banner background
during swampup unibrow 26 desktop content
  • Preisgestaltung
Kontaktieren Sie uns Kostenlos starten
Ressourcen
Lernen
JFrog Academy JFrog Certifications Webinars & Workshops Demo-Center Themen rund um die Software-Lieferkette
Erkunden
Resource Center JFrog Blog Customer Stories Security Research Report zum Stand der Dinge Gartner MQ: Supply Chain Security Events
Support & Services
Kundenerfolg
DevOps-Consulting-Services Support Verwaltung & Troubleshooting
Kontrolle & Vertrauen
JFrog Documentation Mein JFrog Cloud-Status JFrog Trust
Partner
JFrogs Partner-Ökosystem Discover our network of channel, technology, and cloud partners.
Channel-Partner-Finder Nehmen Sie Kontakt mit einem JFrog-Channel-Partner in Ihrer Region auf.
MyJFrog for Partners Manage subscriptions, monitor usage, and track customer renewals.
Community Entdecken Sie die Community von JFrog, greifen Sie auf Expertenressourcen zu, erhalten Sie die neuesten Community-News und vieles mehr
Dokumentation Sehen Sie sich die aktuelle Produktdokumentation an, informieren Sie sich über die Angebote von JFrog und erhalten Sie Antworten darauf, wie Sie JFrog-Produkte konfigurieren und einsetzen
Integrationen Erfahren Sie, wie Sie Produkte von JFrog mit über 100 Anbietern wie ServiceNow, GitHub, NVIDIA, Sonar und mehr integrieren können
Support Eröffnen Sie ein Ticket, erhalten Sie Hilfe oder finden Sie Antworten über den JFrog Support und in den FAQs.

Überblick über KI

Ihre Agenten sind nur so vertrauenswürdig wie das, was sie konsumieren, entwickeln und ausliefern. JFrog verwaltet jedes KI-Modell, jede Agentenfähigkeit, jeden MCP-Server, jeden KI-generierten Code und jedes zusammengesetzte Artefakt in einer Single Source of Truth.

Sichern Sie Ihre gesamte agentische Software-Lieferkette ab, damit Sie vertrauenswürdige Software in Ihrer neuen Geschwindigkeit ausliefern können.

Mehr erfahren
JFrogs KI-Produkte
JFrog AI Catalog Entdecken, steuern und sichern Sie Ihr KI-Ökosystem
JFrogs KI-Ökosysteme
NVIDIA Cursor GitHub
New Capabilities
MCP Registry Agent Skills Registry
JFrogs KI-Ressourcen
Agentische Software-Lieferketten-Sicherheit: KI-gestützte Kuratierung und Remediation Wie Sie Shadow AI in 5 Schritten erkennen und eliminieren Jenseits von Modellen: JFrog AI Catalog entwickelt sich weiter, um Schatten-KI zu erkennen und MCPs zu steuern AppTrust, AI Catalog und mehr – Live-Produktpräsentation von JFrog MLOps Masterclass: Verschaffen Sie sich End-to-End-Kontrolle und -Governance über Ihre KI/ML-Workloads Vom Chaos zur Kontrolle: Machen Sie Ihre KI-Lieferkette fit für die Zukunft Weitere Ressourcen anzeigen
Agentische KI
JFrog boost logo
Zero Configuration, Agentic Software Delivery for Small Teams.
Mehr erfahren

AI Overview

JFrog immunizes what agents consume and controls how they build and deploy — every AI model, agent skill, plugin, MCP server, package, and AI-generated artifact, governed in a single source of truth.

A trusted agentic workforce.
This is AgentSecOps.

Learn More
Trusted AI
JFrog AI Catalog Trust Your Agentic Workforce
Agent Guard
MCP Registry
Agent Skills Registry
Plugins Registry
APM Registry
Model Registry
AI Integrations
Claude Cursor Codex Hugging Face NVIDIA Visual Studio Code Devin Kiro Open Code NanoClaw See all integrations
AI Resources
The Agentic Development Security Discipline Automated Remediation Managing Agent Primitives Like Software Artifacts AI Catalog Solution Sheet Access JFrog with AI Agents AI Assets Under Control: Enforcing Policies on your Coding Agents See More Resources
Agentic Development
JFrog Boost Save Tokens, Maximize Context for Coding Agents.
Learn More
JFrog Agent Plugin Connect Coding Agents Natively to Your JFrog Platform.
Learn More

Supply Chain Solutions

The universal and adaptable JFrog Platform solves essential cross-industry agentic software supply chain challenges.

