For the amount of valuable information that flows through AppSec tools, it’s frustrating how static they are. Most SAST tools are exactly the same on day 100 as they are on day 1 - no smarter, no quieter - despite sitting at the intersection of security and development.
Every false positive closed, every triage note written, every "not exploitable" comment left by a dev - it’s all valuable information you’d expect a smarter system to learn from or even be designed around. Yet SAST tools only view these data points as outputs for reporting, not potential inputs.
In this webinar, we’ll:
Discuss how we used AI to make Semgrep a more dynamic platform, capable of tailoring itself to users’ environments
Share insights and learnings we had while building out our “Memories” feature
Share our philosophy building and operating an application layer AI product