Trust Center - sonatype

Security You Can Trust

Trust is foundational to the success of our business. Trust = Transparency + Accountability. We strive for transparency through clear communication across functions and levels. We hold ourselves accountable for the promise we make to our employees, investors, and customers.

To earn your trust, we share our security and compliance programs with you. We continuously evolve with the ever-changing world around us to safely manage the confidentiality, integrity, and availability of not only Sonatype's but also the customers' data and services that we manage.

Security at Sonatype

Bug Bounty Program

Security Advisories

security@sonatype.com

Privacy Policy

AWS Marketplace listing

FAQ

General

Does Sonatype operate a Bug Bounty Program?

Yes. Sonatype operates a bug bounty program for responsibly reporting security vulnerabilities. Program details, scope, and submission instructions are available at: Bug Bounty Program

Does Sonatype conduct regular penetration testing?

Yes. Sonatype conducts penetration testing at least annually, covering our products and supporting infrastructure. Findings are reviewed by our Security team and tracked through remediation to resolution.