Use Cases
Artifact Management Self-Healing Software Supply Chain Software Supply Chain Governance Artifact Data Retention Global Enterprise Scale Trusted Agentic Workforce
Ecosystem Integrations

Build on a universal platform that gives you freedom of choice across your AI and software supply chain.

Claude Cursor Codex GitHub NVIDIA
Docker npm PyPy Wiz ServiceNow See all Integrations
Industry

Accelerate software delivery while meeting strict regulatory standards like HIPAA and FedRAMP

Financial Services Gaming Public Sector
Automotive Technology Healthcare
Use Case
KI/ML
Modelllebenszyklus-Management (MLOps) Data Engineering und Feature-Management (DataOps) KI/ML-Entwicklung und -Bereitstellung MLSecOps Agentische Remediation Zentralisierte Kontrolle & Governance der KI (AI Catalog)
DevSecOps
Durchgängig sichere Softwarelieferkette Kuratieren von Open-Source-Paketen Scannen von Quellcode (SAST) Software Composition Analysis (SCA) Secrets Detection Infrastructure-as-Code-(IaC)-Security
DevOps
Developer Experience Artefakt-Management Tool-Konsolidierung
Gerät/IoT
Connected Device Management
Cloud-Lösungen
Flexible Cloud-Bereitstellungslösungen
Integrationen
ServiceNow GitHub NVIDIA
Docker Maven Alle Integrationen anzeigen
Branchen
Finanzdienstleistungen Öffentlicher Sektor Technologie Gesundheitswesen
Gaming Automobilbranche Enterprise

Die JFrog Plattform

Verlässliche Software schnell und sicher bereitstellen

Die einzige Software-Lieferkettenplattform, die Ihnen End-to-End-Visibility, Sicherheit und Kontrolle für die automatisierte Bereitstellung von vertrauenswürdigen Releases bietet

Bringen Sie DevOps-, DevSecOps- und MLOps-Teams in einer Single Source of Truth zusammen
Plattform ansehen
DevOps
JFrog Artifactory Universeller Artefakt- und ML-Modell-Repository-Manager
JFrog Distribution Sichere Verteilung über alle Nutzungspunkte hinweg
JFrog Connect IoT-Gerätemanagement mit DevOps-Flexibilität
DevSecOps
JFrog Curation Nahtlose Kuratierung von Softwarepaketen und ML-Modellen
JFrog Security
Essentials (Xray)
Integrierte SCA für Software- und KI-Artefakte
JFrog Advanced Security Lieferketten-Exposure-Scanning & Impact-Analyse
JFrog Runtime Echtzeit-Einblicke in Laufzeitschwachstellen
DevGovOps
JFrog AppTrust Anwendung Risikomanagement
KI/ML
JFrog ML Build, Train, Serve and Monitor AI/ML Models
JFrog AI Catalog Entdecken, steuern und sichern Sie Ihr KI-Ökosystem
Neue Funktionen
MCP-Registry
MCP-Governance und Sicherheit auf Enterprise-Niveau
Agent Skills Registry
Unternehmensweit gesteuerte Skills für vertrauenswürdige KI-Agenten

The JFrog Platform

The Single Source of Truth for the Agentic Software Supply Chain.

The infrastructure that establishes, enforces, and tracks trust in your software. Uniting DevOps, DevSecOps, DevGovOps, and AgentSecOps on a single source of truth.

Trust your speed. Adapt without losing control.
View Platform
DevOps
JFrog Artifactory Universal AI Asset & Artifact Management
JFrog Distribution Secure Distribution Across Consumption Points
JFrog Connect IoT Device Management with DevOps Agility
DevSecOps
JFrog Curation Policy-driven curation of software & AI components
JFrog Xray (SCA) Integrated SCA for Software & AI Artifacts
NEW
Zero-Touch Remediation Automatically Fix Risks at the Speed of Frontier AI
JFrog Advanced Security Supply Chain Exposure Scanning & Impact Analysis
Contextual Analysis
Secrets Detection
SAST
Infrastructure as Code
Runtime Integrity
AgentSecOps
JFrog AI Catalog Immunize and Control Your Agent Lifecycle
Agent Guard NEW
Plugin Registry NEW
APM Registry NEW
MCP Registry
Agent Skills Registry
Model Registry
DevGovOps
JFrog AppTrust Continuous governance and compliance
OOTB Compliance Frameworks NEW
Policy-as-Code Playground NEW
Post-Release Governance NEW
Prompt-to-Release Traceability NEW
  • The JFrog Platform

    The Single Source of Truth for the Agentic Software Supply Chain.

