/Companies

Fossa

San Francisco, US · Founded 2015 · 61 employees on LinkedIn · 10 known investors

Find your way into Fossa

Each arrow is one introduction. Sign up to fill in the first one.

843 people can intro you to Kevin

Ask Kevin Wang to introduce you to Kevin Wang

You →Kevin · together at Codecov →Kevin

Sign up to find every way you can get introduced to Fossa

  • Your email: who you already know at Fossa, and who your contacts know
  • 2nd- and 3rd-degree connections: people you know who worked, studied or invested with the Fossa team
  • Your LinkedIn: the connections who can make the intro for you

We rank every route by how warm it is, so you raise on warm intros instead of cold emails.

FOSSA provides audit-grade open source license compliance software that scans codebases with full-text analysis to detect licenses, enforce policies, and automatically generate attribution documents. It serves both developer and legal teams by integrating license scanning into CI/CD pipelines and development workflows.

Also known as FOSSA

Founders & leadership

Fossa was founded in 2015 by Kevin Wang.

KWKevin Wang
Kevin WangFounder & ChairmanKevin Wang is the founder and CEO of FOSSA, which provides open source license compliance scanning and enforcement software for development teams.

Investors · 10

Funding

SEC filings, press & company announcements

Source: company announcements and press reports — follow each round's link for the claim.

Company profile

researched Aug 2026

FOSSA develops software that helps organizations manage risk in third-party and open source code across the software development lifecycle. The platform scans packages, containers, SBOMs, binaries, and code snippets to identify open source components, detect license obligations, and surface security vulnerabilities, with support advertised for major programming languages, frameworks, and CI/CD runtimes.

The product workflow is organized around four stages: scanning dependencies across the SDLC, preventing issues through automated policy enforcement, remediating vulnerabilities, license problems, and end-of-life components through guided fixes, and reporting via generated SBOMs and license attribution notices. Stated use cases include reducing legal and intellectual property risk, consolidating vulnerability management across security scanning tools, meeting regulatory SBOM reporting requirements, and keeping dependencies up to date. The company has also introduced fossabot, an AI agent for strategic dependency updates.

Business model

FOSSA sells a software platform to organizations, positioning enterprise support and fast onboarding; prospective users can start with a free trial that includes full feature access without a credit card, and sales are supported by demo requests with company experts.

Latest developments

FOSSA announced fossabot, an AI agent for strategic dependency updates, and published customer stories covering software transparency and compliance programs at Omnissa, Sentry, UiPath, and Collibra.

▸Full profile — market position, technology, go-to-market

Market position

Positioned as a developer-first software supply chain management platform spanning license compliance, vulnerability management, and SBOM reporting, citing use by CNCF projects and enterprise software vendors.

Emphasizes developer-first usability, automation, broad artifact and ecosystem coverage, fast insights, and audit-grade compliance reporting, alongside SOC 2 compliance and enterprise support.

Technology

Scanning and analysis across multiple artifact types — packages, containers, SBOMs, binaries, and snippets — combined with automated policy enforcement, guided remediation, SBOM and attribution report generation, and integrations spanning major programming languages, frameworks, and CI/CD runtimes.

Go-to-market

Direct enterprise sales through demo requests, supported by a self-serve free trial, published customer case studies, developer documentation, and adoption among open source foundation projects.

Engineering, developer, security, and legal stakeholders at software-producing organizations, including large enterprises and open source projects; referenced users include Omnissa, Sentry, UiPath, Collibra, and CNCF projects such as Prometheus and Kubernetes.

Compiled by commissioned research from 1 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
HeadcountAug 202661
SOC 2 complianceJan 2025SOC 2 compliant

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Founder mafia

The Fossa mafia →

6 people who came through Fossa went on to found or lead other companies.

Timeline · 1

launches, deals, and filings
Jan 2025
Launch of fossabot, an AI agent for dependency updates

FOSSA announced fossabot, an AI agent focused on strategic dependency updates.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

In the news

▸Research sources · 1

primary sources listed

1 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Fossa do?
FOSSA offers software supply chain tooling for open source license compliance, vulnerability management, and SBOM generation.
Who founded Fossa?
Fossa was founded by Kevin Wang in 2015.
Who are Fossa's investors?
Fossa's investors include Bain Capital Ventures, Canvas Ventures, Metaplanet, Modern Technical, Norwest Venture Partners, Uncorrelated Ventures, 1517, Costanoa Ventures and 2 more.
Where is Fossa headquartered?
Fossa is headquartered in San Francisco, US.