Sonar
Founded Year
2008Stage
Unattributed VC | AliveTotal Raised
$457MValuation
$0000Last Raised
$412M | 2 yrs agoMosaic Score The Mosaic Score is an algorithm that measures the overall financial health and market potential of private companies.
+17 points in the past 30 days
About Sonar
Sonar specializes in code quality and security within the software development industry. The company offers tools for static application security testing, continuous codebase inspection, and real-time coding guidance to improve code reliability, maintainability, and security. Sonar's solutions cater to various sectors including the public sector, enterprise-level businesses, and developers seeking to integrate clean code practices into their development workflows. It was founded in 2008 and is based in Geneva, Switzerland.
Loading...
ESPs containing Sonar
The ESP matrix leverages data and analyst insight to identify and rank leading companies in a given technology landscape.
The code review market is a space where technology vendors offer tools and solutions to help improve the quality, consistency, and speed of software development. Code review involves the systematic examination and analysis of code by developers or peers to identify errors, bugs, vulnerabilities, and adherence to coding standards. Code review tools facilitate the process by automating code analysis…
Sonar named as Leader among 11 other companies, including Atlassian, Veracode, and Codescene.
Loading...
Research containing Sonar
Get data-driven expert analysis from the CB Insights Intelligence Unit.
CB Insights Intelligence Analysts have mentioned Sonar in 5 CB Insights research briefs, most recently on Feb 20, 2024.
Expert Collections containing Sonar
Expert Collections are analyst-curated lists that highlight the companies you need to know in the most important technology spaces.
Sonar is included in 3 Expert Collections, including Unicorns- Billion Dollar Startups.
Unicorns- Billion Dollar Startups
1,244 items
Tech IPO Pipeline
257 items
The tech companies we think could hit the public markets next, according to CB Insights data.
Defense Tech
1,268 items
Defense tech is a broad field that encompasses everything from weapons systems and equipment to geospatial intelligence and robotics. Company categorization is not mutually exclusive.
Sonar Patents
Sonar has filed 31 patents.
The 3 most popular patent topics include:
- intercontinental ballistic missiles
- short-range ballistic missiles
- vehicle law
Application Date | Grant Date | Title | Related Topics | Status |
---|---|---|---|---|
9/23/2023 | 9/17/2024 | Automotive lamps, Standard motorcycles, Limousines, Suzuki motorcycles, Automotive technologies | Grant |
Application Date | 9/23/2023 |
---|---|
Grant Date | 9/17/2024 |
Title | |
Related Topics | Automotive lamps, Standard motorcycles, Limousines, Suzuki motorcycles, Automotive technologies |
Status | Grant |
Latest Sonar News
Aug 8, 2024
Security Boulevard Community Chats Webinars Library How Sonar Helps Meeting NIST SSDF Code Security Requirements What is the NIST SSDF? The NIST Secure Software Development Framework ( SSDF ) brings together security best practices and recommended standards collated from the industry’s best cyber security experts to help organizations minimize the risk of software vulnerabilities and mitigate cyber security attacks. It is designed to be adaptable without being specific to a methodology so you can easily integrate it into your existing software development lifecycle (SDLC) and fit it into your specific organization’s size, risk profile, and security practices. NIST SSDF 1.1 with Sonar, Explained The NIST SSDF 1.1 is organized into four key sections, each focusing on a specific aspect of security risk during software development. The four key practices are as follows, including how Sonar helps with each practice. 1. Prepare the Organization (PO) This section focuses on establishing a security culture within the organization and creating an environment that prioritizes secure software development practices. SonarQube integrates seamlessly into existing toolchains, providing automated code analysis and continuous inspection capabilities throughout the SDLC. Once you define your specific security posture, you can configure SonarQube quality profiles and custom security engine configurations (available in the Enterprise edition), so your development teams follow your company-specific policies as they code. 2. Protect the Software (PS) This section emphasizes safeguarding all software components so that only authorized access is allowed, and any tampering is prevented. SonarQube's integration with version control systems (VCS) like GitHub and GitLab ensures that all code changes are tracked and audited. SonarQube’s strict authentication mechanisms and user and group permissions prevent unauthorized access and maintain the integrity of your codebase. SonarQube's Quality Gates feature allows organizations to set predefined criteria that must be met before code can be released, ensuring code integrity throughout the development process. 