FOSSA
San Francisco-based software composition analysis and SBOM platform helping engineering and security teams manage open-source license, vulnerability, and supply-chain transparency risk.
Visit Website ↗ + Add to CompareOverview
FOSSA, founded in 2015 and headquartered in San Francisco, builds a software composition analysis (SCA) and software bill of materials (SBOM) platform that scans codebases, containers, and binaries to identify open-source components, license-compliance risk, and known vulnerabilities across the software supply chain. The platform generates SBOMs in the SPDX and CycloneDX formats and is positioned to help engineering and security teams meet emerging regulatory transparency requirements, such as US executive-order-driven SBOM mandates, alongside its original open-source license-compliance use case.
FOSSA has raised roughly $35 million in disclosed venture funding, including a $23.2 million Series B in October 2020 led by Bain Capital Ventures, Canvas Ventures, and Costanoa Ventures, and counts Uber, Zendesk, Verizon, and UiPath among publicly cited customers. The company occupies a mature, increasingly commoditized SCA/SBOM segment alongside larger competitors such as Snyk, Black Duck (Synopsys), Sonatype, and GitHub’s native tooling; its differentiation rests on breadth of language and ecosystem coverage plus snippet-level copied-code detection rather than a fundamentally novel technical approach.
Innovation Matrix Assessment
Continues to ship SBOM-format and integration updates (SPDX, CycloneDX, container/binary scanning), though pace has not been publicly benchmarked against competitors in recent years.
CI/CD-integrated SCA tooling is generally straightforward to deploy for engineering teams already using standard build pipelines.
Last disclosed funding round was October 2020; no more recent public funding or major growth announcements were found, suggesting momentum has cooled relative to 2019-2020.
Operates in a mature, well-established SCA/SBOM category alongside larger, better-capitalized competitors; not pioneering a fundamentally new detection approach.
A long list of recognizable enterprise customers (Uber, Zendesk, Verizon, UiPath) is a positive adoption signal, though no independent detection-accuracy benchmarking against competitors was found.
SBOM generation and software-supply-chain transparency are active, growing regulatory and buyer priorities (US federal SBOM mandates, EU Cyber Resilience Act).
Why CISOs Should Care
For CISOs and AppSec leaders facing SBOM-generation mandates (federal contracts, executive-order-driven requirements, EU Cyber Resilience Act) alongside ordinary open-source license and vulnerability risk, FOSSA offers a single platform covering both compliance and security use cases without needing separate license-compliance and SCA tools.
What Makes It Different
Broad multi-language and ecosystem coverage plus binary and snippet-level detection, catching copied code even without a declared dependency, differentiates it somewhat from license-compliance-only or vulnerability-only point tools, though the core SCA/SBOM category itself is now crowded with well-funded incumbents.
The Matrix Verdict
50/100 — INCREMENTAL INNOVATOR
A capable, broadly adopted SCA/SBOM platform well positioned for the current regulatory push toward software transparency, but competing in a mature category against larger, better-capitalized rivals with no recent disclosed funding to signal renewed momentum. An Incremental Innovator.
Editorial Note: Claims vs. Verified Findings
Customer list (Uber, Zendesk, Verizon, UiPath, etc.) and funding totals are vendor/press-release sourced (FOSSA blog, SecurityWeek, PR Newswire) and not independently audited; employee count (approximately 43-62 depending on data provider) is estimated and should be treated as approximate.
Sources
- FOSSA company site - https://fossa.com/
- FOSSA Blog, "FOSSA Raises a $23.2M Series B" - https://fossa.com/blog/fossa-raises-series-b/
- PR Newswire, "FOSSA Raises $8.5 Million in Series A Funding" - https://www.prnewswire.com/news-releases/fossa-raises-8-5-million-in-series-a-funding-led-by-bain-capital-ventures-and-costanoa-ventures-300918654.html
- SecurityWeek, "Open Source Management Firm FOSSA Raises $23 Million" - https://www.securityweek.com/open-source-management-firm-fossa-raises-23-million/
Alternatives to FOSSA
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…