Back to vendors
S

Sonar

Also known as: SonarSource, SonarQube, Gitar

Visit site
Entry priceFree up to 50k lines of code, never expires; Team starts at $34 a month (shown discounted from $68) with Advanced Security, for under 50 developers, 14-day trial; Enterprise customFull pricing detail

Verification layer for AI and agentic coding, and a standard for automated code review.

Sonar is a long-established code verification and automated code review company, the maker of SonarQube, used by more than seven million developers, over twenty two thousand customers, and most of the Fortune 100. Its pitch for the AI era is a neutral trust and verification layer that holds all code to the same standard for quality and security, whether a human or an agent wrote it.

SonarQube's core analysis is deterministic and rule based, producing transparent, auditable findings with a low false positive rate that enterprises can defend for compliance and governance. In May 2026 Sonar acquired Gitar, an AI native code review platform, to add narrative review on top of its verification engine.

What makes Sonar relevant to agentic coding is how it wraps the AI development loop. Its open source MCP server connects coding agents like Cursor, Claude Code, and GitHub Copilot to the SonarQube engine, so an agent checks its own output against your quality gate and fixes its mistakes before a developer ever sees the diff.

Around that sit Agentic Analysis for real time inner loop verification, Context Augmentation to feed agents your standards before they write, a Remediation Agent that fixes issues and opens verified pull requests, and a CLI that intercepts secrets and API keys before they reach an LLM provider. It spans SAST, secrets detection, software composition analysis, and architecture enforcement across more than forty languages.

Sonar reports that teams using it are forty four percent less likely to suffer AI caused outages and that its remediation work can cut agent token usage meaningfully, without a published methodology. It ships as a self managed SonarQube Server, a SaaS SonarQube Cloud, and a free IDE plugin, with a free tier and trial, and it is backed by a major 2022 growth investment from Advent International and General Catalyst. It suits an engineering organization that wants an independent, auditable control plane over both human and AI generated code; teams wanting a purely generative reviewer without a deterministic gate will find it deliberately built the other way around.

Vendor details

Canonical URL

https://www.sonarsource.com

Category

Coding agent

Subcategory

AI code review and assurance

Funding status

An established, independent company headquartered in Geneva with a large Austin presence, founded in 2008 as SonarSource. More than seven million developers and twenty two thousand customers use SonarQube, including over seventy five percent of the Fortune 100. It received a major growth investment led by Advent International and General Catalyst in 2022, and in May 2026 acquired the AI native code review startup Gitar.

Company status

independent

Use cases & customers

Primary use cases

AI and human code verificationagent self verification via MCPautomated code review and remediationSAST, secrets, and dependency security

Target customers

enterprisedevelopers

Deployment options

SonarQube Cloud (SaaS)SonarQube Server (self-managed, per-instance)IDE plugin (SonarQube for IDE)MCP Server as a SonarQube Server extension (2026.3+, tools proxied at customer's own /mcp endpoint)MCP Server self-hosted standalone via official container imageSonarQube Cloud-hosted MCP server (no local setup)

Integrations

Integrates across IDEs via SonarQube for IDE, CI and source platforms including GitHub, GitLab and Jenkins, and agent runtimes via the SonarQube MCP Server, which connects Claude Code, Codex CLI, Cursor, Gemini CLI, GitHub Copilot CLI, GitHub Copilot Cloud Agent, Kiro, VS Code, Windsurf and Zed, with Devin also reported. Agent Apps for GitHub run the SonarQube agent on the platform; dedicated agent plugins ship for Claude Code, Cursor and Codex CLI. A SonarQube CLI supports real-time scanning in agentic environments and intercepts secrets before they reach an LLM provider. Gitar posts AI review comments directly into pull requests. The MCP server can act as a hub coordinating analysis triggers and aggregating insights across projects.

In practice

Your developers use different AI assistants that each write the same feature five different ways. Sonar's MCP server makes every agent check its output against one shared quality gate and fix itself before you see the diff.

AI generated code is reaching production faster than your team can review it. SonarQube verifies every line deterministically against your standards, flags real defects and vulnerabilities with a low false positive rate, and blocks merges that fail the gate.

You need AI code review you can defend to auditors. Sonar's findings are deterministic, explainable, and traceable, covering OWASP, PCI DSS, and CWE, so verification holds up for compliance rather than varying by prompt.

