banner background
swampup unibrow 26 desktop main
  • Pricing
En Fr 日本語 简体中文
Kostenlos starten
Resources
Learn
JFrog Academy JFrog Certifications Webinars & Workshops Demo Center Software Supply Chain Topics
Explore
Resource Center JFrog Blog Customer Stories Security Research State of the Union Report Events
Support & Services
Customer Success
DevOps Consulting Services Support Manage &Troubleshoot
Account & Trust
JFrog Documentation My JFrog Cloud Status JFrog Trust
Partners
JFrog Partner Ecosystem Discover our network of channel, technology, cloud partners.
Channel Partner Finder Connect with a JFrog Channel Partner in your region.
Technology Partner Integrations Accelerate software delivery with native technology integrations.
Partner Login
Community Check out JFrog’s community, review expert resources, get latest community news, and more
Documentation See the latest product documentation, research JFrog offerings and get answers on how to configure and use JFrog products
Integrations Learn how to integrate JFrog products with 100+ providers such as ServiceNow, GitHub, NVIDIA, Sonar and more
Support Open a ticket, get assistance or search for answers with JFrog Support and FAQs.

AI Overview

See More

Your agents are only as trustworthy as what they consume, build, and ship. JFrog governs every AI model, agent skill, MCP server, AI-generated code, and assembled artifact in a single source of truth.

Secure your entire agentic software supply chain so you can ship trusted software at your new speed.

Learn More
JFrog AI Products
JFrog ML
JFrog ML Build, Train, Secure, Deploy, Serve and Monitor ML Models and GenAI
JFrog AI Catalog Discover, Govern and Secure Your AI Ecosystem
New Capabilities
MCP Registry
MCP Governance and Security at Enterprise Scale
Agent Skills Registry
Enterprise governed skills for trusted AI agents
Agentic AI
Zero Configuration, Agentic Software Delivery for Small Teams.
Learn More
JFrog Agentic Solutions
Model Lifecycle Management (MLOps) Data Engineering & Feature Management (DataOps) AI/ML Development and Deployment MLSecOps Agentic Remediation Centralized AI Control & Governance (AI Catalog)
JFrog AI Ecosystems
NVIDIA Cursor GitHub
JFrog AI Resources
Agentic Software Supply Chain Security: AI-Assisted Curation and Remediation How to Detect and Eliminate Shadow AI in 5 Steps Beyond Models: JFrog AI Catalog Evolves to Detect Shadow AI and Govern MCPs AppTrust, AI Catalog, and more – Live product showcase from JFrog MLOps Masterclass: Gain end-to-end control and governance over your AI/ML Workloads From Chaos to Control: Future-Proof Your AI Supply Chain See More Resources
Use Case
AI/ML
Model Lifecycle Management (MLOps) Data Engineering & Feature Management (DataOps) AI/ML Development and Deployment MLSecOps Agentic Remediation Centralized AI Control & Governance (AI Catalog)
DevSecOps
Holistic Software Supply Chain Security Curate Open-Source Packages Source Code Scanning (SAST) Software Composition Analysis (SCA) Secrets Detection Infrastructure as Code (IaC) Security
DevOps
Developer Experience Artifact Management Tool Consolidation Release Lifecycle Management
Device/IoT
Connected Device Management
Cloud Solutions
Flexible Cloud Deployment Solutions
Integrations
ServiceNow GitHub NVIDIA
Docker Maven See all integrations
Industry
Financial Services Public Sector Technology Healthcare
Gaming Automotive Enterprise

The JFrog Platform

Deliver Trusted Software with Speed

The only software supply chain platform to give you end-to-end visibility, security, and control for automating delivery of trusted releases. Bring together DevOps, DevSecOps and MLOps teams in a single source of truth.
View Platform
DevOps
JFrog Artifactory Universal Artifact & ML Model Repository Manager
JFrog Distribution Secure Distribution Across Consumption Points
JFrog Connect IoT Device Management with DevOps Agility
DevSecOps
JFrog Curation Seamlessly Curate Software Packages & ML Models
JFrog Security
Essentials (Xray)
Integrated SCA for Software & AI Artifacts
JFrog Advanced Security Supply Chain Exposure Scanning & Impact Analysis
JFrog Runtime Real-time visibility into runtime vulnerabilities
DevGovOps
JFrog AppTrust Application Risk Governance
AI/ML
JFrog ML Build, Train, Serve and Monitor AI/ML Models
JFrog AI Catalog Discover, Govern and Secure Your AI Ecosystem
New Capabilities
MCP Registry
MCP Governance and Security at Enterprise Scale
Agent Skills Registry
Enterprise governed skills for trusted AI agents

Zero Configuration, Agentic Software Delivery for Small Teams.

