Enforce your policies. Every agent. Every pull.
Govern and secure AI assets as artifacts, so your agents consume only the approved ones.
Discover Pre-Approved AI Assets
One registry for every AI asset, stored as native artifacts in Artifactory alongside your other binaries. Coding agents and developers discover and self-serve pre-approved assets from one source of truth: immutable, versioned, and traceable back to the release they shipped in.
Scan and Detect Shadow AI
Scan your software supply chain to expose every AI asset in use, including the ones pulled without approval. Check each AI asset for vulnerabilities and malicious code. See what's managed, unmanaged, or malicious at a glance, and govern or block it on the spot.
Block Risky AI Assets Before They’re Pulled
Stop unvetted or non-compliant AI assets at the gate before they ever reach your software supply chain. The same Curation control enforces your policies on models, MCPs, plugins, and skills.
NEWEnforce Approved AI Assets with Agent Guard
Your coding agents reach only the assets you've approved, so autonomous development stays fast and on-policy. Agent Guard routes every coding agent (Cursor, Claude Code, Copilot, etc.) through an authenticated bridge that validates each request against your rules.
Doesn’t Mean Losing Control
Additional Resources
-
An AI Registry is a single source of truth for every AI asset an organization uses (models, MCP servers, agent skills, and plugins) so teams can discover, evaluate, and govern them all in one place. Enterprises need one because developers and coding agents now pull these assets directly from public sources onto laptops and into builds, without approval or review. That creates Shadow AI that security teams can’t see or control. An AI Registry closes the gap by treating AI assets like any other software artifact: versioned, scanned, access-controlled, and auditable.
-
JFrog AI Catalog detects Shadow AI by exposing every unmanaged AI model and API call across your supply chain. It gives platform and security teams one complete view of which AI assets are actually in use, so ungoverned, non-compliant, or malicious usage can be identified and blocked before it spreads.
-
JFrog AI Catalog blocks risky AI assets at the point of request, before they ever enter your environment, using JFrog Curation as a preventive gate. When a developer or coding agent requests a model or MCP server, AI Catalog checks it against your policies and physically stops any asset that’s vulnerable, malicious, or unapproved, the same way JFrog gates npm packages and Docker images.
-
JFrog AI Catalog uses Agent Guard that authenticates every tool call or skill usage a coding agent makes and enforces granular, role-based access control. Agents like Cursor and Claude Code can only reach pre-vetted, approved AI assets. Instead of banning agents or granting blanket approvals, you define exactly which assets and actions each agent is allowed, and the Agent Guard enforces it.
-
JFrog AI Catalog integrates with leading AI coding agents and IDEs via the official JFrog agent plugins, including Cursor, Claude Code, GitHub Copilot, OpenAI Codex, Kiro, IntelliJ, Devin, VS Code, and OpenCode.
-
JFrog AI Catalog manages every AI asset in your supply chain from one registry: AI models, MCP servers, agent skills, plugins, and APM packages (coming soon). AI Catalog supports all AI assets, whether they’re remote, third-party, or custom-built, and manages them alongside your Docker images, npm packages, and other software artifacts.