Squarespace onboarded 80% of repositories in the first month, proving secure development can move as fast as engineering.
Explore how Squarespace redefined its AppSec program with Semgrep. Through continuous collaboration, iterative rollout, and direct developer feedback, Squarespace embedded security into every stage of development—transforming AppSec from a blocker into an enabler.
Onboarded 80% of repositories in the first month.
Achieved full coverage in under a year.
Integrated AppSec directly into developer workflows.
Adopted a phased rollout: monitor, comment, block to ensure developer trust and adoption.
“We’re excited about the partnership with Semgrep and what’s next, especially features like AI Assistant Memories that help developers learn and act faster. Semgrep isn’t just evolving with us; it’s helping shape where AppSec is going.”
— Gabriel Bennett, Lead Security Engineer, Squarespace
Key Outcomes