halodoc
 

Stability Issues

Sentiment score
8.0
Semgrep is stable but needs improvements in scan completion, integration, and resources, especially for AI-based and large repos.
Sentiment score
8.3
SentinelOne Singularity Cloud Security is highly stable and reliable, with occasional minor issues, earning praise for its performance.
If there is no master branch or default branch, the tool fails to identify it and will never scan it unless manually somebody looks into it and fixes the issue.
Cloud & Application Security at Sixt SE
Since I have been using it, I have not experienced any downtime.
Angular developer at Flourish software
Semgrep is stable, as far as my experience indicates.
Senior Software Engineer 2 at Porch
I would rate the stability of SentinelOne Singularity Cloud Security a 10 because as of now we have not faced any stability issues.
Security Analyst at Softcell Technologies Limited
SentinelOne Singularity Cloud Security operates consistently, and that is how a product should work—you should not have to worry about it.
Technical Lead at a tech vendor with 51-200 employees
SentinelOne Singularity Cloud is incredibly reliable.
Security Analyst at Intersistemi Italia s.p.a.
 

Room For Improvement

Enhancing Semgrep with better AI, reduced false positives, clear guidance, integration, and business logic focus boosts user experience and utility.
SentinelOne Singularity Cloud Security requires better integration, onboarding, interface, support, and cost-effectiveness with enhanced features desired.
The UI and additional dashboarding and other details would definitely make the tool more user-friendly and more of a candidate to be implemented in an enterprise.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
Currently, they are working on identifying business logic vulnerabilities or privilege escalation vulnerabilities by looking at the code, and they should continue to focus on and improve this effort.
Cloud & Application Security at Sixt SE
More advanced dependency analysis features in the SCA part and deeper vulnerability databases would be beneficial.
SecOps Engineer at a real estate/law firm with 501-1,000 employees
It gives our management a false impression of there being no open incidents over that period.
Information Security Manager at SBI General Insurance
A centralized dashboard with numerous metrics would improve user understanding.
Development Manager at SBI General Insurance
I feel there is room for improvement in SentinelOne Singularity Cloud Security, particularly in creating custom dashboards since it only has a default dashboard feature, and a capability for creating custom dashboards would help us a lot as analysts.
Security Analyst at Softcell Technologies Limited
 

Setup Cost

SentinelOne Singularity offers competitive, flexible pricing with modular options, particularly valued by enterprises for its advanced threat detection.
Once we fully integrated it into our company, it has proven to be price-efficient at around $30 a month.
Senior Software Engineer 2 at Porch
It is basically open-source, so the cost to set up is no cost.
Security Researcher at a tech vendor with 10,001+ employees
It offers very reasonable pricing and costs.
Angular developer at Flourish software
With very little negotiation involved, we just let them know what we could pay and they were willing to meet us at slightly above what we paid with Sophos, which was still very fair for what we were looking at.
IT Support Specialist at a non-tech company with 201-500 employees
I was able to consolidate two security vendors into one by switching to SentinelOne, and I now pay less than I did for either of them.
Director, DevOps at Relay Network
Its high cost may be prohibitive for small and medium-sized businesses.
Technical Support Engineer at a consultancy with 10,001+ employees
 

Valuable Features

Semgrep enhances code quality and security with multi-language integration, custom rules, IDE support, and AI-driven rapid scanning.
SentinelOne Singularity boosts security with AI-driven threat detection, centralized management, and streamlined incident response in multi-cloud environments.
When you triage with AI, it gathers context around the finding and reduces the noise about 80 to 90 percent of the time, asking you to focus only on findings that really matter.
Cloud & Application Security at Sixt SE
The Software Composition Analysis is the most valuable feature in Semgrep.
DevSecOps Security Engineer at a manufacturing company with 10,001+ employees
The best feature of Semgrep is its ability to highlight high priority issues during scanning, making it critical for developers to address these vulnerabilities promptly.
DevOps Engineer at Exponential Craft
This tool has been helpful for us. It allows us to search for vulnerabilities and provides evidence directly on the screen.
Cloud Security Specialist at a insurance company with 10,001+ employees
The cloud misconfiguration feature gave us almost zero false positives.
Sr security engineer at Halodoc
AWS real-time threat protection protects our workloads and provides visibility into anomalies or threats, automatically remediating them at speeds beyond our manual capabilities.
Director, DevOps at Relay Network
 

Categories and Ranking

Semgrep
Average Rating
7.8
Reviews Sentiment
7.4
Number of Reviews
9
Ranking in other categories
Static Application Security Testing (SAST) (10th), Supply Chain Management Software (4th), Software Composition Analysis (SCA) (9th), Static Code Analysis (6th)
SentinelOne Singularity Clo...
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
140
Ranking in other categories
Vulnerability Management (4th), Cloud and Data Center Security (5th), Container Security (3rd), Cloud Workload Protection Platforms (CWPP) (4th), Cloud Security Posture Management (CSPM) (3rd), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (2nd), AI Observability (4th)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Semgrep is designed for Static Application Security Testing (SAST) and holds a mindshare of 2.3%, down 3.1% compared to last year.
SentinelOne Singularity Cloud Security, on the other hand, focuses on Cloud-Native Application Protection Platforms (CNAPP), holds 6.0% mindshare, up 4.6% since last year.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Semgrep2.3%
SonarQube12.6%
Checkmarx One8.1%
Other77.0%
Static Application Security Testing (SAST)
Cloud-Native Application Protection Platforms (CNAPP) Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity Cloud Security6.0%
Wiz12.5%
Prisma Cloud by Palo Alto Networks10.1%
Other71.4%
Cloud-Native Application Protection Platforms (CNAPP)
 