Learn More
Community
Dokumentation
Integrationen
Anwendungen
Anwendungsfall
Cloud-Lösungen
Flexible Cloud-Bereitstellungslösungen
AI/ML
Zentralisierte Kontrolle & Governance Ihrer KI (AI Catalog) Lebenszyklus-Management von ML-Modellen (MLOps) Data Engineering und Feature-Management (DataOps) MLSecOps
DevOps
Entwicklererfahrung Artefakt-Management Tool-Konsolidierung Release-Lifecycle-Management
DevSecOps
Agentic Remediation Durchgängig sichere Softwarelieferkette Kuratieren von Open-Source-Paketen Scannen von Quellcode (SAST) Software Composition Analysis (SCA) Secrets Detection Sicherheit bei Infrastructure as Code (IaC)
Gerät/IoT
Verwaltung vernetzter Geräte
Integrationen
ServiceNow GitHub NVIDIA
Docker Maven Alle Integrationen anzeigen
Industrie
Finanzdienstleistungen Öffentlicher Sektor Technologie Gesundheitswesen
Gaming Automobil

Vertrauenswürdige Software schnell bereitstellen

Die einzige Software-Lieferkettenplattform, die Ihnen End-to-End-Transparenz, Sicherheit und Kontrolle für die automatisierte Bereitstellung von vertrauenswürdigen Releases bietet. Bringen Sie Ihre DevOps-, DevSecOps- und MLOps-Teams in einer Single Source of Truth zusammen.
Plattform ansehen
DevOps
JFrog Artifactory Universeller Artefakt- und ML-Modell-Repository-Manager
JFrog Distribution Sichere Verteilung über Verbrauchsstellen hinweg
JFrog Connect IoT-Gerätemanagement mit DevOps-Flexibilität
DevSecOps
JFrog Curation Nahtlose Kuratierung von Softwarepaketen und ML-Modellen
JFrog Security Essentials (Xray) Integrierte SCA für Software- und KI-Artefakte
JFrog Advanced Security Scannen von Risiken der Software-Lieferkette & Impact-Analyse
JFrog Runtime Echtzeit-Einblick in Laufzeit-Schwachstellen
DevGovOps
JFrog AppTrust Application Risk Governance
KI/ML
JFrog AI Catalog Entdecken, steuern und sichern Sie Ihr KI-Ökosystem
JFrog ML Erstellen, Trainieren, Bereitstellen und Überwachen von KI/ML-Modellen

Konfigurationsfreie, agentengestützte Softwarebereitstellung für kleine Teams.

Mehr erfahren
  • The JFrog Platform

    Deliver Trusted Software with Speed

    The only software supply chain platform to give you end-to-end visibility, security, and control for automating delivery of trusted releases. Bring together DevOps, DevSecOps and MLOps teams in a single source of truth.
    View Platform
    DevOps
    JFrog Artifactory Universal Artifact & ML Model Repository Manager
    JFrog Distribution Secure Distribution Across Consumption Points
    JFrog Connect IoT Device Management with DevOps Agility
    DevSecOps
    JFrog Curation Seamlessly Curate Software Packages & ML Models
    JFrog Security
    Essentials (Xray)
    Integrated SCA for Software & AI Artifacts
    JFrog Advanced Security Supply Chain Exposure Scanning & Impact Analysis
    JFrog Runtime Real-time visibility into runtime vulnerabilities
    DevGovOps
    JFrog AppTrust Application Risk Governance
    AI/ML
    JFrog ML Build, Train, Serve and Monitor AI/ML Models
    JFrog AI Catalog Discover, Govern and Secure Your AI Ecosystem
    New Capabilities
    MCP Registry
    MCP Governance and Security at Enterprise Scale
    Agent Skills Registry
    Enterprise governed skills for trusted AI agents

    Zero Configuration, Agentic Software Delivery for Small Teams.

