Sonar

Code quality and security company behind SonarQube Cloud, Server, and IDE, applying static analysis to both human and AI-generated code.

Track Sonar from Claude, Cursor, Codex, Windsurf

About

Sonar builds code verification tooling focused on quality and security, with growing emphasis on validating AI generated code. The company describes its platform as a neutral, rigorous verification platform that applies consistent standards across human and AI written code.

The product line covers SonarQube Cloud, a cloud based static analysis tool for CI/CD workflows, SonarQube Server for self managed continuous codebase inspection, SonarQube for IDE as a free extension providing on the fly analysis and coding guidance, and SonarQube Advanced Security for securing open source use with SAST and SCA.

More recent additions target agentic workflows: Gitar performs AI code review that fixes issues and commits only when the build passes, while an MCP Server and the SonarQube CLI bring code quality and security into AI and agentic workflows. The company cites an extremely low false positive rate of 3.2%.