Overview

The Semgrep integration monitors your static analysis platform: findings, projects, rules, and deployments. LowerPlane uses read-only access via an API Key to collect compliance evidence automatically.

Prerequisites

You need Semgrep Organization Admin permissions to create an API token.

How to Get Your Credentials

1

Log in to Semgrep

Log in to the Semgrep Console.
2

Select your organization

Select your organization from the organization switcher.
3

Navigate to tokens

Go to Settings > Tokens.
4

Create a new token

Click Create New Token, give it a descriptive name, and copy the Secrets Value.
5

Note your organization slug

Your Organization Slug is visible in the URL when viewing your org settings (e.g., semgrep.dev/orgs/<org-slug>).

Connecting in LowerPlane

  1. Go to Settings > Integrations in LowerPlane
  2. Find Semgrep under Security Tools
  3. Enter your Organization Slug and API Token
  4. Click Connect

What LowerPlane Monitors

Findings

Security findings, severity levels, and remediation status.

Projects

Scanned projects and repository configurations.

Rules & Deployments

Active scanning rules and deployment configurations.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Static code analysis and vulnerability management are in place
ISO 27001Secure development practices are enforced
PCI-DSSApplication security testing is maintained