    Learn More
  • Use Case
    AI/ML
    Model Lifecycle Management (MLOps) Data Engineering & Feature Management (DataOps) AI/ML Development and Deployment MLSecOps Agentic Remediation Centralized AI Control & Governance (AI Catalog)
    DevSecOps
    Holistic Software Supply Chain Security Curate Open-Source Packages Source Code Scanning (SAST) Software Composition Analysis (SCA) Secrets Detection Infrastructure as Code (IaC) Security
    DevOps
    Developer Experience Artifact Management Tool Consolidation Release Lifecycle Management
    Device/IoT
    Connected Device Management
    Cloud Solutions
    Flexible Cloud Deployment Solutions
    Integrations
    ServiceNow GitHub NVIDIA Docker Maven See all integrations
    Industry
    Financial Services Public Sector Technology Healthcare Gaming Automotive Enterprise
  • AI Overview

    Your agents are only as trustworthy as what they consume, build, and ship. JFrog governs every AI model, agent skill, MCP server, AI-generated code, and assembled artifact in a single source of truth.

    Secure your entire agentic software supply chain so you can ship trusted software at your new speed.
    Learn More
    JFrog AI Products
    JFrog ML
    JFrog ML Build, Train, Secure, Deploy, Serve and Monitor ML Models and GenAI
    JFrog AI Catalog Discover, Govern and Secure Your AI Ecosystem
    New Capabilities
    MCP Registry
    MCP Governance and Security at Enterprise Scale
    Agent Skills Registry
    Enterprise governed skills for trusted AI agents
    Agentic AI

    Zero Configuration, Agentic Software Delivery for Small Teams.

    Learn More
    JFrog Agentic Solutions
    Model Lifecycle Management (MLOps) Data Engineering & Feature Management (DataOps) AI/ML Development and Deployment MLSecOps Agentic Remediation Centralized AI Control & Governance (AI Catalog)
    JFrog AI Ecosystems
    NVIDIA Cursor GitHub
    JFrog AI Resources
    Agentic Software Supply Chain Security: AI-Assisted Curation and Remediation How to Detect and Eliminate Shadow AI in 5 Steps Beyond Models: JFrog AI Catalog Evolves to Detect Shadow AI and Govern MCPs AppTrust, AI Catalog, and more – Live product showcase from JFrog MLOps Masterclass: Gain end-to-end control and governance over your AI/ML Workloads From Chaos to Control: Future-Proof Your AI Supply Chain See More Resources
  • Community Check out JFrog’s community, review expert resources, get latest community news, and more
    Documentation See the latest product documentation, research JFrog offerings and get answers on how to configure and use JFrog products
    Integrations Learn how to integrate JFrog products with 100+ providers such as ServiceNow, GitHub, NVIDIA, Sonar and more
    Support Open a ticket, get assistance or search for answers with JFrog Support and FAQs.
  • Resources
    Learn
    JFrog Academy JFrog Certifications Webinars & Workshops Demo Center Software Supply Chain Topics
    Explore
    Resource Center JFrog Blog Customer Stories Security Research State of the Union Report Events
    Support & Services
    Customer Success
    DevOps Consulting Services Support Manage &Troubleshoot
    Account & Trust
    JFrog Documentation My JFrog Cloud Status JFrog Trust
    Partners
    JFrog Partner Ecosystem Discover our network of channel, technology, cloud partners.
    Channel Partner Finder Connect with a JFrog Channel Partner in your region.
    Technology Partner Integrations Accelerate software delivery with native technology integrations.
    Partner Login
  • Pricing
  • Self Hosted Terms and Conditions
    • Self Hosted Terms and Conditions
    • JFrog License Agreements and Terms of Service – Previous Versions
  • Cloud Terms and Conditions
    • Cloud Terms and Conditions
    • JFrog License Agreements and Terms of Service – Previous Versions
  • JFROG SUBSCRIPTION AGREEMENT – HYBRID
  • JFrog ML Addendum
  • About Box
  • Support
    • Standard SLA
    • Gold Support Service & SLA
    • Platinum Support Service & SLA
  • Privacy and Security
    • JFrog Cloud Data Processing Addendum
    • JFrog Cloud Data Security Addendum
    • JFrog Trust Center
    • JFrog Privacy Center
    • JFrog-Datenschutzrichtlinie
    • JFrog Cookie Policy
  • JFrog Consulting Services Agreement
  • JFrog Brand Guidelines
  • Terms of Use
  • JFrog Acceptable Use Policy
  • JFrog Agreement – Trial
  • JFrog FLY Agreement
  • JFrog AI Addendum
  • JFrog EU Data Act Addendum
  • Cloud Terms and Conditions – Monthly
  • JFrog Premium Availability (99.99%) Addendum

