Developer docs
API playgroundTry for free, no card

Search company profiles

Software Package Data Exchange

Full company profile

uuid002bkpv

Namestring
Software Package Data Exchange
Legal namestring
The Linux Foundation
Websiteurl
spdx.org
Company typeenum
Private
Founded yearstring
-
Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
101–250
akta.pro rankint
HeadquartersSan Francisco, United States
HQ citystring
San Francisco
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Keyword5 values
software bill of materials, open source licensing, supply chain security, software compliance standards, SBOM specification
Industry1 code
1DevSecOps & Supply Chain Security (DevOps toolchain security)
CodeBPAEAKAIPrimaryYes
NAICS code1 code
  • Software Publishers513210
SIC code1 code
  • Services-Prepackaged Software7372
Product category
Open Source Software Compliance Standards
No data
Marketing channels4 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Operations, Infrastructure, Others
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

Software Package Data Exchange (SPDX) develops and maintains the SPDX Specification, a freely available international open standard (ISO/IEC 5962:2021) for representing software bill of materials (SBOMs) and other AI, data, and security references supporting risk management use cases. Its core deliverables are the SPDX Specification itself, the SPDX License List of 600+ standardized license identifiers, and SPDX Tools used to create, validate, and process SPDX documents.

Differentiator
Functional benefit
Problem solved
Product overview1 text field

Software Package Data Exchange (SPDX) is an open standards organization that maintains the SPDX Specification, an internationally certified open standard (ISO/IEC 5962:2021) for representing Software Bill of Materials (SBOMs) and related metadata. The product portfolio centers on the SPDX Specification as the core product, supplemented by the SPDX License List and SPDX Tools. The specification supports multiple specialized profiles including Security, Licensing, AI, Lite, Build, Core, Software, Dataset, Hardware, Services, and Supply Chain, enabling organizations to document and manage software components, licensing information, and related risk data across diverse use cases.

Product and service3 records
1SPDX Specification
CategoryOpen Source Specification
Description

An open international standard (ISO/IEC 5962:2021) for representing systems with software components in Software Bill of Materials (SBOMs) and other AI, data, and security references supporting risk management use cases. For organizations that need to document and exchange software component metadata across supply chains.

2SPDX License List
CategoryOpen Source Specification
Description

An integral part of the SPDX Specification containing a list of commonly found licenses and exceptions used in free and open or collaborative software, data, hardware, or documentation. Includes standardized short identifiers, full names, license texts, and canonical permanent URLs for 600+ licenses and exceptions. For compliance teams, legal counsel, and developers identifying license obligations.

3SPDX Tools
CategoryOpen Source Reference Tools
Description

Workgroup-maintained reference tools and resources that enable users to create, validate, and process SPDX documents and SBOMs. For developers and integrators implementing the SPDX Specification.

Partnership37 partners
Strategic tierCoreTypeStrategic or Co-development Partner
Description

SPDX is a Linux Foundation Collaborative Project hosted under the Linux Foundation Projects umbrella, receiving governance support, infrastructure, and operational framework.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

AWS is listed as a supporter of SPDX, contributing to the development and adoption of the open standard for software bill of materials.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Google is listed as a supporter of SPDX, contributing to the development and adoption of the open standard.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Microsoft is listed as a supporter of SPDX, contributing to the development and adoption of the open standard.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Intel is listed as a supporter of SPDX, contributing to hardware-related aspects of the specification.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Red Hat is listed as a supporter of SPDX, contributing to open source software supply chain standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

IBM is listed as a supporter of SPDX, contributing to enterprise software compliance standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Arm is listed as a supporter of SPDX, contributing to hardware bill of materials standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Siemens is listed as a supporter of SPDX, contributing to industrial software supply chain standards.

10SAP
Strategic tierCoreTypeStrategic or Co-development Partner
Description

SAP is listed as a supporter of SPDX, contributing to enterprise software compliance.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Cisco is listed as a supporter of SPDX, contributing to networking and software supply chain standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

VMware is listed as a supporter of SPDX.