3. Produce Well-Secured Software (PW) This section highlights activities that lead to developing software with minimal security vulnerabilities, such as secure design principles , threat modeling, secure coding practices, recurring code reviews, and static code analysis. SonarQube performs automated code reviews using static code analysis to identify security vulnerabilities and code quality issues early in the development process, allowing developers to address issues during the design and implementation phases. SonarQube's detailed reports and dashboards provide visibility into code quality and security, facilitating design reviews and compliance checks. SonarQube can detect code duplication, encouraging developers to reuse existing, well-tested code rather than reinventing the wheel. SonarQube enforces a wide range of coding standards and best practices through its rule sets, which can be customized to follow your organization’s security guidelines. By integrating SonarQube into the build process, organizations can ensure that security checks are performed at every stage of development. A core strength of SonarQube, the SSDF explicitly calls for a static analysis tool “to automatically check code for vulnerabilities and compliance with the organization’s security coding standards.” 4. Respond to Vulnerabilities (RV) Lastly, this section focuses on the processes for identifying, mitigating, and remediating vulnerabilities discovered in software after it is released. SonarQube continuously monitors code for new vulnerabilities, providing real-time feedback to developers. Sonar shortens the detection and remediation cycle by providing developers with accurate, up-to-date vulnerability information within their daily workflows. SonarQube's detailed reports prioritize vulnerabilities based on their severity and impact on code quality, allowing organizations to focus on the most critical issues. SonarQube's detailed issue descriptions, using the Learn as You Code (LaYC) methodology and code navigation features, help developers understand and address the root causes of vulnerabilities. Sonar’s solutions, including SonarLint , SonarQube , and SonarCloud , help you meet NIST SSDF code security requirements and enhance overall code quality. Sonar addresses critical NIST SSDF practices for protecting and securing software and responding to vulnerabilities, making it essential for a comprehensive, secure development lifecycle. With Sonar's Clean Code solutions, you can build secure, reliable, and maintainable software. Not yet using SonarLint , SonarQube , or SonarCloud ? Give them a try now. Or, if you’re already using SonarQube Community Edition, upgrade to SonarQube Enterprise Edition to get the most value and strongest security features Sonar has to offer. *** This is a Security Bloggers Network syndicated blog from Sonar Blog RSS feed authored by Robert Curlee . Read the original post at: https://www.sonarsource.com/blog/how-sonar-helps-with-nist-ssdf
Sonar Frequently Asked Questions (FAQ)
When was Sonar founded?
Sonar was founded in 2008.
Where is Sonar's headquarters?
Sonar's headquarters is located at Route de Pre-Bois 1, Geneva.
What is Sonar's latest funding round?
Sonar's latest funding round is Unattributed VC.
How much did Sonar raise?
Sonar raised a total of $457M.
Who are the investors of Sonar?
Investors of Sonar include Insight Partners, Advent International, General Catalyst and Permira.
Who are Sonar's competitors?
Competitors of Sonar include Aikido, Codescene, Mend, Codacy, Code Intelligence and 7 more.
Loading...
Compare Sonar to Competitors
Snyk focuses on developer security within the technology industry. The company offers services that help developers build secure applications and allow security teams to meet the demands of the digital world. Its services include finding and fixing vulnerabilities in code, dependencies, containers, and infrastructure as code. It was founded in 2015 and is based in Reading, United Kingdom.
Code Climate focuses on software engineering intelligence in the technology sector. The company offers a platform called Velocity, which provides leaders with insights into various aspects of software engineering, including efficiency, code quality, and developer retention. The company primarily serves the software development and tech industries. It was founded in 2011 and is based in New York, New York.
DeepSource is a code health platform focused on helping businesses improve their software quality and security. The company offers tools for static analysis, security testing, and code coverage to identify and fix code quality issues, as well as features for infrastructure as code analysis and automated code fixes. DeepSource primarily serves the software development industry, providing solutions to enhance code maintainability and security. It was founded in 2018 and is based in San Francisco, California.
Semgrep operates in technology. The company offers a tool that helps find and fix bugs and reachable dependency vulnerabilities in code, and enforces code standards. It primarily serves the software development and cybersecurity sectors. Semgrep was formerly known as r2c. It was founded in 2017 and is based in San Francisco, California.
Beanstalk is a software company that provides a complete workflow for code hosting, review, and deployment. It offers services that allow teams to write code, manage code reviews, and deploy code to various environments without the need for additional client software. Beanstalk's solutions cater to organizations of any size, aiming to streamline the development process. It is based in Philadelphia, Pennsylvania.
Checkmarx operates as an application security testing company. It provides software solutions to identify, fix, and block security vulnerabilities in websites and mobile applications. It also provides a way for organizations to introduce security into their software development lifecycle. The company was founded in 2006 and is based in Atlanta, Georgia.
Loading...