Listing Thumbnail

    JFrog Software Supply Chain Platform

     Info
    Sold by: JFrog 
    Deployed on AWS
    Automate trusted releases across the agentic software supply chain
    4.2

    Overview

    Limited time offer: Get JFrog Pro for just $50/month, a $100/month savings. Available only through June 4, 2027.

    Trusted by millions of developers, engineers, architects, and security professionals at thousands of enterprises, including the majority of the Fortune 100, the cloud-native JFrog Software Supply Chain Platform is the single system of record for all software packages, data, and AI assets across the software supply chain.

    The JFrog Platform on AWS manages every input and output across your software supply chain with complete visibility and control. This massively scalable, fit-for-purpose platform is available as a fully managed SaaS, self-managed, and hybrid solution, giving organizations the deployment flexibility this AI era demands. By embedding security and evidence-based governance directly into development workflows from the first line of code to runtime, JFrog enables trusted, risk-mitigated releases without slowing teams down. And as your software factory evolves, JFrog governs every AI model, agent skill, and MCP server alongside traditional artifacts in one place, securing your entire agentic software supply chain.

    JFrog Enterprise subscriptions include 24x7 Support and optional in-region 99.99% uptime SLA, plus an assigned support resource with regular touch points. The JFrog Platform is often leveraged to consolidate enterprise DevSecOps solutions for companies utilizing GitLab, Sonatype, Snyk, or Veracode, among others. Contact JFrog at  cloud@jfrog.com  for private offers on annual subscriptions, or visit < www.jfrog.com/pricing > for more information.

    Key products and capabilities:

    • JFrog Artifactory: Universal artifact management
    • JFrog Xray: Modern, holistic SCA
    • JFrog Advanced Security: Contextual analysis of vulnerabilities
    • JFrog Curation: Early blocking of malicious open source packages
    • JFrog AppTrust: Application risk governance
    • JFrog ML: Control and govern AI/ML development
    • JFrog AI Catalog: Detect, secure, and control every AI asset
    • JFrog Runtime: Real-time Kubernetes security monitoring
    • JFrog Distribution: Speed up secure software consumption
    • JFrog Connect: IoT device management

    Highlights

    • 60+ natively supported package and file types, including ML models and generic repositories.
    • Comprehensive, enterprise-grade security solution integrated across the entire software supply chain, eliminating tool sprawl and alert fatigue. Go beyond scanning with contextual analysis and vulnerability prioritization, anti-tampering mechanisms, and signed provenance, ensuring best practices and compliance.
    • Fast, secure distribution of verified, multi-repository release bundles to sync large-scale geo-distributed teams and accelerate deployments to any target: SaaS, self-managed, or connected devices.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    JFrog Software Supply Chain Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (2)

     Info
    Dimension
    Cost/month
    Pro
    $50.00
    Enterprise X
    $950.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/unit
    JFrog Consumption Unit
    $0.01

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    24/7 SLA support service@jfrog.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Continuous Integration and Continuous Delivery, Application Development, Security
    Top
    50
    In Agile Lifecycle Management
    Top
    10
    In Source Control

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Universal Artifact Management
    Support for 60+ natively supported package and file types, including ML models and generic repositories across the software supply chain.
    Integrated Security Analysis
    Comprehensive security solution with contextual vulnerability analysis, vulnerability prioritization, anti-tampering mechanisms, and signed provenance integrated across the entire software supply chain.
    Supply Chain Visibility and Control
    Single system of record providing complete visibility and control over all inputs and outputs across the software supply chain with evidence-based governance embedded in development workflows.
    Secure Software Distribution
    Fast, secure distribution of verified multi-repository release bundles with capability to sync large-scale geo-distributed teams and accelerate deployments to SaaS, self-managed, or connected devices.
    AI and ML Asset Governance
    Control and governance of AI models, agent skills, and MCP servers alongside traditional artifacts with detection, security, and control capabilities for every AI asset.
    AI-Powered Predictive Analytics
    Generate predictive insights across the software lifecycle to enable data-driven decision making and smarter software investments.
    Unified DevOps and Security Integration
    Integrate DevOps and security capabilities across the full software lifecycle to enable continuous delivery with built-in protections against tampering, reverse-engineering, and application-based attack vectors.
    Enterprise Agile Planning and Scaling
    Scale agile practices across all organizational levels from individual teams to entire product portfolios with consistency and efficiency.
    Multi-Environment Application Deployment
    Deploy applications to any target environment including mainframes, virtual machines, containers, and cloud platforms with support for thousands of simultaneous deployments and automatic rollback capabilities.
    Continuous Testing at Scale
    Enable enterprise-level testing with increased test coverage across web and mobile applications to deliver high-quality, error-free software.
    Universal Package Format Support
    Support for 30 package formats enabling organizations to create a single source of truth for artifact management across diverse software types.
    Dependency Firewall with Vulnerability Scanning
    Caching of packages from open-source repositories with vulnerability scanning and policy compliance validation before distribution to developers.
    Zero Trust Security Architecture
    Automated zero-trust workflows across services, teams and users for controlling software intellectual property and mitigating risks.
    Cloud-Native Global Distribution
    Fully managed, cloud-native architecture optimized for fast and reliable artifact delivery across distributed teams and geographic locations.
    ISO27001 Accreditation and Access Control
    ISO27001 accredited platform with comprehensive access management, compliance enforcement and security best practices implementation.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    163 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    53%
    41%
    4%
    1%
    1%
    6 AWS reviews
    |
    157 external reviews
    External reviews are from G2  and PeerSpot .
    SUMAN K.

