Trust Center - sonatype
Security You Can Trust
Trust is foundational to the success of our business. Trust = Transparency + Accountability. We strive for transparency through clear communication across functions and levels. We hold ourselves accountable for the promise we make to our employees, investors, and customers.
To earn your trust, we share our security and compliance programs with you. We continuously evolve with the ever-changing world around us to safely manage the confidentiality, integrity, and availability of not only Sonatype's but also the customers' data and services that we manage.
FAQ
General
Does Sonatype operate a Bug Bounty Program?
Yes. Sonatype operates a bug bounty program for responsibly reporting security vulnerabilities. Program details, scope, and submission instructions are available at: Bug Bounty Program
Does Sonatype conduct regular penetration testing?
Yes. Sonatype conducts penetration testing at least annually, covering our products and supporting infrastructure. Findings are reviewed by our Security team and tracked through remediation to resolution.