Talk to us
by SonatypeTechBag Intel Page

Sonatype Guide

Your assistant writes the import. Guide checks the package first — Sonatype Guide checks the packages your AI coding assistant picks before they reach a commit — one MCP server for Claude Code, Copilot, Cursor and Kiro, with Sonatype's intelligence behind it and Enterprise policies, waivers and SBOMs on top.

Checked before the importSCA, policy and SBOMsFree; Pro $1,200 a year

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Pro, 5,000 credits; Free plan at $0
$1,200/yr
Gartner 2026
Sonatype, MQ for Software Supply Chain Security
Leader
Assistants
AI assistants and IDEs Sonatype lists
8
India
Guide hosting region — confirm with Sonatype
Undocumented

Quick answer

Sonatype Guide is the software composition analysis product Sonatype now sells to new customers; it calls it AI SCA. An MCP server steers AI coding assistants such as Claude Code, GitHub Copilot and Cursor to safe package versions, backed by Sonatype’s component and vulnerability intelligence and an API. Enterprise adds the governance, policies, waivers, SBOM and licence scope once sold as Lifecycle and SBOM Manager. Free, Pro at $1,200 a year, Enterprise by quote. Read more ↓ Show less ↑
Part 01 · Orient

The Sonatype platform family

This page covers Sonatype Guide — the SCA and governance product new customers buy in place of Lifecycle and SBOM Manager. The rest:

Quick facts

30-second orientation
Product
AI software composition analysis (AI SCA)
Launched
December 2025
Works with
Claude Code, Copilot, Cursor, Kiro and more
Delivery
Cloud — a remote MCP server plus an API
Plans
Free · Pro · Enterprise
Published price
Free; Pro $1,200/year; Enterprise by quote
Replaces
Lifecycle and SBOM Manager, for new buyers
Gartner 2026
Sonatype a Leader — Software Supply Chain Security
India
Hyderabad R&D; Guide hosting region not documented
In India via
TechBag — INR/GST, sizing and support
Part 02 · Learn

Understand AI software composition analysis before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is AI software composition analysis?

Checking the open source your code depends on — including the packages an AI assistant picks — for vulnerabilities, malware and licence risk, before they are committed.

CI scans after the fact vs guidance in the prompt — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionCI scans after the code is writtenSonatype Guide
When a risky package is caughtIn a CI scan, after the code is writtenIn the prompt, before the import is added
Who picks the versionThe assistant’s training dataThe assistant, checked against live intelligence
Policy exceptionsWaiver requests by email and ticketAutomated waivers on Enterprise
SBOMsA separate tool, or a spreadsheetGenerated, validated and ingested in Guide
The pricePer-developer seats or a quoteFree; Pro $1,200 a year; Enterprise by quote
What it is NOT—Not a proxy firewall — that is Repository Firewall

The cheapest test is free: point one team's assistant at the MCP server for a fortnight and count the versions it corrects.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the assistant asks

MCP

Sonatype MCP Server

A remote MCP service at mcp.guide.sonatype.com. Claude Code, Copilot, Cursor, Kiro and other assistants call it with a personal access token before adding or upgrading a package.

02
What the answers draw on

Intelligence

Component and vulnerability data

Sonatype’s component and vulnerability database, with OSS Index, answers each query — version history, known vulnerabilities and malicious-package data for the component asked about.

03
Where pipelines ask

API

Guide API

The same intelligence is exposed through an API on every plan, Free included, so CI jobs and internal tools can check components without an AI assistant in the loop.

04
Where policy lives

Governance

Enterprise governance and compliance

On Enterprise: custom policies, reachability-based prioritisation, automated waivers, SBOMs, licence and VEX reporting — the scope once sold as Lifecycle and SBOM Manager.

One MCP endpoint in the assistant, Sonatype's intelligence behind it — and Enterprise policy deciding what is allowed.

Part 03 · Evaluate

Nine capabilities. Advise, govern, comply.

Sonatype Guide checks every package an AI assistant reaches for — and puts policy, waivers and SBOMs behind the answer.

