FOSSA automates open source license compliance, SBOM management, and vulnerability remediation for engineering teams. Free trial available; custom enterprise…
FOSSA is a software supply chain management platform founded in 2015 and based in San Francisco. It scans an organization's codebase, containers, binaries, and CI/CD pipelines to identify every piece of open source and third-party code in use, then applies automated policy checks for license compliance, security vulnerabilities, and software bill of materials (SBOM) requirements.
The company has raised more than $40 million in venture funding from investors including Bain Capital Ventures and Norwest Venture Partners, and it counts enterprises in financial services, automotive, and medical device manufacturing among its customers — industries where open source license and security compliance carry real regulatory weight.
FOSSA scans across multiple artifact types, including package manifests, container images, SBOMs, compiled binaries, and raw code snippets, and it claims support for essentially all major programming languages, package managers, and CI/CD systems. This breadth lets a single platform sit across an organization's entire dependency graph rather than requiring different tools per language.
Its guided remediation engine recommends specific fixes for license conflicts and known vulnerabilities, and the newer fossabot AI agent extends this by proposing and helping automate dependency version upgrades that resolve compliance or security issues without manual triage. FOSSA also offers SOC 2 compliance and enterprise support tiers for larger deployments.
FOSSA does not publish specific plan tiers or prices on its website. Prospective customers can start with a free trial that includes full feature access, after which sales-assisted custom pricing applies based on organization size, number of projects scanned, and support requirements.
This contact-for-pricing model is typical of enterprise security and compliance tooling, where cost usually scales with the number of repositories, developers, or scans rather than a simple flat subscription.
FOSSA scans code, containers, and dependencies to manage open source license compliance, generate SBOMs, and flag security vulnerabilities.
FOSSA doesn't publish pricing; it offers a free trial with full features, and paid plans use custom, sales-negotiated pricing.
Yes, SBOM generation and management is a core part of the platform.
It's primarily built for mid-size to large engineering organizations; smaller teams may find its enterprise pricing model less cost-effective.
fossabot is FOSSA's AI agent that recommends and helps automate dependency upgrades to resolve license or security compliance issues.