# Security You Can Trust

Trust is foundational to the success of our business. Trust = Transparency + Accountability. We strive for transparency through clear communication across functions and levels. We hold ourselves accountable for the promise we make to our employees, investors, and customers.

To earn your trust, we share our security and compliance programs with you. We continuously evolve with the ever-changing world around us to safely manage the confidentiality, integrity, and availability of not only Sonatype's but also the customers' data and services that we manage.

## Compliance

SOC 2  
ISO 27001:2022  
NIST CSF 2.0

## Resources

### Security Compliance & Assurance

ISO 27001 2022 Certificate

[SOC 2 Type II Report](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=697a6389b47975238eb1260d)

[DHS CISA Secure Software Attestation](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=697a6389a4a71ffef4cec2f6)

[Sonatype SOC 2 Bridge Letter](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=697bad3e5d3ba23940b2d867)

### Security Policies

[Acceptable Use Policy](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=696f97f95e4463e7d0bbed06)

[Business Continuity and Disaster Recovery Policy](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=696f97f95e4463e7d0bbed21)

[Change Management Policy](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=696f97f95e4463e7d0bbed2e)

[AI Acceptable Use Policy](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=696f97f95e4463e7d0bbed14)

### Independent Security Assessment

[Maven Central](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=6978c2d2e21897e2a24b369b)

[Sonatype Nexus Repository](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=6978c2d26b1846dc5c0eac47)

[Sonatype Lifecycle & Firewall (EU)](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=6978c2d2a7a9d06bee3ead50)

[Sonatype Lifecycle (Private Cloud)](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=6978c2d376ca1af3efe53925)

### Other resources

[Information Security Management Program Auditing Policy](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=696f97f95e4463e7d0bbed62)

[Sonatype Statement of Applicability ISO 27001:2022](https://trust.sonatype.com/?requestAccessOpen=true&requestedResources=69a5ffbd0a64a28f3bb98c66)

## Controls

Updated 4 minutes ago

[**Infrastructure security**](https://trust.sonatype.com/controls#infrastructure-security)
- Remote access encrypted enforced

[**Organizational security**](https://trust.sonatype.com/controls#organizational-security)
- Code of Conduct acknowledged by employees and enforced

[**Product security**](https://trust.sonatype.com/controls#product-security)
- Control self-assessments conducted
- Vulnerability and system monitoring procedures established
- Penetration testing performed

[**Internal security procedures**](https://trust.sonatype.com/controls#internal-security-procedures)
- Continuity and Disaster Recovery plans established
- Development lifecycle established
- Management roles and responsibilities defined

[**Data and privacy**](https://trust.sonatype.com/controls#data-and-privacy)
- Data retention procedures established
- Data classification policy established

## FAQ

### Does Sonatype operate a Bug Bounty Program?

## Media

Software Supply Chain Management is Sonatype - YouTube

[Software Supply Chain Management is Sonatype](https://www.youtube.com/watch?v=BBarnJOoDuo)  
Sonatype has been researching, studying and pioneering software supply chains for almost 15 years. And our deep investment in this field has allowed us to experience and understand the many trends that have shaped its direction. Software supply chain management has been a lot of things including difficult and time-consuming, but it's also freeing, collaborative and trust instilling.