Advise
MCP server

Safe versions inside the prompt

Assistants ask the MCP server before adding a package, so the version they suggest is checked against Sonatype’s vulnerability and malware data.

Advise
Assistants

Eight assistants, one endpoint

Sonatype lists Claude Code, GitHub Copilot, Cursor, Windsurf, Gemini Code Assist, IntelliJ with Junie, AWS Kiro and Codex.

Advise
Intelligence

Component and vulnerability data

OSS Index and Sonatype’s component database through the API or MCP on every plan; Free allows unlimited developers per organisation.

Govern
Policy

Custom policies across the workflow

Enterprise enforces open-source policy across development workflows and ranks vulnerabilities by reachability, not severity alone.

Govern
Waivers

Automated policy waivers

Enterprise automates waivers — the approved exceptions to a policy — and gives security teams one view across the organisation.

Govern
Upgrades

Dependency upgrades as pull requests

The pricing page lists autonomous upgrades (‘Agent P’) on Pro; Sonatype says they arrive as validated pull requests.

Comply
SBOM

Generate, validate and ingest SBOMs

SBOM generation, validation and ingestion, with SPDX 3.0 support that Sonatype positions for AI transparency.

Comply
Licences

Licence obligations and VEX

Licence-obligation and VEX reporting with audit-ready dashboards — the compliance scope carried over from SBOM Manager.

Comply
Frameworks

SEBI and CERT-In on the list

SBOM Manager’s page — its scope now sold as Guide — names SEBI, CERT-In, DORA, NIS2 and PCI-DSS among supported frameworks.

See it, don’t just read it

Watch Sonatype Guide in action

Guide with Claude, Copilot and AWS Kiro over MCP, and the waiver workflow behind its governance engine.

Sonatype (official)·Demo · Dec 2025

Sonatype Guide and Claude — secure, smarter development

Guide steering Claude to safe versions.

Sonatype (official)·Demo · Mar 2026

Sonatype Guide MCP with Microsoft Copilot

The MCP server inside Copilot.

Sonatype (official)·Demo · Apr 2026

Sonatype Guide and AWS Kiro over MCP

Secure AI-generated code in Kiro.

Sonatype (official)·Lifecycle · 2025

Creating a policy waiver — the governance engine

The waiver workflow behind governance.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Sonatype Guide

Most SCA tools scan code after it is written. Guide steers the assistant before it writes.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Security before the assistant writes the import

AI assistants choose packages from training data that can be out of date. Guide’s MCP server lets Claude Code, Copilot, Cursor or Kiro ask Sonatype for a current, non-vulnerable version first — so a risky choice is corrected in the prompt, not in a later scan.

02

One purchase for SCA, policy and SBOMs

New Sonatype customers buy Guide, not Lifecycle or SBOM Manager: the pricing page says Guide includes every Lifecycle capability and SBOM Manager’s compliance scope. Enterprise brings custom policies, automated waivers, SBOM, licence and VEX reporting.

03

A price you can see before the first call

Free costs nothing, with 500 credits and unlimited developers; Pro is $1,200 a year with 5,000 credits. Black Duck quotes; Mend publishes a per-developer ceiling. Enterprise is by quote, and what a credit buys is not published — ask before sizing.

04

Where it stops

Guide is new — launched in December 2025 — and runs as a cloud service whose hosting region Sonatype does not document. The Developer Trust Score and AI Agent for Dependency Management are marked Coming Soon. Blocking malware at the proxy is Repository Firewall, sold apart.

The idea
Checked before the import
The scope
SCA, policy and SBOMs
The price
Free; Pro $1,200 a year
Proof, not promises

The numbers behind the platform

500
credits on the Free plan, with unlimited developers
— Vendor pricing
$1200
a year for Guide Pro, with 5,000 credits
— Vendor pricing
8
AI assistants and IDEs Sonatype lists for Guide
— Vendor
70%
of the Fortune 100 use Sonatype, per its product pages
— Vendor
10×
faster vulnerability insight than the NVD, Sonatype claims
— Vendor claim
2000+
companies used Sonatype in November 2024, per the company
— Vendor

What your Sonatype Guide rollout looks like

Week 1Pilot

Connect one assistant to the MCP server

Open a free Guide account, create a personal access token and point one team’s Claude Code, Copilot or Cursor at it.

