Your code can’t leave India. Your code review doesn’t have to — SonarQube Server checks every pull request for bugs, vulnerabilities, secrets and IaC mistakes — on servers you run, in an Indian data centre or cloud region, with a quality gate judged on new code.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers SonarQube Server — Sonar’s self-managed editions. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Automated review of every change — bugs, maintainability, vulnerabilities and leaked secrets — before it is merged.
What consolidation actually replaces, dimension by dimension.
| Dimension | Manual review and scattered linters | SonarQube Server |
|---|---|---|
| Where issues are found | In review, QA or production | In the pull request, before merge |
| The standard applied | Each team’s own linter settings | One quality profile and gate for all |
| Legacy code | An audit backlog nobody finishes | Gate on new code; old code improves as touched |
| Where findings live | A SaaS scanner’s region, often abroad | Your own servers, in India |
| The price | Tool licences plus reviewer hours | Per instance, per year, by lines of code |
| What it is NOT | — | Not SCA — dependencies need Advanced Security |
The cheapest test is one team: gate its pull requests on new code for a fortnight and count what would have merged unchecked.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Scanners for Maven, Gradle, .NET and the CLI analyse the code inside your existing pipeline, then send a report to your server. The source is read where your builds already run.
The server processes each report, applies your quality profiles and the quality gate, and keeps issue history per branch. The Data Center edition spreads it across nodes for high availability.
Issues, metrics and history sit in a database you run — PostgreSQL, Microsoft SQL Server or Oracle — on hardware or a cloud region you pick, including one in India.
Pull request decoration in GitHub, GitLab, Bitbucket and Azure DevOps. The Developer edition allows one integration per platform; the Enterprise edition removes the limit.
Scanner in your pipeline, server and database on your hardware — analysis that never has to leave the building.
SonarQube Server reviews every change before it merges — on your own servers, against one quality gate.
Rules for bugs, code smells and complexity across 37 languages on Developer and 45 on Enterprise, including COBOL, PL/I and RPG.
Traces untrusted input through your own code to injection sinks, and raises security hotspots for a person to review.
Flags hard-coded credentials and tokens, and checks Terraform, CloudFormation, Kubernetes and Docker files for misconfigurations.
The gate fails a branch or pull request that adds issues or drops coverage — judged on new code, not the legacy backlog.
Projects containing AI-generated code can be marked and held to a stricter quality gate. Included from Developer upward.
Enterprise adds portfolio roll-ups, reports against common security standards and SCIM provisioning with Okta or Azure AD.
On Enterprise and Data Center: Sonar’s hosted OpenAI models, or your own Azure OpenAI, AWS Bedrock or a self-hosted gateway.
The free SonarQube for IDE extension, in connected mode, applies your server’s rules and profiles while code is written.
Runs on your hardware or cloud account; Sonar says its 2026.5 agentic add-ons also support air-gapped installs.
The 2026.1 LTA release, deploying at enterprise scale, and what the paid editions add over Community Build.
What the 2026.1 LTA changed.
Sizing a self-managed estate.
What the paid editions add.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
SonarQube Cloud stores data in the EU or the US — there is no India region. SonarQube Server runs where you install it: an Indian data centre or an Indian cloud region. Source, issues and history stay on infrastructure you control — the answer a DPDP or RBI review wants.
The quality gate judges what each pull request adds, so teams stop new problems without first clearing years of legacy findings. CleverTap, on SonarQube Server, estimates 16.6 reviewer-hours saved a week; Freshworks runs SonarQube checks across 2,000+ repositories.
AI CodeFix can call your own Azure OpenAI, AWS Bedrock or a self-hosted LLM gateway instead of Sonar’s hosted models; Sonar’s docs say a fully self-hosted setup needs no outbound internet access. AI Code Assurance holds AI-written code to a stricter gate.
No price is published — every edition is a quote, per instance and by lines of code. Dependency scanning (SCA) is Advanced Security, a separate subscription on Enterprise and up. Support is extra below 30M lines of code. And you run the servers.
Measure the lines of code you will analyse, largest branch per project — that number drives the edition and the quote.
Decide Developer, Enterprise or Data Center, the Indian data centre or cloud region, and whether an LLM is allowed out.
Connect one repository group, decorate its pull requests and turn on the quality gate for new code only. Watch what fails.
Agree one quality profile per language, add scanners to every pipeline, and connect SonarQube for IDE in connected mode.
Once false positives are tuned, make a failed gate block the merge, and review hotspots and security reports each sprint.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We host it in our own Mumbai data centre. The residency question in the vendor-risk review took one line to answer.”
“The gate only judges new code, so nobody had to fix ten years of legacy first. That is what got the teams to accept it.”