Strategic tierCoreTypeTechnology or Integration
Description

Anchore is listed as a supporter and provides tools that integrate with SPDX for container security and compliance.

Strategic tierCoreTypeTechnology or Integration
Description

Snyk is listed as a supporter and provides security scanning tools that support SPDX format for vulnerability management.

Strategic tierCoreTypeTechnology or Integration
Description

Sonatype is listed as a supporter and provides software supply chain security tools supporting SPDX.

Strategic tierCoreTypeTechnology or Integration
Description

Synopsys is listed as a supporter and provides software testing tools that support SPDX standards.

Strategic tierCoreTypeTechnology or Integration
Description

FOSSA is listed as a supporter and provides open source compliance tools that integrate with SPDX.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Eclipse Foundation is listed as a supporter of SPDX, contributing to open source standards development.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

MITRE is listed as a supporter of SPDX, contributing to security and vulnerability standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Bosch is listed as a supporter of SPDX, contributing to industrial IoT and automotive software standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Huawei is listed as a supporter of SPDX.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

HPE is listed as a supporter of SPDX.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Wind River is listed as a supporter of SPDX, contributing to embedded software standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Palo Alto Networks is listed as a supporter of SPDX for security standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

RISC-V is listed as a supporter of SPDX for hardware specification standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Yocto Project is listed as a supporter of SPDX for embedded Linux build systems.

27nexB
Strategic tierCoreTypeTechnology or Integration
Description

nexB is listed as a supporter and provides open source software composition analysis tools.

spdx.dev
Strategic tierCoreTypeStrategic or Co-development Partner
Description

Ericsson is listed as a supporter of SPDX for telecommunications software.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

Scania is listed as a supporter contributing to automotive software standards.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

CARIAD is listed as a supporter contributing to automotive software standards.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

The Walt Disney Company is listed as a supporter of SPDX.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Sony is listed as a supporter of SPDX, contributing to consumer electronics software standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Texas Instruments is listed as a supporter of SPDX for semiconductor software standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Xilinx (now part of AMD) is listed as a supporter of SPDX for FPGA software standards.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

OpenEuler is listed as a supporter contributing to open source Linux ecosystem.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

CAICT is listed as a supporter contributing to Chinese technology standards.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

Cybertrust Japan is listed as a supporter contributing to Japanese market.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
TypeRegional player
Description

NTIA's SBOM working group defines minimum SBOM fields and U.S. government expectations, directly influencing how SPDX and CycloneDX are used in U.S. federal supply chains.

TypeEmerging player
Description

Software Heritage maintains a universal archive of source code and references SPDX for describing software origins, making it an adjacent peer in software provenance metadata.

3SLSA (Supply-chain Levels for Software Artifacts)
TypeEmerging player
Description

SLSA is a security framework specifying supply chain integrity levels. It complements SPDX by providing the attestation layer that consumes SPDX-formatted SBOMs.

TypeDirect peer
Description

OWASP is the parent foundation of CycloneDX and itself develops software security standards and tooling that overlap with SPDX's security profile.

TypeDirect peer
Description

OpenSSF is a Linux Foundation-hosted initiative that develops supply chain security frameworks (SLSA, Sigstore) that intersect directly with SPDX's supply chain and security profiles.

TypeDirect peer
Description

CycloneDX, under OWASP, is the principal competing SBOM standard. Both target the same software supply chain transparency use case and compete for tooling, regulatory, and ecosystem adoption.

TypeRegional player
Description

CISA shapes U.S. federal SBOM policy and references SPDX as one of the accepted formats, directly influencing adoption mandates for vendors serving U.S. government.

TypeEmerging player
Description

Sigstore is a Linux Foundation project for signing and verifying software artifacts. It works alongside SBOM standards like SPDX and is increasingly referenced in the same supply chain security workflows.

TypeDirect peer
Description

OpenChain is a Linux Foundation project setting open source license compliance process standards. Both SPDX and OpenChain address software license compliance and are frequently co-referenced in enterprise compliance programs.