    The infrastructure that establishes, enforces, and tracks trust in your software. Uniting DevOps, DevSecOps, DevGovOps, and AgentSecOps on a single source of truth.

    Trust your speed. Adapt without losing control.
    View Platform
    DevOps
    JFrog Artifactory Universal AI Asset & Artifact Management
    JFrog Distribution Secure Distribution Across Consumption Points
    JFrog Connect IoT Device Management with DevOps Agility
    DevSecOps
    JFrog Curation Policy-driven curation of software & AI components
    JFrog Xray (SCA) Integrated SCA for Software & AI Artifacts
    Zero-Touch RemediationNEW Automatically Fix Risks at the Speed of Frontier AI
    JFrog Advanced Security Supply Chain Exposure Scanning & Impact Analysis
    Contextual Analysis
    Secrets Detection
    SAST
    Infrastructure as Code
    Runtime Integrity
    AgentSecOps
    JFrog AI Catalog Immunize and Control Your Agent Lifecycle
    Agent Guard NEW
    Plugin Registry NEW
    APM Registry NEW
    MCP Registry
    Agent Skills Registry
    Model Registry
    DevGovOps
    JFrog AppTrust Continuous governance and compliance
    OOTB Compliance Frameworks NEW
    Policy-as-Code Playground NEW
    Post-Release Governance NEW
    Prompt-to-Release Traceability NEW
  • Supply Chain Solutions

    The universal and adaptable JFrog Platform solves essential cross-industry agentic software supply chain challenges.
    Use Cases
    Artifact Management Self-Healing Software Supply Chain Software Supply Chain Governance Artifact Data Retention Global Enterprise Scale Trusted Agentic Workforce
    Ecosystem Integrations

    Build on a universal platform that gives you freedom of choice across your AI and software supply chain.

    Claude Cursor Codex GitHub NVIDIA Docker npm PyPy Wiz ServiceNow
    See all Integrations
    Industry

    Accelerate software delivery while meeting strict regulatory standards like HIPAA and FedRAMP

    Financial Services Gaming Public Sector Automotive Technology Healthcare
  • AI Overview

    JFrog immunizes what agents consume and controls how they build and deploy — every AI model, agent skill, plugin, MCP server, package, and AI-generated artifact, governed in a single source of truth.

    A trusted agentic workforce.
    This is AgentSecOps.
    Learn More
    Trusted AI
    JFrog AI Catalog Trust Your Agentic Workforce
    Agent Guard
    MCP Registry
    Agent Skills Registry
    Plugins Registry
    APM Registry
    Model Registry
    AI Integrations
    Claude Cursor Codex Hugging Face NVIDIA
    Visual Studio Code Devin Kiro Open Code NanoClaw
    See all integrations
    AI Resources
    The Agentic Development Security Discipline Automated Remediation Managing Agent Primitives Like Software Artifacts AI Catalog Solution Sheet Access JFrog with AI Agents AI Assets Under Control: Enforcing Policies on your Coding Agents
    See More Resources
    Agentic Development
    JFrog Boost

    Save Tokens, Maximize Context for Coding Agents.

    Learn More
    JFrog Agent Plugin

    Connect Coding Agents Natively to Your JFrog Platform.

