Sonar

Sonar

Code quality and security analysis tools

Overview

SonarSource provides tools to improve code quality and security across development teams. Its products include SonarLint (an IDE plugin that gives real-time feedback as code is written) and SonarQube (a self-managed code analysis platform) and SonarCloud (a cloud-based analysis service), which analyze code for bugs, vulnerabilities, and maintainability and present guidance and reports. The tools work by integrating into developers' workflows—from IDE feedback with SonarLint to repository-wide analysis with SonarQube or SonarCloud—delivering dashboards and trend reports. The company differentiates itself with an end-to-end, subscription-based suite that covers local IDE feedback through centralized governance, serving hundreds of thousands of organizations, with the goal of keeping code clean, secure, and reliable.

About Sonar

Simplify's Rating
Why Sonar is rated
B
Rated B on Competitive Edge
Rated A on Growth Potential
Rated C on Differentiation

Industries

Data & Analytics

Enterprise Software

Cybersecurity

Company Size

501-1,000

Company Stage

Late Stage VC

Total Funding

$457.1M

Headquarters

Vernier, Switzerland

Founded

2008

Get referred to Sonar

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Westcon-Comstor signed Sonar on September 1, 2026 across EMEA and APAC.
  • June 30, 2026 launches cut LLM tokens up to 36% and burn technical debt.
  • Sonar passed $430 million ARR, with 100+ openings and 800+ employees.

What critics are saying

  • Sonar depends on AI coding adoption; if agentic development slows, 2026 growth resets.
  • Microsoft, GitHub, and Snyk bundle adjacent verification features, compressing Sonar pricing.
  • A major SonarQube breach or false-negative scandal would crater trust with regulated banks.

What makes Sonar unique

  • SonarQube now verifies AI code in real time across generation, review, and remediation.
  • Gitar acquisition on May 21, 2026 adds AI-native code review to SonarQube.
  • Sonar claims 7 million developers and 75% of Fortune 100 use its platform.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$457.1M

Above

Industry Average

Funded Over

2 Rounds

Late VC funding comparison data is currently unavailable. We're working to provide this information soon!
Late VC Funding Comparison
Coming Soon

Benefits

Flexible Work Hours

Hybrid Work Options

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Yahoo Finance
Aug 27th, 2026
Sonar launches SonarQube Hunter Agent to catch logic-based security flaws in AI code

Sonar has launched SonarQube Hunter Agent, an AI-powered security tool designed to detect logic-based vulnerabilities that traditional pattern-based scanning cannot identify. The agent finds broken access control, business-logic flaws, and authentication issues by analysing entire codebases and reasoning through how code, data, and identity flow through systems. Unlike conventional scanning tools that catch coding errors, Hunter Agent identifies vulnerabilities where code functions as written but permits unintended actions, such as unauthorised data access or bypassed checkout flows. These issues traditionally required manual security reviews or penetration testing. The agent operates on a scheduled basis without blocking pull requests or disrupting CI/CD pipelines. Verified findings appear directly in SonarQube's existing workflow, allowing teams to triage issues without switching tools. It complements rather than replaces Sonar's existing static application security testing capabilities.

SiliconANGLE Media
Aug 27th, 2026
Sonar launches Hunter Agent to find flaws code scanners can't see.

Sonar launches Hunter Agent to find flaws code scanners can't see. Artificial intelligence code verification and governance company SonarSource Sàrl today released SonarQube Hunter Agent, an AI agent built to find security flaws that pattern-based scanning cannot see. The vulnerabilities it targets are the ones where the code does exactly what it was written to do. A user opens another customer's records. A checkout step gets skipped. A session stays alive long after it should have expired. Nothing in the source reads as broken, because at the level a scanner works, nothing is. Only someone who knows what the feature was meant to do can see the problem. So the work has gone to people. A security engineer reads the code by hand, and when the budget stretches, a penetration tester goes at the running application from outside. Both cost money, both take time and both are out of date as soon as new code ships. Sonar said the shrinking gap between release and exploitation has made that a bigger problem than it used to be, with AI-assisted development pushing code out faster than any audit cycle can follow and logic flaws going unnoticed for months at a time. Broken access control, business-logic flaws and weaknesses in authentication or session handling are the three things the agent looks for. Pattern matching finds none of them. Sonar has it work over a whole codebase, tracing where code, data and a user's identity travel through an application. Out of that comes a theory about where the implementation drifted from what the feature was meant to do, and the agent goes looking for proof. Every candidate issue is investigated and confirmed before a developer sees it. No second tool is involved. Confirmed findings show up in the SonarQube issue list, in the same queue a team is already working through, and get assigned and tracked there like anything else. The agent runs in the background on whatever schedule a team sets. Scans can also be started by hand. Pull requests are never blocked and continuous integration pipelines are not slowed. Johannes Dahse, Sonar's vice president of code security, said AI is changing "not only the speed of software development, but also the scale of the verification challenge." Putting reasoning-based findings into the SonarQube workflow gives security and development teams a practical way to extend verification as the pace of AI-driven development increases, he added. Sonar is positioning the agent as an addition to SonarQube's existing static application security testing rather than a replacement for it. SAST reads how code is written. Hunter Agent goes after what the code was supposed to do in the first place. An enterprise alpha ran earlier this year and beta access opened on July 9 to SonarQube Cloud Enterprise customers. Under the hood the agent runs playbooks, multistep sequences of security prompts that encode the company's own application security expertise. Findings arrive with the discovery path attached. Agents have been the throughline of Sonar's 2026. The company launched Sonar Vortex and the SonarQube Remediation Agent at the AI Engineer World's Fair in June, the latter a background agent that writes fixes for existing issues and opens pull requests. SonarQube Hunter Agent is generally available today on SonarQube Cloud. Support for SonarQube Server is planned, with no date given. Image: Sonar. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from its Marketplace portal page and links: https://siliconangle.com/aws-marketplace/. About SiliconANGLE Media. SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

DevOps Duoo
Aug 8th, 2026
SonarQube integration in CI/CD pipeline - Quality Gate setup.

SonarQube integration in CI/CD pipeline - Quality Gate setup. Tl;dr. * Integrate SonarQube into your CI/CD pipeline to enforce code quality gates and improve overall code health * Use SonarQube's static code analysis capabilities to identify issues before they reach production * Configure Quality Gates to automatically fail builds when code quality thresholds are not met What you'll learn. In this tutorial, DevOps Duoo will cover the step-by-step process of integrating SonarQube into a CI/CD pipeline using GitHub Actions and Docker. DevOps Duoo will focus on setting up a Quality Gate to ensure that code quality standards are met before deploying to production. You will learn how to: * Configure SonarQube to analyze your codebase * Integrate SonarQube with GitHub Actions * Set up a Quality Gate to enforce code quality standards * Troubleshoot common issues and optimize performance Setting up sonarqube. To start, you need to set up a SonarQube instance. You can use the official SonarQube Docker image to run it in a container. Here's an example docker-compose.yml file to get you started: version: '3' services: sonarqube: image: sonarqube:9.9.0-community environment: - SONARQUBE_JDBC_URL=jdbc:postgresql://localhost:5432/sonarqube - SONARQUBE_JDBC_USERNAME=sonarqube - SONARQUBE_JDBC_PASSWORD=sonarqube ports: - "9000:9000" depends_on: - db volumes: - sonarqube-data:/opt/sonarqube/data - sonarqube-extensions:/opt/sonarqube/extensions db: image: postgres:14 environment: - POSTGRES_USER=sonarqube - POSTGRES_PASSWORD=sonarqube - POSTGRES_DB=sonarqube volumes: - sonarqube-db:/var/lib/postgresql/data volumes: sonarqube-data: sonarqube-extensions: sonarqube-db: This configuration sets up a SonarQube instance with a PostgreSQL database. You can adjust the environment variables and volume mounts as needed. To integrate SonarQube with GitHub Actions, you need to create a workflow file that analyzes your codebase and reports the results to SonarQube. Here's an example .github/workflows/sonarqube.yml file: name: SonarQube Analysis on: push: branches: - main jobs: sonarqube: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v3 - name: Login to SonarQube uses: sonarqube/sonarqube-github-action@v1 with: sonarqube-url: ${{ secrets.SONARQUBE_URL}} sonarqube-token: ${{ secrets.SONARQUBE_TOKEN}} project-key: ${{ secrets.SONARQUBE_PROJECT_KEY}} - name: Analyze code run: | sonar-scanner -Dsonar.projectKey=${SONARQUBE_PROJECT_KEY} -Dsonar.projectName=${SONARQUBE_PROJECT_NAME} -Dsonar.sources=. -Dsonar.host.url=${SONARQUBE_URL} -Dsonar.login=${SONARQUBE_TOKEN} - name: Quality Gate uses: sonarqube/sonarqube-github-action@v1 with: sonarqube-url: ${{ secrets.SONARQUBE_URL}} sonarqube-token: ${{ secrets.SONARQUBE_TOKEN}} project-key: ${{ secrets.SONARQUBE_PROJECT_KEY}} quality-gate: true This workflow file checks out the code, logs in to SonarQube, analyzes the code, and checks the Quality Gate. You need to replace the SONARQUBE_URL, SONARQUBE_TOKEN, and SONARQUBE_PROJECT_KEY secrets with your actual SonarQube instance URL, token, and project key. Configuring Quality Gates. To configure Quality Gates, you need to set up a SonarQube project and define the quality criteria. Here's an example of how to create a Quality Gate: # Create a new SonarQube project curl -X POST \ http://localhost:9000/api/projects/create \ -H 'Content-Type: application/json' \ -d '{"name": "My Project", "key": "my-project"}' # Define the quality criteria curl -X POST \ http://localhost:9000/api/qualitygates/create \ -H 'Content-Type: application/json' \ -d '{ "name": "My Quality Gate", "conditions": [{"metric": "coverage", "operator": "LT", "value": "80"}]}' This example creates a new SonarQube project and defines a Quality Gate that fails if the code coverage is less than 80%. Common mistakes. When integrating SonarQube with GitHub Actions, common mistakes include: * Not replacing the SONARQUBE_URL, SONARQUBE_TOKEN, and SONARQUBE_PROJECT_KEY secrets with actual values * Not configuring the Quality Gate correctly * Not adjusting the sonar-scanner command to match the project structure To troubleshoot issues, you can check the SonarQube logs and the GitHub Actions workflow logs. You can also use the SonarQube API to verify the project configuration and Quality Gate settings. Performance considerations. When running SonarQube in a production environment, performance considerations include: * Ensuring sufficient memory and CPU resources for the SonarQube instance * Optimizing the database configuration for better performance * Using a load balancer to distribute traffic across multiple SonarQube instances Security implications. When integrating SonarQube with GitHub Actions, security implications include: * Ensuring that the SonarQube token is stored securely as a secret * Limiting access to the SonarQube instance to authorized personnel * Using SSL/TLS encryption to secure communication between the SonarQube instance and the GitHub Actions workflow Key takeaways. * Integrate SonarQube into your CI/CD pipeline to enforce code quality gates and improve overall code health * Use SonarQube's static code analysis capabilities to identify issues before they reach production * Configure Quality Gates to automatically fail builds when code quality thresholds are not met * Ensure sufficient memory and CPU resources for the SonarQube instance and optimize the database configuration for better performance * Store the SonarQube token securely as a secret and limit access to the SonarQube instance to authorized personnel By following these steps and best practices, you can effectively integrate SonarQube into your CI/CD pipeline and ensure high-quality code deployments. For more information on related topics, see and.

StartupTicker
Jul 2nd, 2026
Building on strong commercial momentum, Sonar launches new products to improve agentic effectiveness.

Building on strong commercial momentum, Sonar launches new products to improve agentic effectiveness. 02.07.2026 AI agents now assist in generating more than 40% of committed enterprise code. Sonar's new offerings improve quality of agentic output, decrease token usage by up to 36%, and autonomously burn down technical debt. The launch is backed by strong commercial traction. The company has surpassed USD 430 million in annual recurring revenue (ARR) with accelerated growth. Agents are limited by what they don't know. They fall down when they lack the context of architecture, security and quality standards, approved libraries, an organization's conventions, and so on. Left ungoverned, they produce code that works in isolation but often violates the rules of the system it's entering. And the fixes cost more with every passing sprint. Sonar's new offerings address these challenges on both sides of the agentic development loop: Sonar Vortex improves the effectiveness of agents building new code, while the SonarQube Remediation Agent stops the accumulation of technical debt in the existing codebase. Available today, the new products improve agentic development in three ways: * Ensure agents write conformant code from the start by injecting your project's standards before generation, and then verifies the agent-written code against your team's quality and security standards while it's being written * Cut LLM token consumption by up to 36% by delivering precise, governed context in a single call, eliminating the iterative file discovery that drives up cost * Autonomously burn down technical debt at scale, working asynchronously in the background to generate, verify, and raise ready-to-merge PRs without pulling developers away from new work "The industry conversation about AI slop, token efficiency, and compounding technical risk has been building for months, if not longer," said Tariq Shaukat, CEO of Sonar. "What's been missing is a way to address those three issues where they occur: inside the agentic loop. We're delivering AI and development leaders a solution they can trust to make their investments in AI more efficient, effective, and sustainable." The announcement is backed by the strongest financial position in Sonar's history. The company has surpassed $430 million in annual recurring revenue (ARR) with accelerated growth. More than 7 million developers use Sonar - 75% of the Fortune 100 rely on it, including 19 of the top 20 banks globally outside China, as well as leading organizations like Nvidia, AstraZeneca, and Mercedes-Benz. That scale reflects a market that considers verification mandatory. Organizations trust Sonar to analyze more than 750 billion lines of code daily. Teams using Sonar are 44% less likely to experience outages from AI-generated code. 0Comments. More news about.

PR Newswire
Jun 30th, 2026
Sonar launches Vortex and remediation agent, cuts token use by 36% and burns down technical debt

Sonar has launched Sonar Vortex and the SonarQube Remediation Agent to improve AI agent code quality and efficiency. The company, which has surpassed $430 million in annual recurring revenue, reports that AI agents now assist in generating over 40% of committed enterprise code. Sonar Vortex guides AI agents with organisational standards before code generation and verifies output in real time, reducing large language model token consumption by up to 36% in testing. The SonarQube Remediation Agent autonomously addresses technical debt by generating verified, ready-to-merge pull requests without developer intervention. More than seven million developers use Sonar, including 75% of Fortune 100 companies. The platform analyses over 750 billion lines of code daily, and teams using it are 44% less likely to experience outages from AI-generated code.

Recently Posted Jobs

Sign up to get curated job recommendations

Sonar is Hiring for 91 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →