SCANOSS
- Company typePrivate
- Founded2018
- HeadquartersMadrid, Spain
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
SCANOSS firmographics
Firmographics- Name
- SCANOSS
- Legal name
- SCAN OPEN SOURCE SOLUTIONS, S.L.
- Website
- https://scanoss.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
SCANOSS industry classification
Industry- Product category
- Software Composition Analysis (Software Supply Chain Security)
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industries
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC), Vulnerability Assessment & Scanning (HDADAHAA)
Keywords
Where SCANOSS is headquartered
LocationHeadquarters
- HQ city
- Madrid
- HQ country
- Spain
- HQ region
- Europe
Offices1 record
Markets served
SCANOSS business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Subscription Licenses: Annual subscription model with tiered pricing (Small dev teams from €35K/yr, Medium dev teams from €53K/yr, Enterprise custom pricing). Includes guaranteed availability and throughput. Multi-year contracts and Enterprise License Agreements available for larger organisations with consolidated billing.
- Dedicated SaaS: Dedicated single-tenant SaaS deployment option alongside shared SaaS, providing guaranteed throughput and isolation for enterprise customers.
- On-Premises Deployment: On-premises deployment option alongside SaaS, for organisations with data sovereignty or air-gapped requirements. Pricing included within the subscription tiers.
- Open Source Tools: Core engine, CLI tools, and knowledge base datasets are open source (GPL-2.0, MIT, CC0 depending on component). Community contributions and integration support through GitHub. Commercial API keys required for Knowledge Base API access.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Small dev teams — from €35K/yr |
| Subscription | Multi-year contract | Medium dev teams — from €53K/yr |
| Subscription | Multi-year contract | Enterprise — custom pricing |
Go-to-market motion3 records
Distribution channels9 records
Marketing channels9 records
SCANOSS product offering
Product offeringCore offering
SCANOSS provides an open-source software risk intelligence platform that scans source code to detect declared and undeclared open source at the snippet level using a Winnowing-based fingerprinting algorithm, backed by a Knowledge Base indexing 334M+ URLs, 100B+ files, and 3T+ lines of code. The platform outputs SPDX Lite and CycloneDX SBOMs, generates Cryptography Bills of Materials (CBOMs) via its crypto-finder engine, and surfaces vulnerabilities, license obligations, and AI-generated code matches for enterprise engineering, security, and compliance teams. It is delivered as Shared SaaS, Dedicated SaaS, or On-Premises, with SDKs (Python/Java/JavaScript), GUI workbench, and CI/CD integrations.
Product overview
SCANOSS is an open-source software risk intelligence platform that analyzes source code to identify declared and undeclared open-source usage. The platform consists of a core Knowledge Base containing over 334 billion URLs indexed, multiple SDKs and CLI tools (SCANOSS-PY, SCANOSS-JS, SCANOSS-JAVA, SCANOSS-CC), and GUI/automation tools (SBOM Workbench, crypto-finder, GitHub Actions, Azure DevOps, Jenkins, SonarQube integrations). The product generates standards-based SBOMs (SPDX Lite, CycloneDX) and CBOMs (Cryptographic Bill of Materials), supporting multiple deployment options including Shared SaaS, Dedicated SaaS, and On-premise. Five specialized datasets power the platform: License Dataset, Encryption Dataset, Security Dataset, Geo Provenance Dataset, and AI Governance Dataset. Pricing starts at €35K/year for small dev teams and €53K/year for medium dev teams, with custom enterprise pricing available.
Differentiator
Problem solved
Functional benefit
Products and services
- SCANOSS Knowledge Base (OSS KB) Cloud-scale open source intelligence database indexing over 334 million URLs, 49 million PURLs, 4 billion unique files, and 100 billion lines of code from package registries, source forges, code hosts, and OS distribution mirrors. Powers snippet-level detection of open source components, licenses, vulnerabilities, and cryptographic algorithms for enterprise engineering and compliance teams.
- SCANOSS Engine Core scanning engine implemented in C with a Go-based REST API layer. Uses Winnowing-based fingerprinting optimised for detecting code fragments with up to 15x performance improvement, licensed under GPL-2.0.
- SCANOSS-PY Python CLI and SDK for scanning, fingerprinting, and interacting with SCANOSS APIs. Performs snippet-level open source detection and integrates into local developer workflows and scripted environments.
- SCANOSS-JS JavaScript/Node.js client library for interacting with SCANOSS APIs. Enables scanning, fingerprinting, and SBOM generation for JavaScript and Node.js codebases.
- SCANOSS-JAVA Java SDK for interacting with SCANOSS APIs, distributed via Maven and Gradle dependency management, enabling JVM-based application scanning and SBOM generation.
- SCANOSS-CC (Code Compare) Lightweight command-line tool for comparing source code against the SCANOSS Knowledge Base, enabling side-by-side visual inspection of matched code for granular compliance decisions.
- SBOM Workbench Desktop GUI tool for scanning and auditing source code, managing license obligations, and generating SBOMs in SPDX Lite, CycloneDX, JSON, and CSV formats.
- crypto-finder CLI tool for detecting cryptographic algorithms in source code using AST-aware semantic analysis beyond keyword matching. Generates Cryptography Bills of Materials (CBOM) in CycloneDX 1.6 format. Open source, GPL-2.0 licensed.
- gha-code-scan GitHub Action for embedding snippet-level SCANOSS detection directly into continuous integration pipelines. Enables automated compliance checks on every pull request or push.
- ado-code-scan Azure DevOps extension for SCANOSS scanning directly within Azure DevOps pipelines.
- scanoss-sonar-plugin SonarQube plugin for SonarQube 10.x that extends SonarQube analysis with SCANOSS license and vulnerability data.
- integration-jenkins Sample Jenkins integrations for SCANOSS tools, enabling SCANOSS scanning within CI pipelines.
- pre-commit-hooks Pre-commit hooks that automatically scan code for open source similarities before commits reach the repository, providing detection at the earliest point in the development workflow.
- License Dataset Dataset mapping every file in the Knowledge Base to declared and detected licenses, with obligation metadata, compatibility classifications, and SPDX mappings. Foundation for SBOM generation and license-risk analysis.
- Encryption Dataset Dataset of cryptographic algorithms, primitives, and libraries detected across the index, including post-quantum readiness status. Foundation for cryptographic asset inventories and quantum-migration planning.
- Security Dataset Vulnerabilities mapped directly to the code where they live, drawing on GitHub Security Advisories and NVD CVEs. Resolves to file and version level rather than package level.
- Geo Provenance Dataset Geographic origin metadata for code contributions across the index, derived from commit signals and repository hosting. Built for export-control compliance and supply-chain due diligence.
- AI Governance Dataset Dataset for AI governance and AIBOM (AI Bill of Materials) compliance, providing visibility into AI-generated code and artifacts.
- AI Finder Product providing full visibility into AI artifacts and AI-generated code, enabling organisations to understand what AI components are present in their software.
Quantifiable outcome
- Fast Winnowing provides up to 15x performance improvement over baseline fingerprinting algorithm
- +4 more outcomes
Companies that use SCANOSS
Customer profileNamed customers5 records
Segments8 records
Ideal customer profiles6 records
SCANOSS technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability3 records
Feature8 records
SCANOSS partnerships and signals
Strategic signalPartnerships
19 partnerships are on record, tiered core and minor.
- SanheTrustcoreStrategic cooperation marks SCANOSS's official entry into the Chinese market. Beijing SanheTrust Technology Co., Ltd. is fully responsible for market promotion, network development, sales, and technical support in China. Responsibilities include product localisation (Chinese translation), pre-sales consultation, POC testing, implementation delivery, 24/7 technical support, training, compliance consulting, and joint market operations (online salons, industry summits, whitepaper releases, case studies). Target industries: finance, manufacturing, automotive, government and enterprises.
- FrontiercorePartnership brings SCANOSS's cryptographic and open source visibility to UK enterprise platforms. Frontier (Glasgow-based) integrates SCANOSS into Kubernetes, CI/CD, and policy automation platforms for regulated enterprises in financial services, telecoms, and energy. Makes software transparency continuous within established engineering workflows rather than a periodic compliance exercise. Frontier has G-Cloud 14 framework access for UK public sector procurement. Notable customers include SIX Group, HSBC, Fidelity International, SITA, and Vitol.
