Cloudsmith Enterprise Artifact Management logo

    Cloudsmith Enterprise Artifact Management

    Sold by
    Cloudsmith is the only cloud-native, global, universal artifact management platform to securely develop and distribute software.

    Ratings and reviews

    4.5
    44 ratings
    2 star
    1 star
    75%
    20%
    5%
    0%
    0%
    0 AWS reviews
    |
    44 external reviews
    External reviews are from G2 .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (44)
    Dan M.

    Exemplary Support and an Easy Web UI That Boosts Team Efficiency

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    Cloudsmith's feature-set and their support are exemplary. They have been very fast to respond to suggestions and improvements we have requested, and are always quick to resolve any issues encountered. The new web-UI is very easy to use, and has helped our team be more efficient. I have very much valued the long-term relationship we have had with them.
    What do you dislike about the product?
    We could benefit from some more visibility of the redundancy and backups provided, especially when we place so much trust in storing valuable assets.
    What problems is the product solving and how is that benefiting you?
    Cloudsmith allow us to have a single controlled source of dependencies for our projects. This means we can control what dependencies can be used, and more easily audit them.
    Marketing and Advertising

    Cloudsmith: Effortless Artifact Management with Powerful Security Scanning

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    Cloudsmith is a cloud native and fully managed solution for artifact management. I don't have to operate anything special on my end, it just works. It provides me with a single source of truth for all of my artifacts with a rich feature set supporting all of the formats I use and more. I love the security scanning and BOM it provides out of the box. Other solutions support this but none of them can scan my build artifacts inside of the final Docker container product; they all require an intermediary package for scanning. This made it simple to update my build processes to simply point to Cloudsmith with no additional setup. The support team is also fantastic and made onboarding a breeze. They took the time and attention to understand our needs, make actionable recommendations, and made us aware of early access and preview features we were very excited to try out such as the Enterprise Policy Management. Lastly, everything is completely configurable with IaC using Terraform, from retention rules to policies we implement. I can't ask for a better tool. We were able to onboard and see value from the feature set within weeks of signing a contract.
    What do you dislike about the product?
    One feature we would really like is the ability to get a complete picture of all vulnerabilities for all packages as a single dashboard so we can provide this to our stakeholders as a self-serve option to see high-level risk with the ability to drill down into the details for developers to understand and address. This is the only major gap we've identified.
    What problems is the product solving and how is that benefiting you?
    Cloudsmith is the single source of truth for us and unifies several tools we were self managing. The operational overhead of self managed container storage, artifact bill of materials, and vulnerability scanning is now completely gone. Additionally, we use cooldown policies to protect both our supply chain and our developers from compromised packages in external, public repositories like NPM and PyPI. As the frequency of these attacks increase, we have the confidence that we will not be breached and need to respond to a security incident because of our supply chain.
    Benjamin J.

    Streamlined Artifact Management with Stellar Support

    Reviewed on Jun 04, 2026
    Review provided by G2
    What do you like best about the product?
    I use Cloudsmith for centralizing the storage, consumption, and distribution of internal and external artifacts at DPG Media. I appreciate that it offers a great balance between pricing and features without over-offering functionality. I really like their customer support because they are very approachable and helpful, just one click away within Slack. The UI is really intuitive, and they support a lot of package managers, which makes it very convenient. The initial setup was very easy thanks to the workshops and guidance from the team at Cloudsmith, making it a smooth sailing experience.
    What do you dislike about the product?
    A lot of 'solutions', usually for niche problems, are behind feature flags. So we often have to raise an issue before it gets fixed, but then it does usually get fixed quite quickly, even if there is no feature flag available for it yet. Also, authentication is a little buggy on the website.
    What problems is the product solving and how is that benefiting you?
    I use Cloudsmith to centralize storage, consumption, and distribution of artifacts with a balance of pricing and features without over-offering functionality.
    Semiconductors

