FossID
- Company typePrivate
- Founded2016
- HeadquartersStockholm, Sweden
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
FossID firmographics
Firmographics- Name
- FossID
- Legal name
- FossID AB
- Website
- https://fossid.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
FossID industry classification
Industry- Product category
- Software Composition Analysis
- NAICS
- Software Publishers (5132), Software Publishers (513210), Software Publishers (51321)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- App Security, Compliance & Review Automation Platforms (BPAMADAJ)
Keywords
Where FossID is headquartered
LocationHeadquarters
- HQ city
- Stockholm
- HQ country
- Sweden
- HQ region
- Europe
Offices1 record
Markets served
FossID business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SCA Software Licenses: FossID Workbench SCA application licensing for enterprise software composition analysis. Subscription-based licensing model for the SCA toolset with different deployment options including cloud, hybrid, and offline deployment.
- Professional Services: Expert-led services including Open Source Risk Audits, Technical Due Diligence, SAST Code Review, Code Quality Audits, Third-Party API Risk Audits, Application Penetration Testing, and Baselining services. Includes Virtual Open Source Auditor staffing model.
- Custom Volumes Add-on: Premium add-on capability for FossID SCA tooling that enables custom knowledge base volumes for detecting proprietary and commercial components.
Go-to-market motion3 records
Distribution channels4 records
Marketing channels7 records
FossID product offering
Product offeringCore offering
FossID develops and sells a Software Composition Analysis (SCA) platform that uses signature-based fuzzy hashing to identify open source, commercial, and proprietary code at the snippet level. The platform is backed by a proprietary knowledge base of over 3 petabytes of software components and is complemented by expert-led professional services covering open source risk audits, technical due diligence, SAST code review, and baselining for enterprise software teams.
Product overview
FossID provides software risk management solutions through a unified SCA platform centered on FossID Workbench and FossID Toolbox, complemented by specialized modules including Agentic SCA for AI-era compliance, Vulnerable Snippet Finder for precise vulnerability detection, Dependency Analysis for package manager scanning, and Custom Volumes for proprietary component detection. The platform also includes FossID Workflows for enterprise SBOM lifecycle management. FossID's scanning technology uses fuzzy hashing against a knowledge base covering over 3 petabytes of software components to detect open source, commercial, and AI-generated code at the snippet level. The offering spans both tooling products and professional services including Open Source Risk Audits, Technical Due Diligence, SAST Code Review, Baselining, and Virtual Open Source Auditor services.
Differentiator
Problem solved
Functional benefit
Products and services
- FossID Workbench
- FossID Toolbox
- Vulnerable Snippet Finder
- FossID Dependency Analysis
- Custom Volumes
- Open Source Risk Audit
- Open Source Insights
- SAST Code Review
- Code Quality Audit
- Third-Party API Risk Audit
- Application Penetration Testing
- Tech Due Diligence
- Baselining
- Virtual Open Source Auditor
Quantifiable outcome
- Elastic reduced open source audit time from months to same-day real-time scanning with narrowed results
- +2 more outcomes
Companies that use FossID
Customer profileNamed customers18 records
Segments4 records
Ideal customer profiles4 records
FossID technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability5 records
Feature7 records
FossID partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered strategic and core.
- BearingPointstrategicStrategic Open Source Software Governance Partnership. BearingPoint provides modular FOSS services including streamlined processes for software lifecycle management and comprehensive compliance and security reports. FOSSID technology provides high performance and accuracy in code analysis services. After successfully cooperating in selected projects for over two years, BearingPoint selected FOSSID as its strategic provider of open source analysis tools. Donald Wachs, Head of BearingPoint Business Services, stated the partnership enables more value delivery with higher speed and better accuracy.
- Linux FoundationcoreSilver member of the Linux Foundation, demonstrating commitment to the open source ecosystem and community. Supports open source compliance programs and initiatives.