Featured Reviews

Manjunath Maneppagol - PeerSpot reviewer
Cloud & Application Security at Sixt SE
Context-aware code analysis has reduced noise and now improves developer experience with actionable security findings
I have consistently observed that their scan time is an issue for mono repos. Sometimes with their AI-based scanning, when you triage that scan, the scan never completes or finishes(, which makes it difficult. Another consistent issue is that whenever you have a new repo to onboard to the platform, the tool ideally should detect the master branch by default. However, sometimes the tool fails to identify it and will never scan it unless manually somebody looks into it and fixes the issue. Although their support team is really good, this issue was present six or eight months ago during the POC and is still present now. If it is affecting multiple customers, it should be prioritized and fixed. I would say that their integration aspects could have been improved. I see a lot of different security solutions that provide flexibility to the security teams based on Jira project, team divisions, Slack, and all those can be very much easily customized. Semgrep needs to work on the enhancement of their notification capabilities. Currently, they are working on identifying business logic vulnerabilities or privilege escalation vulnerabilities by looking at the code, and they should continue to focus on and improve this effort. Regarding stability, whenever you have a mono-repo which is a very large repository, the scan never finishes or the scan never kicks in. At that time, you have to reach out to the support team and ask them to expand the resources in the back end to fix it. This is an issue I keep seeing often on that platform.
KP
Software Developer at Softcell Technologies Limited
Advanced rollback and AI-driven insights have protected endpoints and simplified security operations
We can check multiple types of alerts and triggers, and we can analyze these. There are many types of functions such as Kill, Quarantine, and remediate rollback types of features, which we can use for client safety. The rollback feature is the best feature because it is only used in SentinelOne Singularity Cloud Security. We have used multiple types of EDR, but the rollback feature is unique to SentinelOne Singularity Cloud Security. When many types of attacks happen in an organization, the rollback feature deletes all types of malicious files and other malware-type files and completely cleans your system. This feature is very interesting according to me. SentinelOne Singularity Cloud Security provides many types of features such as Kill and Quarantine, which are very interesting features for security operations. There are deep visibility features, and Purple AI is also one of the best features. It is easy for security operations and incident response. We can check log analysis with the help of deep visibility, and any types of attacks, malware, and phishing attacks are detected by SentinelOne Singularity Cloud Security. Many types of security operations can be tracked and observed with the help of SentinelOne Singularity Cloud Security. Purple AI is one of the interesting features in SentinelOne Singularity Cloud Security. Deep visibility is one of the best features in SentinelOne Singularity Cloud Security. You can find any types of logs and any types of devices through searching portals, similar to Google search. It gives you information regarding this. With deep visibility, you can search for any name. For example, we can search for any name and check what is happening with that person's laptops, what USB is connected or disconnected, and whether the network is connected or not. This is with the help of Purple AI.
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
916,117 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
10%
Comms Service Provider
9%
Outsourcing Company
8%
Financial Services Firm
13%
Manufacturing Company
9%
Computer Software Company
9%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise3
Large Enterprise6
By reviewers
Company SizeCount
Small Business63
Midsize Enterprise28
Large Enterprise64
 

Questions from the Community

What needs improvement with Semgrep?
Regarding improvements for Semgrep, I have noticed that it occasionally provides false positive results, although it does not happen consistently. That is the only major improvement I can think of,...
What is your primary use case for Semgrep?
Semgrep serves as an open-source static application security testing tool for my organization. We work under a microservices model with multiple repositories, around eight in total. Whenever we mak...
What advice do you have for others considering Semgrep?
Although not directly in the development process, Semgrep has saved substantial time in the review process. For instance, when a developer raises a pull request, Semgrep automatically reviews it be...
What is your experience regarding pricing and costs for PingSafe?
I have not personally dealt with pricing, setup costs, and licensing because in the end I only work on the console and do not do the installations.
What needs improvement with PingSafe?
In my opinion, there is not much to improve with SentinelOne Singularity Cloud Security as it is really good software. SentinelOne Singularity Cloud Security already gives you all the data you need...
What is your primary use case for PingSafe?
My main use case for SentinelOne Singularity Cloud Security is managing security incidents for the various companies we provide support to. A quick and specific example of a type of incident I have...
 

Also Known As

Semgrep Code, Semgrep Supply Chain, Semgrep AppSec Platform
PingSafe
 

Overview

 

Sample Customers

Policygenius, Tide, Lyft, Thinkific, FloQast, Vanta, and Fareportal
Information Not Available
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Static Application Security Testing (SAST). Updated: September 2026.
916,117 professionals have used our research since 2012.