Case Study: Tide reaches an 80% noise reduction and 100% fix rate with Semgrep
Key results
The challenge
Tide set out to transition to developer-first security, embedding tools across each step of the software development lifecycle and empowering developers to understand and fix security issues themselves. Doing so required security products that developers would trust and that would not drown them in false positives.
The solution
Tide adopted Semgrep to run a developer-first secure SDLC, using Semgrep Supply Chain's reachability analysis to prioritize real dependency risk, Semgrep Code's custom rules for issues specific to its code, Semgrep Assistant for AI-assisted remediation, and IDE extensions to surface issues early. The team paired the tooling with a Security Champions program to democratize security.
The results, in context
Semgrep Supply Chain's reachability analysis reduced Tide's false positives in software composition analysis by 80%, and Semgrep Code's custom rules achieved a 100% fix rate for the issues they found. The developer-first model spread security ownership across engineering through the Security Champions program.