Talk to us
by SonarTechBag Intel Page

SonarQube Server

Your code can’t leave India. Your code review doesn’t have to — SonarQube Server checks every pull request for bugs, vulnerabilities, secrets and IaC mistakes — on servers you run, in an Indian data centre or cloud region, with a quality gate judged on new code.

A gate on every pull requestSelf-hosted, in IndiaPer instance, by lines of code

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
per instance, per year, by lines of code
On request
Gartner 2026
Technical Debt Management Tools MQ
Leader
Languages
on Enterprise edition (37 on Developer)
45
India
data stays on servers you choose
Self-hosted

Quick answer

SonarQube Server is Sonar’s self-managed code quality and security platform: analysis for bugs, maintainability, vulnerabilities (SAST), secrets and infrastructure-as-code, with a quality gate on every pull request. The Developer, Enterprise and Data Center editions run on servers you choose, which makes it the route to keeping code and findings in India. It is licensed per instance, per year, by lines of code, and Sonar does not publish the price. Read more ↓ Show less ↑
Part 01 · Orient

The Sonar platform family

This page covers SonarQube Server — Sonar’s self-managed editions. The rest:

Quick facts

30-second orientation
Product
Self-managed code quality and security
Editions
Developer, Enterprise, Data Center
Analysis
Quality, SAST, secrets, IaC, quality gates
Languages
37 on Developer · 45 on Enterprise
Licensing
Per instance, per year, by lines of code
Published price
None — Sonar says contact sales
Free starting point
Community Build (LGPL-3.0), no LTA
Gartner 2026
Leader — Technical Debt Management Tools
India
Self-host in India; SonarQube Cloud is EU/US only
In India via
TechBag — INR/GST, sizing and support
Part 02 · Learn

Understand code quality and security analysis before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is code quality and security analysis?

Automated review of every change — bugs, maintainability, vulnerabilities and leaked secrets — before it is merged.

Manual review and scattered linters vs one self-hosted quality gate — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionManual review and scattered lintersSonarQube Server
Where issues are foundIn review, QA or productionIn the pull request, before merge
The standard appliedEach team’s own linter settingsOne quality profile and gate for all
Legacy codeAn audit backlog nobody finishesGate on new code; old code improves as touched
Where findings liveA SaaS scanner’s region, often abroadYour own servers, in India
The priceTool licences plus reviewer hoursPer instance, per year, by lines of code
What it is NOT—Not SCA — dependencies need Advanced Security

The cheapest test is one team: gate its pull requests on new code for a fortnight and count what would have merged unchecked.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where analysis runs

Scanner

SonarScanner in your build

Scanners for Maven, Gradle, .NET and the CLI analyse the code inside your existing pipeline, then send a report to your server. The source is read where your builds already run.

02
Rules, history, gates

Server

SonarQube Server

The server processes each report, applies your quality profiles and the quality gate, and keeps issue history per branch. The Data Center edition spreads it across nodes for high availability.

03
Where results live

Database

Your own database

Issues, metrics and history sit in a database you run — PostgreSQL, Microsoft SQL Server or Oracle — on hardware or a cloud region you pick, including one in India.

04
Where developers see it

DevOps

DevOps platform integration

Pull request decoration in GitHub, GitLab, Bitbucket and Azure DevOps. The Developer edition allows one integration per platform; the Enterprise edition removes the limit.

Scanner in your pipeline, server and database on your hardware — analysis that never has to leave the building.

Part 03 · Evaluate

Nine capabilities. Detect, govern, fix.

SonarQube Server reviews every change before it merges — on your own servers, against one quality gate.

Detect
Code quality

Bugs and maintainability, 45 languages

Rules for bugs, code smells and complexity across 37 languages on Developer and 45 on Enterprise, including COBOL, PL/I and RPG.

Detect
SAST

Taint analysis for vulnerabilities

Traces untrusted input through your own code to injection sinks, and raises security hotspots for a person to review.

Detect
Secrets and IaC

Leaked keys and bad config

Flags hard-coded credentials and tokens, and checks Terraform, CloudFormation, Kubernetes and Docker files for misconfigurations.

Govern
Quality gate

A pass or fail on every PR

The gate fails a branch or pull request that adds issues or drops coverage — judged on new code, not the legacy backlog.

Govern
AI Code Assurance

Stricter gates for AI-written code

Projects containing AI-generated code can be marked and held to a stricter quality gate. Included from Developer upward.

Govern
Portfolios

Portfolios, reports and SCIM

Enterprise adds portfolio roll-ups, reports against common security standards and SCIM provisioning with Okta or Azure AD.

Fix
AI CodeFix

Suggested fixes, your choice of LLM

On Enterprise and Data Center: Sonar’s hosted OpenAI models, or your own Azure OpenAI, AWS Bedrock or a self-hosted gateway.

Fix
In the IDE

The same rules in the editor

The free SonarQube for IDE extension, in connected mode, applies your server’s rules and profiles while code is written.

Fix
Deployment

On your own servers

Runs on your hardware or cloud account; Sonar says its 2026.5 agentic add-ons also support air-gapped installs.