Scale indicators3 records
Recent moves7 records
Expansion highlights6 records
FossID competitors and assessment
Company assessmentDirect peers
- Snyk: Snyk is a leading developer security platform with a directly competing Software Composition Analysis (Snyk Open Source) product, and was FossID's parent company from 2021–2022 before a founder buyout — making it both the closest direct competitor and a current minority shareholder.
- Mend (formerly WhiteSource): Mend provides Software Composition Analysis focused on open source license compliance and vulnerability management, serving enterprise customers in regulated industries — a near-direct competitor with overlapping customer segments and feature parity in SBOM, license, and vulnerability workflows.
- Sonatype: Sonatype is a long-standing leader in SCA and software supply chain security, with Nexus Lifecycle as its enterprise flagship — competing head-to-head with FossID in license compliance, SBOM generation, and vulnerability detection for large enterprises.
- FOSSA: FOSSA is a Software Composition Analysis and license compliance platform targeting enterprise engineering teams, with overlapping capabilities in dependency scanning, SBOM generation, and vulnerability management — directly comparable to FossID's Workbench offering.
Broad incumbents
- Synopsys (Black Duck): Synopsys Black Duck is one of the most established SCA platforms globally, offering open source license compliance and vulnerability detection to large enterprises — directly overlapping with FossID's core use cases while operating as part of a much broader Synopsys software integrity portfolio.
- JFrog: JFrog's Artifactory and Xray products offer software composition analysis as part of a broader DevOps / artifact management platform, making JFrog a direct competitor in SCA while competing in adjacent categories like binary security and software supply chain integrity.
- GitHub Advanced Security: GitHub Advanced Security (Dependabot, Code Scanning, secret scanning) is bundled into GitHub Enterprise and offers SCA-style dependency and vulnerability analysis — a broad incumbent that competes with FossID for developer mindshare and budget inside organizations already standardized on the GitHub platform.
Emerging players
- ScanOSS: ScanOSS offers snippet-level open source detection similar to FossID, using fingerprinting techniques to identify copy-pasted and modified code — a closely comparable emerging competitor in the precise code-detection niche where FossID differentiates.
- ReversingLabs: ReversingLabs provides software supply chain security including binary analysis and SBOM-focused compliance — competing with FossID in the broader software supply chain integrity space, particularly for customers needing binary-level visibility.
- Anchore: Anchore offers SBOM generation, container security, and software composition analysis focused on DevSecOps workflows — overlapping with FossID's SBOM and compliance use cases, particularly for regulated industries adopting container and cloud-native architectures.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
FossID social profiles
Digital presenceFossID compliance and trust
Trust signalCompliance4 records
FossID financial estimates
Financial estimateRevenue estimate
Valuation estimate
FossID leadership team
Management profileNumber of profiles
Profiles6 records
FossID subsidiaries and ownership
Company hierarchySubsidiaries1 record
FossID funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
FossID M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about FossID
What does FossID do?
FossID develops and sells a Software Composition Analysis (SCA) platform that uses signature-based fuzzy hashing to identify open source, commercial, and proprietary code at the snippet level. The platform is backed by a proprietary knowledge base of over 3 petabytes of software components and is complemented by expert-led professional services covering open source risk audits, technical due diligence, SAST code review, and baselining for enterprise software teams.
Is FossID a public or private company?
FossID is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was FossID founded?
FossID was founded in 2016. It employs 11 to 50 people.
Where is FossID based?
FossID is headquartered in Stockholm, Sweden, in the Europe region.
How does FossID make money?
Three revenue lines are on record. SCA Software Licenses are the primary driver. The others are professional Services and custom Volumes Add-on.
Who are FossID's main competitors?
Direct peers on record are Snyk, Mend (formerly WhiteSource), Sonatype and FOSSA. Broad incumbents are Synopsys (Black Duck), JFrog and GitHub Advanced Security. Emerging players are ScanOSS, ReversingLabs and Anchore.
Does FossID have an API?
No public API is recorded for FossID.
What industry is FossID in?
FossID's product category is Software Composition Analysis. Its primary akta.pro industry code is BPAMADAJ, App Security, Compliance & Review Automation Platforms. Its NAICS code is 5132 and its SIC code is 7372.