Listing Thumbnail

    JFrog Software Supply Chain Platform

     Info
    Sold by: JFrog 
    Deployed on AWS
    The only platform to give you end-to-end visibility, security, and control for automating delivery of trusted releases.
    4.2

    Overview

    Trusted by millions of developers, engineers, architects, and security professionals at thousands of enterprises, including the majority of the Fortune 100, the cloud-native JFrog Software Supply Chain Platform is the single source of truth for all software packages, data, and ML models utilized and generated in the development process.

    The JFrog Platform on AWS manages all software inputs and outputs, providing organizations with complete visibility across their supply chain. This flexible, massively scalable, and hybrid platform helps improve developer efficiency by reducing wait times from builds to security scans. It allows organizations to take to the clouds with agility, leveraging both managed and self-managed instances. Critically, it enables teams to manage application risk end-to-end by applying evidence-based policies across the SDLC. Finally, the JFrog Platform helps accelerate AI/ML pipelines by treating models like a package, simplifying AI development and ensuring the success of initiatives.

    Contact JFrog at cloud@jfrog.com  for private offers on annual subscriptions, or visit <www.jfrog.com/pricing > for more information.

    The JFrog Platform is often leveraged to consolidate enterprise DevSecOps solutions for companies utilizing GitLab, Sonatype, Snyk, or Veracode, among other solutions. Key capabilities include:

    • Universal artifact management with JFrog Artifactory
    • Modern, holistic SCA with JFrog Xray
    • Contextual analysis of vulnerabilities with JFrog Advanced Security
    • Early blocking of malicious open source packages with JFrog Curation
    • Application risk governance with JFrog AppTrust
    • Control and govern AI/ML development with JFrog ML
    • Simplify model discovery and access with JFrog AI Catalog
    • AI-assisted remediation with Agentic Software Supply Chain Security
    • Real-time Kubernetes security monitoring with JFrog Runtime
    • Speed up secure software consumption with JFrog Distribution
    • IoT device management with JFrog Connect
    • Includes 24x7 Support and in-region 99.99% uptime SLA, plus an assigned support resource with regular touch points

    Highlights

    • 50+ natively supported package and file types, including ML models and generic repositories.
    • Comprehensive, enterprise-grade security solution integrated across the entire SDLC, eliminating tool sprawl and alert fatigue. Go beyond scanning with contextual analysis and vulnerability prioritization, anti-tampering mechanisms, and signed provenance, ensuring best practices and compliance.
    • Fast, secure distribution of verified, multi-repository release bundles to sync large-scale geo-distributed teams and accelerate deployments to any target: SaaS, self-managed, or connected devices.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    JFrog Software Supply Chain Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (2)

     Info
    Dimension
    Cost/month
    Pro
    $50.00
    Enterprise X
    $950.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/unit
    JFrog Consumption Unit
    $0.01

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    24/7 SLA support service@jfrog.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Continuous Integration and Continuous Delivery, Application Development, Security
    Top
    50
    In Agile Lifecycle Management
    Top
    10
    In Source Control

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Artifact Repository Management
    Universal artifact management supporting 50+ natively supported package and file types, including ML models and generic repositories.
    Software Composition Analysis
    Modern, holistic software composition analysis with contextual vulnerability analysis and prioritization across the software development lifecycle.
    Supply Chain Security Governance
    Application risk governance with evidence-based policy enforcement, anti-tampering mechanisms, and signed provenance across the entire software development lifecycle.
    Secure Artifact Distribution
    Fast, secure distribution of verified, multi-repository release bundles with geo-distributed synchronization capabilities to multiple deployment targets.
    AI-Powered Predictive Analytics
    Generate predictive insights across the software lifecycle to enable data-driven decision making and smarter software investments.
    Unified DevOps and Security Integration
    Integrate DevOps and security capabilities across the full software lifecycle to enable continuous delivery with built-in protections against tampering, reverse-engineering, and application-based attack vectors.
    Enterprise Agile Planning and Scaling
    Scale agile practices across all organizational levels from individual teams to entire product portfolios with consistency and efficiency.
    Multi-Environment Application Deployment
    Deploy applications to any target environment including mainframes, virtual machines, containers, and cloud platforms with support for thousands of simultaneous deployments and automatic rollback capabilities.
    Continuous Testing at Scale
    Enable enterprise-level testing with increased test coverage across web and mobile applications to deliver high-quality, error-free software.
    Universal Package Format Support
    Support for 30 package formats enabling organizations to create a single source of truth for artifact management across diverse software types.
    Dependency Firewall with Vulnerability Scanning
    Caching of packages from open-source repositories with vulnerability scanning and policy compliance validation before distribution to developers.
    Zero Trust Security Architecture
    Automated zero-trust workflows across services, teams and users for controlling software intellectual property and mitigating risks.
    Cloud-Native Global Distribution
    Fully managed, cloud-native architecture optimized for fast and reliable artifact delivery across distributed teams and geographic locations.
    ISO27001 Accreditation and Access Control
    ISO27001 accredited platform with comprehensive access management, compliance enforcement and security best practices implementation.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    151 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    52%
    41%
    5%
    1%
    1%
    6 AWS reviews
    |
    145 external reviews
    External reviews are from G2  and PeerSpot .
    ANSHU R.

