Black Duck vs FOSSA
Black DuckSoftware Composition Analysis
CustomPublished price
FOSSAVulnerability Scanning
Black Duck Software Composition Analysis Open source security and compliance. | FOSSA Vulnerability Scanning Open-source compliance and security. | |
|---|---|---|
| Overview | ||
| Category | Software Composition Analysis | Vulnerability Scanning |
| What it is | Black Duck provides software composition analysis that helps organizations manage security, quality, and license compliance risks from open-source and third-party code. | FOSSA is a software composition analysis platform that automates open-source license compliance, vulnerability scanning, and SBOM generation for enterprise development teams. |
| Pricing | ||
| Published price | Custom No public list price; quote-only, and AWS Marketplace listings are private-offer. Black Duck (formerly Synopsys' app-security business) SCA is sold by contract. Procurement benchm… | See FOSSA's website for pricing. Plans scale by team size and usage. |
| Pricing model | Custom quote | Tiered plans |
| Free options | No free plan · Free trial | Free plan · Free trial |
| Deal on Cubbie | None right now | None right now |
| Company | ||
| Founded | 2002 | 2015 |
| Team size | 1001-5000 employees | 51-200 employees |
| Headquarters | Burlington, Massachusetts | San Francisco, California |
| Featured clients | BMW, Siemens, Bosch | Uber, Yelp, Siemens |