SonarQube is an open-core static code analysis platform developed by Sonar. It scans source code to detect issues like bugs, vulnerabilities and code smells on various programming languages and infrastructure technologies.
Summary from Wikipedia.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
-
ISO 27018
Publicly advertised on the organization’s trust center.
-
CSA STAR
Publicly advertised on the organization’s trust center.
Compliance timeline
-
2007
Company founded
-
September 8, 2026
Posture last observed by Trust Index
Named as a subprocessor by
Organizations in the Trust Index that disclose SonarQube as a subprocessor.
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.