Skip to content

FOSSA

San Francisco-based software composition analysis and SBOM platform helping engineering and security teams manage open-source license, vulnerability, and supply-chain transparency risk.

Visit Website ↗ + Add to Compare
50/100Incremental Innovator

Overview

FOSSA, founded in 2015 and headquartered in San Francisco, builds a software composition analysis (SCA) and software bill of materials (SBOM) platform that scans codebases, containers, and binaries to identify open-source components, license-compliance risk, and known vulnerabilities across the software supply chain. The platform generates SBOMs in the SPDX and CycloneDX formats and is positioned to help engineering and security teams meet emerging regulatory transparency requirements, such as US executive-order-driven SBOM mandates, alongside its original open-source license-compliance use case.

FOSSA has raised roughly $35 million in disclosed venture funding, including a $23.2 million Series B in October 2020 led by Bain Capital Ventures, Canvas Ventures, and Costanoa Ventures, and counts Uber, Zendesk, Verizon, and UiPath among publicly cited customers. The company occupies a mature, increasingly commoditized SCA/SBOM segment alongside larger competitors such as Snyk, Black Duck (Synopsys), Sonatype, and GitHub’s native tooling; its differentiation rests on breadth of language and ecosystem coverage plus snippet-level copied-code detection rather than a fundamentally novel technical approach.

Innovation Matrix Assessment

Innovation Velocity 5/10

Continues to ship SBOM-format and integration updates (SPDX, CycloneDX, container/binary scanning), though pace has not been publicly benchmarked against competitors in recent years.

Operational Value 6/10

CI/CD-integrated SCA tooling is generally straightforward to deploy for engineering teams already using standard build pipelines.

Market Momentum 4/10

Last disclosed funding round was October 2020; no more recent public funding or major growth announcements were found, suggesting momentum has cooled relative to 2019-2020.

Category Disruption 3/10

Operates in a mature, well-established SCA/SBOM category alongside larger, better-capitalized competitors; not pioneering a fundamentally new detection approach.

Real-World Efficacy 5/10

A long list of recognizable enterprise customers (Uber, Zendesk, Verizon, UiPath) is a positive adoption signal, though no independent detection-accuracy benchmarking against competitors was found.

Enduring Relevance 7/10

SBOM generation and software-supply-chain transparency are active, growing regulatory and buyer priorities (US federal SBOM mandates, EU Cyber Resilience Act).

Why CISOs Should Care

For CISOs and AppSec leaders facing SBOM-generation mandates (federal contracts, executive-order-driven requirements, EU Cyber Resilience Act) alongside ordinary open-source license and vulnerability risk, FOSSA offers a single platform covering both compliance and security use cases without needing separate license-compliance and SCA tools.

What Makes It Different

Broad multi-language and ecosystem coverage plus binary and snippet-level detection, catching copied code even without a declared dependency, differentiates it somewhat from license-compliance-only or vulnerability-only point tools, though the core SCA/SBOM category itself is now crowded with well-funded incumbents.

The Matrix Verdict

50/100 — INCREMENTAL INNOVATOR

A capable, broadly adopted SCA/SBOM platform well positioned for the current regulatory push toward software transparency, but competing in a mature category against larger, better-capitalized rivals with no recent disclosed funding to signal renewed momentum. An Incremental Innovator.

Editorial Note: Claims vs. Verified Findings

Customer list (Uber, Zendesk, Verizon, UiPath, etc.) and funding totals are vendor/press-release sourced (FOSSA blog, SecurityWeek, PR Newswire) and not independently audited; employee count (approximately 43-62 depending on data provider) is estimated and should be treated as approximate.

Sources