- CodelabcoreSCANOSS joins Codelab's CRA Secure Pipeline for embedded software. Codelab (DACH region, Poland, Sweden) integrates SCANOSS data as the open source and cryptography data layer within its CRA Secure Pipeline combining GitLab and SonarQube. Supports SBOM and CBOM generation directly from GitLab workflows. Codelab delivers local-language enablement, first-line support, and deep implementation expertise for automotive OEMs, Tier 1 suppliers, and industrial manufacturers. Codelab is ISO 27001/9001 certified and TISAX assessed.
- FOSSAcoreTechnology partnership combining SCANOSS's open source risk intelligence platform and snippet detection capabilities with FOSSA's license compliance workflows. Addresses growing concerns that developers using AI coding tools may unknowingly violate open source license compliance. Nearly 40% of code in Copilot-enabled files is AI-generated, and 1-5% of LLM-generated code is highly similar to open source. Partnership gives engineering and legal teams deeper visibility into code components to manage IP risks without slowing development.
- IBMcoreStrategic collaboration to improve cryptographic detection and support post-quantum readiness in the software supply chain. Joint effort focuses on enhancing cryptographic visibility in source code to meet regulatory demands (EU CRA, NIST SSDF) and prepare for future quantum threats. IBM and SCANOSS contributed to the SPDX Cryptographic Algorithms List V1.0 together. Collaboration aims to extract exact cryptographic parameters, usage contexts, and implementation configurations for CBOM generation.
- ISITcorePartnership strengthens open source compliance in French-speaking embedded markets (France, Belgium, Luxembourg, Switzerland). ISIT combines regulatory expertise (CRA-focused courses) with SCANOSS datasets for customers moving from one-off compliance projects to continuous governance. ISIT provides local language enablement, first-line support, and training. SCANOSS provides SCANOSS KB and datasets as the underlying open source risk intelligence layer for CI/CD pipelines and toolchains. Target: automotive, medical, industrial, and IoT organisations.
- TCEminorListed as a trusted SCANOSS partner with logo displayed on partner page.
- SIOSminorListed as a trusted SCANOSS partner with logo displayed on partner page.
- MeritominorListed as a trusted SCANOSS partner with logo displayed on partner page.
- TCRminorListed as a trusted SCANOSS partner with logo displayed on partner page.
- SettletopminorListed as a trusted SCANOSS partner with logo displayed on partner page.
- LyraminorListed as a trusted SCANOSS partner with logo displayed on partner page.
- EACGminorListed as a trusted SCANOSS partner with logo displayed on partner page.
- Source Code ControlminorListed as a trusted SCANOSS partner with logo displayed on partner page.
- SnimbusminorListed as a trusted SCANOSS partner with logo displayed on partner page.
- Software Transparency Foundation (STF)coreSCANOSS founded the Software Transparency Foundation, a dedicated organization committed to increasing transparency across the software supply chain. The OSS KB was launched through STF with SCANOSS as a founding contributor. STF provides governance and neutrality for the open source knowledge base.
- OpenChainminorSCANOSS participates in the OpenChain community, supporting open source compliance standards. Listed as a community supporter alongside Eclipse Foundation, OSPO Alliance, Open Regulatory Compliance.
- Eclipse FoundationminorSCANOSS supports Eclipse Foundation initiatives and participates in the Eclipse Software Defined Vehicle project. Listed as a community supporter.
- SPDX CommunitycoreSCANOSS collaborates with SPDX community on standards alignment. SCANOSS's cryptographic algorithms dataset became the starting point for the SPDX Cryptographic Algorithms List V1.0. Supports SPDX Lite SBOM output format. CycloneDX formats supported alongside SPDX.
Scale indicators8 records
Recent moves7 records
Expansion highlights6 records
SCANOSS competitors and assessment
Company assessmentBroad incumbents
- Veracode: Veracode provides enterprise application security testing including SCA, SAST, and DAST. It overlaps with SCANOSS in SBOM-driven compliance workflows for regulated industries (financial services, healthcare, government) and is frequently benchmarked against SCANOSS in enterprise RFPs.
- Checkmarx: Checkmarx is an application security platform offering SAST, SCA, and IaC scanning under the Checkmarx One platform. It competes with SCANOSS in the SCA portion of the stack, particularly for enterprise customers consolidating AppSec tooling.
- GitHub Advanced Security: GitHub Advanced Security (Dependabot, Code Scanning, secret scanning) is bundled into GitHub Enterprise and offers free-tier SCA and SBOM capabilities that compete directly with SCANOSS for any developer team already standardized on the GitHub platform.