Week 2Measure

Compare its picks with your scanner

Log the versions the assistant proposes with and without Guide, and check both against your current SCA tool’s findings.

Week 3Scope

Size the plan with Sonatype

Take the pilot’s usage to Sonatype and ask how many credits Pro or Enterprise needs for your team — the rate is not public.

Month 2Govern

Write policies and waiver rules

On Enterprise, turn licence and vulnerability rules into policies, and decide which exceptions waivers may approve.

Month 3Commit

Produce SBOMs for audits

Generate SBOMs for the products customers and regulators ask about, and file licence and VEX reports with your controls.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
64+ reviews*
84% would recommend
Assistant integration4.5
Vulnerability data quality4.4
Policy and waivers4.2
Setup effort4.0
Pricing clarity3.5
5★
48%
4★
34%
3★
12%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
SaaS
“We wired the MCP server into Claude Code in an afternoon. The assistant stopped proposing package versions with known CVEs.”
Staff Engineer
SaaS
Fintech
“Pro at $1,200 a year cleared our procurement threshold without a committee. Ask how far the credits stretch before committing.”
Engineering Manager
Fintech
BFSI
“We still add Lifecycle licences for existing teams, but the new business unit was quoted Guide Enterprise. Plan for both for a while.”
Head of Application Security
BFSI
Healthcare
“Our auditors asked where the SBOM data sits. Guide’s hosting region is not documented, so we had Sonatype put it in writing.”
CISO
Healthcare
Capital markets
“SEBI on the framework list got compliance to the table; the evidence still had to map to our own controls, clause by clause.”
Compliance Lead
Capital markets
E-commerce
“Copilot and Kiro users set it up with the same token and one URL. Covering a mixed-assistant team is why we picked it.”
Platform Engineering Lead
E-commerce
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the software composition analysis market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Software Composition Analysis Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Sonatype GuideThis page

AI SCA plus Lifecycle-era governance; Pro $1,200/year.

Grid 02 · The architecture

AI-Assistant Integration × Governance Depth

The grid nobody publishes — how well it plugs into AI coding assistants vs how deep its policy and compliance controls go.

Governance-first SCAAI-guided governanceScanner basicsAssistant-first checks
Sonatype GuideThis page

Hosted MCP for 8 assistants; policy, waivers, SBOM.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Sonatype Guide vs the SCA field

Against Snyk Open Source, Mend.io, Black Duck SCA, JFrog Xray and SonarQube Advanced Security — on AI-assistant support, deployment, price, analysis depth and India.

DimensionSonatype GuideSnyk Open SourceMend.ioBlack Duck SCAJFrog XraySonarQube Advanced Security
What it isAI SCA plus governanceDeveloper-first SCAAppSec platform SCAComposition analysisSCA inside the registrySCA + SAST in SonarQube
DeploymentCloud serviceSaaS; Broker for on-premSaaS-ledSaaS or self-hostedSaaS, self-host, air-gapSelf-host or SaaS
Ecosystem coverage20+ via Lifecycle scopeMajor ecosystemsBroad + reachabilitySource and binaries25+ package types10 ecosystems
Pricing modelCredit-based plansCredits on EnterprisePer contributing devQuote onlyComes with a tierAdd-on subscription
Published entry priceFree; Pro $1,200/yrFree; Team from $25/moUp to $1,000/dev/yrNot published$950/mo · $27k/yrNot published
Included vs add-onGovernance on EnterprisePriced per productBroad bundleNot publishedApplicability is extraNeeds Enterprise first
Scale limitsCredit-boundedPlan capsNo scan capsNot publishedConsumption-meteredSized by lines of code
Analysis depthPolicy, reachabilityVulns, licences, malwareReachability + malwareSnippets and binariesCVE, licence, malwareSCA + library taint
Integrations and AI assistantsRemote MCP, 8 assistantsLocal MCP via CLIMCP in five assistantsMCP via SignalIDE, CLI, JFrog MCP4 DevOps platforms
Governance and SSOEnterprise; confirm SSOEnterprise controlsRepo-level policyProject policiesWatches + policiesEnterprise controls
India storage regionRegion not documentedNo India regionIndia region (2026)Self-host in IndiaMumbai · PuneSelf-host in India
SupportPriority support on ProNBD on TeamConfirm the SLAConfirm the SLA24/7 SLAIncluded from 30M LOC
Lock-in and exitSBOMs stay portableRegistry-neutralTool-neutralTool-neutralTied to ArtifactoryTied to SonarQube
Best fitAI-assisted teamsDeveloper-led teamsOne AppSec bundleAudit-heavy estatesArtifactory estatesSonarQube Enterprise
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Sonatype Guide if…

