The check every pull request passes before it merges— quality, security and now AI review, self-managed or hosted. This hub is your complete intel file.
Buy through TechBag
Same software. Better outcome — at a lower cost.
The company, at a glance
Quick answer
Sonar, product by product — every linked card is a full intel page, from the analysis you run yourself to the AI review on every pull request.
The analysis on your own infrastructure.
Quality gates, SAST, secrets and IaC checks in Developer, Enterprise and Data Center editions, for code that cannot leave your estate.
The same checks, nothing to run.
Wired into GitHub, GitLab, Bitbucket and Azure DevOps, priced by lines of code. Stores data in the EU or US — no India region.
What your dependencies bring in.
SCA for direct and transitive dependencies, malicious-package detection, SBOMs and taint analysis that follows data through libraries.
A reviewer on every pull request.
AI review that comments on, fixes and validates pull requests across GitHub, GitLab, Bitbucket and Azure DevOps. Still sold on its own.
Sonar sells across 4 of the products TechBag carries in DevOps. The DevOps guide shows how the category splits and which part is yours. →
A flaw found after release costs a hotfix; the same flaw found in the pull request costs a comment. Sonar bet on a gate every change passes before it merges— quality first, security in the same pass — and buying Gitar for AI code review in 2026 doubled down on it.
Each pull request passes or fails against rules the team agreed — new code is held to the standard, old code is not blamed for it.
The same rules run in the IDE, the pipeline and the server, so a developer sees locally what the gate will say later.
Server is licensed per instance and Cloud per organisation, both by lines of code — never by how many people read the results.
Remediation and Hunter agents and the Vortex context engine are Enterprise add-ons, launched June to September 2026 and priced by quote.
Start with Server or Cloud; Advanced Security and Gitar add to the same pull-request check.
Every claim on this hub traces to one of these public signals.
report dated 20 May 2026
application security testing
Sonar's own figure
Sonar's own figure
Advent, General Catalyst
named Sonar customer stories
What the product does, in one sitting.
Quality gates across a large estate.
Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.
Each dot is a Sonar solution area: competitive position vs category momentum.
The core: quality gates and maintainability.
How deep each tool goes on code quality and maintainability vs how deep on application security.
Deepest on quality; security added on top.
Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Zero-jargon starting points, in reading order. Each links into the deep education on the product page.
Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.
1. What is forcing the decision?
2. Who is asking for it?
3. What do you run today?
It fails new code that breaks the agreed rules, without blaming the codebase you inherited.
Read →The same analysis. The difference is who runs it — and where your code is stored.
Read →Your code's flaws, or your dependencies' — Advanced Security adds the second.
Read →One reads intent in a diff; the other applies rules to all of it. They catch different things.
Read →Technical Debt Management Tools, 2026. Not application security testing.
Read →SonarQube Cloud stores data in the EU or US. Residency means self-hosting Server.
Read →The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.
Both products are priced by lines of code — Cloud counts the largest branch per organisation. Measure it before any quote.
SonarQube Cloud stores data in the EU or US only. If code must stay in India, the answer is SonarQube Server on your infrastructure.
Enterprise adds COBOL, APEX, PL/I and more, plus portfolios and AI CodeFix. Check your languages before choosing Developer.
It is an additional subscription on Server Enterprise. Sonar's pages disagree on Cloud Team — get the answer in writing.
Run the free trial against a busy service. Whether the gate is trusted or bypassed in week two is the real test.
Server, Advanced Security and Gitar can be bundled. TechBag models the mix and quotes in INR with GST.
| Product | Licensing model | How you enter | Best for |
|---|---|---|---|
| SonarQube Server | Per instance, per year, by LOC | Quote · Developer, Enterprise, Data Center | Code stays on your estate |
| SonarQube Cloud | Per organisation, by LOC | Team from $34/month, 100k LOC | Nothing to operate |
| Advanced Security | Additional subscription | Quote · Enterprise tiers | Dependency risk and SBOMs |
| Gitar | Per user; Enterprise per PR | $20/user/month, annual | AI review on every PR |
Server and Cloud are priced by lines of code, Gitar per user — TechBag measures your code and quotes in INR with GST.
Sonar leads the 2026 Technical Debt Management MQ. It has no Application Security Testing MQ placement — don't buy it as if it had.
SonarQube Cloud stores data in the EU or US, chosen at sign-up and fixed. Residency means SonarQube Server on your own estate.
Sonar no longer publishes Server prices. Figures on third-party sites are old list prices, not a quote.
Seats don't drive the bill — lines of code do. A monorepo with generated code can push you into a higher band.
A quality gate the team can override without review is a dashboard, not a control. Agree who can bypass it first.
Each intel page carries an 8-question vendor checklist and a value calculator:
Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.
Book a discovery call →Four trends with momentum scores (TechBag’s read of analyst and market signals) — and what each means for your next decision.
*TechBag’s illustrative estimate, not a quoted analyst figure. The takeaway: AI code review is where the new money is going — which is why Sonar bought Gitar.
Assistants generate code faster than people can review it.
What it means for you
Verification before merge becomes the bottleneck.
Malicious packages are now published to be installed.
What it means for you
SCA with malicious-package detection joins SAST.
Reviewers on every pull request, not just humans.
What it means for you
Hence Sonar buying Gitar in May 2026.
Gartner published an MQ for it in 2026.
What it means for you
Maintainability is argued in money, not taste.
Open any of the four intel pages for the deep dive, or let a TechBag advisor build the case with you — lines-of-code sizing, Server-or-Cloud scoping, quotes, trials, GST invoicing and lifecycle support included.
Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.