TypeDirect peer
Description

in-toto is a supply chain integrity framework providing attestation and verification that complements SPDX's SBOM data model; both address software supply chain assurance.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Segment1 record

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile1 record

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature3 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
No data
Compliance1 record

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Software Package Data Exchange

Open Source Software Compliance Standardsspdx.org

Software Package Data Exchange firmographics

Firmographics
Name
Software Package Data Exchange
Legal name
The Linux Foundation
Website
https://spdx.org
Company type
Private
Operating status
Operating
Headcount range
101–250 employees
Ownership category
akta.pro rank

Software Package Data Exchange industry classification

Industry
Product category
Open Source Software Compliance Standards
NAICS
Software Publishers (513210)
SIC
Services-Prepackaged Software (7372)
akta.pro primary industry
DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI)

Keywords

  • Software bill of materials
  • Open source licensing
  • Supply chain security
  • Software compliance standards
  • SBOM specification

Where Software Package Data Exchange is headquartered

Location

Headquarters

HQ city
San Francisco
HQ country
United States
HQ region
North America

Markets served

Software Package Data Exchange business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Operations, Infrastructure, Others

Distribution channels3 records

Marketing channels4 records

Software Package Data Exchange product offering

Product offering

Core offering

Software Package Data Exchange (SPDX) develops and maintains the SPDX Specification, a freely available international open standard (ISO/IEC 5962:2021) for representing software bill of materials (SBOMs) and other AI, data, and security references supporting risk management use cases. Its core deliverables are the SPDX Specification itself, the SPDX License List of 600+ standardized license identifiers, and SPDX Tools used to create, validate, and process SPDX documents.

Product overview

Software Package Data Exchange (SPDX) is an open standards organization that maintains the SPDX Specification, an internationally certified open standard (ISO/IEC 5962:2021) for representing Software Bill of Materials (SBOMs) and related metadata. The product portfolio centers on the SPDX Specification as the core product, supplemented by the SPDX License List and SPDX Tools. The specification supports multiple specialized profiles including Security, Licensing, AI, Lite, Build, Core, Software, Dataset, Hardware, Services, and Supply Chain, enabling organizations to document and manage software components, licensing information, and related risk data across diverse use cases.

Differentiator

Problem solved

Functional benefit

Products and services

  • SPDX Specification An open international standard (ISO/IEC 5962:2021) for representing systems with software components in Software Bill of Materials (SBOMs) and other AI, data, and security references supporting risk management use cases. For organizations that need to document and exchange software component metadata across supply chains.
  • SPDX License List An integral part of the SPDX Specification containing a list of commonly found licenses and exceptions used in free and open or collaborative software, data, hardware, or documentation. Includes standardized short identifiers, full names, license texts, and canonical permanent URLs for 600+ licenses and exceptions. For compliance teams, legal counsel, and developers identifying license obligations.
  • SPDX Tools Workgroup-maintained reference tools and resources that enable users to create, validate, and process SPDX documents and SBOMs. For developers and integrators implementing the SPDX Specification.

Companies that use Software Package Data Exchange

Customer profile

Segments1 record

Ideal customer profiles1 record

Software Package Data Exchange technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature3 records

Software Package Data Exchange partnerships and signals

Strategic signal

Partnerships

37 partnerships are on record, tiered core and minor.