Agentic Index coverage score

10.5 / 14 capabilities · 75%

Integrations & Tool Calling Full

Integration spans IDEs through SonarQube for IDE plugins, CI and source platforms including GitHub, GitLab and Jenkins, and agent runtimes through the MCP server, which connects Claude Code, Codex CLI, Cursor, Gemini CLI, GitHub Copilot CLI, GitHub Copilot Cloud Agent, Kiro, VS Code, Windsurf and Zed, with Devin also reported; Agent Apps for GitHub run the SonarQube agent directly on the platform, dedicated agent plugins ship for Claude Code, Cursor and Codex CLI, and a CLI plus hooks cover scripted and agentic environments. Gitar posts review comments directly into pull requests.

Sourcesonarsource.com/products/sonarqube/mcp-server and docs.sonarsource.com/agent-centric-development-cycle/developer-tools/agent-pluginsread 2026-08-30

Workflow Orchestration Partial

The Agent Centric Development Cycle defines a fixed continuous three-stage loop applied to every AI-assisted change, Guide providing project context to agents before they write, Verify analyzing the resulting code, and Solve fixing what verification found; the Remediation Agent chains detection, fix, re-verification and opening a pull request, and Agentic Analysis runs verification inside the agent's inner loop. This is a defined pipeline the vendor ships rather than a workflow the customer composes: no multi-agent coordination, branching logic, customer-defined stages or agent handoff is documented.

Sourcedocs.sonarsource.com/agent-centric-development-cycle and docs.sonarsource.com/sonarqube-cloud/ai-capabilitiesread 2026-08-30

Knowledge Grounding & RAG Full

Context Augmentation forms the Guide stage of the Agent Centric Development Cycle, providing project context to agents before they write or edit code, exposed through the MCP server as code architecture search, call flows, coding guidelines and SCA dependency checks; analysis is grounded in full project context together with the organization's own quality profiles, rule sets and architecture standards, and SonarQube Architecture enforces architectural standards as a distinct product. Context Augmentation and Agentic Analysis are SonarQube Cloud add-ons.

Sourcedocs.sonarsource.com/agent-centric-development-cycle and docs.sonarsource.com/sonarqube-mcp-serverread 2026-08-30

Human Oversight & Guardrails Partial

Oversight is by gate and review, not by an approval step inside Sonar: organization-defined quality gates block merges that fail deterministic checks, AI CodeFix is switched on by an admin for all or selected projects, and the Remediation Agent proposes its fixes as a new pull request for the customer to review on its own code host. A quality gate is a constraint and review of the agent's pull request is the customer's own merge gate, and no step where a person approves an agent action before Sonar executes it is documented.

Sourcedocs.sonarsource.com/sonarqube-cloud/managing-your-projects/issues/with-ai-features and /administering-your-projects/ai-features/enable-ai-codefixread 2026-09-29

Security, Identity & Governance Full

The trust center states that at the company level Sonar maintains ISO 27001:2022 certification and a SOC 2 Type II attestation for all products and services, with both available from its security profile and the SOC 2 report under NDA. The access surface is documented for SonarQube Cloud Enterprise: SSO with SCIM provisioning, organization, portfolio, project and enterprise permissions with permission templates, IP allow lists, customer-managed encryption keys with rotation, and audit logs of sign-ins and permission changes.

Sourcesonarsource.com/trust-center and docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/enterprise-securityread 2026-09-29

Observability & Auditability Partial

Every Remediation Agent run is recorded on an Agent activity page with its status and duration, what started it (the backlog schedule, Fix with Agent or Fix automatically on a failed gate), where it worked and a link to its pull request; Enterprise audit logs, readable through an API, record sign-ins, user, group and permission changes and key rotation events; and deterministic findings trace to a named rule and code location. That is a per run record of the agent and an administrative log, not a per step or per tool call record of what the agent did.

Sourcedocs.sonarsource.com/sonarqube-cloud/managing-your-projects/issues/with-ai-features and /administering-sonarcloud/enterprise-security/audit-logsread 2026-09-29

Memory & State Persistence Partial

Analysis state persists between runs: the baseline from the last full project scan carries forward so subsequent analyses evaluate new code against it, issue history and dispositions such as accepted or won't-fix persist per project, and quality profiles and gates are stored organization-wide and applied consistently across runs. This is project and analysis state rather than agent memory; no memory carrying learned context, corrections or preferences across agent sessions is documented.