    An Excellent Platform for a Secure Software Supply Chain

    Reviewed on Mar 18, 2026
    Review provided by G2
    What do you like best about the product?
    We adopted Cloudsmith as a modern, cloud‑native replacement for Artifactory to improve our software supply‑chain posture through mandatory authentication, fine‑grained access control, policy enforcement, and strong CI/CD integration. Our teams really value its broad support for package types (npm, NuGet, Docker, PyPI, raw binaries) and its ability to consolidate ingress mirroring, internal artifacts, and external distribution into a single platform, reducing fragmentation and bespoke solutions. The team at Cloudsmith has also been an incredible partner, working very closely with us on our migration as well as new features needed to meet our use cases.
    What do you dislike about the product?
    Moving from Artifactory with its file-system based organization of raw repos to Cloudsmith's label based organization can be tricky. Support for security scanning of AI models is not yet publicly available.
    What problems is the product solving and how is that benefiting you?
    It’s great to have all our packages in one central service, giving us clear visibility across our software supply chain. We really like the model of having a single repo be able to handle multiple package types/ecosystems as it greatly simplifies things for our developers.
    Rob G.

    Excellent Security and Support, Smooth Package Management

    Reviewed on Mar 18, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Cloudsmith offers excellent customer support, they are very hands-on, easy to get hold of and respond quickly. Good performance for everyone wherever they are located, which is great. Cloudsmith allows us to effectively manage our security posture, including defining policies for handling malicious packages, open source licensing and more.
    What do you dislike about the product?
    The UI refresh is nearing completion not complete quite yet, with some features only available in the older UI. It's just a few minor features that we still rely on, like the recycle bin.
    What problems is the product solving and how is that benefiting you?
    Cloudsmith helps us manage over 100,000 packages and images, improving our security by handling supply chain risks and vulnerabilities. It provides insights into package usage for better response to threats, and it supports our global teams with consistent performance.
    Karthik G.

    Unified Artifact Management with Strong Security

    Reviewed on Nov 18, 2025
    Review provided by G2
    What do you like best about the product?
    I highly appreciate Cloudsmith for its simplicity and comprehensive support for all artifact types, including Docker, PyPI, npm, and even raw files, which eliminates the need to juggle multiple registries and thereby reduces complexity and increases efficiency. The platform's cloud-native, fully managed nature functions as a centralized hub for securing, controlling, and distributing software assets globally. Moreover, Cloudsmith's built-in security features, such as automatic vulnerability scanning, license checks, and policy enforcement, impressively eliminate the need for additional tools, ensuring robust protection against supply-chain security risks. I am also highly satisfied with the universal format support provided by Cloudsmith, accommodating over 30 different formats, simplifying artifact management, and improving visibility by consolidating scattered artifacts into a single, easy-to-access repository. The CDN-backed delivery network augments this by ensuring speedy and reliable access to artifacts on a global scale. Overall, Cloudsmith addresses fragmented artifact management issues by offering an integrated solution that greatly enhances the modern software delivery and DevOps processes.
    What do you dislike about the product?
    I find the pricing model of Cloudsmith problematic. The pricing is based on bandwidth and storage, which can become expensive for teams with large artifacts or frequent downloads. Additionally, there’s a lack of personal experience with setup and usage due to the SaaS model, which may imply a non-intuitive onboarding process or lack of clarity in its native integrations.
    What problems is the product solving and how is that benefiting you?
    Cloudsmith centralizes artifact management, solving fragmentation by supporting 30+ formats and improving security with vulnerability scanning and policy enforcement, all while easing global distribution through a CDN network.
    Computer & Network Security

    The Swiss Army Knife Platform to manage dependencies

    Reviewed on Sep 26, 2025
    Review provided by G2
    What do you like best about the product?
    We use Cloudsmith for several purposes, including as an artifact repository and as a private Helm Chart repository. Integrating Cloudsmith with our pipelines has been very straightforward, and its Helm Chart repository feature allows us to securely and easily provide our charts to customers. We push and pull our built artifacts to Cloudsmith daily, and so far, we have not experienced any issues or downtime.
    Up until today, I have never had to interact with the customer support, because I didn't need to.
    What do you dislike about the product?
    Although the web UI is easy to use, I sometimes get the sense that something isn't quite right. I'm not a web designer, so I can't identify exactly what feels off.
    What problems is the product solving and how is that benefiting you?
    Cloudsmith helps us address two main challenges: sharing specific artifacts with customers after they have been built in our pipeline, and distributing private Helm charts to our clients. Both of these issues are effectively resolved due to the seamless integration between our CI system and Cloudsmith.
    Computer Software

