Everyone's going to tell you to buy Snyk or Checkmarx because they have the shiniest marketing decks. They'll conveniently forget you're a tiny team trying to ship code, not run a full-time security triage center.
For 5 people on Python/Lambda, your biggest problems aren't the top 10 OWASP—they're:
* **Noise-to-signal ratio:** Most SAST tools are terrible at Python frameworks (FastAPI, Django) and generate hundreds of false positives about "potential" issues. You'll spend more time whitelisting than fixing.
* **Lambda-specific blindness:** Does the tool actually understand the Lambda execution context, environment variables, and IAM permissions as an attack vector? Or is it just scanning raw source files?
* **The pricing trap:** "Per developer" or "per repo" licensing that quadruples in cost the moment you add a sixth engineer or a second microservice.
Before you even look at tools, answer this: are you prepared to:
* Tune out 80% of the default rule set?
* Write custom rules for your actual deployment model?
* Pay for a "platform" where you'll use 5% of the features?
The cloud vendors will push you toward their bundled tools (AWS CodeGuru, etc.), which is just a prettier form of lock-in. The open-source crowd will point to Bandit, which is good for basic patterns but won't catch your custom insecure deserialization in a Lambda handler.
Just my 2 cents
Trust but verify.