SOC2 compliance and SSO for SonarCloud

Greetings.

I’m evaluating SonarQube/SonarCloud for my company. I’ve been told to ask about SOC2 compliance and SSO access.

Specifically:

  1. Does SonarCloud have any SOC2 compliance, or other similar quality compliance? If not, exactly how much data is shared with SonarCloud servers?
  2. Is it possible to control access to a company SonarCloud account via a custom company SSO? We would want to allow a non-trivial number of people to view analysis results (basically the whole engineering team), but we would need a central point of revocation when someone leaves.

Thank you for any information you can provide.

1 Like

Hello Larry,

Thank you for reaching out.

  1. Does SonarCloud have any SOC2 compliance, or other similar quality compliance? If not, exactly how much data is shared with SonarCloud servers?

SonarCloud does not have SOC 2. We are considering it for 2023. We have ISO 27001 at the Company level and we are in Y2, so mature. You can read more about the data we store here.

  1. Is it possible to control access to a company SonarCloud account via a custom company SSO? We would want to allow a non-trivial number of people to view analysis results (basically the whole engineering team), but we would need a central point of revocation when someone leaves.

This is not supported. All authentication is through your chosen DevOps platform. GitHub has SSO. You can read about the authentication mechanisms available here.

Kind regards,
Mark

Do you have any update on SoC2 compliance ?
I am slightly confused as your trust center page says SonarCloud is SoC2 compliant
Trust Center | Security & Compliance | Sonar SonarSource.

But this answer says it is not.
Can you please share what is the latest status of SoC2 compliance of SonarCloud

I believe that refers to AWS and it’s security standards rather than Sonarcloud.

I’m also interested to hear whether there has been any progress with SOC2 compliance on the Sonarcloud side of things though…

2 Likes

If that’s the case , this is very poorly worded here : Trust Center | Security & Compliance | Sonar SonarSource

Not being a SoC2 compliant is a no-go for us to even consider sonar cloud