Overview
The Semgrep integration monitors your static analysis platform: findings, projects, rules, and deployments. LowerPlane uses read-only access via an API Key to collect compliance evidence automatically.Prerequisites
How to Get Your Credentials
Log in to Semgrep
Log in to the Semgrep Console.
Connecting in LowerPlane
- Go to Settings > Integrations in LowerPlane
- Find Semgrep under Security Tools
- Enter your Organization Slug and API Token
- Click Connect
What LowerPlane Monitors
Findings
Security findings, severity levels, and remediation status.
Projects
Scanned projects and repository configurations.
Rules & Deployments
Active scanning rules and deployment configurations.
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Static code analysis and vulnerability management are in place |
| ISO 27001 | Secure development practices are enforced |
| PCI-DSS | Application security testing is maintained |