# Security You Can Trust

Trust is foundational to the success of our business. Trust = Transparency + Accountability. We strive for transparency through clear communication across functions and levels. We hold ourselves accountable for the promise we make to our employees, investors, and customers.

To earn your trust, we share our security and compliance programs with you. We continuously evolve with the ever-changing world around us to safely manage the confidentiality, integrity, and availability of not only Sonatype's but also the customers' data and services that we manage.

[Security at Sonatype](/content/security-at-sonatype/index.html)

[Bug Bounty Program](/content/report-a-security-vulnerability/index.html)

[Security Advisories](https://support.sonatype.com/hc/en-us/sections/203012668-Security-Advisories)

[security@sonatype.com](mailto:security@sonatype.com)

[Privacy Policy](/content/privacy-policy/index.html)

[AWS Marketplace listing](https://aws.amazon.com/marketplace/seller-profile?id=718e316c-3329-4c1c-9404-f76e71a58347)

## FAQ

### General

### Does Sonatype operate a Bug Bounty Program?

**Yes.** Sonatype operates a bug bounty program for responsibly reporting security vulnerabilities. Program details, scope, and submission instructions are available at: [Bug Bounty Program](/content/report-a-security-vulnerability/index.html)

### Does Sonatype conduct regular penetration testing?

**Yes.** Sonatype conducts penetration testing at least annually, covering our products and supporting infrastructure. Findings are reviewed by our Security team and tracked through remediation to resolution.
