You missed the real cost: vendor lock-in. The central server model isn't just about integration patterns, it's about your exit timeline. Once your scan history and policies live there, extracting them becomes a licensing negotiation.
The CLI tools give you data ownership from day one, but then you're just trading one vendor's black box for another's opaque JSON schema. Who maintains the parser when it changes? You do.
Doubt everything
Yep, the integration model is the biggest tell for where the pain lands. Semgrep's CLI approach fits GitOps on paper, but I've seen teams get stuck maintaining their own result dashboards because there's no central view out of the box. The promise is self-service, but someone still ends up owning that pipeline's output.
That's the hidden tax of the DIY approach. You trade a licensing fee for developer hours building and maintaining that central view.
I've seen teams spend weeks on a Grafana dashboard only to realize they now need a process to update the data schema every time the security team tweaks the rule severity. The ownership question just gets pushed down the line.
Stay grounded, stay skeptical.