    Learn More
  • Community Entdecken Sie die Community von JFrog, greifen Sie auf Expertenressourcen zu, erhalten Sie die neuesten Community-News und vieles mehr
    Dokumentation Sehen Sie sich die aktuelle Produktdokumentation an, informieren Sie sich über die Angebote von JFrog und erhalten Sie Antworten darauf, wie Sie JFrog-Produkte konfigurieren und einsetzen
    Integrationen Erfahren Sie, wie Sie Produkte von JFrog mit über 100 Anbietern wie ServiceNow, GitHub, NVIDIA, Sonar und mehr integrieren können
    Support Eröffnen Sie ein Ticket, erhalten Sie Hilfe oder finden Sie Antworten über den JFrog Support und in den FAQs.
  • Ressourcen
    Lernen
    JFrog Academy JFrog Certifications Webinars & Workshops Demo-Center Themen rund um die Software-Lieferkette
    Erkunden
    Resource Center JFrog Blog Customer Stories Security Research Report zum Stand der Dinge Gartner MQ: Supply Chain Security Events
    Support & Services
    Kundenerfolg
    DevOps-Consulting-Services Support Verwaltung & Troubleshooting
    Kontrolle & Vertrauen
    JFrog Documentation Mein JFrog Cloud-Status JFrog Trust
    Partner
    JFrogs Partner-Ökosystem Discover our network of channel, technology, and cloud partners.
    Channel-Partner-Finder Nehmen Sie Kontakt mit einem JFrog-Channel-Partner in Ihrer Region auf.
    MyJFrog for Partners Manage subscriptions, monitor usage, and track customer renewals.
  • Preisgestaltung
Get a Demo Kontaktieren Sie uns
  • Self Managed Terms and Conditions
    • Self Managed Terms and Conditions
    • JFrog License Agreements and Terms of Service – Previous Versions
  • SaaS Terms and Conditions
    • SaaS Terms and Conditions
    • JFrog License Agreements and Terms of Service – Previous Versions
  • JFROG SUBSCRIPTION AGREEMENT – HYBRID
  • SaaS Terms and Conditions – Monthly
  • JFrog Agreement – Trial
  • Support
    • JFrog Standard Support & SLA
    • JFrog Gold Support and SLA
    • JFrog Platinum Support and SLA
    • JFrog Platform Service Level Agreement – Previous Versions
  • Privacy and Security
    • JFrog Data Processing Addendum
    • JFrog Cloud Data Security Addendum
    • JFrog Trust Center
    • JFrog Privacy Center
    • JFrog-Datenschutzrichtlinie
    • JFrog Cookie Policy
  • JFrog Brand Guidelines
  • About Box
  • JFrog Acceptable Use Policy
  • JFrog AI Addendum
  • JFrog EU Data Act Addendum
  • JFrog Premium Availability (99.99%) Addendum
  • JFrog ML Addendum

JFrog Cloud Data Security Addendum

Last Updated: August 01, 2024

This JFrog Cloud Data Security Addendum (“DSA” or “TOMs”) describes the technical and organizational security measures (TOMs) that JFrog maintains to protect Customer Data (including Personal Data, as applicable) and Confidential Information. JFrog reserves the right to update the DSA, at its sole discretion, where updates will not materially degrade the security protocols or security levels in place as of the Effective Date during the applicable Subscription Term. Changes will be reflected at https://jfrog.com/jfrog-toms. This DSA forms part of the JFrog Agreement between JFrog and Customer and applies to Self-Hosted Subscriptions as applicable. Any capitalized terms which are not defined herein, shall have the meaning provided to them in the Agreement or the DPA.

  1. JFrog Security Program
    JFrog has implemented and maintains appropriate administrative, technical, physical, and organizational measures to ensure a level of security appropriate to the level of risk, in accordance with industry standards. JFrog maintains security policies, standards, and controls related to security, confidentiality, integrity, and availability. These policies are reviewed and approved annually and updated as needed.
  2. Certificate Program / Security Certifications
    JFrog maintains the following certifications and governance methods:

    1. Certification under ISO/IEC 27001:2013, ISO/IEC 27701:2019, ISO 27017:2014, and SOC 2, Type 2.
    2. Annual security audits by an independent third party, covering security, confidentiality, and availability control criteria.
    3. Regularly tests and monitors the effectiveness of its information security program through internal audits aligned with the relevant compliance controls and frameworks. Issues identified are documented, tracked, and remediated as appropriate.
  3. Access and Authentication Controls
    JFrog has implemented and maintains the following measures:

    1. Access Control Policy in accordance with the “least privileges” and “need to know” principles.
    2. Strict role-based permissions are granted in accordance with the role requirements.
    3. Access permissions are reviewed on a regular basis. Any access which is inappropriate for a role function is promptly removed.
    4. Access to JFrog systems and networks are disabled promptly upon notification in the event of termination of personnel.
    5. Unique usernames and passwords with minimum length and complexity requirements are enforced for all users.
    6. Two-factor authentication (2FA) is required for remote access and privileged account access.
    7. Physical access to JFrog facilities is restricted and requires a key-card, access is logged and maintained. Visitors are accompanied at all times and confidentiality measures are in place. Additional measures include video surveillance and other industry-standard practices.
    8. Services operate on a multitenant architecture designed to segregate and restrict access to Customer Data hosted on the JFrog platform. JFrog architecture provides a logical data separation for each different Customer via a unique ID.
  4. HR, Security, Training and Awareness
    JFrog has implemented and maintains the following measures:

