Case Study Deskcasestudydesk.com
SoftwareSourced

Case Study: Homebase cuts weekly triage from ~8 hours to 1-2 with Semgrep

Homebase Case StudySourced & dated by Case Study Desk
Key facts · TL;DR
Company
Homebase
Industry
Software
Challenge
Noisy scanners and manual review left the team unsure critical logic bugs were caught
Headline result
Homebase reduces triage time to 1-2 hours a week and catches authorization flaws before production

Key results

1-2 hrs
Weekly triage time
down from ~8 hrs/week
~75%
Of identified vulnerabilities required remediation
Weeks to days
Time-to-remediation for authorization vulns

The challenge

Homebase, a workforce management platform, outgrew traditional scanning as its applications grew in complexity and needed precise coverage of business-logic and authorization risk. Its mix of static analysis tools, manual review, annual penetration tests, and a bug bounty program produced high noise, low confidence that critical logic bugs were detected, late discovery of serious issues by external researchers, and real costs from bug bounty payouts and emergency fixes.

The solution

Homebase replaced noisy scanning and manual review with Semgrep Code and its AI-powered detection to identify authorization and business-logic vulnerabilities before they reach production, giving developers vetted, actionable findings they could trust and fix quickly.

We had scanners, but they weren't useful for what we actually cared about. We still didn't feel confident we were seeing the critical issues. We needed a clear baseline.

MN
Minh Nghiem
Senior Security Engineer, Homebase

The results, in context

Homebase reduced time spent on triage from roughly 8 hours per week to 1-2 hours, and about 75% of the vulnerabilities Semgrep identified required remediation. Early detection of authorization vulnerabilities prevented costly bug bounty payouts, saving tens of thousands each year, and cut time-to-remediation for authorization vulnerabilities from weeks to days.

Products used

Semgrep Semgrep Code