SOC 2 company profile

SonarSource SOC 2 status and provider evidence

Review SonarSource’s public SOC 2 statement, report type, evidence source, and freshness.

SOC 2 statusself attested
Report typeType II
Providers found0
Last checked2026-08-30
Providers

SonarSource’s SOC 2 stack

No provider is named on the current source.

We will update this page if the company publishes more detail.

Compliance coverage

Frameworks named by SonarSource

ISO 27001

ssessing and improving our controls and associated processes by driving priorities through our Information Security Management framework.At the company level, Sonar maintains both ISO 27001:2022 certification and SOC 2 Type II attestation for all products and services. Both are available for download from our Security Profile. An NDA is required to access the SOC 2 Type II report, which can be signed electronically on the Security Profile. Softw

Checked 2026-08-30
View source ↗
PCI DSS

it card information never transits through our system, nor does it get stored on our server. It is handed off to Stripe, a company dedicated to storing customers sensitive data on PCI-Compliant servers.System SecuritySonarQube Cloud uses its own Virtual Private Cloud (AWS VPC) and runs its workloads inside private networks behind firewalls.Permissions to infrastructure resources are modeled through IAM policies. Secure tokens and devices a

Checked 2026-08-30
View source ↗
SOC 2

ls and associated processes by driving priorities through our Information Security Management framework.At the company level, Sonar maintains both ISO 27001:2022 certification and SOC 2 Type II attestation for all products and services. Both are available for download from our Security Profile. An NDA is required to access the SOC 2 Type II report, which can be signed electronically on the Security Profile. Software SecurityOur software deve

Checked 2026-08-30
View source ↗

Primary compliance evidence

SonarSource public statement

ls and associated processes by driving priorities through our Information Security Management framework.At the company level, Sonar maintains both ISO 27001:2022 certification and SOC 2 Type II attestation for all products and services. Both are available for download from our Security Profile. An NDA is required to access the SOC 2 Type II report, which can be signed electronically on the Security Profile. Software SecurityOur software development

Classification: self attested · checked 2026-08-30
Open source ↗
SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement
What SOC 2 Provider Does SonarSource Use? | SOC2Market