    Reliable and Scalable for CI/CD Workflows

    Reviewed on Jun 15, 2026
    Review provided by G2
    What do you like best about the product?
    I like JFrog for its ability to centralize artifact management and integrate seamlessly with CI/CD workflows. The artifact traceability is extremely valuable because it helps us quickly identify which build version was deployed, reducing troubleshooting time during incidents. JFrog is reliable, scalable, and makes release management more organized across multiple environments. The platform improves deployment reliability and version consistency, and it is a valuable solution for teams managing modern DevOps workflows.
    What do you dislike about the product?
    One area that could be improved is the learning curve for new users. Some administrative configurations and advanced repository management features can be complex to understand initially. Additionally, troubleshooting permission-related issues sometimes requires deeper knowledge of the platform. More guided documentation and simplified onboarding for new users would make adoption easier.
    What problems is the product solving and how is that benefiting you?
    JFrog centralizes artifact management, integrates with our CI/CD pipelines, ensures deployment consistency, and improves artifact traceability across releases, making troubleshooting and release management easier.
    Saurabh B.

    Effective Version Management, Needs Improved Pricing

    Reviewed on Jun 13, 2026
    Review provided by G2
    What do you like best about the product?
    I find the experience with JFrog fine as of now. I use it for handling images and specifically for taking the immediate made of the newer version and working back, which is helpful for the tasks I do. The initial setup was quite easy and we didn't face any difficulty.
    What do you dislike about the product?
    Your work on pricing. You can work on a subscription plan, because it is highly expensive for startups, individual developers, and smaller organizations. I want you to make it a smart input for small startups. Also, you can introduce a modern UI in your JSON so that it will be better.
    What problems is the product solving and how is that benefiting you?
    I use JFrog for managing variables for a newer version of our product, saving data, and adding new engines.
    G Srivastava

    Centralized artifact management has accelerated global releases and simplified version rollbacks

    Reviewed on Jun 11, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I primarily used JFrog Artifactory  for package management because it provides a remote proxy and caching that helped accelerate our release lifecycle and made our releases much easier and faster. We were uploading all of our artifacts to this repository, and it provides build tools like Maven. Since we were using the JBoss application, uploading our JAR and WAR files directly to JFrog Artifactory  really helped us deploy applications in a fast manner.

    Earlier, we used Git  and GitHub  for our version control system and uploaded all our JAR and WAR files directly to GitHub . However, when we discovered that JFrog Artifactory is a tool that helps in directly uploading all those artifacts, the versioning feature stood out to us. It also provides the build tool within itself, so we do not need to build the source code individually or on another system. As soon as we discovered these features in JFrog Artifactory, we switched to using it, and it has helped us with many releases. For example, if we deployed the application today on version one and the artifacts for version one are already stored in JFrog Artifactory, after a couple of days if we need to add other features, it will be version two and we need not commit again and again or undo the commit to get the release. We simply deploy our changes and version two is created in JFrog Artifactory, and if we want to roll back those changes, we can simply click from version two to version one and the changes are rolled back.

    We have used JFrog Artifactory in a limited capacity, as they have many other features but that depends on their cost and models. We used the free version earlier and then moved to the Pro version.

    What is most valuable?

    JFrog Artifactory offers many features, but the system's stability stands out the most to me since whenever we want to use those artifacts, they are almost always available globally. I work from India and my colleagues work from Europe or the USA and they can also access those artifacts without issues. It is a great tool for managing binaries across different environments such as Development, QA, Prod, Non-prod, and SIT, handling all those environments without issues, and it provides very good security and access control if we are using the Pro version, allowing us to monitor who made changes and when. We started using it with Docker , which also helps in managing and distributing our Docker  images, so that is a very great feature.

    In our day-to-day operations, we were using Docker since we had the chance to containerize our application, so we were using a repo server to manage all those images. However, JFrog Artifactory has the feature to keep those images within itself, making it very easy for us to keep all those images in one place. This was the feature we started using once we discovered it. Regarding security and access control, we can easily trace changes. For example, if I work on an application today and make changes, a version one is created for this application and tomorrow a colleague makes some changes creating version two. My manager can easily identify the changes I made versus my colleague's changes with the help of traceability and access control on the system.

    Since we started using JFrog Artifactory, we no longer manage our own server just to keep source code and binary code. All our binary repositories are in JFrog Artifactory, so I can say it is a very good repository manager. This is where we can store all our artifacts without needing to find another server or directory, and it is very easily accessible so we do not have to wait for JFrog Artifactory to be down or for our application to be unavailable. We have not experienced that. Another very good feature is that it provides a proxy for remote applications, enabling us to use build tools not available within our intranet, allowing us to compile our source code into binary code easily, which has transformed our release process to be faster.

    What needs improvement?

    I think JFrog Artifactory already has good features and has evolved since its inception, incorporating AI/ML and supporting Kubernetes  and Docker images. JFrog Artifactory is progressing well, and I do not see many other features according to my requirements that are needed. I would only suggest that the cost could be reduced for older customers or made consumption-based so that more people can opt for it.

