Listing Thumbnail

    JFrog Software Supply Chain Platform

     Info
    Sold by: JFrog 
    Deployed on AWS
    The only platform to give you end-to-end visibility, security, and control for automating delivery of trusted releases.
    4.2

    Overview

    Trusted by millions of developers, engineers, architects, and security professionals at thousands of enterprises, including the majority of the Fortune 100, the cloud-native JFrog Software Supply Chain Platform is the single source of truth for all software packages, data, and ML models utilized and generated in the development process.

    The JFrog Platform on AWS manages all software inputs and outputs, providing organizations with complete visibility across their supply chain. This flexible, massively scalable, and hybrid platform helps improve developer efficiency by reducing wait times from builds to security scans. It allows organizations to take to the clouds with agility, leveraging both managed and self-managed instances. Critically, it enables teams to manage application risk end-to-end by applying evidence-based policies across the SDLC. Finally, the JFrog Platform helps accelerate AI/ML pipelines by treating models like a package, simplifying AI development and ensuring the success of initiatives.

    Contact JFrog at cloud@jfrog.com  for private offers on annual subscriptions, or visit <www.jfrog.com/pricing > for more information.

    The JFrog Platform is often leveraged to consolidate enterprise DevSecOps solutions for companies utilizing GitLab, Sonatype, Snyk, or Veracode, among other solutions. Key capabilities include:

    • Universal artifact management with JFrog Artifactory
    • Modern, holistic SCA with JFrog Xray
    • Contextual analysis of vulnerabilities with JFrog Advanced Security
    • Early blocking of malicious open source packages with JFrog Curation
    • Application risk governance with JFrog AppTrust
    • Control and govern AI/ML development with JFrog ML
    • Simplify model discovery and access with JFrog AI Catalog
    • AI-assisted remediation with Agentic Software Supply Chain Security
    • Real-time Kubernetes security monitoring with JFrog Runtime
    • Speed up secure software consumption with JFrog Distribution
    • IoT device management with JFrog Connect
    • Includes 24x7 Support and in-region 99.99% uptime SLA, plus an assigned support resource with regular touch points

    Highlights

    • 50+ natively supported package and file types, including ML models and generic repositories.
    • Comprehensive, enterprise-grade security solution integrated across the entire SDLC, eliminating tool sprawl and alert fatigue. Go beyond scanning with contextual analysis and vulnerability prioritization, anti-tampering mechanisms, and signed provenance, ensuring best practices and compliance.
    • Fast, secure distribution of verified, multi-repository release bundles to sync large-scale geo-distributed teams and accelerate deployments to any target: SaaS, self-managed, or connected devices.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    JFrog Software Supply Chain Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (2)

     Info
    Dimension
    Cost/month
    Pro
    $50.00
    Enterprise X
    $950.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/unit
    JFrog Consumption Unit
    $0.01

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    24/7 SLA support service@jfrog.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Continuous Integration and Continuous Delivery, Application Development, Security
    Top
    50
    In Agile Lifecycle Management
    Top
    10
    In Source Control

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Artifact Repository Management
    Universal artifact management supporting 50+ natively supported package and file types, including ML models and generic repositories.
    Software Composition Analysis
    Modern, holistic software composition analysis with contextual vulnerability analysis and prioritization across the software development lifecycle.
    Supply Chain Security Governance
    Application risk governance with evidence-based policy enforcement, anti-tampering mechanisms, and signed provenance across the entire software development lifecycle.
    Secure Artifact Distribution
    Fast, secure distribution of verified, multi-repository release bundles with geo-distributed synchronization capabilities to multiple deployment targets.
    AI-Powered Predictive Analytics
    Generate predictive insights across the software lifecycle to enable data-driven decision making and smarter software investments.
    Unified DevOps and Security Integration
    Integrate DevOps and security capabilities across the full software lifecycle to enable continuous delivery with built-in protections against tampering, reverse-engineering, and application-based attack vectors.
    Enterprise Agile Planning and Scaling
    Scale agile practices across all organizational levels from individual teams to entire product portfolios with consistency and efficiency.
    Multi-Environment Application Deployment
    Deploy applications to any target environment including mainframes, virtual machines, containers, and cloud platforms with support for thousands of simultaneous deployments and automatic rollback capabilities.
    Continuous Testing at Scale
    Enable enterprise-level testing with increased test coverage across web and mobile applications to deliver high-quality, error-free software.
    Universal Package Format Support
    Support for 30 package formats enabling organizations to create a single source of truth for artifact management across diverse software types.
    Dependency Firewall with Vulnerability Scanning
    Caching of packages from open-source repositories with vulnerability scanning and policy compliance validation before distribution to developers.
    Zero Trust Security Architecture
    Automated zero-trust workflows across services, teams and users for controlling software intellectual property and mitigating risks.
    Cloud-Native Global Distribution
    Fully managed, cloud-native architecture optimized for fast and reliable artifact delivery across distributed teams and geographic locations.
    ISO27001 Accreditation and Access Control
    ISO27001 accredited platform with comprehensive access management, compliance enforcement and security best practices implementation.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    147 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    52%
    41%
    5%
    1%
    1%
    6 AWS reviews
    |
    141 external reviews
    External reviews are from G2  and PeerSpot .
    G Srivastava

    Centralized artifact management has accelerated global releases and simplified version rollbacks

    Reviewed on Jun 11, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I primarily used JFrog Artifactory  for package management because it provides a remote proxy and caching that helped accelerate our release lifecycle and made our releases much easier and faster. We were uploading all of our artifacts to this repository, and it provides build tools like Maven. Since we were using the JBoss application, uploading our JAR and WAR files directly to JFrog Artifactory  really helped us deploy applications in a fast manner.

