Vendor hubPriced by lines of codeTechBag Intel Hub

Sonar

The check every pull request passes before it merges— quality, security and now AI review, self-managed or hosted. This hub is your complete intel file.

4 intel pages insideGartner Leader, Tech Debt 2026Self-host for India residency

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

The company, at a glance

Founded2008 · Geneva
OwnershipPrivate · CEO Tariq Shaukat
Scale7M+ developers (Sonar)
RecognitionGartner Tech Debt MQ Leader 2026
IndiaCloud in EU/US; Server self-hosted

Quick answer

Sonar (SonarSource, founded in 2008; headquarters in Austin and Geneva) makes SonarQube, which checks code for bugs, maintainability problems and security flaws before it merges. It comes self-managed as SonarQube Server or hosted as SonarQube Cloud, with Advanced Security for dependencies and Gitar for AI code review. Gartner named Sonar a Leader in its 2026 Magic Quadrant for Technical Debt Management Tools. SonarQube Cloud stores data in the EU or US only. Read more ↓ Show less ↑
The portfolio

Four intel pages. One check before the merge.

Sonar, product by product — every linked card is a full intel page, from the analysis you run yourself to the AI review on every pull request.

Sonar sells across 4 of the products TechBag carries in DevOps. The DevOps guide shows how the category splits and which part is yours. →

The thesis

Why “before the merge” is the whole story

A flaw found after release costs a hotfix; the same flaw found in the pull request costs a comment. Sonar bet on a gate every change passes before it merges— quality first, security in the same pass — and buying Gitar for AI code review in 2026 doubled down on it.

01
One pass/fail

Quality gates

Each pull request passes or fails against rules the team agreed — new code is held to the standard, old code is not blamed for it.

02
One engine

Analysers

The same rules run in the IDE, the pipeline and the server, so a developer sees locally what the gate will say later.

03
One meter

Lines of code

Server is licensed per instance and Cloud per organisation, both by lines of code — never by how many people read the results.

04
The 2026 layer

Agents

Remediation and Hunter agents and the Vortex context engine are Enterprise add-ons, launched June to September 2026 and priced by quote.

Start with Server or Cloud; Advanced Security and Gitar add to the same pull-request check.

The trophy wall

Peer & market recognition

Every claim on this hub traces to one of these public signals.

Gartner 2026

Leader — Technical Debt Management Tools

report dated 20 May 2026

GigaOm 2025

Leader & Fast Mover — AST Radar

application security testing

Reach

7M+ developers

Sonar's own figure

Fortune 100

75% are users

Sonar's own figure

2022 round

$412M at $4.7B

Advent, General Catalyst

India

Freshworks, CleverTap

named Sonar customer stories

By the numbers

The company in six figures

2026
Leader in Gartner's Magic Quadrant for Technical Debt Management Tools
— Gartner
7M+
developers use Sonar's products
— Sonar
75%
of the Fortune 100, by Sonar's count
— Sonar
$34/month
SonarQube Cloud Team, up to 100k lines of code
— Sonar pricing
2008
founded in Geneva
— Reported
4 products
Server, Cloud, Advanced Security and Gitar
— Sonar

See the platform, hear the pitch

Sonar (official)·Overview

What Is SonarQube | Static Code Analysis & Verification Explained

What the product does, in one sitting.

Sonar (official)·Sonar Summit 2026

What's New in SonarQube | Governance and Quality Gates at Scale

Quality gates across a large estate.

The market maps

Where Sonar sits — the grids

Two company-level views you won’t find on any vendor site — tap any dot for the rationale. The category-level grid lives on the product page.

Grid 01 · The portfolio

Sonar Across Its Solution Areas

Each dot is a Sonar solution area: competitive position vs category momentum.

Emerging betsCrown jewelsSteady nicheAnchor strengths
Code qualitySonar

The core: quality gates and maintainability.

Grid 02 · The industry

Code Quality × Security Depth

How deep each tool goes on code quality and maintainability vs how deep on application security.

Security-first platformsQuality and securityPoint checkersQuality-first tools
SonarSonar

Deepest on quality; security added on top.

Positions are TechBag’s illustrative synthesis of public review-platform standings and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Track 01 · Beginner guides

New to this? Learn it properly.

Zero-jargon starting points, in reading order. Each links into the deep education on the product page.

Interactive · 30 seconds

Where should you start with Sonar?

