KANGL + SEMGREP · ECOSYSTEM ROADMAP

Kangl + Semgrep.

Semgrep made static analysis fast, hackable, and developer-first. Kangl is designed to deliver it on both Azure DevOps surfaces — PR checks on the diff, pipeline injection for the full artifact — under one policy.

WHAT SEMGREP DOES BRILLIANTLY

Semgrep's lightweight, rule-based engine runs in seconds, and its open rule format lets teams write organization-specific checks — a genuinely developer-friendly approach to SAST and beyond.

Its speed makes it ideal for pull-request feedback, where heavyweight analyzers are too slow to gate merges.

THE OPERATING GAP AT ESTATE SCALE

Two surfaces, twice the wiring

Semgrep shines at the PR and works in the build — but wiring both across hundreds of repositories and pipelines, consistently, is exactly the toil that erodes over time. None of this is a criticism of the scanner — it is the operating layer every scanner needs and none of them ship, because their job is detection, not estate management.

Rules drift like code

Per-repo configuration and ignore files accumulate into unaudited local policy — the same finding blocks in one repo and passes in another.

Coverage accounting

Which repositories run which rulesets at which enforcement level is a spreadsheet nobody maintains.

WHAT KANGL ADDS

Your scanner, amplified.
Not replaced.

Kangl performs no scanning of any kind. Everything below is estate operations: the layer that turns a great scanner into an enforced, observable, auditable program across Azure DevOps.

Dual delivery, one policy

Kangl is designed to run Semgrep as both a PR-gate provider (fast diff checks as required statuses) and a pipeline-injection provider (full scans in the build) — with one backend policy issuing consistent verdicts on both surfaces.

Estate-wide state

Enrollment, ruleset assignment, and enforcement mode held as central state — visible, bulk-operable, and audited.

Drift-proofing

Reconciliation detects repositories and pipelines that fell out of coverage and repairs them deliberately.

This integration is on the Kangl ecosystem roadmap — it describes designed delivery mechanics, not a live integration. Snyk is production supported today →

FREQUENTLY ASKED

Kangl + Semgrep, in practice.

Does Kangl compete with Semgrep's own platform features?

Kangl's scope is the Azure DevOps estate: coverage, policy verdicts, drift, and audit there. Semgrep's engine, rules, and platform remain the detection layer.

Is Semgrep support available now?

Semgrep is on the ecosystem roadmap, planned for both PR-gate and pipeline-injection delivery. Snyk is the production-supported provider today.

Can custom rules still be used?

That is the intent — Kangl operates delivery and policy, not rule content. Your rules stay yours.

Semgrep capabilities are described at a general, publicly-known level. See all providers →

SECURITY OPERATIONS, UNIFIED

Bring your security tools.
Kangl makes them one platform.

Start with seven days of full plan access — or see it live with our team first.