    Earlier, we used Git  and GitHub  for our version control system and uploaded all our JAR and WAR files directly to GitHub . However, when we discovered that JFrog Artifactory is a tool that helps in directly uploading all those artifacts, the versioning feature stood out to us. It also provides the build tool within itself, so we do not need to build the source code individually or on another system. As soon as we discovered these features in JFrog Artifactory, we switched to using it, and it has helped us with many releases. For example, if we deployed the application today on version one and the artifacts for version one are already stored in JFrog Artifactory, after a couple of days if we need to add other features, it will be version two and we need not commit again and again or undo the commit to get the release. We simply deploy our changes and version two is created in JFrog Artifactory, and if we want to roll back those changes, we can simply click from version two to version one and the changes are rolled back.

    We have used JFrog Artifactory in a limited capacity, as they have many other features but that depends on their cost and models. We used the free version earlier and then moved to the Pro version.

    What is most valuable?

    JFrog Artifactory offers many features, but the system's stability stands out the most to me since whenever we want to use those artifacts, they are almost always available globally. I work from India and my colleagues work from Europe or the USA and they can also access those artifacts without issues. It is a great tool for managing binaries across different environments such as Development, QA, Prod, Non-prod, and SIT, handling all those environments without issues, and it provides very good security and access control if we are using the Pro version, allowing us to monitor who made changes and when. We started using it with Docker , which also helps in managing and distributing our Docker  images, so that is a very great feature.

    In our day-to-day operations, we were using Docker since we had the chance to containerize our application, so we were using a repo server to manage all those images. However, JFrog Artifactory has the feature to keep those images within itself, making it very easy for us to keep all those images in one place. This was the feature we started using once we discovered it. Regarding security and access control, we can easily trace changes. For example, if I work on an application today and make changes, a version one is created for this application and tomorrow a colleague makes some changes creating version two. My manager can easily identify the changes I made versus my colleague's changes with the help of traceability and access control on the system.

    Since we started using JFrog Artifactory, we no longer manage our own server just to keep source code and binary code. All our binary repositories are in JFrog Artifactory, so I can say it is a very good repository manager. This is where we can store all our artifacts without needing to find another server or directory, and it is very easily accessible so we do not have to wait for JFrog Artifactory to be down or for our application to be unavailable. We have not experienced that. Another very good feature is that it provides a proxy for remote applications, enabling us to use build tools not available within our intranet, allowing us to compile our source code into binary code easily, which has transformed our release process to be faster.

    What needs improvement?

    I think JFrog Artifactory already has good features and has evolved since its inception, incorporating AI/ML and supporting Kubernetes  and Docker images. JFrog Artifactory is progressing well, and I do not see many other features according to my requirements that are needed. I would only suggest that the cost could be reduced for older customers or made consumption-based so that more people can opt for it.

    The user interface can be better. It has evolved significantly since I started using JFrog Artifactory, so it can improve further.

    I choose a nine out of ten because, as mentioned in my previous answer, it sometimes faces performance issues due to slow repository response and long download times for artifacts, which affects overall performance. That is why I feel it needs improvement to achieve a perfect ten.

    For how long have I used the solution?

    I have used JFrog Artifactory for over one year in my previous company.

    What do I think about the stability of the solution?

    In my experience, JFrog Artifactory is stable and available for usage most of the time globally. It does have performance issues at times for certain locations, but overall, it has been a very good experience.

    What do I think about the scalability of the solution?

    We have effectively used JFrog Artifactory within a good team of ten to twelve people. However, there are performance issues when two or three people are using it simultaneously for our code, which results in performance lags.

    How are customer service and support?

    We have utilized support from JFrog Artifactory, which has been very good. Opening a ticket on the customer portal yields a response, especially if using the Pro or Enterprise version. For the free trial, support is unavailable, but the assistance we received was fast and helpful, with easy tracking of ticket status and history on their portal.

    Which solution did I use previously and why did I switch?

    We previously used Git  and GitHub, which just stored repositories and artifacts, but without the additional features JFrog Artifactory offers. Hence, we switched from GitHub to JFrog Artifactory.

    How was the initial setup?

    The setup was very easy, and the setup cost was reasonable. We started with a free trial before moving to the Pro version, which costs around one hundred dollars per month for us. We had a ticket with the support team, who provided very good discounts, although I cannot share the specifics, but they were very helpful.

