FOSSA
FOSSA provides a software supply chain management platform that automates open source license compliance, vulnerability detection, and SBOM management for enterprise engineering and security teams, now extending into AI-driven autonomous dependency remediation via its fossabot agent.
- Company typePrivate
- Founded2015
- HeadquartersSan Francisco, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What FOSSA does
FOSSA is a software supply chain management platform that helps engineering and security teams automate open source license compliance, security vulnerability detection, and Software Bill of Materials (SBOM) generation across third-party code dependencies. The platform is built around a core scanning engine (FOSSA Scan) that ingests packages, containers, SBOMs, binaries, and code snippets, with specialized modules including Binary Composition Analysis for firmware and compiled artifacts, FOSSA Snippets for detecting undisclosed and AI-generated code, and SBOM Management supporting CycloneDX and SPDX formats. Most recently, the company has pivoted toward autonomous remediation through fossabot, an AI agent (powered by Anthropic LLMs combined with static analysis acquired via EdgeBit) that researches dependency versions, detects breaking changes, adapts code, and commits fixes.
FOSSA serves enterprise organizations, growing development teams, and individual developers through a three-tier SaaS model: a free tier with PLG onboarding, a Business tier at $20/project/month billed annually, and a custom-priced Enterprise tier with SSO, RBAC, on-premises deployment, and advanced compliance reporting. Named enterprise customers span UiPath, Collibra, Confluent, Cloudera, Digicert, Sentry, Applause, Lattice, Omnissa, SmartThings, and the US Navy, indicating broad vertical penetration rather than concentration. The company distributes through direct sales, a partner network of resellers and SIs (Hitachi, Thundercat, SAIC, GlobalDots), and developer channels including a GitHub App marketplace listing for fossabot. FOSSA holds SOC 2 Type 2 certification and supports regulatory regimes including FDA, CRA, and PCI DSS.
The company has raised approximately $43.5M across seed (2017, $2.2M, Bain Capital Ventures), Series A (2019, $8.5M), Series B (2020, $23.2M, Bain Capital Ventures / Canvas Prime / Costanoa Ventures), and subsequent exempt offerings (2023, 2025). It has executed three acquisitions — Dawn Labs (2019), StackShare (Aug 2024, 1.5M-user developer community), and EdgeBit (Sep 2025, static-analysis technology) — and has built flagship technology partnerships with New Relic's Secure Developer Alliance (May 2024) and SCANOSS (Feb 2026, AI coding risk). Aaron Williams serves as CEO, with co-founder Kevin Wang as founder & chairman and EdgeBit founder Rob Szumski as Head of R&D.
FOSSA firmographics
Firmographics- Name
- FOSSA
- Legal name
- FOSSA, Inc.
- Website
- https://fossa.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- FOSSA provides a software supply chain management platform that automates open source license compliance, vulnerability detection, and SBOM management for enterprise engineering and security teams, now extending into AI-driven autonomous dependency remediation via its fossabot agent.
- Ownership category
- akta.pro rank
FOSSA industry classification
Industry- Product category
- Software Composition Analysis / Software Supply Chain Security
- NAICS
- Custom Computer Programming Services (541511), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI)
Keywords
Where FOSSA is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
FOSSA business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Subscription SaaS (Free Tier): Free tier providing basic scanning capabilities for individuals and small teams to get started with open source management. Limited to 5 projects, 10 contributing developers, and 1 release group.
- Subscription SaaS (Business Tier): Per-project subscription at $20/project/month billed annually, providing unlimited dependency scanning levels, automated license and vulnerability scanning, multi-project reporting, and priority support.
- Subscription SaaS (Enterprise Tier): Custom enterprise pricing with unlimited projects, custom developer counts, advanced compliance reporting, SSO, RBAC, custom deployment options (SaaS, private cloud, on-premises), and enterprise-grade SLAs.
- Add-on Products: Additional revenue from add-on products including Snippet Scanning Add-On and Binary Scanning Add-On for advanced AI coding risk management and binary analysis capabilities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free tier for individuals and small teams getting started |
| Subscription | Annual | Business tier for growing teams needing advanced compliance and security |
| Subscription | Multi-year contract | Enterprise tier for organizations needing custom deployment and enterprise features |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels8 records
FOSSA product offering
Product offeringCore offering
FOSSA provides a unified software supply chain management platform that automatically scans codebases, containers, SBOMs, binaries, and code snippets to identify open source dependencies, detect license compliance issues and security vulnerabilities, and generate Software Bills of Materials. The platform supports all major programming languages, integrates with CI/CD pipelines (GitHub, GitLab, Jenkins, etc.), and is complemented by fossabot, an AI agent that autonomously performs strategic dependency updates with breaking change detection and code adaptation.