See it, don’t just read it

Watch SonarQube Server in action

The 2026.1 LTA release, deploying at enterprise scale, and what the paid editions add over Community Build.

Sonar (official)·Release

Inside the SonarQube Server 2026.1 LTA release

What the 2026.1 LTA changed.

Sonar (official)·Sonar Summit 2026

SonarQube enterprise architecture — deploying at scale

Sizing a self-managed estate.

Sonar (official)·Editions

From SonarQube Community Build to Enterprise

What the paid editions add.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why SonarQube Server

Most code scanners run in someone else’s cloud. SonarQube Server runs in yours.

Here’s what genuinely sets it apart — and exactly where it stops.

01

The route to keeping code analysis in India

SonarQube Cloud stores data in the EU or the US — there is no India region. SonarQube Server runs where you install it: an Indian data centre or an Indian cloud region. Source, issues and history stay on infrastructure you control — the answer a DPDP or RBI review wants.

02

A gate on new code, not a backlog audit

The quality gate judges what each pull request adds, so teams stop new problems without first clearing years of legacy findings. CleverTap, on SonarQube Server, estimates 16.6 reviewer-hours saved a week; Freshworks runs SonarQube checks across 2,000+ repositories.

03

AI help that stays inside your perimeter

AI CodeFix can call your own Azure OpenAI, AWS Bedrock or a self-hosted LLM gateway instead of Sonar’s hosted models; Sonar’s docs say a fully self-hosted setup needs no outbound internet access. AI Code Assurance holds AI-written code to a stricter gate.

04

Where it stops

No price is published — every edition is a quote, per instance and by lines of code. Dependency scanning (SCA) is Advanced Security, a separate subscription on Enterprise and up. Support is extra below 30M lines of code. And you run the servers.

The idea
A gate on every pull request
The residency
Self-hosted, in India
The price
Per instance, by lines of code
Proof, not promises

The numbers behind the platform

45
languages and frameworks on the Enterprise edition
— Vendor
37
languages and frameworks on the Developer edition
— Vendor
2000+
repositories at Freshworks gated by SonarQube checks
— Customer story
1500
developers on Freshworks’ SonarQube-gated platform
— Customer story
75%
of the Fortune 100 use Sonar, in Sonar’s own words
— Vendor
7M+
developers use Sonar, per the company
— Vendor

What your SonarQube Server rollout looks like

Week 1Model

Count lines of code and repositories

Measure the lines of code you will analyse, largest branch per project — that number drives the edition and the quote.

Week 2Scope

Pick the edition and where it runs

Decide Developer, Enterprise or Data Center, the Indian data centre or cloud region, and whether an LLM is allowed out.

Week 3Pilot

Gate one team’s pull requests

Connect one repository group, decorate its pull requests and turn on the quality gate for new code only. Watch what fails.

Month 2Rollout

Roll out profiles to every team

Agree one quality profile per language, add scanners to every pipeline, and connect SonarQube for IDE in connected mode.

Month 3Commit

Make the gate block merges

Once false positives are tuned, make a failed gate block the merge, and review hotspots and security reports each sprint.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.4
210+ reviews*
87% would recommend
Rule coverage4.6
Pull request feedback4.5
False-positive rate4.0
Administration effort3.7
Pricing clarity3.4
5★
57%
4★
29%
3★
9%
2★
3%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We host it in our own Mumbai data centre. The residency question in the vendor-risk review took one line to answer.”
Head of Application Security
BFSI
SaaS
“The gate only judges new code, so nobody had to fix ten years of legacy first. That is what got the teams to accept it.”
Engineering Manager
SaaS
E-commerce
“Budget it as a quote, not a list price. A monorepo import grew our lines of code and the renewal grew with it.”
VP Engineering
E-commerce
Fintech
“Dependency scanning was not in Enterprise out of the box — Advanced Security is its own subscription. Ask in the first call.”
DevSecOps Lead
Fintech
Healthcare
“We pointed AI CodeFix at our own Azure OpenAI deployment, so snippets never went to a model outside our tenancy.”
Platform Architect
Healthcare
Telecom
“One node was fine until every pipeline queued behind it. Data Center fixed that, but plan the upgrade window early.”
SRE Manager
Telecom
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the code quality and security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Code Quality and Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
SonarQube ServerThis page

Quality plus SAST, 45 languages; self-managed, price on request.

Grid 02 · The architecture

Deployment Control × Security Testing Depth

The chart no vendor publishes — control over where it runs and keeps your data, plotted against the depth of its security testing.

Cloud AppSec suitesSelf-hostable AppSec suitesCloud developer toolsSelf-hosted code gates
SonarQube ServerThis page

Fully self-hosted; SCA needs Advanced Security.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

SonarQube Server vs the code security field

Against Checkmarx One, Veracode, Snyk Code, GitHub Code Security on Enterprise Server and Semgrep — on deployment, languages, price, scanning depth and India.

