Semgrep at BSidesSF / RSAC 2026

Semgrep is the leader in code security for builders.

AI has changed how code is written. Traditional SAST misses business logic. Pure AI tools can feel inconsistent and noisy.

We're launching the next generation of AppSec at RSA. Stop by our booth at BSides or RSAC (#1743) to get a first look.

Insider tip: ask us about joining our "Zero Trust Club" to build a better conference experience!

tl;dr sec Kick-off to BSidesSF and RSAC

location icon San Francisco, CA, United States
time icon Mar 20, 2026

BSidesSF

location icon City Metreon
time icon Mar 21, 2026

Security Leaders Dinner @ Saison

location icon San Francisco, CA, United States
time icon Mar 25, 2026

The Builders Lounge

location icon 799 Market St.
time icon Mar 23, 2026 - Mar 26, 2026

March 23, 2026 | 11:00am - 8:00 PT

Start RSA 2026 off right. Join Semgrep for an exclusive RSA launch party at EL DORADO Latin Fusion!

Come for lunch and stay for the party to kick off one of the industry's biggest weeks. There'll be great food, incredible networking, and a first look at Semgrep’s big reveal.

Schedule

3/20: Tl;dr sec Kickoff Event 5pm - 9pm PT

Semgrep Office, 799 Market St.

Join tl;dr sec for a laid-back community evening hosted by Clint Gibler, featuring a fireside chat with industry leaders. Connect with the people shaping modern AppSec in a relaxed, welcoming setting.

Register here!

3/21: BSides SF 8am - 5pm PT

City Metreon

Semgrep is heading to BSides SF to connect with builders and security leaders shaping the future of AppSec.

Stop by to learn more about our latest product launch to help developers reduce noise and ship secure code faster.

3/21: State of (Absolute) AppSec 11:20am-12:05pm PT

City Metreon

BSides panel at City Metreon featuring Clint Gibler.

Application Security is deep into its Artificial Intelligence phase, causing continuous evolution across the industry.

Absolute AppSec will ask panelists their opinion on topics covering generative AI, the OWASP Top 10, takeaways from 2025, and predictions for the future.

3/22: BSides Talk 1:30 - 2:15pm PT

City Metreon - AMC Theatre 04

Speaker: Dr. Katie Paxton-Fear

AI huh? What is good for? Absolutely Nothin'!

It's killing the planet, rotting your brain, and every product has slapped the AI label onto their product to get investors. AI is here whether we want it to or not. This bird of a feather discussion invites AI skeptics, realists and fearmongers to moan, complain and criticise AI and the new AI era.

3/22: BSides Talk 2:10pm - 2:55pm PT

City Metreon - AMC Theatre 10

Speaker: Claudio Merloni

The great SAST dissonance: how to please every audience, at scale.

SAST tools hit a sour note with modern apps with a dissonant coverage that leaves stretches of code unheard: dangerous sense of security. An AI conductor can fine-tune the orchestration for each application, let human experts focus and produce the right mix of coverage and findings.

3/22: BSides Talk 2:15 - 3pm PT

City Metreon - AMC Theatre 14

Presenter: Brandon Wu

One Thousand and One AI-Prevented CVEs: Vibe Coding a Whole New Supply Chain Defense
Supply chain attacks are everywhere.

With over 20,000 CVEs filed in Q2 2025. We wrote a non-agentic internal tool which combines deterministic callgraph-based methods with selective LLM reasoning to “vibe code” Semgrep rules, colossally decreasing the time security researchers spend processing CVEs.

3/23: Purple Book Club Event 11am-3:30pm PT

KPMG Building

Meet some of the Semgrep team at the ArmorCode Purple Book Club CISO networking event.

Register here.

3/23: RSA Booth Expo 5pm-7pm PT

Moscone South, Booth #1743

Stop by booth #1743 to meet the Semgrep team, learn about our newest product release, and claim your Zero Trust Membership Card for VIP access to extra sessions and swag!

3/23: Builders Lounge 12pm-5pm PT

Semgrep Office, 799 Market St.

Step into our lounge, where builders work with zero friction, zero frustration, and zero F’s for unnecessary complexity.
Enjoy espresso from Hedge Coffee Roasters, customize a survival kit or candy mix, recharge your devices, and relax in a space designed to keep you focused, fueled, and building.

3/23: Lunch & Learn at 12 PT

Semgrep Office, 799 Market St.

Miss BSidesSF? Join us for a lightning round session with BSidesSF speakers who will do tl;dr recap and get right to the point of their presentations from BSidesSF. Once more, with feeling.

3/23: Technical Workshop 12:30pm PT

Semgrep Office, 799 Market St.

Responding to Emergent Supply Chain Threats Workshop

A practical walkthrough for responding to fast-moving supply chain issues with Semgrep, from detection through remediation. You will see Malicious Dependency Detection (now GA) in action and leave with a repeatable playbook for the next high-profile dependency incident.

3/24: Builders Lounge 8am-5pm PT

Semgrep Office, 799 Market St.

Step into our lounge, where builders work with zero friction, zero frustration, and zero F’s for unnecessary complexity.
Enjoy espresso from Hedge Coffee Roasters, customize a survival kit or candy mix, recharge your devices, and relax in a space designed to keep you focused, fueled, and building.

3/24: From Supply Chains to AI-Assisted Development: How Security Leaders Navigate Modern Risk Breakfast 8:30am PT

Semgrep Office, 799 Market St.

Security leaders will discuss the challenges shaping 2026, from lessons learned from recent supply chain attacks to the security implications of AI coding assistants, along with the growing pressures CISOs face, including hiring gaps, shadow AI, budget constraints, and tool sprawl.
Register here.

3/24: RSA Booth Expo 10am - 6pm PT

Moscone South, Booth #1743

Stop by booth #1743 to meet the Semgrep team, learn about our newest product release, and claim your Zero Trust Membership Card for VIP access to extra sessions and swag!

3/24: Semgrep & Palo Alto Networks Workshop 12pm - 1pm PT

Semgrep Office, 799 Market St.

Hands-on Interactive Workshop: Securing AI-Generated Code with Cortex Cloud & Semgrep

See how Cortex Cloud by Palo Alto Networks integrates with Semgrep to help teams identify risks from AI-generated code, prioritize the most business-critical vulnerabilities using cloud and runtime context, and automate workflows from detection to developer remediation.

3/24: No Security, Just Vibes: Fixing Vibe Coded Apps Without Security Knowledge 2:25pm PT

RSA Conference Session

Speaker: Dr. Katie Paxton-Fear
Tuesday, Mar 24
2:25 PM - 3:15 PM PDT
[APP-T10] Reserved Seating

Vibe coding is enabling everyone and anyone to build software, even if they have no dev experience, with just a chat box and an idea. But while these tools excel at resolving bugs, going from error message to fix in a few seconds, this isn't true of security issues. Explore a collaboration between vibe coder, hacker, and AI agent, working together to fix vulnerabilities before the app launches.

Save your seat!

3/24: The Women in Security Documentary Screening 4:45 - 6:15pm PT

City Metreon

The WOMEN IN SECURITY documentary takes a powerful look at the women reshaping the security industry sharing real stories, lived experiences, and what it takes to lead in a space that hasn’t always made room for them.

Register here

3/25: RSA Booth Expo 10am - 6pm PT

Moscone South, Booth #1743

Stop by booth #1743 to meet the Semgrep team, learn about our newest product release, and claim your Zero Trust Membership Card for VIP access to extra sessions and swag!

3/25 Builders Lounge 8am-5pm PT

Semgrep Office, 799 Market St.

Step into our lounge, where builders work with zero friction, zero frustration, and zero F’s for unnecessary complexity.
Enjoy espresso from Hedge Coffee Roasters, customize a survival kit or candy mix, recharge your devices, and relax in a space designed to keep you focused, fueled, and building.

3/25: RSA Robs a Bank: Interactive Threat Modelling for Non-Technical Staff 8:30am PT

RSA Conference Session

Speaker: Dr. Katie Paxton-Fear
Wednesday, Mar 25
8:30 AM - 10:30 AM PDT
[LAB3-W01] Reserved seating; conference badge required.

And here's how they got away with it? Or, and here's how they got caught? Join this interactive experience and plot an attack or defense. Part game, part threat model, and part chaos. The attackers try to get out with the cash, the bank tries to stop them by following what little clues they have. Will they get away with it? Or will the attacker be spending life behind bars?

Reserve your seat!

3/25: Operationalizing AppSec with ASPM with ArmorCode & Semgrep 9am PT

Semgrep Office, 799 Market St.

Join Semgrep to see how it integrates with ArmorCode to transform developer-trusted code findings into risk-normalized, prioritized remediation workflows.

3/25: SAST + DAST in Sync with Semgrep & StackHawk From Prioritization to Proof 10am PT

Semgrep Office, 799 Market St.

Join us for a live, interactive demo of the Semgrep & StackHawk integration, showing a unified workflow from code scanning to runtime validation, with correlated findings that connect what you see in SAST to what’s discoverable and exploitable in a running application.

3/25: Lunch & Learn at 12pm PT

Semgrep Office, 799 Market St.

In this lunch and learn session, we’ll share how Semgrep Workflows enables security teams to orchestrate LLM agents, static analysis, and custom tools as executable security logic.

3/25: Technical Workshop 12:30pm PT

Semgrep Office, 799 Market St.

In this technical workshop, you’ll see how Semgrep’s AI-powered detection combines static analysis with LLM reasoning to uncover business logic vulnerabilities without custom rule writing.

3/25: The Women in Security Documentary Screening 4:45 - 6:15pm PT

City Metreon

The WOMEN IN SECURITY documentary takes a powerful look at the women reshaping the security industry sharing real stories, lived experiences, and what it takes to lead in a space that hasn’t always made room for them.

Register here.

3/25: AWS After Hours RSA Cocktail Reception 5:30pm - 8:30pm PT

Novela Restaurant

We're proud to sponsor the AWS Global Startup Program reception, an evening of cocktails, networking, and cybersecurity conversations.

Register here.

3/26: RSA Booth Expo 10am - 2pm PT

Moscone South, Booth #1743

Stop by booth #1743 to meet the Semgrep team, learn about our newest product release, and claim your Zero Trust Membership Card for VIP access to extra sessions and swag!

3/26: Builders Lounge 8am-12pm PT

Semgrep Office, 799 Market St.

Step into our lounge, where builders work with zero friction, zero frustration, and zero F’s for unnecessary complexity.
Enjoy espresso from Hedge Coffee Roasters, customize a survival kit or candy mix, recharge your devices, and relax in a space designed to keep you focused, fueled, and building.

3/26: Lunch & Learn 10am PT

Semgrep Office, 799 Market St.

What Top Security Teams Do Differently: Trends in SAST

We provided a sample of data to OWASP for prioritizing the Top 10, but there was more to learn from our data across 88k repositories, 2500+ organizations, and 127 Million findings. Come listen as we share the data analysis and discuss other data-driven decisions behind AI detection and the future of code security.

3/26: Technical Workshop 1030am PT

Semgrep Office, 799 Market St.

Vibe Coding and AI Security Primer: From MCP to Mad Skills

A hands-on workshop for all skill levels to build an AI-assisted workflow in Cursor with security hooks. Get practical experience with agentic workflows and MCP skills, with security and AI experts available for help along the way.

Come meet our team

Request a meeting

Leading engineering organizations rely on Semgrep to embed security into the development workflow without sacrificing speed or scale.

Connect with us at RSA, attend a live demo, and visit our office near Moscone.

Your privacy matters to us. By submitting this form, you agree to our Privacy Policy