
Sonar
Founded Year
2008Stage
Unattributed VC | AliveTotal Raised
$457MValuation
$0000Last Raised
$412M | 3 yrs agoMosaic Score The Mosaic Score is an algorithm that measures the overall financial health and market potential of private companies.
+25 points in the past 30 days
About Sonar
Sonar specializes in code quality and security within the software development industry. The company offers tools for static application security testing, continuous codebase inspection, and real-time coding guidance to improve code reliability, maintainability, and security. Sonar's solutions cater to various sectors, including the public sector, enterprise-level businesses, and developers seeking to integrate clean code practices into their development workflows. It was founded in 2008 and is based in Vernier, Switzerland.
Loading...
ESPs containing Sonar
The ESP matrix leverages data and analyst insight to identify and rank leading companies in a given technology landscape.
The code review market is a space where technology vendors offer tools and solutions to help improve the quality, consistency, and speed of software development. Code review involves the systematic examination and analysis of code by developers or peers to identify errors, bugs, vulnerabilities, and adherence to coding standards. Code review tools facilitate the process by automating code analysis…
Sonar named as Leader among 11 other companies, including Atlassian, Veracode, and Codescene.
Loading...
Research containing Sonar
Get data-driven expert analysis from the CB Insights Intelligence Unit.
CB Insights Intelligence Analysts have mentioned Sonar in 5 CB Insights research briefs, most recently on Feb 20, 2024.
Expert Collections containing Sonar
Expert Collections are analyst-curated lists that highlight the companies you need to know in the most important technology spaces.
Sonar is included in 2 Expert Collections, including Unicorns- Billion Dollar Startups.
Unicorns- Billion Dollar Startups
1,257 items
Tech IPO Pipeline
257 items
The tech companies we think could hit the public markets next, according to CB Insights data.
Sonar Patents
Sonar has filed 32 patents.
The 3 most popular patent topics include:
- intercontinental ballistic missiles
- short-range ballistic missiles
- vehicle law

Application Date | Grant Date | Title | Related Topics | Status |
---|---|---|---|---|
10/27/2022 | 11/12/2024 | Grant |
Application Date | 10/27/2022 |
---|---|
Grant Date | 11/12/2024 |
Title | |
Related Topics | |
Status | Grant |
Latest Sonar News
Jan 3, 2025
Financing 03.01.2025 Geneva-based Sonar has signed a definitive agreement to acquire Tidelift, a provider of software supply chain security solutions that help organizations manage the risk of open source software. The acquisition will extend Sonar’s scope of coverage to include open source libraries, in addition to code written by developers and AI. With more than 90% of software built using open source components, evaluating open source risks is critical to the sustainability and security of organizations’ applications. Tidelift helps improve the health and security of open source by paying the maintainers behind thousands of the world’s most-relied-upon open source projects to follow industry-leading secure software development practices. Paid open source maintainers are 55% more likely to implement critical security and maintenance practices than unpaid maintainers. Sonar analyzes all code, regardless of who writes it—an internal team or genAI—resulting in more secure, reliable, and maintainable software. Rooted in the open source community, Sonar’s solutions support over 30 programming languages, frameworks, and infrastructure technologies. Today, Sonar is used by 7M+ developers and 400K organizations worldwide, including Microsoft, NASA, MasterCard, Siemens, and T-Mobile “Tidelift and Sonar are naturally aligned through a common vision – improve code everywhere and supercharge the developer experience. We have been impressed with Tidelift’s approach to improving open source software and look forward to welcoming the team to Sonar,” said Tariq Shaukat, CEO of Sonar. “Tidelift provides insight into many factors that could adversely impact applications relying on open source, so that developers can remediate issues proactively at the point they are introduced.” Established in 2017, Tidelift customers include a broad range of enterprise technology, federal, and financial institutions, like Cisco, Fannie Mae, and the U.S. Air Force. The Tidelift offering will continue to be available – there are no immediate planned changes to the current Tidelift product. Tidelift customers and maintainer partners will not experience any disruption to their current experiences. (Press release / SK)
Sonar Frequently Asked Questions (FAQ)
When was Sonar founded?
Sonar was founded in 2008.
Where is Sonar's headquarters?
Sonar's headquarters is located at Route de Pre-Bois 1, Vernier.
What is Sonar's latest funding round?
Sonar's latest funding round is Unattributed VC.
How much did Sonar raise?
Sonar raised a total of $457M.
Who are the investors of Sonar?
Investors of Sonar include Insight Partners, Advent International, General Catalyst and Permira.
Who are Sonar's competitors?
Competitors of Sonar include Aikido, Codescene, Mend, Codacy, Code Intelligence and 7 more.
Loading...
Compare Sonar to Competitors

Checkmarx provides a platform for securing application development from code to cloud across various sectors. The company's offerings include static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and tools for API security, container security, infrastructure as code security, and malicious package protection. Checkmarx serves a range of industries, with an aim to integrate security within the software development lifecycle. It was founded in 2006 and is based in Paramus, New Jersey.

Snyk focuses on developer security within the technology industry. The company offers services that help developers build secure applications and allow security teams to meet the demands of the digital world. Its services include finding and fixing vulnerabilities in code, dependencies, containers, and infrastructure as code. It was founded in 2015 and is based in Boston, Massachusetts.

Semgrep operates in the technology sector. The company offers a tool that helps find and fix bugs and reachable dependency vulnerabilities in code and enforces code standards. It primarily serves the software development and cybersecurity sectors. Semgrep was formerly known as r2c. It was founded in 2017 and is based in San Francisco, California.

Mend.io focuses on application security. It provides tools to manage application risk across various domains. Its main offerings include automated dependency updates, open source security management, proprietary code security, and risk analysis for AI models. Mend.io serves sectors that require application security measures, such as software development and IT security. Mend was formerly known as WhiteSource. It was founded in 2011 and is based in Givatayim, Israel.
Beanstalk is a software company that provides a complete workflow for code hosting, review, and deployment. It offers services that allow teams to write code, manage code reviews, and deploy code to various environments without the need for additional client software. Beanstalk's solutions cater to organizations of any size, aiming to streamline the development process. It is based in Philadelphia, Pennsylvania.

Cycode specializes in application security posture management (ASPM) within the cybersecurity industry. The company offers a comprehensive platform that integrates with or replaces existing application security testing tools, providing visibility, risk-driven prioritization, and just-in-time remediation of code vulnerabilities at scale. Cycode primarily serves sectors that require robust application security solutions, such as the finance, software, retail, banking, and telecommunications industries. It was founded in 2019 and is based in Tel Aviv, Israel.
Loading...