“Budget it as a quote, not a list price. A monorepo import grew our lines of code and the renewal grew with it.”
“Dependency scanning was not in Enterprise out of the box — Advanced Security is its own subscription. Ask in the first call.”
“We pointed AI CodeFix at our own Azure OpenAI deployment, so snippets never went to a model outside our tenancy.”
“One node was fine until every pipeline queued behind it. Data Center fixed that, but plan the upgrade window early.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the code quality and security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quality plus SAST, 45 languages; self-managed, price on request.
The chart no vendor publishes — control over where it runs and keeps your data, plotted against the depth of its security testing.
Fully self-hosted; SCA needs Advanced Security.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Checkmarx One, Veracode, Snyk Code, GitHub Code Security on Enterprise Server and Semgrep — on deployment, languages, price, scanning depth and India.
| Dimension | SonarQube Server | Checkmarx One | Veracode | Snyk Code | GitHub Code Security (GHES) | Semgrep |
|---|---|---|---|---|---|---|
| What it is | Self-managed code checks | AppSec platform | AppSec platform (SaaS) | Developer-first SAST | CodeQL inside GitHub | Rule-based SAST platform |
| Deployment | Self-hosted | Cloud or on-prem | SaaS only | SaaS only | Your own GHES appliance | SaaS; scans in your CI |
| Language coverage | 37 / 45 languages | 35+ languages | 100+ claimed | 17 language entries | CodeQL: 12 targets | 35+, about 16 GA |
| Pricing model | Per instance, by LOC | Quote only | Quote only | Tiers, then credits | Per active committer | Per contributor |
| Published entry price | Not published | Not published | Not published | Free, then $25/month | $30/committer/month | Free to 10 contributors |
| Included vs add-on | SCA is an add-on | Package not published | Scope not published | SCA and IaC in plan | Secrets sold separately | Products priced apart |
| Scale and limits | Sized by lines of code | Not published | Not published | Test and project caps | Scales with committers | 500 repos on Teams |
| Security scanning depth | SAST, secrets, IaC | Broad AppSec suite | Binary SAST + DAST | SAST + Snyk platform | CodeQL semantic SAST | Fast, pattern-led |
| Integrations | 4 DevOps platforms | SCM, CI and IDE | CI plugins, SaaS scan | IDE, CLI, SCM, CI | GitHub repos only | GitHub, GitLab first |
| Governance and SSO | SAML; SCIM on Ent. | SAML and OIDC | SAML with JIT | Enterprise controls | SAML, LDAP or CAS | SAML/OIDC on Teams |
| India storage region | Your servers in India | India environment | No India region | No India region | On your own GHES | Code stays in your CI |
| Support | Paid below 30M LOC | Not published | Not published | Next business day | With GitHub Enterprise | Account manager on Ent. |
| Lock-in and exit | Community Build fallback | Proprietary queries | Findings live in SaaS | Region is permanent | Tied to GitHub | Open rule syntax |
| Best fit | Residency and PR gates | One AppSec suite | Many apps, SaaS OK | Cloud-first dev teams | GHES organisations | Custom-rule writers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
SonarQube Server is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (developers; developer-hour cost). Estimates model developer time lost to bugs and vulnerabilities found after merge — traced back, reworked and re-reviewed — at an assumed 1.5 hours per developer a year, with 70% of it avoided by a quality gate on every pull request. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Sonar licenses SonarQube Server per instance, per year, based on the lines of code you analyse, and asks you to contact sales for every edition. Advanced Security (SCA) and the AI agents are additional subscriptions. TechBag measures your lines of code first, then quotes in INR with GST.
Best from about 100K lines of code
Best for a broader rollout
Best from about 1M lines of code
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many lines of code will you analyse, counted on the largest branch — and how fast is that number growing?
Do you need portfolios, SCIM, security reports, AI CodeFix or legacy languages? Those start at Enterprise, not Developer.
How many instances will you license? Each production instance is licensed on its own — plan test and staging too.
Which Indian data centre or cloud region will host the server and database, and who runs upgrades and backups?
If AI CodeFix is enabled, which LLM will it call — Sonar’s hosted models, or your own Azure OpenAI, Bedrock or gateway?
Do you need dependency scanning and SBOMs? That is Advanced Security, a separate subscription — price it now.
Is standard support included at your size, or is it an extra line? Sonar includes it only on Enterprise and Data Center from 30M lines.
What happens to the price at renewal if your lines of code grow — is the band and uplift written into the agreement?
Measure your lines of code and plan the Indian hosting first, or let a TechBag advisor scope a pilot that gates one team's pull requests.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.