FossID Software Composition
FossID Software Composition Analysis on SecurityListing: SCA tool for code scanning, license identification, and SBOM generation

FossID Software Composition
FossID Software Composition Analysis on SecurityListing: SCA tool for code scanning, license identification, and SBOM generation
Rating
4.5 / 5.0
Pricing
Contact vendor
Deployment
SaaS / Cloud
Category
Software Composition Analysis
Product Description
FossID provides Software Composition Analysis (SCA) technology and audit services for enterprise software development teams. The company's platform detects open source software components, including complete packages and code snippets as small as six lines, within complex codebases. Using digital fingerprinting methodology, FossID identifies components while preserving source code confidentiality and draws from an extensive open source software knowledge base.
The company was founded in 2016 by open source software auditors to address license compliance and security vulnerability risks associated with open source software use in proprietary development. FossID was acquired by Snyk in 2021 but was reacquired by its founders in 2022. The platform generates Software Bills of Materials (SBOMs) in standard formats including SPDX and CycloneDX, supporting Source and Build SBOM types through integration with CI/CD workflows.
FossID serves Fortune 500 organizations across automotive, financial services, manufacturing, technology, and telecommunications sectors. The technology is designed for developers working with C/C++ and other languages, as well as business users in legal and compliance roles. The company offers both automated SCA tooling and professional audit services for technical due diligence in M&A transactions, intellectual property protection, and software supply chain integrity. The platform integrates into existing software development lifecycles to enable detection of declared and undeclared open source components, direct and transitive dependencies, and associated license and vulnerability information.
Contact Vendor
Interested in FossID Software Composition Analysis? Get in touch with the vendor.
arrow_upwardPOPULAR
IGRC Square
IGRC Square provides cybersecurity solutions for organizations, focusing on governance, risk management, and compliance to safeguard data, devices, and employees. The company emphasizes state-of-the-a
Bulwark Technologies
Bulwark Technologies is a cybersecurity distributor focused on the Middle East, with headquarters in Dubai and regional offices in Saudi Arabia and India. The company acts as a value-added distributor
ICT Misr
ICT Misr is a technology consulting and system integration firm based in Egypt. It provides IT services and solutions across hardware infrastructure, cloud and virtualization, business continuity, sec
Cyber 50 Defense
Cyber 50 Defense is an UAE-based cybersecurity company offering governance, risk and compliance (GRC) solutions, 24/7 managed protection, security assessments, incident response, and compliance servic