    The user interface can be better. It has evolved significantly since I started using JFrog Artifactory, so it can improve further.

    I choose a nine out of ten because, as mentioned in my previous answer, it sometimes faces performance issues due to slow repository response and long download times for artifacts, which affects overall performance. That is why I feel it needs improvement to achieve a perfect ten.

    For how long have I used the solution?

    I have used JFrog Artifactory for over one year in my previous company.

    What do I think about the stability of the solution?

    In my experience, JFrog Artifactory is stable and available for usage most of the time globally. It does have performance issues at times for certain locations, but overall, it has been a very good experience.

    What do I think about the scalability of the solution?

    We have effectively used JFrog Artifactory within a good team of ten to twelve people. However, there are performance issues when two or three people are using it simultaneously for our code, which results in performance lags.

    How are customer service and support?

    We have utilized support from JFrog Artifactory, which has been very good. Opening a ticket on the customer portal yields a response, especially if using the Pro or Enterprise version. For the free trial, support is unavailable, but the assistance we received was fast and helpful, with easy tracking of ticket status and history on their portal.

    Which solution did I use previously and why did I switch?

    We previously used Git  and GitHub, which just stored repositories and artifacts, but without the additional features JFrog Artifactory offers. Hence, we switched from GitHub to JFrog Artifactory.

    How was the initial setup?

    The setup was very easy, and the setup cost was reasonable. We started with a free trial before moving to the Pro version, which costs around one hundred dollars per month for us. We had a ticket with the support team, who provided very good discounts, although I cannot share the specifics, but they were very helpful.

    What about the implementation team?

    We have definitely seen a return on investment in terms of savings. Money has been saved through intelligent utilization. It has positively impacted both money and time saved, facilitating the downloading of artifacts and uploading of source code into a central repository easily. Thus, there is no need for more than two or three people to manage it, making it a cost-saving solution.

    What was our ROI?

    We have definitely seen a return on investment in terms of savings. Money has been saved through intelligent utilization. It has positively impacted both money and time saved, facilitating the downloading of artifacts and uploading of source code into a central repository easily. Thus, there is no need for more than two or three people to manage it, making it a cost-saving solution.

    What's my experience with pricing, setup cost, and licensing?

    The setup was very easy, and the setup cost was reasonable. We started with a free trial before moving to the Pro version, which costs around one hundred dollars per month for us.

    Which other solutions did I evaluate?

    We have not tried any other options besides Git and GitHub. Once we started working with JFrog Artifactory, we never looked back.

    What other advice do I have?

    If you want to minimize efforts in compiling source code without frequently downloading and maintaining a server, you should definitely consider JFrog Artifactory. They offer vast tools for different coding environments such as Maven and NuGet, and they are continuously evolving, adding support for Docker images and Kubernetes . Companies utilizing Docker or Kubernetes will benefit significantly from a reliable tool to compile their source code into binary code. I recommend trying JFrog Artifactory once because you will probably start loving it. I have rated this product as a nine out of ten.

    Suji R.

    Simplifies Dependency Management for Faster, More Reliable Builds

    Reviewed on Jun 10, 2026
    Review provided by G2
    What do you like best about the product?
    Best thing is how it simplifies dependency management Our build are faster and more reliable because package is centrally managed and cached without worrying about missing dependencies
    What do you dislike about the product?
    I guess it’s all fine for now. As a developer I am good with jfrog. The only thing I can think of right now is time taking to understand and learn, otherwise good.
    What problems is the product solving and how is that benefiting you?
    Instead of all the developers that n Ed’s downloading libraries directly from maven central repository, artifactory acts as a central repository. This reduce build failures
    Information Technology and Services

    Jfrog- Artifact management

    Reviewed on Jun 10, 2026
    Review provided by G2
    What do you like best about the product?
    - JFrog Artifactory is a very reliable artifact repos and works with many package types like npm, docker, python and more.
    - UI is clean and easy to use for daily work.
    - It integrates well with popular CI/CD tools like Jenkins, GitHub Actions.
    - Features like caching and high availability help it perform well even for large teams and organizations.
    - The starting price is reasonable, but enterprise plans can become expensive.
    - Documentation is helpful, and support is good.
    - JFrog has strong AI and security features. Xray helps scan ML models and detect security risks
    What do you dislike about the product?
    - One thing I don't like about Jfrog is that it can feel complex, especially for new users.
    - The UI is okay but not very modern, and it takes some time to understand all the features.
    - The pricing can also increase quickly when you add products like Xray and other enterprise features.
    What problems is the product solving and how is that benefiting you?
    - JFrog helps manage all artifacts in one place instead of using different repo for npm, docker, python and other package types. This is making it easier to manage dependencies and releases across different projects.

    - For my team, it has helped improve build reliability and made artifact management much simpler.
    - Features like caching improve build performance, and Xray helps identify security issues early in the development process.

    Overall, it reduces manual effort, improves security, and helps keep the development process more organized.
    View all reviews