Case Study: Thinkific reduces false positives by 85% with Semgrep
Key results
The challenge
Thinkific's lean security team needed to give developers the right security data so engineering could meet its Service Level Objectives without slowing development. Its previous application security products scanned slowly (hours on the monorepo), produced extremely noisy results with a high false-positive rate, and could not be configured to fit Thinkific's environment.
The solution
Thinkific uses Semgrep Code (SAST) to communicate security issues to developers efficiently and Semgrep Supply Chain (SCA) to manage open-source dependency risk. The team applies guardrails so pull requests are only blocked when high-confidence or reachable issues are detected, and found Semgrep highly customizable to its program's requirements.
The results, in context
Semgrep Supply Chain reduced Thinkific's false positives by 85% compared with its previous tools, cutting the noise developers encounter. The setup lets the security team surface reachable issues without blocking routine pull requests, keeping development velocity intact.