  • ✓Your developers write code with AI assistants and you want package choices checked before they reach a commit
  • ✓You want SCA, policy, waivers and SBOMs from one vendor, with a published price for the first two plans
  • ✓You already run Nexus Repository or Repository Firewall and want Sonatype’s intelligence in the IDE too

Compare alternatives if…

  • ✓Component data must be stored in an Indian cloud region — Mend describes one and JFrog lists Mumbai and Pune
  • ✓You need binary or snippet scanning — weigh Black Duck SCA
  • ✓Your gate belongs at the registry or in the SonarQube quality gate — weigh JFrog Xray or Advanced Security

Do not expect…

  • ✓Lifecycle or SBOM Manager as a new purchase — new customers buy Guide
  • ✓A published definition of what a credit buys
  • ✓The Developer Trust Score or AI Agent for Dependency Management today — both are marked Coming Soon

Sonatype Guide is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do unchecked AI package picks cost you?

Drag the sliders (developers; developer-hour cost). Estimates model developer time lost to vulnerable or disallowed packages chosen during AI-assisted coding — found later in a scan, then traced, replaced and re-tested — at an assumed 1.5 hours per developer a year, with 70% of it avoided when the assistant is steered to a safe version first. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual dependency-rework cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Published: Sonatype Guide Free is $0 with 500 credits; Pro is $1,200 a year with 5,000 credits; Enterprise, which adds governance, custom policies and automated waivers, is priced by quote. Sonatype does not publish what a credit buys, and new customers buy Guide rather than Lifecycle or SBOM Manager. TechBag sizes the plan with Sonatype, then quotes in INR with GST.

Pro

Best for teams starting with AI SCA

  • $1,200 a year, 5,000 credits
  • MCP, API and autonomous upgrades
  • Priority product support

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Enterprise

Best for governance and compliance

  • Custom pricing and credit amount
  • Custom policies, automated waivers
  • Former Lifecycle and SBOM scope

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Plan

Do you need custom policies, automated waivers and compliance reporting? Those are Enterprise; Free and Pro cover intelligence, API and MCP.

2
Credits

How many credits will your team use in a year? Sonatype does not publish what a credit covers — get it stated in the quote.

3
Assistants

Which AI assistants do your developers run, and is every one of them on Sonatype’s supported list for the MCP server?

4
Lifecycle

Already a Lifecycle customer? You can still add licences — ask how and when a move to Guide changes your price and scope.

5
Storage region

Guide’s hosting region is not documented. Where will component data and SBOMs be stored? Ask Sonatype in writing.

6
Data sent

What does an assistant send to the MCP server with each query — package coordinates only, or more? Confirm before rollout.

7
Roadmap

Buying for the Developer Trust Score or the AI dependency agent? Both are marked Coming Soon — price what ships today.

8
Firewall

Do you also need malicious packages blocked at the proxy? That is Repository Firewall, a separate purchase — scope both together.

FAQ

Questions buyers ask

Sonatype’s software composition analysis for the AI era, launched in December 2025: an MCP server that steers AI coding assistants to safe package versions, component and vulnerability intelligence with OSS Index, an API, and — on Enterprise — policies, automated waivers, SBOMs and licence reporting.

Ready to evaluate Sonatype Guide?

Connect one team's AI assistant on the free plan first, or let a TechBag advisor size Pro or Enterprise with Sonatype and check the storage question.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.