SonarQube logo

    SonarQube

    Freemium
    https://sonarsource.com
    >> OPEN TOOL

    SonarQube is an open-source platform for continuous code quality and security inspection that uses AI to detect bugs, vulnerabilities, and code smells across 30+ programming languages. Its AI-powered SonarCloud cloud service and IDE plugins provide instant code quality feedback in developer workflows.

    Category

    Security

    Subcategory

    Vulnerability Scanning

    Free Tier

    SonarQube Community Edition free forever; SonarCloud free for open-source

    Paid Plans

    Developer Edition from $150/year, Enterprise and Data Center editions available

    API Cost

    Not available yet

    Web AppAPIVS Code ExtensionCLI

    SonarQube Trust & Security Report

    Certifications, AI-training posture, and security controls, with sourced proof.

    VIEW
    SOC 2 Type IIISO/IEC 27001:2022ISO/IEC 27018:2019 (PII protection in public cloud)CSA STAR (Level 1, self-assessment)PCI DSS (SAQ-A self-assessment)GDPR (compliance posture, not a certification)

    Verified against SonarQube's own trust and security pages. See the full report for sourced proof →

    Region

    SonarSource Sàrl is a Swiss entity (Geneva); DPA references processing under EU, UK, Switzerland, Singapore, and US region-specific terms with EU Standard Contractual Clauses governing transfers outside Europe. Privacy notice states data 'may be stored and processed in these jurisdictions and in other countries where SonarSource Sàrl, its affiliates, or authorized processors or subprocessors maintain operations' -- no fixed customer-selectable data residency documented for SonarQube Cloud beyond this.

    Trains on Data

    No

    Self-hostable

    Yes

    Continuous code quality inspectionSecurity vulnerability detectionTechnical debt managementCode review automationCI/CD quality gates

    // MORE IN VULNERABILITY SCANNING

    CodeQL logoCodeQL
    Free
    SecurityVulnerability ScanningVerified
    #code-analysis#security
    GitGuardian logoGitGuardian
    Freemium
    SecurityVulnerability ScanningVerified
    #secrets detection#credential scanning
    Semgrep logoSemgrep
    Freemium
    SecurityVulnerability ScanningVerified
    #static analysis#sast