STAR Registry Listing for
SonarQube Cloud
SonarQube Cloud
SonarQube Cloud (formerly known as SonarCloud) is a Software-as-a-Service (SaaS) code analysis tool designed to detect coding issues in 30+ languages, frameworks, and IaC platforms. By integrating directly with your CI pipeline or one of the supported DevOps platforms, your code is checked against an extensive set of rules that cover many attributes of code, such as maintainability, reliability, and security issues, on each merge/pull request.
SonarQube Cloud extends your DevOps experience by performing automated code checks within minutes.

Listed Since: 04/04/2025
Last Updated: 04/04/2025
STAR Level 1
Self-Assessment & Partner-Provided

CAIQ Self-assessment v4.0.3
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).