Answer three questions; we’ll point you at the right starting product. No email required — this isn’t that kind of quiz.

1. What is forcing the decision?

2. Who is asking for it?

3. What do you run today?

The acronym decoder

Every term on these pages, in one place
Sonar
SonarSource, the maker of SonarQube; founded 2008, Austin and Geneva HQs.
SonarQube Server
The self-managed product, licensed per instance by lines of code.
SonarQube Cloud
The hosted product, formerly SonarCloud; priced by lines of code.
Community Build
The free, open-source SonarQube (LGPL-3.0), updated monthly.
Quality gate
The pass/fail check a pull request must meet before it merges.
SAST
Static application security testing: finding flaws in source code.
SCA
Software composition analysis: finding risk in dependencies.
Taint analysis
Tracing untrusted input to a dangerous call — Advanced SAST follows it through libraries.
Technical debt
The future cost of shortcuts in code; what Gartner's MQ here measures tools on.
LOC
Lines of code — the meter both Server and Cloud are priced by.
SonarQube for IDE
The free IDE extension, formerly SonarLint.
Gitar
AI code review on pull requests; a Sonar company since May 2026.
Track 02 · Buying guides

Buy it like you’ve done this before

The procurement playbook TechBag runs with IT buyers — steps, licensing cheat-sheet, and the pitfalls that cost quarters.

01

Count lines of code first

Both products are priced by lines of code — Cloud counts the largest branch per organisation. Measure it before any quote.

02

Decide where the code may be stored

SonarQube Cloud stores data in the EU or US only. If code must stay in India, the answer is SonarQube Server on your infrastructure.

03

Match the edition to the languages

Enterprise adds COBOL, APEX, PL/I and more, plus portfolios and AI CodeFix. Check your languages before choosing Developer.

04

Confirm what Advanced Security costs

It is an additional subscription on Server Enterprise. Sonar's pages disagree on Cloud Team — get the answer in writing.

05

Trial on a real repository

Run the free trial against a busy service. Whether the gate is trusted or bypassed in week two is the real test.

06

Price the bundle together

Server, Advanced Security and Gitar can be bundled. TechBag models the mix and quotes in INR with GST.

The licensing cheat-sheet

ProductLicensing modelHow you enterBest for
SonarQube ServerPer instance, per year, by LOCQuote · Developer, Enterprise, Data CenterCode stays on your estate
SonarQube CloudPer organisation, by LOCTeam from $34/month, 100k LOCNothing to operate
Advanced SecurityAdditional subscriptionQuote · Enterprise tiersDependency risk and SBOMs
GitarPer user; Enterprise per PR$20/user/month, annualAI review on every PR

Server and Cloud are priced by lines of code, Gitar per user — TechBag measures your code and quotes in INR with GST.

Five pitfalls that cost buyers quarters

1

Reading the wrong Gartner report

Sonar leads the 2026 Technical Debt Management MQ. It has no Application Security Testing MQ placement — don't buy it as if it had.

2

Assuming Cloud can stay in India

SonarQube Cloud stores data in the EU or US, chosen at sign-up and fixed. Residency means SonarQube Server on your own estate.

3

Pricing Server from old blog posts

Sonar no longer publishes Server prices. Figures on third-party sites are old list prices, not a quote.

4

Counting developers, not code

Seats don't drive the bill — lines of code do. A monorepo with generated code can push you into a higher band.

5

Letting the gate be bypassed

A quality gate the team can override without review is a dashboard, not a control. Agree who can bypass it first.

Skip the homework entirely

Bring your requirements and current tool bills — a TechBag advisor models the whole decision for you.

Book a discovery call →
FAQ

Questions buyers ask about Sonar

SonarSource, the company behind SonarQube, founded in Geneva in 2008 and now headquartered in Austin and Geneva. Its CEO is Tariq Shaukat and founder Olivier Gaudin is Chairman. It is privately held — its last disclosed round was $412M at a $4.7B valuation in 2022 — and does not publish revenue. Sonar says 7M+ developers use its products.

Ready to shortlist Sonar?

Open any of the four intel pages for the deep dive, or let a TechBag advisor build the case with you — lines-of-code sizing, Server-or-Cloud scoping, quotes, trials, GST invoicing and lifecycle support included.

Stats, positions and figures are illustrative syntheses of public materials; verify before purchase.