Trust Center - sonatype

Security You Can Trust

Trust is foundational to the success of our business. Trust = Transparency + Accountability. We strive for transparency through clear communication across functions and levels. We hold ourselves accountable for the promise we make to our employees, investors, and customers.

To earn your trust, we share our security and compliance programs with you. We continuously evolve with the ever-changing world around us to safely manage the confidentiality, integrity, and availability of not only Sonatype's but also the customers' data and services that we manage.

Compliance

SOC 2
ISO 27001:2022
NIST CSF 2.0

Resources

Security Compliance & Assurance

ISO 27001 2022 Certificate

SOC 2 Type II Report

DHS CISA Secure Software Attestation

Sonatype SOC 2 Bridge Letter

Security Policies

Acceptable Use Policy

Business Continuity and Disaster Recovery Policy

Change Management Policy

AI Acceptable Use Policy

Independent Security Assessment

Maven Central

Sonatype Nexus Repository

Sonatype Lifecycle & Firewall (EU)

Sonatype Lifecycle (Private Cloud)

Other resources

Information Security Management Program Auditing Policy

Sonatype Statement of Applicability ISO 27001:2022

Controls

Updated 4 minutes ago

Infrastructure security

Organizational security

Product security

Internal security procedures

Data and privacy

FAQ

Does Sonatype operate a Bug Bounty Program?

Media

Software Supply Chain Management is Sonatype - YouTube

Software Supply Chain Management is Sonatype
Sonatype has been researching, studying and pioneering software supply chains for almost 15 years. And our deep investment in this field has allowed us to experience and understand the many trends that have shaped its direction. Software supply chain management has been a lot of things including difficult and time-consuming, but it's also freeing, collaborative and trust instilling.