  • The Linux FoundationcoreStrategic or Co-development PartnerSPDX is a Linux Foundation Collaborative Project hosted under the Linux Foundation Projects umbrella, receiving governance support, infrastructure, and operational framework.
  • Amazon Web Services (AWS)coreStrategic or Co-development PartnerAWS is listed as a supporter of SPDX, contributing to the development and adoption of the open standard for software bill of materials.
  • GooglecoreStrategic or Co-development PartnerGoogle is listed as a supporter of SPDX, contributing to the development and adoption of the open standard.
  • MicrosoftcoreStrategic or Co-development PartnerMicrosoft is listed as a supporter of SPDX, contributing to the development and adoption of the open standard.
  • Intel CorporationcoreStrategic or Co-development PartnerIntel is listed as a supporter of SPDX, contributing to hardware-related aspects of the specification.
  • Red HatcoreStrategic or Co-development PartnerRed Hat is listed as a supporter of SPDX, contributing to open source software supply chain standards.
  • IBMcoreStrategic or Co-development PartnerIBM is listed as a supporter of SPDX, contributing to enterprise software compliance standards.
  • ArmcoreStrategic or Co-development PartnerArm is listed as a supporter of SPDX, contributing to hardware bill of materials standards.
  • SiemenscoreStrategic or Co-development PartnerSiemens is listed as a supporter of SPDX, contributing to industrial software supply chain standards.
  • SAPcoreStrategic or Co-development PartnerSAP is listed as a supporter of SPDX, contributing to enterprise software compliance.
  • CiscocoreStrategic or Co-development PartnerCisco is listed as a supporter of SPDX, contributing to networking and software supply chain standards.
  • VMwarecoreStrategic or Co-development PartnerVMware is listed as a supporter of SPDX.
  • AnchorecoreTechnology or IntegrationAnchore is listed as a supporter and provides tools that integrate with SPDX for container security and compliance.
  • SnykcoreTechnology or IntegrationSnyk is listed as a supporter and provides security scanning tools that support SPDX format for vulnerability management.
  • SonatypecoreTechnology or IntegrationSonatype is listed as a supporter and provides software supply chain security tools supporting SPDX.
  • SynopsyscoreTechnology or IntegrationSynopsys is listed as a supporter and provides software testing tools that support SPDX standards.
  • FOSSAcoreTechnology or IntegrationFOSSA is listed as a supporter and provides open source compliance tools that integrate with SPDX.
  • Eclipse FoundationcoreStrategic or Co-development PartnerEclipse Foundation is listed as a supporter of SPDX, contributing to open source standards development.
  • MITREcoreStrategic or Co-development PartnerMITRE is listed as a supporter of SPDX, contributing to security and vulnerability standards.
  • BoschcoreStrategic or Co-development PartnerBosch is listed as a supporter of SPDX, contributing to industrial IoT and automotive software standards.
  • HuaweicoreStrategic or Co-development PartnerHuawei is listed as a supporter of SPDX.
  • Hewlett Packard EnterprisecoreStrategic or Co-development PartnerHPE is listed as a supporter of SPDX.
  • Wind RivercoreStrategic or Co-development PartnerWind River is listed as a supporter of SPDX, contributing to embedded software standards.
  • Palo Alto NetworkscoreStrategic or Co-development PartnerPalo Alto Networks is listed as a supporter of SPDX for security standards.
  • RISC-V InternationalcoreStrategic or Co-development PartnerRISC-V is listed as a supporter of SPDX for hardware specification standards.
  • Yocto ProjectcoreStrategic or Co-development PartnerYocto Project is listed as a supporter of SPDX for embedded Linux build systems.
  • nexBcoreTechnology or IntegrationnexB is listed as a supporter and provides open source software composition analysis tools.
  • EricssoncoreStrategic or Co-development PartnerEricsson is listed as a supporter of SPDX for telecommunications software.
  • ScaniaminorStrategic or Co-development PartnerScania is listed as a supporter contributing to automotive software standards.
  • CARIADminorStrategic or Co-development PartnerCARIAD is listed as a supporter contributing to automotive software standards.
  • The Walt Disney CompanyminorStrategic or Co-development PartnerThe Walt Disney Company is listed as a supporter of SPDX.
  • Sony GroupcoreStrategic or Co-development PartnerSony is listed as a supporter of SPDX, contributing to consumer electronics software standards.
  • Texas InstrumentscoreStrategic or Co-development PartnerTexas Instruments is listed as a supporter of SPDX for semiconductor software standards.
  • Xilinx (AMD)coreStrategic or Co-development PartnerXilinx (now part of AMD) is listed as a supporter of SPDX for FPGA software standards.
  • OpenEulercoreStrategic or Co-development PartnerOpenEuler is listed as a supporter contributing to open source Linux ecosystem.
  • CAICTminorStrategic or Co-development PartnerCAICT is listed as a supporter contributing to Chinese technology standards.
  • Cybertrust JapanminorStrategic or Co-development PartnerCybertrust Japan is listed as a supporter contributing to Japanese market.