Sourcedocs.sonarsource.com/sonarqube-cloud/ai-capabilities and docs.sonarsource.com/agent-centric-development-cycleread 2026-08-30

Deployment & Data Residency Full

SonarQube Server is a self-managed deployment priced per instance and installable in the customer's own environment, alongside SonarQube Cloud as SaaS and a free IDE plugin; the MCP Server installs as an extension on SonarQube Server 2026.3 and later so the customer's own server proxies agent tools at its own /mcp endpoint, or self-hosts standalone via the official container image, keeping the agentic surface inside the boundary. Gitar retains no code after processing and supports bring your own Anthropic key. MCP telemetry excludes source code and IP address and is disableable.

Sourcedocs.sonarsource.com/sonarqube-mcp-server and sonarsource.com/products/sonarqube/mcp-serverread 2026-08-30

Prebuilt Agents, Templates & Packs Full

Sonar ships prebuilt rule sets and quality profiles covering more than forty languages, maintained by Sonar and adopted by the customer as defaults or customized, together with prebuilt quality gates and architecture standards, and compliance rule mappings for OWASP, CWE and STIG, PCI DSS and CASA; dedicated agent plugins and slash commands ship for named harnesses including Claude Code, Cursor, Codex CLI and Gemini, and Agent Apps for GitHub package the SonarQube agent for direct installation on the platform.

Sourcedocs.sonarsource.com/agent-centric-development-cycle/developer-tools/agent-plugins and docs.sonarsource.comread 2026-08-30

Triggers & Channel Coverage Full

Analysis runs automatically on CI builds and pull requests through GitHub, GitLab and Jenkins, and the Remediation Agent starts on an Automated backlog remediation schedule, from Fix with Agent on the Issues page, or from Fix automatically in a failed quality gate comment on a pull request; Agentic Analysis runs inside a coding agent's loop, and developers and agents invoke analysis through IDE plugins, the CLI and MCP tool calls.

Sourcedocs.sonarsource.com/sonarqube-cloud/managing-your-projects/issues/with-ai-features and /agent-centric-development-cycleread 2026-09-29

Model Flexibility & Routing Partial

Core static analysis is deterministic and rule-based with no model involved, so model choice does not arise for the majority of the product; the LLM-powered surfaces, AI CodeFix for fix suggestions and Gitar for pull request review, support bring your own Anthropic key so enterprises run those calls on their own provider agreement, and AI CodeFix is enabled per organization by an admin rather than per developer. No selection across multiple model providers, no per-task routing and no local model option is documented.

Sourcedocs.sonarsource.com/sonarqube-cloud/ai-capabilities and sonarsource.com/company/press-releases/sonar-acquires-gitarread 2026-08-30

APIs, SDKs & MCP Extensibility Full

The SonarQube MCP Server connects an AI coding agent to SonarQube's code quality and security data as a documented tool bag, with tools to analyze code, retrieve issues, check quality gates, inspect security hotspots and measure coverage; it works with Claude Code, Codex CLI, Cursor, Gemini CLI, GitHub Copilot CLI, GitHub Copilot Cloud Agent, Kiro, VS Code, Windsurf and Zed, and powers the SonarQube agent through Agent Apps for GitHub.

SonarQube Cloud includes a hosted MCP server needing no local setup; on SonarQube Server 2026.3 and later it installs as an extension so the server proxies tools at a single /mcp endpoint. A SonarQube CLI supports real-time scanning in agentic environments, alongside IDE plugins, hooks and agent plugins for Claude Code, Cursor and Codex CLI. Source-available under the SONAR Source-Available License v1.0.

Sourcedocs.sonarsource.com/sonarqube-mcp-server and sonarsource.com/products/sonarqube/mcp-serverread 2026-08-30

Testing, Debugging & Optimization Full

Deterministic rule-based static analysis checks code against quality and security standards across more than forty languages, spanning SAST, secrets detection, software composition analysis and architecture enforcement, tracking test coverage and re-verifying every fix before merge; Agentic Analysis brings verification into the agent's inner loop so agents check their own work as they write, AI CodeFix suggests LLM-generated fixes for found issues under organization admin control, and the Remediation Agent fixes issues and opens verified pull requests.

Gitar, acquired May 2026, adds narrative pull request review posting comments directly on pull requests. Vendor-reported outcomes of 44 percent fewer AI-caused outages and up to 8 percent lower agent token usage carry no published methodology.

Sourcedocs.sonarsource.com/sonarqube-cloud/ai-capabilities and sonarsource.com/company/press-releases/sonar-acquires-gitarread 2026-08-30

Browser & Computer Use Not documented

The product operates on source code within developer, CI and agent environments through programmatic interfaces throughout: static analysis of repositories, MCP tool calls, IDE plugins, a CLI, CI integrations and source platform APIs. No browser control, screenshot capture, visual verification or operation of software lacking a programmatic interface is documented on the AI capabilities documentation, the MCP server documentation or the product pages.