    Easy to use artifact storage

    Reviewed on Jul 16, 2025
    Review provided by G2
    What do you like best about the product?
    What I like best about Cloudsmith is its support for a wide range of package formats like Docker, RPM, DEB, and more — it’s incredibly versatile and saves us time managing multiple repositories. I also really like the new web app; it's clean, modern, and intuitive to use, which makes everyday tasks much easier and more efficient.
    On top of that, having a direct Slack channel with the Cloudsmith developers has been incredibly helpful, their responsiveness and willingness to assist make a big difference.
    What do you dislike about the product?
    For the way I’ve used Cloudsmith so far, I’ve identified a few areas that could be improved:
    • Intermittent CI/CD install failures – our pipelines sometimes fail when adding repositories; a simple re‑run usually succeeds, but the flakiness costs time.
    • New web‑app usability – there’s no “select all packages on this page” option, and for DEB / RPM packages the target distribution and architecture aren’t immediately visible (both these were available in the old web-app).
    • Bulk deletion via API – it would be much handier to delete packages in groups instead of having to specify each one individually.
    • openSUSE repo re‑installation – reinstalling a repository that already exists fails on openSUSE, whereas the same action works on RHEL and Debian/Ubuntu.
    • Distinct RPM icons – SLES and RHEL packages use the same logo; separate icons would make them easier to tell apart.
    • Multi‑platform Docker copies – when copying a multi‑platform Docker image from one repo to another (via API or UI), only the primary image gets copied; the additional ones are left behind.
    What problems is the product solving and how is that benefiting you?
    Cloudsmith helps us solve the challenge of managing multiple types of artifacts in one place. We use it primarily as a repository manager and Docker registry, which allows us to centralize and secure our packages, streamline our CI/CD pipelines, and simplify customer access.
    Computer Software

    Reliable

    Reviewed on Jul 13, 2025
    Review provided by G2
    What do you like best about the product?
    Doesn't have frequent outages, pulls images as and when necessary
    What do you dislike about the product?
    nothing particular, it's pretty convenient to use
    What problems is the product solving and how is that benefiting you?
    We store binaries for our repositories
    Ryan L.

    Best of the bunch

    Reviewed on Jul 10, 2025
    Review provided by G2
    What do you like best about the product?
    Cloudsmith provides a simple UI to configure multiple internal and external repositories for various projects and repository types. We have some configured for our internal development uses and others for distributing artefacts and container images to customers.

    We moved to Cloudsmith from Sonatype Nexus repository OSS to gain support and move to a hosted solution. The onboarding was simple, and it was easy to get our CI pipelines integrated with the service.

    I particularly liked that Cloudsmith can handle the signing of RPMs, which previously was cumbersome and prone to breaking in our automated pipelines.

    The ability to throttle and limit individual entitlement tokens has also been a key tool for us.
    What do you dislike about the product?
    When we first started using Cloudsmith, on paper it seemed like it ticked a lot of boxes, with security scanning, audit logging and it would allow us to simplify all our disparate repository services into one. As we are a small ISV, we opted for the Pro plan, as $700 per month to host some artefacts seemed like a silly amount of money. We understood the usage-based limits of our plan; however, we quickly realised that many of the features we liked about Cloudsmith also required the next tier plan. Even things as simple as audit logs to identify excessive bandwidth use.

    Unfortunately, looking at the cost of artefact management solutions, it seems that this pricing is the norm. Whilst we like what Cloudsmith offers, the value for money doesn't quite stack up in the way it is currently priced.
    What problems is the product solving and how is that benefiting you?
    Consolidating multiple disprate repositories. Hosting artifacts and containers for customers and developers.