SCANOSS Logo

SCANOSS

Software Composition Analysis for open source component identification and SBOM

Product
Application Security
GRC
Vulnerability Management
API

450+ Data Points Per Product and Company

Track competitive landscapes, evaluate vendor risk for investments, or find the right security stack for your clients.

Request Access

SCANOSS Description

SCANOSS provides Software Composition Analysis (SCA) tools and services focused on identifying open source components in software projects. The company operates an Open Source Software Knowledge Base (OSS KB) that is universally accessible through open APIs and distributed by the Software Transparency Foundation. Their platform enables organizations to detect both declared and undeclared open source software in their codebases, including code introduced through copy/paste or AI assistants. The company's core offering centers on building comprehensive Software Bills of Materials (SBOM) for development teams and businesses. Their technology integrates into development pipelines and delivery processes to provide visibility into software composition. SCANOSS addresses compliance requirements by helping organizations understand licensing terms, manage intellectual property risks, and meet export regulations associated with open source components. SCANOSS supports multiple open source initiatives and standards organizations including the Eclipse Foundation, OpenChain Project, FOSSology, and Software Heritage. The company's approach emphasizes open standards and open data in the SCA landscape. Their solutions are designed for industries with complex software development needs, including video game companies and enterprises with stringent compliance requirements. The platform helps organizations manage security vulnerabilities, ensure license compliance, and maintain transparency in their software supply chains.