Recent moves6 records

Expansion highlights5 records

Software Package Data Exchange competitors and assessment

Company assessment

Regional players

  • NTIA SBOM Working Group: NTIA's SBOM working group defines minimum SBOM fields and U.S. government expectations, directly influencing how SPDX and CycloneDX are used in U.S. federal supply chains.
  • CISA (Cybersecurity and Infrastructure Security Agency): CISA shapes U.S. federal SBOM policy and references SPDX as one of the accepted formats, directly influencing adoption mandates for vendors serving U.S. government.

Emerging players

  • Software Heritage: Software Heritage maintains a universal archive of source code and references SPDX for describing software origins, making it an adjacent peer in software provenance metadata.
  • SLSA (Supply-chain Levels for Software Artifacts): SLSA is a security framework specifying supply chain integrity levels. It complements SPDX by providing the attestation layer that consumes SPDX-formatted SBOMs.
  • Sigstore: Sigstore is a Linux Foundation project for signing and verifying software artifacts. It works alongside SBOM standards like SPDX and is increasingly referenced in the same supply chain security workflows.

Direct peers

  • OWASP Foundation: OWASP is the parent foundation of CycloneDX and itself develops software security standards and tooling that overlap with SPDX's security profile.
  • OpenSSF (Open Source Security Foundation): OpenSSF is a Linux Foundation-hosted initiative that develops supply chain security frameworks (SLSA, Sigstore) that intersect directly with SPDX's supply chain and security profiles.
  • CycloneDX: CycloneDX, under OWASP, is the principal competing SBOM standard. Both target the same software supply chain transparency use case and compete for tooling, regulatory, and ecosystem adoption.
  • OpenChain (Linux Foundation): OpenChain is a Linux Foundation project setting open source license compliance process standards. Both SPDX and OpenChain address software license compliance and are frequently co-referenced in enterprise compliance programs.
  • in-toto: in-toto is a supply chain integrity framework providing attestation and verification that complements SPDX's SBOM data model; both address software supply chain assurance.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks5 records

Key highlights6 records

Customer concentration

Software Package Data Exchange compliance and trust

Trust signal

Compliance1 record

Software Package Data Exchange financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Software Package Data Exchange leadership team

Management profile

Number of profiles

Software Package Data Exchange funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Software Package Data Exchange M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Software Package Data Exchange

What does Software Package Data Exchange do?

Software Package Data Exchange (SPDX) develops and maintains the SPDX Specification, a freely available international open standard (ISO/IEC 5962:2021) for representing software bill of materials (SBOMs) and other AI, data, and security references supporting risk management use cases. Its core deliverables are the SPDX Specification itself, the SPDX License List of 600+ standardized license identifiers, and SPDX Tools used to create, validate, and process SPDX documents.

Is Software Package Data Exchange a public or private company?

Software Package Data Exchange is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was Software Package Data Exchange founded?

Software Package Data Exchange was founded in -1. It employs 101 to 250 people.

Where is Software Package Data Exchange based?

Software Package Data Exchange is headquartered in San Francisco, United States, in the North America region.

Who are Software Package Data Exchange's main competitors?

Regional players on record are NTIA SBOM Working Group and CISA (Cybersecurity and Infrastructure Security Agency). Emerging players are Software Heritage, SLSA (Supply-chain Levels for Software Artifacts) and Sigstore. Direct peers are OWASP Foundation, OpenSSF (Open Source Security Foundation), CycloneDX, OpenChain (Linux Foundation) and in-toto.

Does Software Package Data Exchange have an API?

No public API is recorded for Software Package Data Exchange.

What industry is Software Package Data Exchange in?

Software Package Data Exchange's product category is Open Source Software Compliance Standards. Its primary akta.pro industry code is BPAEAKAI, DevSecOps & Supply Chain Security (DevOps toolchain security). Its NAICS code is 513210 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales