Fundraising Fox

Semmle

Acquired

Oxford · Founded 2014 · 6,772 employees on LinkedIn · 2 known investors

Find your way into Semmle

104 people in our graph share verified history with the Semmle team — schools, employers, funds. One of them is your warm intro.

Sanjot Malhiunlockedknows Oege de Moor · together at XBOW (overlapped)
×3knows the team · via XBOW
×7knows the team · via University of Oxford
knows the team · via Semmle

Semmle built a semantic code analysis engine that lets developers and security researchers write declarative queries to find vulnerabilities and code patterns across large codebases. The company, acquired by GitHub, serves security teams and open source communities, and operates lgtm.com.

Also known as LGTM · Semmle Inc · SemmleCode

Founders & leadership

Semmle was founded in 2014 by Oegerikus de Moor and Oege de Moor.

OD
Oegerikus de MoorCo-founder
ODOege de Moor
Oege de MoorinFounderOege de Moor founded Semmle, a code analysis company acquired by GitHub, and previously was a computer science professor at the University of Oxford for more than two decades.

Board

JC
Joseph C. M. HallBoard director

Investors · 2

Reported raises · per SEC filings

Form D private placements

$8M disclosed across 1 of 3 rounds · 2011–2018

$8MraisedAug 2014 · 3 investors · Other Technology
Rule 506(b)
Officers, directors & promoters on the filing
  • Oegerikus de MoorExecutive Officer, Director
  • Joseph C. M. HallDirector
Offering amount
$8M
Amount sold
$8M
First sale
Aug 2014
Incorporated
Corporation, Delaware, 2014
Federal exemptions
06b
Full filing on SEC EDGAR ↗

Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.

Company profile

researched Aug 2026

Semmle Inc was a code-analysis company founded as a spin-out of research at the University of Oxford. Its core idea was to treat source code as data and analysis problems as queries against a database, using an object-oriented query language derived from Datalog. The query language was known as QL (earlier SemmleCode, renamed CodeQL in 2019) and supported recursive queries, which allowed inspection of hierarchical program structures such as call graphs. Users could encode security or domain expertise as declarative queries and run them repeatedly against large codebases to detect a coding mistake and all of its variants, a process the company described as variant analysis.

The company shipped two main products: the QL/CodeQL query engine and LGTM, a platform for running queries at scale as part of developer workflows. LGTM automated code review, tracked developer contributions and flagged security issues, and was offered both as the free lgtm.com service for public repositories and open source projects and as LGTM Enterprise, with deployment tooling and integrations for Jira, IntelliJ and Eclipse (later Visual Studio Code). Early tooling provided an Eclipse IDE interface for querying Java source and bytecode plus XML files.

Semmle was acquired by GitHub, itself owned by Microsoft, on 18 September 2019 for an undisclosed amount. GitHub stated that existing Semmle products would continue without disruption, that lgtm.com would remain free for public repositories and open source projects, and that Semmle technology would be integrated into GitHub for continuous vulnerability detection. In November 2019 CodeQL was made free for research and open source use. The Semmle GitHub organization was archived in May 2023, with repositories redirected to github/codeql and github/security-lab.

Founding story

Founder Oege de Moor taught at the University of Oxford for 21 years, working primarily on programming-language theory. During a sabbatical at Microsoft he worked with a large codebase and found that structural questions about it were time-consuming to answer, prompting the idea of indexing source code like a database that could be queried. The underlying academic lineage runs through Linton's Omega system, the XL C++ Browser and the CodeQuest system developed at Oxford, which established Datalog as a practical balance between expressive power and query efficiency. Semmle was founded in December 2006 to build the technology from scratch and was separated from Oxford at founding to avoid ambiguity over IP ownership.

Business model

Semmle sold its code-analysis platform to enterprises, including an on-premises LGTM Enterprise offering, while providing the lgtm.com service free to open source projects and public repositories. Community sharing of queries — including contributions from customer security teams — supplemented the company's own query libraries.

Paid commercial licensing of its code analysis products to enterprise customers, alongside a free tier for open source and public repositories.

Traction

By August 2018 the company had roughly 60 employees and was analysing every commit of almost 80,000 open source projects. As of early 2019 more than 1,600 publicly available QL queries ran across hundreds of thousands of private and open source codebases. Named customers over time included Google, Microsoft, Uber, Credit Suisse, NASDAQ, NASA, Dell, Murex, Certipost and EMC, plus open source projects such as systemd and AMP. The technology helped find thousands of vulnerabilities and over 100 CVEs in open source projects, including 46 vulnerabilities found in 2018 by a two-engineer research team and disclosures in projects such as Ghostscript and macOS. In a NASA engagement, QL identified 33 undetected variants of a landing-software bug in the Curiosity rover codebase in about 20 minutes.

Latest developments

GitHub announced the acquisition of Semmle on 18 September 2019, stating that Semmle's engineers and security researchers would join GitHub, that existing products and the free lgtm.com service for open source would continue, and that the technology would support continuous vulnerability detection. CodeQL was made free for research and open source in November 2019, and the Semmle GitHub organization was archived in May 2023 with repositories migrated to github/codeql and github/security-lab.