    JFrog Excels for CI/CD, Vulnerability Scanning, and Software Distribution

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    JFrog works best when you need CI/CD or want to scan your entire software for vulnerabilities. Our team has been using it for those purposes, and also for managing software distribution.
    What do you dislike about the product?
    I mainly face two major issues: first, the pricing; and second, it takes a lot of resources to run. Also, there’s a pretty steep learning curve for newcomers.
    What problems is the product solving and how is that benefiting you?
    The best things it helps us achieve are high availability and local caching. And by using CI/CD, it also helps us deploy faster than any other available options.
    Anonymous

    User-Friendly with Dynamic Image Management

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    I find JFrog to be simple and user-friendly, which really helps with managing images. It creates a separate folder for every feature build, making it easy to identify which image is mine. This feature is very user-friendly and solves the big issue of managing images. With 10 to 20 repositories, each having around 100 to 200 images, JFrog serves as a one-stop place for image management. Overall, I find it very helpful and I like that about JFrog.
    What do you dislike about the product?
    I mean, I use JFrog in our company's network. Basically, most of the time, JFrog is very slow. The website is very slow, and it takes a lot of time to load.
    What problems is the product solving and how is that benefiting you?
    I find JFrog solves image management problems by dynamically fetching images to run in our ECS cluster without packaging the code, which simplifies execution. It's user-friendly, with separate folders for easy image identification, managing numerous repos and images effectively.
    Ankit J.

    Best Artifactory for Secure, Safe Deployment Containers

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    Its the best artifactory for keeping the deployment containers secured and safe. Their AI ML engine js also very great based on the time I have used it for.
    What do you dislike about the product?
    Nothing as such for my case the supply and chain management is really great and much appreciated in the IT industry asi got to know about this service from my provider.
    What problems is the product solving and how is that benefiting you?
    Dependency Hell" and Fragmentation: Developers use multiple languages (Python, Java, Go). Managing different packages across separate tools is chaotic. JFrog solves this by acting as a single, universal repository for all package types.
    Rahul D.

    Scalable Artifact Management with Strong Security Scanning and CI/CD Integration

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    I like JFrog most for its artifact management and security scanning. It makes handling binaries smooth, integrates well with CI/CD pipelines, and adds strong, reliable vulnerability checks for DevOps teams, even though it can feel a bit complex for beginners.

    In short: scalable, secure, and integration-friendly.
    What do you dislike about the product?
    I dislike that JFrog can feel complex to use for beginners, with a steep learning curve. Its pricing is also on the higher side compared to alternatives, and some users find the reporting features limited when it comes to advanced analytics.
    What problems is the product solving and how is that benefiting you?
    JFrog helps solve the challenge of managing artifacts across the software lifecycle. Rather than dealing with scattered binaries and dependencies, it offers a centralized repository that keeps everything organized, tracked, and properly versioned.

    It also addresses security vulnerabilities by scanning artifacts and containers, which supports safer releases. In addition, its CI/CD integration streamlines pipelines, cutting down on manual work and helping teams deliver faster.

    Overall, the result is smoother DevOps workflows, fewer security risks, and quicker, more reliable software releases.
    Megha C.

    Reliable Artifact Manager with Seamless CI/CD Integration

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    I like JFrog because it securely stores all artifacts in one place, integrates seamlessly with CI/CD pipelines, and manages artifact versions. This makes deployments more reliable, simplifies rollbacks, and helps the team use the same tested build across all environments. I also find its integration with Jenkins particularly effective. JFrog is reliable for artifact management, supports version control, and makes deployments consistent and easy to manage. Using JFrog in the CI/CD pipeline was quite easy once the repository and credentials were set up.
    What do you dislike about the product?
    I find JFrog's UI challenging as a beginner, and setting up permissions can be complex for me in large environments.
    What problems is the product solving and how is that benefiting you?
    I securely store artifacts with JFrog, integrating with CI/CD for reliable deployments and consistency across environments. It makes rollbacks easy but I find the UI tough as a beginner, and managing permissions and repositories gets complex in large setups.
    View all reviews