    What about the implementation team?

    We have definitely seen a return on investment in terms of savings. Money has been saved through intelligent utilization. It has positively impacted both money and time saved, facilitating the downloading of artifacts and uploading of source code into a central repository easily. Thus, there is no need for more than two or three people to manage it, making it a cost-saving solution.

    What was our ROI?

    We have definitely seen a return on investment in terms of savings. Money has been saved through intelligent utilization. It has positively impacted both money and time saved, facilitating the downloading of artifacts and uploading of source code into a central repository easily. Thus, there is no need for more than two or three people to manage it, making it a cost-saving solution.

    What's my experience with pricing, setup cost, and licensing?

    The setup was very easy, and the setup cost was reasonable. We started with a free trial before moving to the Pro version, which costs around one hundred dollars per month for us.

    Which other solutions did I evaluate?

    We have not tried any other options besides Git and GitHub. Once we started working with JFrog Artifactory, we never looked back.

    What other advice do I have?

    If you want to minimize efforts in compiling source code without frequently downloading and maintaining a server, you should definitely consider JFrog Artifactory. They offer vast tools for different coding environments such as Maven and NuGet, and they are continuously evolving, adding support for Docker images and Kubernetes . Companies utilizing Docker or Kubernetes will benefit significantly from a reliable tool to compile their source code into binary code. I recommend trying JFrog Artifactory once because you will probably start loving it. I have rated this product as a nine out of ten.

    Suji R.

    Simplifies Dependency Management for Faster, More Reliable Builds

    Reviewed on Jun 10, 2026
    Review provided by G2
    What do you like best about the product?
    Best thing is how it simplifies dependency management Our build are faster and more reliable because package is centrally managed and cached without worrying about missing dependencies
    What do you dislike about the product?
    I guess it’s all fine for now. As a developer I am good with jfrog. The only thing I can think of right now is time taking to understand and learn, otherwise good.
    What problems is the product solving and how is that benefiting you?
    Instead of all the developers that n Ed’s downloading libraries directly from maven central repository, artifactory acts as a central repository. This reduce build failures
    Computer Software

    Artifactory’s Offline Mode Feels Complex for Air-Gapped Deployments

    Reviewed on Jun 10, 2026
    Review provided by G2
    What do you like best about the product?
    I think it does a lot more as a repository management system. I based msr 2 and 3 and frog artifactoey definitely does a lot more than msr. Not sure about msr 4 since its built on top of harbor.
    What do you dislike about the product?
    I think Jfrog Artifactory offline mode can be complex like any airgapped deployments. Haven't touched it in couple years though.

    I also did struggle with deployment when I tried few years back. The deployment guide was complex even for someone with 3 to 4 years of technical experience.
    What problems is the product solving and how is that benefiting you?
    The only problem jfrog is solving for use Mirantis people i guess is being able to perform A/B testing and compare how MSR 4 stacks up to jfrog artifactory.

    Sorry if this response doesn't help.
    Akash v.

    Secure, Cloud-Native DevSecOps Platform Built for Enterprise Scale

    Reviewed on Jun 09, 2026
    Review provided by G2
    What do you like best about the product?
    It feels very secure. The platform helps organizations manage, secure, and automate software delivery from development through production. I also appreciate the company’s strong focus on DevSecOps, software supply chain security, and support for modern cloud-native environments, which all feel highly relevant to where the industry is heading.
    What do you dislike about the product?
    I wouldn’t say this is a dislike, but one challenge with JFrog is that the platform is extremely comprehensive. For new users, or for organizations that are still early in their DevOps journey, that breadth of capabilities can come with a real learning curve. Still, it’s often the trade-off for having a powerful platform that can support complex enterprise needs at scale.
    What problems is the product solving and how is that benefiting you?
    JFrog addresses the challenge of managing and securing the software supply chain. Modern applications rely on thousands of libraries, containers, packages, and deployment artifacts, and without strong controls, organizations can quickly run into problems with version management, security vulnerabilities, compliance requirements, and unreliable releases.

    JFrog offers a unified platform to manage artifacts, automate CI/CD pipelines, scan for vulnerabilities, and maintain traceability across the software development lifecycle. In my view, this enables teams to ship software faster while also strengthening security and improving overall reliability.
    Abhinav G.

    User-Friendly with Minor Performance Lag

    Reviewed on Jun 08, 2026
    Review provided by G2
    What do you like best about the product?
    I like JFrog's fast responses and how its UI is user-friendly, making it easy to use for me. The initial setup was easy, thanks to the straightforward and well-documented instructions on their website. Installing JFrog on my MacBook was simple.
    What do you dislike about the product?
    The response can be a bit faster. I feel it's slow at times. Sometimes I click and it takes time, or I have to reload the page. So somewhere, it's lagging. More refactoring is needed inside.
    What problems is the product solving and how is that benefiting you?
    I use JFrog for my day-to-day tasks, and it makes my life easy.
    View all reviews