Microsoft MDASH vs ZeroPath vs DryRun Security vs Semgrep AI

A side-by-side look at scores, pricing and features — with RECATOOLS' ASEAN-aware verdict for each.

Microsoft MDASH Multiple models argue over a suspected bug until one can prove it Visit ZeroPath AI-native AppSec that verifies findings before flagging them. Visit DryRun Security AI-native contextual security for every pull request — catch exploitab... Visit Semgrep AI AI-augmented static analysis (open source) Visit
RECATOOLS Score 7 / 10 7.8 / 10 8.1 / 10 8.2 / 10
Capability 8 8.5 8.8 8
Value for money 8.5 6.5 7.5 8
Ease of use 5.5 8 8.5 7
ASEAN readiness 5.5 6.5 5.5 6
API quality 6 7.5 7.8 8
Pricing Contact Freemium Freemium Open Source
Free tier Public preview — external security teams can run the scanner against their own code Free plan: unlimited PR scans for 1 repo, 1 full scan/month, core SAST/SCA Free: basic scans, GitHub integration, limited monthly code reviews Free and open source — self-host at no cost
Paid from Team from $1,000/month base + $60/developer/month (14-day free trial) Tiered plans plus custom Enterprise; official per-seat pricing not publicly listed
Has API
Open source
Free to use
Users 1,000+ organisations, 200k+ scans/month (Mar 2026) Customers ran 250,000+ code reviews/month as of early 2025; customer count undisclosed
Founded 2026 2024 2023 2017
Maker Microsoft ZeroPath Corp. James Wickett (CEO) and Ken Johnson (CTO)
Verdict

The design is the interesting part. Most AI code-scanning fails on precision rather than recall, and MDASH is engineered around exactly that — agents that debate each other, then a proof-of-concept requirement before a f...

ZeroPath's LLM-plus-verification pipeline demonstrably catches business-logic and auth vulnerabilities that pattern-matching scanners miss — the Aptos Labs case study (1M+ line Rust codebase, a replay bug that Semgrep, C...

DryRun Security's pitch — trace actual data flow instead of matching regex patterns — holds up under testing. Its own 2025 SAST Accuracy Report caught 23 of 26 seeded vulnerabilities across four public benchmarks (Rails,...

Semgrep is one of the strongest developer-first application security platforms: fast pattern-based static analysis, secrets detection, supply-chain (SCA) scanning, and an AI layer (Semgrep Assistant) that triages finding...

Full review → Full review → Full review → Full review →
← Back to AI Directory

Comparisons cover up to 4 tools. Scores are RECATOOLS editorial assessments; verify current pricing on each vendor's site.