Overview
Trusted by millions of developers, engineers, architects, and security professionals at thousands of enterprises, including the majority of the Fortune 100, the binary-centric JFrog Platform is the single system of record for software releases. All software development inputs and outputs flow through and are managed by JFrog, providing organizations complete visibility across their software supply chain. This provides a central point of control for standardizing, securing, and automating the process of delivering trusted software.
The massively scalable, hybrid JFrog Platform on AWS is flexible and integrated with all the software package technologies and tools comprising the modern software supply chain. Organizations benefit from full traceability to any type of release and deployment environment including ML models, software that runs on the edge, and software deployed in production data centers.
Contact JFrog at cloud@jfrog.com for private offers on annual subscriptions, or visit <www.jfrog.com/pricing/#public-marketplace-aws > for more information on pricing.
As the single system of record for secure, automated software releases, the JFrog Platform is often leveraged to consolidate enterprise DevSecOps solutions for companies utilizing GitLab, Sonatype, Snyk, or Veracode, among other notable solutions. Key capabilities include:
- Universal artifact management with JFrog Artifactory
- Modern, holistic SCA with JFrog Xray
- Deep scanning for real-world risk analysis and exposure discovery with JFrog Advanced Security
- Early blocking of malicious open source packages with JFrog Curation
- Control and govern AI/ML development with JFrog ML
- Speed up secure software consumption with JFrog Distribution
- IoT device management with JFrog Connect
- Agentic AI-driven automation with JFrog MCP Server
- Includes 24x7 Support and uptime SLA, plus an assigned support resource with regular touch points
Highlights
- 40+ natively supported package and file types, including ML models and generic repositories.
- Comprehensive, enterprise-grade security solution integrated across the entire SDLC, eliminating tool sprawl and alert fatigue. Go beyond scanning with contextual analysis and vulnerability prioritization, anti-tampering mechanisms, and signed provenance, ensuring best practices and compliance.
- Fast, secure distribution of verified, multi-repository release bundles to sync large-scale geo-distributed teams and accelerate deployments to any target: on-premises, cloud, or connected devices.
Details
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Contact service@jfrog.comÂ
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
24/7 SLA support service@jfrog.comÂ
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Supports a wide variety of packages with robust security features but needs tighter cloud integration
What is our primary use case?
JFrog Artifactory is designed for software management. We used it for storing all assets and packages that were downloaded from external package systems, making them available for our development teams to use in their builds.
It primarily supported a fail-fast approach, where vulnerabilities were identified ahead of time, enabling us to alert our development team to use the latest packages without those vulnerabilities.
JFrog Artifactory proved very helpful in supporting a variety of package types for different projects.
What is most valuable?
The best features of JFrog Artifactory include the core functionality of package management and software management, along with scanning capabilities to prevent vulnerabilities from being introduced.
The metadata management feature was particularly useful for managing packages within JFrog Artifactory.
We utilized Xray integration with JFrog Artifactory, which was instrumental in managing vulnerabilities overall.
JFrog Artifactory has robust functionality in terms of access control, which helped us ensure minimal access to various artifacts.
I would rate it eight out of ten because it is a great product that is widely used in the industry. It has excellent features from an artifact management perspective and maintains good integrations.
What needs improvement?
JFrog could improve this product with tighter integration capabilities.
For how long have I used the solution?
I used JFrog Artifactory in the last twelve months.
How are customer service and support?
I would rate their support for JFrog Artifactory as seven out of ten.
How would you rate customer service and support?
Positive
What other advice do I have?
I am no longer using JFrog Artifactory in my current role as I moved away from the team. The metadata management features were very useful, particularly for managing packages inside JFrog Artifactory. We were customers of JFrog. Based on my experience, I would rate JFrog Artifactory eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Perplexing Engineering
2. Ability to support various out-of-the-box registry support
2. Cloud Pro account requires business email but logging in from Github works with personal account (perplexing access policies)
3. JFrog CLI is separately downloadable and configurable, the use of which remains a big mystery since we can use cURL to do pretty much everything in Artifacts (again perplexing strategy)
4. Setting multiple Repositories is required for simple task of pulling packages from public registries
JFrog for devops
Scans for vulnerabilities across your artifacts.
Easy to use.
Works with Jenkins, GitHub Actions and other cicd.
Available on-prem, in the cloud, suitable for all types of deployments.
Tracks metadata, dependencies, and environment details for every build.
Need to invest much time to learn about how things works in jFrog.
Complex to work compared to other tools
2. Container images repository.
3. Package management.
4. Backup repository for container images.
5. For federating other repositories.
My JFrog Experience
2. Supports hybrid cloud environments and is offered as SaaS or on-premises.
3. Easily integrates with Jenkins, GitHub Actions, and other CI/CD tools to manage artifacts.
4. Stores build artifacts in a centralized, versioned including Docker images.
5. Supports a variety of package formats Maven, Gradle, and npm.
6. Serves as a private Docker registry for safely managing and storing container images.
2. Comparatively high cost with other of same type
3. Customer support delays sometimes
1. Artifact management in on-prem and cloud.
2. Storing artifacts in repos of jfrog
3. Seamless Integration with CICD
4. Global Federation with all other jfrog deployments
My Go-To Artifactory
1. Supports all major package types: Maven, npm, Docker, PyPI, NuGet, Helm, Go, and gz
2. Integrates with CI/CD tools and deployment systems.
3.Keeps track of all versions of artifacts and rollback support.
4. Very good access control.
5.Designed for large-scale enterprise use.
6.Available on-prem, in the cloud, or as a hybrid solution.
7. Automate everything from artifact uploads to repository management.
2. performance issues sometimes
3. time taken to leaning is high
2. Docor Repository
3. Package management
4. Version control for some external zip files
and many