Product overview
FOSSA is a unified software supply chain management platform comprising a core platform with integrated modules and solutions. The core FOSSA Core Platform provides automated license compliance, security scanning, and SBOM management. Key products include: FOSSA Scan (core scanning engine for packages, containers, SBOMs, binaries, and snippets), fossabot (AI agent for autonomous dependency updates), Binary Composition Analysis (add-on for compiled artifact scanning), and FOSSA Snippets (add-on for detecting AI-generated and copied code). Solutions layer on top including OSS License Compliance, Code Security (SCA/BCA), SBOM Management, AI Coding Guardrails, Due Diligence, Supplier Risk Management, and Obsolescence Management. The platform supports all major programming languages and integrates with enterprise CI/CD, identity, and collaboration tools.
Differentiator
Problem solved
Functional benefit
Brands
- fossabot: AI Agent for making strategic dependency updates, powered by static analysis and large language models to automatically detect, analyze, and fix dependency update issues in codebases.
- Binary Composition Analysis
- FOSSA Snippets
Products and services
- FOSSA Scan Core scanning engine that analyzes dependencies across the entire software development lifecycle, including packages, containers, SBOMs, binaries, and code snippets. Targeted at engineering and security teams needing full-spectrum dependency visibility.
- fossabot AI-powered autonomous agent for strategic dependency updates that analyzes breaking changes, detects code impact, and automatically fixes or adapts application code. Works alongside or independently from Dependabot, Renovate, and Snyk.
- Binary Composition Analysis Advanced binary scanning technology that decomposes and analyzes compiled artifacts, firmware, and containers to identify embedded open source components, detect vulnerabilities, and generate comprehensive SBOMs.
- FOSSA Snippets Advanced code snippet detection and management product that identifies undisclosed open source, copied snippets, and AI-generated code that could pose legal or security risks, with function-level matching and license compliance tracking.
Quantifiable outcome
- Organizations using fossabot merge dependency updates over 50% faster
- +3 more outcomes
Companies that use FOSSA
Customer profileNamed customers12 records
Segments4 records
Ideal customer profiles4 records
FOSSA technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration22 records
AI capability5 records
Feature5 records
FOSSA partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core, flagship and minor.
- SCANOSScoreTechnology partnership to enhance AI coding risk management capabilities. Combines SCANOSS's open source risk intelligence platform and snippet detection with FOSSA's license compliance workflows to address copyright and license violations in AI-generated code. Nearly 40% of code in Copilot-enabled files is AI-generated, creating new compliance challenges.
- New RelicflagshipFOSSA joined New Relic's Secure Developer Alliance (SDA) as a founding partner alongside Gigamon, Lacework, Aviatrix, and Opus. The partnership focuses on education, best practices for DevSecOps, and technology integrations to help organizations efficiently prioritize and remediate vulnerabilities.
- npmcoreEarly partnership to deliver open source license compliance through npm Enterprise add-on. FOSSA's Licenses add-on proactively assessed public and proprietary packages in npmE registries to identify licensing issues, with real-time notifications and integration with GitHub and JIRA.
- ALM ToolboxminorPartner in FOSSA's partner network offering reselling and distribution of FOSSA solutions.
- ArctiqminorPartner in FOSSA's partner network offering reselling and distribution of FOSSA solutions.
- GlobalDotsminorPartner in FOSSA's partner network offering reselling and distribution of FOSSA solutions.
- HitachiminorPartner in FOSSA's partner network offering reselling and distribution of FOSSA solutions.
- TechnologentminorPartner in FOSSA's partner network offering reselling and distribution of FOSSA solutions.
- TevoraminorPartner in FOSSA's partner network offering reselling and distribution of FOSSA solutions.
- ThundercatminorPartner in FOSSA's partner network offering reselling and distribution of FOSSA solutions.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
FOSSA competitors and assessment
Company assessmentDirect peers
- Snyk: Direct competitor in developer-first SCA, SBOM, and code security. Snyk's Open Source and SBOM products overlap almost 1:1 with FOSSA Core, and Snyk's reach into CI/CD and IDE workflows makes it the most comparable direct peer for both PLG and enterprise sales motions.
- Sonatype: Pioneer of SCA and creator of the Nexus repository, Sonatype competes head-to-head with FOSSA on dependency scanning, license compliance, and SBOM. Strong overlap in enterprise procurement use cases and integration with artifact repositories like Nexus and Artifactory.
