Trust Center - sonatype

Security You Can Trust

Trust is foundational to the success of our business. Trust = Transparency + Accountability. We strive for transparency through clear communication across functions and levels. We hold ourselves accountable for the promise we make to our employees, investors, and customers.

To earn your trust, we share our security and compliance programs with you. We continuously evolve with the ever-changing world around us to safely manage the confidentiality, integrity, and availability of not only Sonatype's but also the customers' data and services that we manage.

Controls

Infrastructure security

Control Status
Remote access encrypted enforced
The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection.

Organizational security

Control Status
Code of Conduct acknowledged by employees and enforced
The company requires employees to acknowledge a code of conduct at the time of hire. Employees who violate the code of conduct are subject to disciplinary actions in accordance with a disciplinary policy.

Product security

Control Status
Control self-assessments conducted
The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA.
Vulnerability and system monitoring procedures established
The company's formal policies outline the requirements for the following functions related to IT / Engineering:
- vulnerability management;
- system monitoring.
Penetration testing performed
The company's penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs.

Internal security procedures

Control Status
Continuity and Disaster Recovery plans established
The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel.
Development lifecycle established
The company has a formal systems development life cycle (SDLC) methodology in place that governs the development, acquisition, implementation, changes (including emergency changes), and maintenance of information systems and related technology requirements.
Management roles and responsibilities defined
The company management has established defined roles and responsibilities to oversee the design and implementation of information security controls.
Organization structure documented
The company maintains an organizational chart that describes the organizational structure and reporting lines.
Roles and responsibilities specified
Roles and responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally assigned in job descriptions and/or the Roles and Responsibilities policy.
Security policies established and reviewed
The company's information security policies and procedures are documented and reviewed at least annually.
System changes communicated
The company communicates system changes to authorized internal users.
Access requests required
The company ensures that user access to in-scope system components is based on job role and function or requires a documented access request form and manager approval prior to access being provisioned.
Incident response policies established
The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users.
Company commitments externally communicated
The company's security commitments are communicated to customers in Master Service Agreements (MSA) or Terms of Service (TOS).

Data and privacy

Control Status
Data retention procedures established
The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data.
Data classification policy established
The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel.