Semgrep matches patterns.
Hyrax evaluates six domains.
Semgrep is fast, transparent and easy to extend, and custom rules make it excellent for enforcing known patterns. Hyrax answers a broader question across six domains, and verifies every change against the project test suite before opening a pull request.
- Hyrax audits roughly 400 of its own repositories.
- Free plan: full access, up to 100 PR reviews a month, a $30 starter credit, and $10/month ongoing.
Verified end to end, with no Semgrep handoff
What changes when Hyrax runs above the tools.
Six domains, not one
Semgrep covers its own scanning domain well. Hyrax evaluates security, correctness, maintainability, performance, architecture and operations together.
Verified against the project tests
A rules engine confirms a change satisfies its own rules. Hyrax runs the project test suite and build, so a change is proven against the real system.
Context that compounds
The map of the codebase lives in the repository and strengthens with every merge, so the next decision starts from everything learned before it.
How Hyrax and Semgrep make decisions.
| Decision criteria | Semgrep | Hyrax |
|---|---|---|
| Unit of work | The file, matched against rules and patterns. | The whole repository, audited continuously across six domains. |
| Codebase context | Syntax-aware pattern rules, with cross-file dataflow on paid plans. | A durable map committed to the repository as HYRAX.md and .hyrax/discovery, so it strengthens as the codebase changes. |
| Output type | Rule issues, with autofix available for some rules. | Verified pull requests, plus issues ranked by severity and effort. |
| Verification | Autofix applies a pattern rewrite. Repository CI runs the tests. | Baseline tests, build, lint and a second reviewer agent run against the project itself before a pull request opens. |
| Human control | The team triages issues and merges. | A human approves and merges every pull request. Hyrax never merges on its own. |
| Delivery surface | CI, CLI, IDE and pull request comments. | GitHub pull requests, with issues and posture in the Hyrax console. |
| Pricing model | Open source engine free, then per contributor from around $40 per month. | Free plan with a $30 starter credit and $10/month ongoing. Paid is $30 per user per month and each paid user gets $30/month of credits. |
Read how Semgrep describes itself: semgrep.dev(opens in a new tab)
Comments on a diff, or a verified pull request.
- 01Semgrep scans the project against its rule set.
- 02Issues arrive as a list to triage, with severity attached.
- 03The team decides what is worth resolving, makes the edits, and merges.
- 01Maps the codebase and keeps the map in the repository
- 02Applies architectural judgment across six domains
- 03Opens a verified pull request that a human merges
GitHub-native. Human-controlled. Verified before merge. No training on customer code.
From install to the first verified pull request.
Install the GitHub App
Grant read access to the repositories in scope. No card is required to start.
Hyrax maps the repository
Discovery writes HYRAX.md and .hyrax/discovery into the repository, so humans and AI tools read the same context.
Review the first pull request
Approved upgrades arrive as verified pull requests. A human merges every one.
Both tools solve real problems.
Choose Semgrep if
The team has patterns it needs enforced and wants rules it can read, write and version itself. Semgrep is the right instrument for known problems.
Choose Hyrax if
The problems worth issue are not all known in advance. Hyrax reasons about the codebase across six domains rather than matching a pattern catalogue, and verifies each change against the project itself.
Open source engine free, then priced per contributor.
Free plan with a $30 starter credit and $10/month ongoing. Paid is $30 per user per month, and each paid user gets $30/month of credits.
Questions about Semgrep and Hyrax.
Does Hyrax work alongside Semgrep?
Yes, and most teams run both. Semgrep keeps doing its job. Hyrax works at the level of the whole codebase, decides what is worth changing, and delivers verified pull requests. Nothing about the Semgrep setup has to change.
What does Hyrax change in the repository?
Discovery writes HYRAX.md and a .hyrax/discovery directory, which document the architecture, conventions and risk areas of the codebase. Everything else arrives as a normal pull request on its own branch. Hyrax has no write access to the default branch.
How does pricing work?
The free plan includes full access, a $30 starter credit and $10/month of credits ongoing, with no card required. The paid plan is $30 per user per month, and each paid user gets $30/month of credits. Pull request reviews are included on every plan.
What happens after signup?
Installing the GitHub App and granting access to a repository takes a few minutes. Hyrax maps the codebase, then runs the first audit and returns issues ranked by severity and effort. The first verified pull requests follow once an audit is approved.