# FOSSA

> Automated open source dependency, license, and vulnerability management platform for controlling software supply chains

- **Canonical URI:** https://www.vioscale.ai/software/fossa
- **Category:** Dependency Management
- **Homepage:** https://fossa.com
- **Also known as:** fossa
- **Profile claimed by vendor:** no
- **Last updated:** 2026-08-25T08:42:35.353Z

## Vioscale score

**49.4 / 100**, confidence 56% (medium). Computed 2026-09-01.

Composite of weighted, independently-sourced signals (no user reviews, no vendor payment).

| Signal | Score | Weight | Contribution | Evidence present |
|---|--:|--:|--:|:--:|
| price_level | 50 | 0.052 | 2.6 | ✓ |
| reliability | 0 | 0.073 | 0 | - |
| capabilities | 86.7 | 0.04877777777777778 | 4.2 | ✓ |
| integrations | 29.9 | 0.04066666666666666 | 1.2 | ✓ |
| security_posture | 40 | 0.073 | 2.9 | ✓ |
| pricing_transparency | 45 | 0.084 | 3.8 | ✓ |

## Pricing

_As of 2026-08-25, [verify at source](https://fossa.com/pricing/). Independently observed._

from $20/project/mo · Subscription · Free tier

> Free plan available; Business from $20/project/month billed annually; Enterprise custom pricing

| Plan | Price | Free | Commitment |
|---|---|:--:|---|
| Free | Free | ✓ | - |
| Business | $20/project/month billed annually | - | annual |
| Enterprise | Contact sales | - | - |

### Free

For individuals and small teams getting started.

**Included limits:** projects: 5, imported_sboms: 5, quality_checks: 1, dependency_levels: 5

- Container scanning
- Identify dependencies at any depth
- Basic email support
- API access
- SaaS (multi-tenant cloud)
- Limited Filters
- Export SBOMs

### Business

For growing teams needing advanced compliance and security.

**Included limits:** projects: 10, imported_sboms: Unlimited, release_groups: 1, contributing_developers: 10

- Everything in Free, plus:
- Unlimited imported SBOMs
- Automated license and vulnerability scanning
- Multi-project reporting
- Priority support
- Full suite of quality checks

### Enterprise (Contact sales)

For organizations needing custom deployment and enterprise features.

**Included limits:** projects: Unlimited, dependency_levels: Unlimited

- Everything in Business, plus:
- Enterprise-grade SLAs
- Custom retention policies
- Advanced compliance reporting
- Enterprise-grade APIs
- Custom deployment options
- SSO
- Rules based access controls (RBAC)

### Add-ons

- **Snippet Scanning Add-On**
- **Binary Scanning Add-On**

## About

A platform that helps teams identify and manage open source dependencies across their codebase, enforce license compliance policies, detect and remediate security vulnerabilities, and generate regulatory-compliant software bills of materials (SBOMs).

_Independently observed._

## Platform & deployment

- **Platforms:** CLI, Web
- **Deployment:** Cloud / SaaS, On-premise, Self-hosted

## Integrations (10)

_Independently observed._

- GitHub
- CI/CD platforms
- Gradle
- Maven
- JavaScript/TypeScript ecosystems
- Python
- Golang
- Ruby
- Rust
- Kotlin

## Capabilities

_The capabilities that matter for Dependency Management. "-" = undocumented, not absent._

| Capability | Supported |
|---|:--:|
| **Capabilities** | |
| Update automation | ✓ |
| Vuln scanning | ✓ |
| Reachability analysis | ✗ |
| License compliance | ✓ |
| Sbom generation | ✓ |
| Ci gating | ✓ |
| Container image scanning | ✓ |
| Auto merge policy | ✗ |
| Open source | ✓ |

## Facts

Every value below carries its source and our confidence. Facts are re-crawled on a freshness schedule.

### integrations

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| integrations.count | 10 | [link](https://fossa.com/pricing/) | 2026-08-25 | 60% (medium) |

### market

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| market.availability | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | [link](https://fossa.com/pricing/) | 2026-08-25 | 50% (medium) |

### pricing

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| pricing.free_tier | yes | [link](https://fossa.com/pricing/) | 2026-08-25 | 60% (medium) |
| pricing.model | freemium | [link](https://fossa.com/pricing/) | 2026-08-25 | 60% (medium) |
| pricing.price_level | mid | [link](https://fossa.com/pricing/) | 2026-08-25 | 60% (medium) |
| pricing.starting_price | `{"amount":20,"currency":"USD"}` | [link](https://fossa.com/pricing/) | 2026-08-25 | 60% (medium) |
| pricing.transparent | no | [link](https://fossa.com/pricing/) | 2026-08-25 | 60% (medium) |

### security

| Attribute | Value | Source | Retrieved | Confidence |
|---|---|---|---|---|
| security.soc2 | yes | [link](https://fossa.com/resources/regulatory-compliance-tools/ntia-sbom-validator/) | 2026-08-25 | 75% (high) |

---
*Source: Vioscale (https://www.vioscale.ai/software/fossa). Independent, evidence-based software intelligence. Cite the canonical URI.*
