# FOSSA > FOSSA is a software supply chain security company. Our platform helps engineering, security, and legal teams manage open source license compliance, software composition analysis (SCA), vulnerability remediation, and software bill of materials (SBOM) generation across the SDLC. FOSSA helps organizations manage open source software risk across license compliance, security vulnerabilities, software bills of materials, and related application-security workflows. Every public page on this site is also available as Markdown: append `.md` to any page URL. The site root is served at https://fossa.com/index.md. Markdown documents are generated from the same source as the HTML page and point back to it with a canonical link header. Content is proprietary to FOSSA, Inc. and available for reference with attribution: "Source: FOSSA — https://fossa.com". ## Start here - [FOSSA overview](https://fossa.com/index.md): What the FOSSA platform does and who it is for. - [Software composition analysis](https://fossa.com/learn/software-composition-analysis.md): What SCA is, how it works, and how to evaluate it. - [Software bill of materials](https://fossa.com/learn/sboms.md): SBOM data fields, use cases, formats, and management. - [Open source licenses](https://fossa.com/learn/open-source-licenses.md): How open source licenses work and what obligations they carry. - [Software supply chain security](https://fossa.com/learn/software-supply-chain-security.md): Threats to the software supply chain and the controls that address them. - [Pricing](https://fossa.com/pricing.md): FOSSA plans and what each includes. ## Products and capabilities - [FOSSA Scan](https://fossa.com/products/scan.md): Scanning for open source dependencies, licenses, and vulnerabilities. - [Binary composition analysis](https://fossa.com/products/binary-composition-analysis.md): Identifying open source inside compiled binaries and firmware. - [Snippets](https://fossa.com/products/snippets.md): Snippet-level detection of copied open source code. - [FOSSAbot](https://fossa.com/products/fossabot.md): Automated triage and remediation assistance. - [Free tools](https://fossa.com/products/tools.md): FOSSA's free developer and compliance tools. ## Solutions - [Open source license compliance](https://fossa.com/solutions/oss-license-compliance.md): Automating license policy, review, and attribution. - [SBOM management](https://fossa.com/solutions/sbom-management.md): Generating, storing, and sharing SPDX and CycloneDX SBOMs. - [Code security](https://fossa.com/solutions/code-security.md): Prioritizing and remediating open source vulnerabilities. - [Supplier risk management](https://fossa.com/solutions/supplier-risk-management.md): Assessing third-party and supplier software risk. - [Due diligence](https://fossa.com/solutions/due-diligence.md): Open source audits for M&A and transactions. - [Obsolescence management](https://fossa.com/solutions/obsolescence-management.md): Tracking unmaintained and end-of-life dependencies. - [AI coding guardrails](https://fossa.com/solutions/ai-coding-guardrails.md): Controls for AI-generated code entering the codebase. ## Regulations and compliance - [Regulatory compliance tools](https://fossa.com/resources/regulatory-compliance-tools.md): FOSSA's free tools for regulatory readiness. - [EU Cyber Resilience Act readiness assessment](https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment.md): A survey-based readiness assessment for the CRA. - [CRA vulnerability reporting](https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment/cra-vulnerability-reporting.md): The CRA's vulnerability reporting obligations. - [NTIA SBOM validator](https://fossa.com/resources/regulatory-compliance-tools/ntia-sbom-validator.md): Checking an SBOM against the NTIA minimum elements. - [SBOM compliance requirements](https://fossa.com/learn/sbom-compliance-requirements.md): Which regulations require SBOMs and what they ask for. ## Educational resources - [SPDX](https://fossa.com/learn/spdx.md): The SPDX SBOM standard. - [CycloneDX](https://fossa.com/learn/cyclonedx.md): The CycloneDX SBOM standard. - [Developer's guide to open source licenses](https://fossa.com/learn/developers-guide-open-source-software-licenses.md): License obligations from a developer's point of view. - [Open source license security in automotive](https://fossa.com/learn/open-source-license-security-automotive.md): License and security practice for automotive software. - [Android open source](https://fossa.com/learn/android-open-source.md): Open source considerations for Android development. - [Glossary](https://fossa.com/glossary.md): Definitions for software supply chain, compliance, and security terms. - [Implementation guides](https://fossa.com/resources/guides.md): CI/CD setup and integration guides. - [Blog](https://fossa.com/blog.md): Technical articles on open source security, license compliance, SBOMs, and regulation. ## Industries - [Medical devices](https://fossa.com/industries/medical-device.md): Open source risk management for medical device software. - [Manufacturing and automotive](https://fossa.com/industries/manufacturing-autos.md): Open source risk management for manufactured and vehicle software. - [Financial services](https://fossa.com/industries/financial-services.md): Open source risk management for financial services. ## Customer resources - [Customer stories](https://fossa.com/customers.md): How organizations use FOSSA. - [Resource library](https://fossa.com/resource-library.md): Reports, webinars, and guides. - [Black Duck alternatives](https://fossa.com/compare/black-duck-alternatives.md): Comparison of Black Duck alternatives. - [Partners](https://fossa.com/partners.md): FOSSA's partner program. ## Company information - [About FOSSA](https://fossa.com/about.md): Company mission and background. - [Trust and security](https://fossa.com/trust.md): FOSSA's security and trust posture. - [Careers](https://fossa.com/careers.md): Working at FOSSA. - [Press](https://fossa.com/press.md): Company news and press coverage. ## Content APIs - [Blog API](https://fossa.com/api/llms/blog): All blog posts as JSON with markdown content. - [Glossary API](https://fossa.com/api/llms/glossary): Glossary terms as JSON with definitions. - [Guides API](https://fossa.com/api/llms/guides): CI/CD setup and integration guides. - [Pillar Pages API](https://fossa.com/api/llms/pillar-pages): In-depth educational pages. - [Sitemap API](https://fossa.com/api/llms/sitemap): Structured content index. - [Full Export](https://fossa.com/api/llms/all): All content in one response. ## Complete Markdown index - [All machine-readable FOSSA resources](https://fossa.com/ai-index.md): Categorized directory of every Markdown document on the site. - [Markdown sitemap](https://fossa.com/sitemap-markdown.xml): Machine-readable list of every Markdown URL. ## Optional - [Full content (llms-full.txt)](https://fossa.com/llms-full.txt): Expanded plain-text index of all sections. - [Sitemap](https://fossa.com/sitemap.xml): Canonical HTML URL index. - [Contact](mailto:sales@fossa.com): Licensing and API access inquiries.