ssessing and improving our controls and associated processes by driving priorities through our Information Security Management framework.At the company level, Sonar maintains both ISO 27001:2022 certification and SOC 2 Type II attestation for all products and services. Both are available for download from our Security Profile. An NDA is required to access the SOC 2 Type II report, which can be signed electronically on the Security Profile. Softw
View source ↗SonarSource SOC 2 status and provider evidence
Review SonarSource’s public SOC 2 statement, report type, evidence source, and freshness.
SonarSource’s SOC 2 stack
No provider is named on the current source.
We will update this page if the company publishes more detail.
Frameworks named by SonarSource
it card information never transits through our system, nor does it get stored on our server. It is handed off to Stripe, a company dedicated to storing customers sensitive data on PCI-Compliant servers.System SecuritySonarQube Cloud uses its own Virtual Private Cloud (AWS VPC) and runs its workloads inside private networks behind firewalls.Permissions to infrastructure resources are modeled through IAM policies. Secure tokens and devices a
View source ↗ls and associated processes by driving priorities through our Information Security Management framework.At the company level, Sonar maintains both ISO 27001:2022 certification and SOC 2 Type II attestation for all products and services. Both are available for download from our Security Profile. An NDA is required to access the SOC 2 Type II report, which can be signed electronically on the Security Profile. Software SecurityOur software deve
View source ↗Primary compliance evidence
ls and associated processes by driving priorities through our Information Security Management framework.At the company level, Sonar maintains both ISO 27001:2022 certification and SOC 2 Type II attestation for all products and services. Both are available for download from our Security Profile. An NDA is required to access the SOC 2 Type II report, which can be signed electronically on the Security Profile. Software SecurityOur software development
Open source ↗