JFrog Cloud Data Security Addendum

Last Updated: August 01, 2024

This JFrog Cloud Data Security Addendum (“DSA” or “TOMs”) describes the technical and organizational security measures (TOMs) that JFrog maintains to protect Customer Data (including Personal Data, as applicable) and Confidential Information. JFrog reserves the right to update the DSA, at its sole discretion, where updates will not materially degrade the security protocols or security levels in place as of the Effective Date during the applicable Subscription Term. Changes will be reflected at https://jfrog.com/jfrog-toms. This DSA forms part of the JFrog Agreement between JFrog and Customer and applies to Self-Hosted Subscriptions as applicable. Any capitalized terms which are not defined herein, shall have the meaning provided to them in the Agreement or the DPA.

  1. JFrog Security Program
    JFrog has implemented and maintains appropriate administrative, technical, physical, and organizational measures to ensure a level of security appropriate to the level of risk, in accordance with industry standards. JFrog maintains security policies, standards, and controls related to security, confidentiality, integrity, and availability. These policies are reviewed and approved annually and updated as needed.
  2. Certificate Program / Security Certifications
    JFrog maintains the following certifications and governance methods:
    1. Certification under ISO/IEC 27001:2013, ISO/IEC 27701:2019, ISO 27017:2014, and SOC 2, Type 2.
    2. Annual security audits by an independent third party, covering security, confidentiality, and availability control criteria.
    3. Regularly tests and monitors the effectiveness of its information security program through internal audits aligned with the relevant compliance controls and frameworks. Issues identified are documented, tracked, and remediated as appropriate.
  3. Access and Authentication Controls
    JFrog has implemented and maintains the following measures:
    1. Access Control Policy in accordance with the “least privileges” and “need to know” principles.
    2. Strict role-based permissions are granted in accordance with the role requirements.
    3. Access permissions are reviewed on a regular basis. Any access which is inappropriate for a role function is promptly removed.
    4. Access to JFrog systems and networks are disabled promptly upon notification in the event of termination of personnel.
    5. Unique usernames and passwords with minimum length and complexity requirements are enforced for all users.
    6. Two-factor authentication (2FA) is required for remote access and privileged account access.
    7. Physical access to JFrog facilities is restricted and requires a key-card, access is logged and maintained. Visitors are accompanied at all times and confidentiality measures are in place. Additional measures include video surveillance and other industry-standard practices.
    8. Services operate on a multitenant architecture designed to segregate and restrict access to Customer Data hosted on the JFrog platform. JFrog architecture provides a logical data separation for each different Customer via a unique ID.
  4. HR, Security, Training and Awareness
    JFrog has implemented and maintains the following measures:
    1. Background checks are conducted commensurate with job duties, in accordance with applicable laws and regulations.
    2. Personnel are subjected to non-disclosure or confidentiality obligations.
    3. Personnel are required to complete security awareness and privacy training during onboarding and at least annually thereafter.
    4. Personnel are required to review and acknowledge security policies during onboarding and annually thereafter.
    5. Periodic security and privacy awareness campaigns aimed to further educate personnel about their responsibilities.
  5. Risk Management and Infrastructure Control
    JFrog has implemented and maintains the following measures:
    1. JFrog Management reviews documented risks to determine appropriate risk levels and treatment options.
    2. Encryption and Key Management: Industry-standard encryption techniques (TLS 1.2 for data in transit and 256-bit AES for data at rest). Encryption keys are managed in a cloud-hosted key management service (KMS).
    3. Threat and Vulnerability Management: Continuous monitoring, annual penetration tests, and ongoing vulnerability scans are performed to identify and remediate potential threats. Patches are applied regularly after testing for safety. Vulnerabilities are classified based on the Common Vulnerability Scoring System (CVSS), a remediation plan is developed, including the steps required to address the vulnerability and the timeline for completion based on the remediation time for each severity level.