DimensionSonarQube ServerCheckmarx OneVeracodeSnyk CodeGitHub Code Security (GHES)Semgrep
What it isSelf-managed code checksAppSec platformAppSec platform (SaaS)Developer-first SASTCodeQL inside GitHubRule-based SAST platform
DeploymentSelf-hostedCloud or on-premSaaS onlySaaS onlyYour own GHES applianceSaaS; scans in your CI
Language coverage37 / 45 languages35+ languages100+ claimed17 language entriesCodeQL: 12 targets35+, about 16 GA
Pricing modelPer instance, by LOCQuote onlyQuote onlyTiers, then creditsPer active committerPer contributor
Published entry priceNot publishedNot publishedNot publishedFree, then $25/month$30/committer/monthFree to 10 contributors
Included vs add-onSCA is an add-onPackage not publishedScope not publishedSCA and IaC in planSecrets sold separatelyProducts priced apart
Scale and limitsSized by lines of codeNot publishedNot publishedTest and project capsScales with committers500 repos on Teams
Security scanning depthSAST, secrets, IaCBroad AppSec suiteBinary SAST + DASTSAST + Snyk platformCodeQL semantic SASTFast, pattern-led
Integrations4 DevOps platformsSCM, CI and IDECI plugins, SaaS scanIDE, CLI, SCM, CIGitHub repos onlyGitHub, GitLab first
Governance and SSOSAML; SCIM on Ent.SAML and OIDCSAML with JITEnterprise controlsSAML, LDAP or CASSAML/OIDC on Teams
India storage regionYour servers in IndiaIndia environmentNo India regionNo India regionOn your own GHESCode stays in your CI
SupportPaid below 30M LOCNot publishedNot publishedNext business dayWith GitHub EnterpriseAccount manager on Ent.
Lock-in and exitCommunity Build fallbackProprietary queriesFindings live in SaaSRegion is permanentTied to GitHubOpen rule syntax
Best fitResidency and PR gatesOne AppSec suiteMany apps, SaaS OKCloud-first dev teamsGHES organisationsCustom-rule writers
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose SonarQube Server if…

  • ✓Code and findings must stay in India, on your own servers
  • ✓You want a quality gate on every pull request, judged on new code rather than the backlog
  • ✓You want AI fixes that can run against your own LLM instead of a hosted one

Compare alternatives if…

  • ✓You would rather not run servers — SonarQube Cloud or a SaaS scanner removes that work
  • ✓You need DAST and API testing from the same vendor — weigh Checkmarx One or Veracode
  • ✓All your code is on GitHub Enterprise Server and per-committer CodeQL fits the budget

Do not expect…

  • ✓A published price — every edition is quoted per instance, by lines of code
  • ✓Dependency scanning (SCA) in the base editions — that is Advanced Security
  • ✓Standard support included below 30M lines of code

SonarQube Server is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do bugs found after merge cost you?

Drag the sliders (developers; developer-hour cost). Estimates model developer time lost to bugs and vulnerabilities found after merge — traced back, reworked and re-reviewed — at an assumed 1.5 hours per developer a year, with 70% of it avoided by a quality gate on every pull request. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual post-merge rework cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Sonar licenses SonarQube Server per instance, per year, based on the lines of code you analyse, and asks you to contact sales for every edition. Advanced Security (SCA) and the AI agents are additional subscriptions. TechBag measures your lines of code first, then quotes in INR with GST.

Developer

Best from about 100K lines of code

  • 37 languages, branch and PR analysis
  • AI Code Assurance, secrets detection
  • Price on request, per instance

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Enterprise

Best from about 1M lines of code

  • 45 languages, portfolios, SCIM
  • AI CodeFix, security reports
  • Advanced Security as an add-on

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Lines of code

How many lines of code will you analyse, counted on the largest branch — and how fast is that number growing?

2
Edition

Do you need portfolios, SCIM, security reports, AI CodeFix or legacy languages? Those start at Enterprise, not Developer.

3
Instances

How many instances will you license? Each production instance is licensed on its own — plan test and staging too.

4
Hosting

Which Indian data centre or cloud region will host the server and database, and who runs upgrades and backups?

5
LLM use

If AI CodeFix is enabled, which LLM will it call — Sonar’s hosted models, or your own Azure OpenAI, Bedrock or gateway?

6
SCA

Do you need dependency scanning and SBOMs? That is Advanced Security, a separate subscription — price it now.

7
Support

Is standard support included at your size, or is it an extra line? Sonar includes it only on Enterprise and Data Center from 30M lines.

8
Renewal

What happens to the price at renewal if your lines of code grow — is the band and uplift written into the agreement?

FAQ

Questions buyers ask

Sonar’s self-managed platform for code quality and code security. It analyses code in your build for bugs, maintainability issues, vulnerabilities (SAST), secrets and infrastructure-as-code problems, and applies a quality gate to every branch and pull request. It comes in Developer, Enterprise and Data Center editions.

Ready to evaluate SonarQube Server?

Measure your lines of code and plan the Indian hosting first, or let a TechBag advisor scope a pilot that gates one team's pull requests.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.