S
Semmle
Other B2B Software · Oxford, United Kingdom · Founded 2006
Code analysis platform for finding software vulnerabilities MoreLess
Semmle is a code analysis platform founded in December 2006 by Oege de Moor, a former professor of computer science at the University of Oxford. The company originated as a spin-out from the University of Oxford, building on de Moor's academic research on programming tools and treating code as data. De Moor's journey began during a sabbatical at Microsoft, where he identified the need for a way to query large, complex codebases as if they were a database. This idea formed the technical foundation for Semmle.
The company provides software engineering analytics and security tools designed to help development and security teams identify critical vulnerabilities and their variants. Its core technology is CodeQL, a powerful, object-oriented query language and code analysis engine that automates security checks by allowing developers to query code as data. This enables the discovery of specific coding patterns and bugs that could lead to security exploits. Semmle's other key product, LGTM (Looks Good To Me), is a platform that integrates with development workflows to automate code review, identify vulnerabilities early, and prevent them from reaching production. The technology has been used by prominent organizations such as Google, Microsoft, NASA, and Uber.
Semmle's business model focused on providing its platform to large enterprises to help them manage software development, reduce costs, and improve code quality. It generated revenue by selling its industrial-strength platform to clients including financial institutions and technology companies. The company raised a total of $31 million in funding over three rounds from investors like Accel. In September 2019, Semmle was acquired by GitHub, a subsidiary of Microsoft, for an undisclosed amount, although some reports suggest a figure around $410 million. Following the acquisition, Semmle's technology has been integrated into GitHub's platform as the native code scanning feature, making CodeQL analysis available to millions of developers to secure the open-source ecosystem.
Keywords: code analysis, vulnerability detection, software security, static analysis, CodeQL, variant analysis, code as data, semantic code analysis, developer security tools, application security, automated code review, software engineering analytics, vulnerability query, bug detection, open source security, DevSecOps, GitHub integration, continuous security
Talent graph
Semmle's talent
Source: Dealroom Talent Intelligence.
Global footprint
Where Semmle has talent and traffic
team presence
Market sentiment
What the market is saying about Semmle
An AI-synthesized read of the highest-engagement posts about Semmle on X over the past 7 days. We rank by likes & retweets, ignore corporate channels, and surface the themes that broke out from real people.
Reading the room on X — pulling top posts and synthesizing themes…
Source: X recent search ranked by engagement (likes + retweets) · Synthesis by Claude · Cached for 1 hour
See Semmle on the full Dealroom platform
Live deal flow, founder pedigree, hiring signals, revenue trajectory, and the full cap table.