    4. Logging and Monitoring: Monitoring tools and services are used to monitor systems for various events. Logs are stored securely and reviewed by the security team utilizing Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) technology.
    5. Network Security: Zero-Trust Security Technology to prevent unauthorized access to JFrog networks, servers, or applications.
    6. Cloud Security: Utilization of cloud provider-managed DDoS mitigation services, next-generation Web Application Firewall (WAF), API protection, advanced rate limiting, and bot protection. These measures are designed to safeguard against various types of cyber threats. Regular cloud security scanning tools are employed, including advanced Cloud Security Posture Management (CSPM) solutions, to enforce security best practices and mitigate potential misconfigurations.
    7. Development Security: Software Development Life Cycle (SDLC) methodology governs the acquisition, development, implementation, and management of software components. JFrog follows OWASP (Open Web Application Security Project) guidelines to ensure that security is integrated throughout the development process.
    8. Infrastructure as Code: Infrastructure as Code (IaC) serves as a critical component aligning DevOps, Security, and compliance efforts within JFrog’s operational framework. This approach ensures secure management of infrastructure processes by automating and standardizing deployments. JFrog’s application images undergo rigorous hardening using secured base images and deployment configurations. Continuous security scanning through JFrog’s Xray during the CI build process further enhances security measures.
  6. Incident Response
    JFrog maintains an Incident Response Plan and computer incident response team (CIRT) to respond to Security Incidents. The plan is reviewed at least annually. Affected Customers will be notified in accordance with the applicable Security Incident section in the Agreement or DPA.
  7. Third-Party Risk Management
    JFrog has implemented and maintains the following measures:
    1. JFrog conducts security due diligence and risk assessments of Third Parties.
    2. Periodic audits validate the ongoing governance of control operations and risk.
    3. Security controls and obligations are incorporated into Third Party contracts.
    4. Data Center Security: JFrog Data Centers are hosted by Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP) which offer robust data center security measures. These include physical security with 24/7 staff and access control, advanced environmental controls, extensive network security, and compliance with standards like ISO/IEC 27001:2013 and SOC 2 Type II. Data centers are designed for high availability with redundancy and failover capabilities, and data is encrypted both at rest and in transit to ensure protection against unauthorized access.
  8. Customer Security Considerations
    Customers are responsible for their own security measures, including secure password practices, user management, timely software updates (outside of JFrog cloud), and proper access controls. JFrog is not liable for security incidents or data losses resulting from client-side vulnerabilities. JFrog maintains an inventory of infrastructure assets and has documented data disposal policies. Customer Data will be securely deleted as referenced in the Agreement.
  9. Contingency Planning
    JFrog has implemented and maintains the following measures:
    1. A Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP), which are reviewed annually, to manage significant disruptions.
    2. Data backup, replication, and recovery systems are deployed to support resilience.
    3. Annual Disaster Recovery drills are conducted to test and validate JFrog recovery procedures.
Produkte
  • Artifactory
  • Xray
  • Kuratierung
  • Advanced Security
  • Distribution
  • Connect
  • JFrog ML
  • JFrog Platform
  • Kostenlos starten
Resources
  • Blog
  • Events
  • Integrationen
  • JFrog Documentation
  • JFrog Fly Documentation
  • Open Source
  • JFrog Trust
  • Compare JFrog
Company
  • Über
  • Management
  • Investor Relations
  • Partner
  • Kunden
  • Stellenangebote
  • Presse
  • Kontaktieren Sie uns
  • Markenrichtlinien
Community
  • Community
  • Downloads
  • Community Events
  • Community-Forum
  • Anwendungen
lang-switcherDearrow
  • En
  • Fr
  • De
  • 日本語
  • 简体中文
Follow Us
© 2026 JFrog Ltd All Rights Reserved
Terms of Use | Privacy Policy | Cookies Policy | Impressum |
Privacy Options Cookies Settings
| Accessibility Notice | Accessibility Mode

Success

Your action was successful

Ups ... Da ist etwas schiefgelaufen

Bitte versuchen Sie es später noch einmal.

Information

frog hand

Modale Nachricht

US Flag
Click Here
JFrog Logo
Chinese Flag
请点这里

Vdoo is now part of JFrog

helping to deliver secure software updates from code to the edge.
You have been redirected to the JFrog website