Hi Team,
After upgrading our Test environment to SonarQube 2025.1.4, we observed that several newly introduced AI‑related capabilities are enabled by default. We have noticed AI CodeFix and AI‑generated code detection features, AI Code Assurance, AI‑qualified quality gates etc introduced in the 2025.1 LTA release.
Since we do not intend to use these AI capabilities in our Production environment at this time, particularly due to internal security and compliance considerations, we would like to understand the following:
Is there a way to keep all AI‑related features disabled during installation or the upgrade process itself, rather than disabling them individually after the upgrade?
From a security perspective, could you clarify whether any of these AI features including:
AI CodeFix (AI‑generated fix suggestions),
AI‑generated code detection,
AI Code Assurance workflows,
AI‑qualified quality gates (e.g., Sonar way for AI Code),
transmit any source code, scan data, metadata, contributor signals, or project information outside our SonarQube instance to SonarSource‑hosted services or any third‑party LLM/AI infrastructure?
If any outbound communication is involved, could you provide details on:
what data is transmitted ?,
the destination (e.g., SonarSource servers, OpenAI endpoints for AI CodeFix) ? ,
how this data is secured and stored ? ,
whether such communication can be restricted or fully disabled ?
For the features that rely on external services such as AI CodeFix using any AI model need confirmation on whether our organization’s code or scan data is ever sent to these LLMs for processing, even in anonymized or partial form ?
Given that our organization handles sensitive code and operates under strict security controls, it is essential for us to verify that no project code, scan artifacts, or metadata leave our environment without explicit approval.
Your guidance on how these AI functions operate ? , how data is managed ? , and whether we can fully disable all AI‑related features during the upgrade will help us complete our internal security assessment.