Sonar Achieves SOC 2 Type II Compliance

Milestone highlights company’s commitment to safeguarding user data and delivering secure, reliable solutions for millions of developers worldwide

GENEVA AND AUSTIN — February 12, 2025 — Sonar, the leading provider of code quality and security solutions, today announced that it has achieved Service and Organization Controls (SOC) 2 Type II compliance, a gold standard in data security and operational excellence. This accomplishment underscores Sonar’s dedication to protecting customer data and ensuring the highest level of trust and transparency in its operations as well as its SonarQube offering — SonarQube Server, SonarQube Cloud, and SonarQube for IDE


The SOC 2 Type II compliance is awarded following an in-depth independent audit, which evaluates a company’s controls, policies, and procedures, against the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria over an extended period. Achieving this compliance demonstrates Sonar’s ability to implement and maintain effective controls to protect sensitive information and ensure security reliability. 


“Attaining SOC 2 Type II compliance is a testament to our unwavering dedication to data security and our customers,” said Andrea Malagodi, CIO of Sonar. “This achievement not only validates the robust systems and processes we’ve built but also assures our customers that their trust in us is well-placed. We will continue to invest in our infrastructure and practices to deliver not only best-in-class solutions for code quality and security but also peace of mind to our customers.”


By achieving compliance, Sonar has met the stringent criteria outlined in the SOC 2 framework and further solidifies its investment in protecting customer data.


For more information about Sonar’s SOC 2 Type II compliance and its commitment to security, visit https://www.sonarsource.com/trust-center/.


About Sonar   

Sonar helps prevent code quality and security issues from reaching production, amplifies developers' productivity in concert with AI assistants, and improves the developer experience with streamlined workflows. Sonar analyzes all code, regardless of who writes it—your internal team or genAI—resulting in more secure, reliable, and maintainable software. Rooted in the open source community, Sonar’s solutions support over 30 programming languages, frameworks, and infrastructure technologies. Today, Sonar is used by 7M+ developers and 400K organizations worldwide, including the DoD, Microsoft, NASA, MasterCard, Siemens, and T-Mobile.


 To learn more about Sonar, please visit: https://www.sonarsource.com/products/all/   

  • 法律文件
  • 信任中心
  • Follow SonarSource on Twitter
  • Follow SonarSource on Linkedin

© 2008-2024 SonarSource SA. All rights reserved. SONAR, SONARSOURCE, SonarQube for IDE, SonarQube Server, SonarQube Cloud, and CLEAN AS YOU CODE are trademarks of SonarSource SA.