Case Study: Homebase cuts weekly triage from ~8 hours to 1-2 with Semgrep
Key results
The challenge
Homebase, a workforce management platform, outgrew traditional scanning as its applications grew in complexity and needed precise coverage of business-logic and authorization risk. Its mix of static analysis tools, manual review, annual penetration tests, and a bug bounty program produced high noise, low confidence that critical logic bugs were detected, late discovery of serious issues by external researchers, and real costs from bug bounty payouts and emergency fixes.
The solution
Homebase replaced noisy scanning and manual review with Semgrep Code and its AI-powered detection to identify authorization and business-logic vulnerabilities before they reach production, giving developers vetted, actionable findings they could trust and fix quickly.
“We had scanners, but they weren't useful for what we actually cared about. We still didn't feel confident we were seeing the critical issues. We needed a clear baseline.”
MNMinh NghiemSenior Security Engineer, Homebase
The results, in context
Homebase reduced time spent on triage from roughly 8 hours per week to 1-2 hours, and about 75% of the vulnerabilities Semgrep identified required remediation. Early detection of authorization vulnerabilities prevented costly bug bounty payouts, saving tens of thousands each year, and cut time-to-remediation for authorization vulnerabilities from weeks to days.