Sourcedocs.sonarsource.com/sonarqube-cloud/ai-capabilities and docs.sonarsource.com/sonarqube-mcp-serverread 2026-08-30

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-29·Deployment / data residencyVerified

SonarQube Server 2026.5 LTA brings Sonar's Remediation Agent, Hunter Agent and Vortex to self managed deployments, including on premises and locked down VPCs, where before they ran only in SonarQube Cloud. The agents run as optional sandboxed containers behind an egress proxy, and admins plug in their own model provider, such as AWS Bedrock, Azure AI Foundry or a self hosted gateway.

Bears on: Agent capability

View source
2026-07-24·MCP / tool calling / APIVerified

Sonar introduced seamless hooks for Claude Code and GitHub Copilot CLI within the SonarQube CLI, powered by a new Model Context Protocol (MCP) server. This update includes a pre-tool-use hook that scans for secrets locally, preventing hardcoded credentials from being transmitted to LLM providers during agentic workflows.

Bears on: MCP / tool calling / API

View source
2026-07-17·Security / enterpriseVerified

Sonar introduced SonarQube Server 2026.4, featuring built-in architecture analysis that automatically visualizes source code dependency graphs across commercial editions. The release also added beta support for Cross-Translation-Unit (CTU) and taint analysis for C and C++, allowing the symbolic-execution engine to track untrusted data flows across multiple files.

Bears on: Security / enterprise

View source
View all 3 changes for Sonar →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Free up to 50k lines of code, never expires; Team starts at $34 a month (shown discounted from $68) with Advanced Security, for under 50 developers, 14-day trial; Enterprise custom

lines of code

Free tierTrial available

What is public

The plans page lists a free tier up to 50k lines of code that never expires, free open source use, Team starting at $34 a month (shown as a discount from $68) with Advanced Security included for teams under 50 developers and a 14-day trial with no sales call, and a custom Enterprise plan for over 50 developers bundling SSO and SCIM, portfolios, Advanced Security, Gitar AI Code Review with outcome-based pricing per PR, Sonar Vortex, the Remediation Agent and the Hunter Agent. SonarQube Server pricing sits on a separate page.

Billing mechanics

SonarQube Cloud is a self serve SaaS with free and paid tiers priced by lines of code analyzed; Team includes Advanced Security for teams under 50 developers, and Enterprise bundles it with Gitar AI code review priced per pull request, the Remediation Agent and the Hunter Agent. SonarQube Server is licensed per instance per year, also by lines of code, for self managed deployments.

Cost watchouts

Advanced Security, software composition analysis, and Agent Essentials are add ons beyond the base tier. LOC based pricing means codebase growth, not team size, drives cost, so a growing repo can raise the bill even with a stable headcount.

Variable cost rationale

Priced by lines of code, so cost scales as the codebase grows rather than with usage; predictable per year once codebase size is known, but large or fast growing repos raise the tier.

Additional watchouts

Because pricing is per lines of code, a large or fast growing monorepo can jump tiers; confirm which edition, add ons, and LOC band you fall into, and whether Advanced Security and agent features are included.

Sales call required

Mixed (some tiers require a call)

Free / trial

Free forever up to 50k lines of code in private projects, free for open source, and a 14-day Team trial with no credit card

Lowest paid plan

Team, starts at $34 a month (shown discounted from $68)

Key ambiguities

Free and lower tiers are public, but exact pricing at higher lines of code bands and for SonarQube Server and Enterprise is quoted through sales.

Agentic Index verified 2026-09-29

Alternatives to Sonar

The closest documented capability profiles to Sonar among coding agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Greptile11.0 / 14Fuller documented coverage on Workflow Orchestration and Model Flexibility & RoutingSonar vs Greptile →
  • Qodo12.0 / 14Fuller documented coverage on Workflow Orchestration and Memory & State PersistenceSonar vs Qodo →
  • cubic9.5 / 14Fuller documented coverage on Memory & State Persistence
  • Moderne10.5 / 14Fuller documented coverage on Human Oversight & Guardrails and Observability & Auditability
  • Augment Code12.0 / 14Fuller documented coverage on Workflow Orchestration and Human Oversight & Guardrails
  • Baz13.0 / 14Adds documented Browser & Computer UseSonar vs Baz →

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.