DryRun Security vs Microsoft MDASH vs Semgrep AI vs ZeroPath

A side-by-side look at scores, pricing and features — with RECATOOLS' ASEAN-aware verdict for each.

DryRun Security AI-native contextual security for every pull request — catch exploitab... Visit Microsoft MDASH Multiple models argue over a suspected bug until one can prove it Visit Semgrep AI AI-augmented static analysis (open source) Visit ZeroPath AI-native AppSec that verifies findings before flagging them. Visit
RECATOOLS Score 8.1 / 10 7 / 10 8.2 / 10 7.8 / 10
Capability 8.8 8 8 8.5
Value for money 7.5 8.5 8 6.5
Ease of use 8.5 5.5 7 8
ASEAN readiness 5.5 5.5 6 6.5
API quality 7.8 6 8 7.5
Pricing Freemium Contact Open Source Freemium
Free tier Free: basic scans, GitHub integration, limited monthly code reviews Public preview — external security teams can run the scanner against their own code Free and open source — self-host at no cost Free plan: unlimited PR scans for 1 repo, 1 full scan/month, core SAST/SCA
Paid from Tiered plans plus custom Enterprise; official per-seat pricing not publicly listed Team from $1,000/month base + $60/developer/month (14-day free trial)
Has API
Open source
Free to use
Users Customers ran 250,000+ code reviews/month as of early 2025; customer count undisclosed 1,000+ organisations, 200k+ scans/month (Mar 2026)
Founded 2023 2026 2017 2024
Maker James Wickett (CEO) and Ken Johnson (CTO) Microsoft ZeroPath Corp.
Verdict

DryRun Security's pitch — trace actual data flow instead of matching regex patterns — holds up under testing. Its own 2025 SAST Accuracy Report caught 23 of 26 seeded vulnerabilities across four public benchmarks (Rails,...

The design is the interesting part. Most AI code-scanning fails on precision rather than recall, and MDASH is engineered around exactly that — agents that debate each other, then a proof-of-concept requirement before a f...

Semgrep is one of the strongest developer-first application security platforms: fast pattern-based static analysis, secrets detection, supply-chain (SCA) scanning, and an AI layer (Semgrep Assistant) that triages finding...

ZeroPath's LLM-plus-verification pipeline demonstrably catches business-logic and auth vulnerabilities that pattern-matching scanners miss — the Aptos Labs case study (1M+ line Rust codebase, a replay bug that Semgrep, C...

Full review → Full review → Full review → Full review →
← Back to AI Directory

Comparisons cover up to 4 tools. Scores are RECATOOLS editorial assessments; verify current pricing on each vendor's site.