- Mend (formerly WhiteSource): Direct SCA and license compliance competitor targeting enterprise AppSec buyers. Overlaps with FOSSA on open source license detection, vulnerability prioritization, and SBOM generation, and is often benchmarked alongside FOSSA in SCA market evaluations.
- JFrog: JFrog Xray provides binary and dependency scanning tightly integrated with Artifactory — a key FOSSA integration partner. Direct overlap on binary composition analysis, SBOM, and supply-chain security for enterprises standardizing on JFrog repositories.
Broad incumbents
- GitHub Advanced Security / Dependabot: GitHub ships Dependabot and Advanced Security natively to its vast developer base, providing "good enough" dependency scanning and SBOM that competes on convenience with standalone SCA tools like FOSSA, especially for organizations already deep in the GitHub ecosystem.
- Synopsys (Black Duck): Synopsys Black Duck is an established enterprise SCA platform with deep coverage of license compliance, security, and SBOM. As part of Synopsys's broader software integrity portfolio, it competes with FOSSA in large enterprise AppSec procurements.
- Veracode: Enterprise application security platform whose software composition analysis module overlaps with FOSSA on open source dependency and license risk. Veracode is typically evaluated in the same enterprise AppSec RFPs as FOSSA.
Emerging players
- Anchore: Emerging player focused on container and SBOM-centric software supply chain security. Anchore's container scanning and SBOM tooling overlaps with FOSSA's container and SBOM capabilities, particularly for security and compliance teams standardizing on CycloneDX/SPDX.
- Cycode: Application security posture management (ASPM) and software supply chain security vendor that competes with parts of FOSSA's vulnerability management and pipeline security story. Comparable as an emerging challenger consolidating AppSec use cases.
- Endor Labs: Software supply chain security startup focused on dependency selection, SCA, and reaching production-grade open source. Targets similar developer-led enterprise buyers as FOSSA and is often listed alongside FOSSA in SCA-adjacent market maps.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
FOSSA social profiles
Digital presenceFOSSA compliance and trust
Trust signalCompliance1 record
FOSSA financial estimates
Financial estimateRevenue estimate
Valuation estimate
FOSSA leadership team
Management profileNumber of profiles
Profiles7 records
FOSSA subsidiaries and ownership
Company hierarchySubsidiaries3 records
FOSSA funding detail
Funding detailFunding overview
Funding rounds6 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
FOSSA M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about FOSSA
What does FOSSA do?
FOSSA provides a unified software supply chain management platform that automatically scans codebases, containers, SBOMs, binaries, and code snippets to identify open source dependencies, detect license compliance issues and security vulnerabilities, and generate Software Bills of Materials. The platform supports all major programming languages, integrates with CI/CD pipelines (GitHub, GitLab, Jenkins, etc.), and is complemented by fossabot, an AI agent that autonomously performs strategic dependency updates with breaking change detection and code adaptation.
Is FOSSA a public or private company?
FOSSA is a private company. It is classified as venture growth investor backed and is currently operating.
When was FOSSA founded?
FOSSA was founded in 2015. It employs 51 to 100 people.
Where is FOSSA based?
FOSSA is headquartered in San Francisco, United States, in the North America region.
How does FOSSA make money?
Four revenue lines are on record. Subscription SaaS (Free Tier) is the primary driver. The others are subscription SaaS (Business Tier), subscription SaaS (Enterprise Tier) and add-on Products.
Who are FOSSA's main competitors?
Direct peers on record are Snyk, Sonatype, Mend (formerly WhiteSource) and JFrog. Broad incumbents are GitHub Advanced Security / Dependabot, Synopsys (Black Duck) and Veracode. Emerging players are Anchore, Cycode and Endor Labs.
Does FOSSA have an API?
Yes. FOSSA provides a public API for integration and automation purposes. The API supports authentication, project management, dependency analysis, license compliance data, vulnerability reporting, SBOM generation, and attribution report generation. API endpoints include Issues API for configuration, and support for creating Jira tickets, downloading attribution reports, and managing release groups. Rate limits and versioning information available in API documentation. Developer documentation is at docs.fossa.com/docs/api-documentation.
What industry is FOSSA in?
FOSSA's product category is Software Composition Analysis / Software Supply Chain Security. Its primary akta.pro industry code is BPAEAKAI, DevSecOps & Supply Chain Security (DevOps toolchain security). Its NAICS code is 541511 and its SIC code is 7372.