Software Package Data Exchange
- Company typePrivate
- Founded-
- HeadquartersSan Francisco, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
Software Package Data Exchange firmographics
Firmographics- Name
- Software Package Data Exchange
- Legal name
- The Linux Foundation
- Website
- https://spdx.org
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Ownership category
- akta.pro rank
Software Package Data Exchange industry classification
Industry- Product category
- Open Source Software Compliance Standards
- NAICS
- Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI)
Keywords
Where Software Package Data Exchange is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Markets served
Software Package Data Exchange business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure, Others
Distribution channels3 records
Marketing channels4 records
Software Package Data Exchange product offering
Product offeringCore offering
Software Package Data Exchange (SPDX) develops and maintains the SPDX Specification, a freely available international open standard (ISO/IEC 5962:2021) for representing software bill of materials (SBOMs) and other AI, data, and security references supporting risk management use cases. Its core deliverables are the SPDX Specification itself, the SPDX License List of 600+ standardized license identifiers, and SPDX Tools used to create, validate, and process SPDX documents.
Product overview
Software Package Data Exchange (SPDX) is an open standards organization that maintains the SPDX Specification, an internationally certified open standard (ISO/IEC 5962:2021) for representing Software Bill of Materials (SBOMs) and related metadata. The product portfolio centers on the SPDX Specification as the core product, supplemented by the SPDX License List and SPDX Tools. The specification supports multiple specialized profiles including Security, Licensing, AI, Lite, Build, Core, Software, Dataset, Hardware, Services, and Supply Chain, enabling organizations to document and manage software components, licensing information, and related risk data across diverse use cases.
Differentiator
Problem solved
Functional benefit
Products and services
- SPDX Specification An open international standard (ISO/IEC 5962:2021) for representing systems with software components in Software Bill of Materials (SBOMs) and other AI, data, and security references supporting risk management use cases. For organizations that need to document and exchange software component metadata across supply chains.
- SPDX License List An integral part of the SPDX Specification containing a list of commonly found licenses and exceptions used in free and open or collaborative software, data, hardware, or documentation. Includes standardized short identifiers, full names, license texts, and canonical permanent URLs for 600+ licenses and exceptions. For compliance teams, legal counsel, and developers identifying license obligations.
- SPDX Tools Workgroup-maintained reference tools and resources that enable users to create, validate, and process SPDX documents and SBOMs. For developers and integrators implementing the SPDX Specification.
Companies that use Software Package Data Exchange
Customer profileSegments1 record
Ideal customer profiles1 record
Software Package Data Exchange technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Software Package Data Exchange partnerships and signals
Strategic signalPartnerships
37 partnerships are on record, tiered core and minor.
- The Linux FoundationcoreSPDX is a Linux Foundation Collaborative Project hosted under the Linux Foundation Projects umbrella, receiving governance support, infrastructure, and operational framework.
- Amazon Web Services (AWS)coreAWS is listed as a supporter of SPDX, contributing to the development and adoption of the open standard for software bill of materials.
- GooglecoreGoogle is listed as a supporter of SPDX, contributing to the development and adoption of the open standard.
- MicrosoftcoreMicrosoft is listed as a supporter of SPDX, contributing to the development and adoption of the open standard.
- Intel CorporationcoreIntel is listed as a supporter of SPDX, contributing to hardware-related aspects of the specification.
- Red HatcoreRed Hat is listed as a supporter of SPDX, contributing to open source software supply chain standards.
- IBMcoreIBM is listed as a supporter of SPDX, contributing to enterprise software compliance standards.
- ArmcoreArm is listed as a supporter of SPDX, contributing to hardware bill of materials standards.
- SiemenscoreSiemens is listed as a supporter of SPDX, contributing to industrial software supply chain standards.
- SAPcoreSAP is listed as a supporter of SPDX, contributing to enterprise software compliance.
- CiscocoreCisco is listed as a supporter of SPDX, contributing to networking and software supply chain standards.
- VMwarecoreVMware is listed as a supporter of SPDX.
- AnchorecoreAnchore is listed as a supporter and provides tools that integrate with SPDX for container security and compliance.
- SnykcoreSnyk is listed as a supporter and provides security scanning tools that support SPDX format for vulnerability management.
- SonatypecoreSonatype is listed as a supporter and provides software supply chain security tools supporting SPDX.
- SynopsyscoreSynopsys is listed as a supporter and provides software testing tools that support SPDX standards.
- FOSSAcoreFOSSA is listed as a supporter and provides open source compliance tools that integrate with SPDX.
- Eclipse FoundationcoreEclipse Foundation is listed as a supporter of SPDX, contributing to open source standards development.
- MITREcoreMITRE is listed as a supporter of SPDX, contributing to security and vulnerability standards.
- BoschcoreBosch is listed as a supporter of SPDX, contributing to industrial IoT and automotive software standards.
- HuaweicoreHuawei is listed as a supporter of SPDX.
- Hewlett Packard EnterprisecoreHPE is listed as a supporter of SPDX.
- Wind RivercoreWind River is listed as a supporter of SPDX, contributing to embedded software standards.
