Perimattic Managed SonarQube - Code Quality Platform on AWS
Perimattic ManageStacks · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
This fully managed SonarQube solution delivers a production-ready code quality and security analysis platform on AWS, built on Ubuntu 24.04 LTS. Every instance is pre-configured with security best practices, optimized settings, and automated operations.
Key Features
Show the rest of the publisher’s description (22 more lines)
Complete Code Quality Platform
SonarQube pre-configured with quality profiles for 30+ programming languages. Detect bugs, code smells, security vulnerabilities, and technical debt across your codebase.
Automated Setup
On first login, an interactive setup script configures SonarQube, sets up the database, and applies firewall rules - all within minutes.
Security Hardened
UFW firewall pre-configured, HTTPS-ready, authentication enabled by default, and latest security patches applied.
CI/CD Integration Ready
Integrate with Jenkins, GitLab CI, GitHub Actions, Azure DevOps, and Bitbucket Pipelines. Enforce quality gates before merging code.
Use Cases
Continuous code quality inspection in CI/CD pipelines
Security vulnerability detection (OWASP Top 10, CWE)
Technical debt tracking and reduction
Code review automation and quality gate enforcement
Compliance-driven code analysis (MISRA, CERT)
Multi-project portfolio quality management
Getting Started
Launch the AMI from AWS Marketplace on your preferred instance type
SSH into your instance and follow the interactive setup wizard
Integrate SonarQube with your CI/CD pipeline and start analyzing code
Book a free setup consultation at https://cal.com/gaurav-pareek-perimattic/marketplace-setup-consultations or email us at aws-support@perimattic.com.
Support
Managed and supported by Perimattic, a cloud infrastructure company with 13+ years of experience serving global clients. We offer free setup assistance, custom integrations, infrastructure consulting, and 24/7 support.
Highlights
Highlighted by the publisher on AWS Marketplace.
Self-Hosted Code Quality Platform: Full root access to configure quality profiles, security rules, and plugins for 30+ languages without per-user pricing or data residency concerns.
CI/CD Integration Ready: Pre-configured for Jenkins, GitLab CI, GitHub Actions, and Azure DevOps. Enforce quality gates and catch vulnerabilities before merging code.
24/7 Expert Support by Perimattic: 13+ years of cloud infrastructure expertise with free setup assistance, pipeline integration, and dedicated support at aws-support@perimattic.com.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Plans and pricing as listed
8 listed- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
Refund terms
As stated by the publisher on AWS Marketplace.
For any questions or concerns, please contact: Perimattic.com Email: aws-support@perimattic.com
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

