SonarQube Server is the self-managed edition of the SonarQube platform, the industry standard for code verification and automated code review. It integrates directly with DevOps platforms and AI coding tools in CI/CD pipelines to automatically verify developer-written, third-party, and AI-generated code, helping teams reduce outages, improve security, and lower risk.
For questions about private offers, pricing, plans and options, or other products such as SonarQube Cloud, please contact your Sonar representative at www.sonarsource.com/company/contact.
Sonar is the industry standard for code verification and automated code review, helping reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Analyzing over 750 billion lines of code daily and trusted by 7M+ developers globally (including 75% of the Fortune 100) Sonar is the foundation for high-performance software engineering.
SonarQube Server is the self-managed edition of the SonarQube platform. It integrates seamlessly with DevOps platforms and AI coding tools in the CI/CD pipeline to automatically verify code across projects, providing development teams with immediate, precise insights on quality issues and security exposures. With built-in tools like AI CodeFix, SonarQube Server accelerates issue resolution and ensures that developer-written, third-party, and AI-generated code meets quality and security standards.
SonarQube Server Enterprise delivers a range of advanced features offering mission-critical flexibility, scalability, and performance.
For custom pricing, EULA, or a private contract, please contact cloud-marketplace-offers@sonarsource.com for a private offer.
Features:
Advanced static code analysis across 40+ languages, frameworks & IaC for developer-written, third-party, and AI-generated code
Detection of code bugs, vulnerabilities, maintainability issues, security hotspots, secrets, SAST exposures, and much more
Native integration with all major DevOps platforms and AI coding tools
Automatic branch and pull request analysis, including verification of AI-generated code changes
Show output from code coverage measurement tools alongside the SonarQube platform's quality analysis
Quality gates ensure new code, whether written by developers or generated by AI agents, complies with quality profiles customized to your standards
AI-generated code fix suggestions
Works with SonarQube for IDE and integrates via MCP and CLI to assist developers in resolving issues directly in their code, including issues introduced by AI coding tools
SSO through SAML / SCIM identity and access management
Management visibility through portfolios, security reports, and project reports
Organization-wide project configuration
Commercial support (24/7 premium support at additional cost)
Want developer-first security for your first-party, AI-generated, and open source code, powered by advanced SAST and integrated SCA? SonarQube Advanced Security is available at additional cost via private offer.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy two separate contract options, each priced by lines of code (LOC) analyzed. The first covers the SonarQube Server Enterprise plan at 5 million LOC. The second is SonarQube Advanced Security (SQAS) at 5 million LOC, which extends analysis to open source dependencies and supply chain risk. These are independent units, not a single tier ladder, so you can select the core plan, the security add-on, or both. Each is sized to a 5M LOC capacity. For other LOC volumes beyond 5 million, you contact sales for custom options.
Top-of-mind questions for buyers
What counts as a Line of Code (LOC) for billing purposes?
A LOC is the sum of code lines across each analyzed project. Only your largest branch is counted per project. The count does not depend on how often you run analysis. Analyzing a project many times in a month still counts its lines once.
What does the SonarQube Advanced Security unit add beyond the Enterprise plan?
Advanced Security extends analysis to open source dependencies and the software supply chain. It adds known-vulnerability (CVE) detection, malicious package detection, dependency-aware taint analysis, software bill of materials export, and license policy management. It builds on the core code analysis rather than replacing it.
What happens if my codebase grows past the 5 million LOC capacity?
Each unit is sized to a 5 million LOC capacity. If your projects approach that limit, you contact sales for other LOC options. The listing offers 5M LOC as the set capacity, so larger volumes require a custom arrangement through the vendor.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
If you need help with our solutions, you can seek support from our Community and our Commercial Support. Community Support is a collaborative forum where SonarSourcers and community users post every day. It contains detailed articles and technical discussions that cover the most common usages. Community Support: community@sonarsource.com and cloud-partnerships@sonarsource.com Commercial Support is a private communication channel between you and our Services team. It can be used to solve advanced issues and get the guidance you need for the implementation of our products in complex corporate environments. The privacy of this channel also eases the resolution of problems that require sharing sensitive information. Commercial Support:Sales Support Squad sales.support@sonarsource.com and cloud-partnerships@sonarsource.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for technical support with a 24-hour response time. This AMI provides Rocky Linux 10.2 on a minimal installation with the latest updates, repackaged by Easycloud with continuous support.
This product has charges associated with it for technical support with a 24-hour response time. This AMI provides CentOS Stream 10 ARM64 on a minimal installation with the latest updates, repackaged by Easycloud with continuous support.
This product includes SonarQube CE an open-source platform for continuous inspection of code quality. With SonarQube you can perform automatic reviews with static analysis of code to detect bugs, coding standards violations, unit test coverage, code complexity, comments, etc.
This product includes SonarQube CE an open-source platform for continuous inspection of code quality. With SonarQube you can perform automatic reviews with static analysis of code to detect bugs, coding standards violations, unit test coverage, code complexity, comments, etc.
SonarQube Cloud is the fully managed, cloud-based edition of the SonarQube platform, the industry standard for code verification and automated code review. It integrates easily with popular DevOps platforms, delivering real-time security and quality verification to help teams reduce outages, improve security, and lower risk.
Ready to launch SonarQube Community Build server for code quality, code security, technical debt tracking, and CI CD code analysis on Ubuntu with PostgreSQL, Docker Compose, first boot setup, and scanner examples. This product has charges associated with it for the provision and deployment of the application and AMI support.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.