SonarQube is an open-source platform for continuous code quality and security inspection that uses AI to detect bugs, vulnerabilities, and code smells across 30+ programming languages. Its AI-powered SonarCloud cloud service and IDE plugins provide instant code quality feedback in developer workflows.
Category
Security
Subcategory
Vulnerability Scanning
Free Tier
Paid Plans
API Cost
SonarQube Trust & Security Report
Certifications, AI-training posture, and security controls, with sourced proof.
Verified against SonarQube's own trust and security pages. See the full report for sourced proof →
Region
SonarSource Sàrl is a Swiss entity (Geneva); DPA references processing under EU, UK, Switzerland, Singapore, and US region-specific terms with EU Standard Contractual Clauses governing transfers outside Europe. Privacy notice states data 'may be stored and processed in these jurisdictions and in other countries where SonarSource Sàrl, its affiliates, or authorized processors or subprocessors maintain operations' -- no fixed customer-selectable data residency documented for SonarQube Cloud beyond this.
Trains on Data
No
Self-hostable
Yes