- Palo Alto NetworkscorePalo Alto Networks is listed as a supporter of SPDX for security standards.
- RISC-V InternationalcoreRISC-V is listed as a supporter of SPDX for hardware specification standards.
- Yocto ProjectcoreYocto Project is listed as a supporter of SPDX for embedded Linux build systems.
- nexBcorenexB is listed as a supporter and provides open source software composition analysis tools.
- EricssoncoreEricsson is listed as a supporter of SPDX for telecommunications software.
- ScaniaminorScania is listed as a supporter contributing to automotive software standards.
- CARIADminorCARIAD is listed as a supporter contributing to automotive software standards.
- The Walt Disney CompanyminorThe Walt Disney Company is listed as a supporter of SPDX.
- Sony GroupcoreSony is listed as a supporter of SPDX, contributing to consumer electronics software standards.
- Texas InstrumentscoreTexas Instruments is listed as a supporter of SPDX for semiconductor software standards.
- Xilinx (AMD)coreXilinx (now part of AMD) is listed as a supporter of SPDX for FPGA software standards.
- OpenEulercoreOpenEuler is listed as a supporter contributing to open source Linux ecosystem.
- CAICTminorCAICT is listed as a supporter contributing to Chinese technology standards.
- Cybertrust JapanminorCybertrust Japan is listed as a supporter contributing to Japanese market.
Recent moves6 records
Expansion highlights5 records
Software Package Data Exchange competitors and assessment
Company assessmentRegional players
- NTIA SBOM Working Group: NTIA's SBOM working group defines minimum SBOM fields and U.S. government expectations, directly influencing how SPDX and CycloneDX are used in U.S. federal supply chains.
- CISA (Cybersecurity and Infrastructure Security Agency): CISA shapes U.S. federal SBOM policy and references SPDX as one of the accepted formats, directly influencing adoption mandates for vendors serving U.S. government.
Emerging players
- Software Heritage: Software Heritage maintains a universal archive of source code and references SPDX for describing software origins, making it an adjacent peer in software provenance metadata.
- SLSA (Supply-chain Levels for Software Artifacts): SLSA is a security framework specifying supply chain integrity levels. It complements SPDX by providing the attestation layer that consumes SPDX-formatted SBOMs.
- Sigstore: Sigstore is a Linux Foundation project for signing and verifying software artifacts. It works alongside SBOM standards like SPDX and is increasingly referenced in the same supply chain security workflows.
Direct peers
- OWASP Foundation: OWASP is the parent foundation of CycloneDX and itself develops software security standards and tooling that overlap with SPDX's security profile.
- OpenSSF (Open Source Security Foundation): OpenSSF is a Linux Foundation-hosted initiative that develops supply chain security frameworks (SLSA, Sigstore) that intersect directly with SPDX's supply chain and security profiles.
- CycloneDX: CycloneDX, under OWASP, is the principal competing SBOM standard. Both target the same software supply chain transparency use case and compete for tooling, regulatory, and ecosystem adoption.
- OpenChain (Linux Foundation): OpenChain is a Linux Foundation project setting open source license compliance process standards. Both SPDX and OpenChain address software license compliance and are frequently co-referenced in enterprise compliance programs.
- in-toto: in-toto is a supply chain integrity framework providing attestation and verification that complements SPDX's SBOM data model; both address software supply chain assurance.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Software Package Data Exchange compliance and trust
Trust signalCompliance1 record
Software Package Data Exchange financial estimates
Financial estimateRevenue estimate
Valuation estimate
Software Package Data Exchange leadership team
Management profileNumber of profiles
Software Package Data Exchange funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Software Package Data Exchange M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Software Package Data Exchange
What does Software Package Data Exchange do?
Software Package Data Exchange (SPDX) develops and maintains the SPDX Specification, a freely available international open standard (ISO/IEC 5962:2021) for representing software bill of materials (SBOMs) and other AI, data, and security references supporting risk management use cases. Its core deliverables are the SPDX Specification itself, the SPDX License List of 600+ standardized license identifiers, and SPDX Tools used to create, validate, and process SPDX documents.
Is Software Package Data Exchange a public or private company?
Software Package Data Exchange is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Software Package Data Exchange founded?
Software Package Data Exchange was founded in -1. It employs 101 to 250 people.
Where is Software Package Data Exchange based?
Software Package Data Exchange is headquartered in San Francisco, United States, in the North America region.
Who are Software Package Data Exchange's main competitors?
Regional players on record are NTIA SBOM Working Group and CISA (Cybersecurity and Infrastructure Security Agency). Emerging players are Software Heritage, SLSA (Supply-chain Levels for Software Artifacts) and Sigstore. Direct peers are OWASP Foundation, OpenSSF (Open Source Security Foundation), CycloneDX, OpenChain (Linux Foundation) and in-toto.
Does Software Package Data Exchange have an API?
No public API is recorded for Software Package Data Exchange.
What industry is Software Package Data Exchange in?
Software Package Data Exchange's product category is Open Source Software Compliance Standards. Its primary akta.pro industry code is BPAEAKAI, DevSecOps & Supply Chain Security (DevOps toolchain security). Its NAICS code is 513210 and its SIC code is 7372.