- Sonatype Nexus: Sonatype operates the Central Repository and offers Nexus SCA plus repository management. It competes with SCANOSS on open source dependency intelligence and SBOM generation, and overlaps in serving regulated enterprises with software supply-chain compliance needs.
- Synopsys Black Duck: Synopsys Black Duck is an incumbent SCA platform widely deployed in regulated industries (automotive, medical, industrial) — directly overlapping SCANOSS's vertical sweet spots. It offers SBOM generation, license compliance, and vulnerability scanning, bundled into the broader Synopsys Software Integrity Platform.
Direct peers
- FOSSA: FOSSA is an open source license compliance and SBOM management platform that SCANOSS both partners with (Jan 2026) and competes with in license-compliance workflows. FOSSA bundles AI-coding risk modules, creating overlap with SCANOSS's AI Finder capability.
- Mend (formerly WhiteSource): Mend is an established SCA platform focused on open source license compliance and vulnerability detection. It serves a similar enterprise customer profile to SCANOSS and overlaps directly in SBOM generation, license classification, and CI/CD integration use cases.
- Snyk: Snyk is a leading developer security platform offering SCA, SAST, container, and IaC scanning. It directly competes with SCANOSS in software composition analysis and SBOM generation for enterprise DevSecOps teams, and recently added AI-generated code risk capabilities — overlapping with SCANOSS's AI Finder.
- JFrog Xray: JFrog Xray provides SCA and security scanning tightly integrated with Artifactory, used by enterprise DevOps teams for vulnerability and license compliance. It competes head-to-head with SCANOSS in SBOM-driven supply-chain security, particularly in CI/CD pipelines.
Emerging players
- Anchore: Anchore provides SBOM-centric software supply chain security and container compliance, including policy-driven SCA. It is comparable to SCANOSS as a focused SBOM-and-compliance platform targeting regulated DevSecOps buyers, particularly in U.S. federal and enterprise accounts.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
SCANOSS social profiles
Digital presenceSCANOSS compliance and trust
Trust signalCompliance3 records
SCANOSS financial estimates
Financial estimateRevenue estimate
Valuation estimate
SCANOSS leadership team
Management profileNumber of profiles
Profiles3 records
SCANOSS funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SCANOSS M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SCANOSS
What does SCANOSS do?
SCANOSS provides an open-source software risk intelligence platform that scans source code to detect declared and undeclared open source at the snippet level using a Winnowing-based fingerprinting algorithm, backed by a Knowledge Base indexing 334M+ URLs, 100B+ files, and 3T+ lines of code. The platform outputs SPDX Lite and CycloneDX SBOMs, generates Cryptography Bills of Materials (CBOMs) via its crypto-finder engine, and surfaces vulnerabilities, license obligations, and AI-generated code matches for enterprise engineering, security, and compliance teams. It is delivered as Shared SaaS, Dedicated SaaS, or On-Premises, with SDKs (Python/Java/JavaScript), GUI workbench, and CI/CD integrations.
Is SCANOSS a public or private company?
SCANOSS is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SCANOSS founded?
SCANOSS was founded in 2018. It employs 11 to 50 people.
Where is SCANOSS based?
SCANOSS is headquartered in Madrid, Spain, in the Europe region.
How does SCANOSS make money?
Four revenue lines are on record. SaaS Subscription Licenses are the primary driver. The others are dedicated SaaS, on-Premises Deployment and open Source Tools.
Who are SCANOSS's main competitors?
Broad incumbents on record are Veracode, Checkmarx, GitHub Advanced Security, Sonatype Nexus and Synopsys Black Duck. Direct peers are FOSSA, Mend (formerly WhiteSource), Snyk and JFrog Xray. Anchore is listed as an emerging player.
Does SCANOSS have an API?
Yes. SCANOSS provides a REST API (PAPI - Public API) for querying the OSS Knowledge Base, performing SCA tasks, and generating SBOMs. The API enables programmatic access to license intelligence, vulnerability data, cryptographic detection, and component search by software name/PURL. It supports real-time integration with CI/CD pipelines. API keys are provided under commercial licenses and can be obtained through sales or support contacts. Developer documentation is at docs.scanoss.com/en/latest.
What industry is SCANOSS in?
SCANOSS's product category is Software Composition Analysis (Software Supply Chain Security). Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 5415 and its SIC code is 7372.