Full profile — market position, technology, go-to-market, geography, history, risks & controversies

Market position

Positioned in the static program analysis and code-search market, differentiated from source-code-mining and software-renovation vendors such as CAST and BluePhoenix by its object-oriented query language that lets developers author project-specific queries. The company reported customers among large technology firms and financial institutions and became part of GitHub's developer-security portfolio after acquisition.

Rather than a fixed set of built-in checks, Semmle exposed code as a queryable database so that security expertise could be codified once as a declarative query and applied automatically at scale, including to find all variants of a known defect. Queries were shared publicly with a community that included security teams at Google and Microsoft, producing a query library larger than any single team could maintain.

Technology

A semantic code analysis engine that converts source code into a relational database that can be queried with QL/CodeQL, an object-oriented query language in the Datalog family that supports recursion. Queries express code patterns and vulnerability conditions declaratively and can be run continuously against builds; the LGTM platform executes queries at scale across large numbers of private and open source codebases. Tooling included an Eclipse plugin for querying Java and XML, later replaced by a Visual Studio Code-based workflow, plus Jira and IntelliJ integrations and deployment scripts for Azure, Google Cloud, Ansible and Bash.

Go-to-market

Early customer acquisition relied on cold outreach to prospects identified on LinkedIn, followed by referrals and reference customers as awareness grew. Publicised vulnerability research in widely used open source projects and the free lgtm.com service for open source developers served as awareness channels, and strategic enterprise partnerships were a primary source of business. Proceeds of the 2018 Series B were earmarked for building out sales and marketing to reach a broader enterprise market.

Enterprise security and development teams working with large codebases, security researchers, and open source project maintainers.

Geography

Headquartered in San Francisco, California, with development operations in Blue Boar Court, Alfred Street, central Oxford, England. Additional US offices in Seattle and New York, and international offices in Oxford, Valencia and Copenhagen.

History

Founded in December 2006 in Oxford, England, the company initially targeted general code quality and business intelligence over software data sources rather than program analysis alone; six patents were filed after incorporation. Commercial sales began in 2008, and in 2009 Semmle signed license agreements with Murex and NASA. NASA used the technology in connection with the 2012 landing of the Curiosity Mars rover. A $2 million seed round in 2011 was followed by an $8 million Series A from Accel in 2014 and a $21 million Series B led by Accel in August 2018, bringing total funding to $31 million. The company shifted emphasis to security applications, launching a vulnerability-research effort in late 2017. GitHub acquired Semmle in September 2019, and CodeQL was made free for research and open source in November 2019.

Risks & controversies

The acquisition consideration was not disclosed. Following integration into GitHub, Semmle-branded assets were wound down: the Eclipse-based workflow was replaced by a Visual Studio Code workflow, LGTM and SecurityQueries repositories were deprecated or migrated, and the Semmle GitHub organization was archived in May 2023.

Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
CVEs found in open source projectsSep 2019100 CVEs
EmployeesAug 201860 people
HeadcountAug 20266,772
Open source projects analysed (every commit)Aug 201880,000 projects
Patents filed after company creationJan 20146 patents
Publicly available QL queriesFeb 20191,600 queries
Total funding raisedAug 2018$31M
Vulnerabilities found by security research team in 2018Jan 201846 vulnerabilities

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Timeline · 7

launches, deals, and filings
May 2023
Semmle GitHub organization archived

The Semmle GitHub organization was marked as archived and is no longer maintained; repositories were migrated to github/codeql and github/security-lab.

source ↗

Nov 2019
CodeQL made free for research and open source

Use of CodeQL was made free for research and open source purposes.

source ↗

Sep 2019
GitHub acquires Semmle

GitHub announced it had acquired Semmle for an undisclosed amount, bringing Semmle's semantic code analysis engine, engineers and security researchers to GitHub; existing products and the free lgtm.com service for public repositories and open source were to continue.

source ↗

Sep 2019
QL renamed CodeQL

Semmle renamed its QL product and tooling to CodeQL, with QL snapshots becoming CodeQL databases.

source ↗

Jan 2012
Technology used in Curiosity Mars rover landing

NASA used Semmle's technology to analyse the Curiosity rover codebase; QL found 33 undetected variants of a landing-software bug in about 20 minutes ahead of the 2012 landing.

source ↗

Jan 2009
License agreements with Murex and NASA

Semmle signed two license agreements, with Murex and with NASA.

source ↗

Jan 2008
First commercial sales

The platform began being sold to customers in 2008, including a multinational financial services holding company and NASA.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

In the news

Research sources · 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Semmle do?
Semmle built a semantic code analysis engine and the LGTM platform for querying codebases to find security vulnerabilities; acquired by GitHub in 2019.
Who founded Semmle?
Semmle was founded by Oegerikus de Moor, Oege de Moor in 2014.
Who are Semmle's investors?
Semmle's investors include Accel, Work-Bench.
How much funding has Semmle raised?
Semmle has disclosed $8M raised across 1 of its 3 known rounds.
Where is Semmle headquartered?
Semmle is headquartered in Oxford.