    1. Background checks are conducted commensurate with job duties, in accordance with applicable laws and regulations.
    2. Personnel are subjected to non-disclosure or confidentiality obligations.
    3. Personnel are required to complete security awareness and privacy training during onboarding and at least annually thereafter.
    4. Personnel are required to review and acknowledge security policies during onboarding and annually thereafter.
    5. Periodic security and privacy awareness campaigns aimed to further educate personnel about their responsibilities.
  5. Risk Management and Infrastructure Control
    JFrog has implemented and maintains the following measures:

    1. JFrog Management reviews documented risks to determine appropriate risk levels and treatment options.
    2. Encryption and Key Management: Industry-standard encryption techniques (TLS 1.2 for data in transit and 256-bit AES for data at rest). Encryption keys are managed in a cloud-hosted key management service (KMS).
    3. Threat and Vulnerability Management: Continuous monitoring, annual penetration tests, and ongoing vulnerability scans are performed to identify and remediate potential threats. Patches are applied regularly after testing for safety. Vulnerabilities are classified based on the Common Vulnerability Scoring System (CVSS), a remediation plan is developed, including the steps required to address the vulnerability and the timeline for completion based on the remediation time for each severity level.
    4. Logging and Monitoring: Monitoring tools and services are used to monitor systems for various events. Logs are stored securely and reviewed by the security team utilizing Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) technology.
    5. Network Security: Zero-Trust Security Technology to prevent unauthorized access to JFrog networks, servers, or applications.
    6. Cloud Security: Utilization of cloud provider-managed DDoS mitigation services, next-generation Web Application Firewall (WAF), API protection, advanced rate limiting, and bot protection. These measures are designed to safeguard against various types of cyber threats. Regular cloud security scanning tools are employed, including advanced Cloud Security Posture Management (CSPM) solutions, to enforce security best practices and mitigate potential misconfigurations.
    7. Development Security: Software Development Life Cycle (SDLC) methodology governs the acquisition, development, implementation, and management of software components. JFrog follows OWASP (Open Web Application Security Project) guidelines to ensure that security is integrated throughout the development process.
    8. Infrastructure as Code: Infrastructure as Code (IaC) serves as a critical component aligning DevOps, Security, and compliance efforts within JFrog’s operational framework. This approach ensures secure management of infrastructure processes by automating and standardizing deployments. JFrog’s application images undergo rigorous hardening using secured base images and deployment configurations. Continuous security scanning through JFrog’s Xray during the CI build process further enhances security measures.
  6. Incident Response
    JFrog maintains an Incident Response Plan and computer incident response team (CIRT) to respond to Security Incidents. The plan is reviewed at least annually. Affected Customers will be notified in accordance with the applicable Security Incident section in the Agreement or DPA.
  7. Third-Party Risk Management
    JFrog has implemented and maintains the following measures:

    1. JFrog conducts security due diligence and risk assessments of Third Parties.
    2. Periodic audits validate the ongoing governance of control operations and risk.
    3. Security controls and obligations are incorporated into Third Party contracts.
    4. Data Center Security: JFrog Data Centers are hosted by Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP) which offer robust data center security measures. These include physical security with 24/7 staff and access control, advanced environmental controls, extensive network security, and compliance with standards like ISO/IEC 27001:2013 and SOC 2 Type II. Data centers are designed for high availability with redundancy and failover capabilities, and data is encrypted both at rest and in transit to ensure protection against unauthorized access.
  8. Customer Security Considerations
    Customers are responsible for their own security measures, including secure password practices, user management, timely software updates (outside of JFrog cloud), and proper access controls. JFrog is not liable for security incidents or data losses resulting from client-side vulnerabilities. JFrog maintains an inventory of infrastructure assets and has documented data disposal policies. Customer Data will be securely deleted as referenced in the Agreement.
  9. Contingency Planning
    JFrog has implemented and maintains the following measures:

    1. A Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP), which are reviewed annually, to manage significant disruptions.
    2. Data backup, replication, and recovery systems are deployed to support resilience.
    3. Annual Disaster Recovery drills are conducted to test and validate JFrog recovery procedures.
Produkte
  • Artifactory
  • Xray
  • Distribution
  • Container Registry
  • Connect
  • AI Catalog
  • JFrog Platform
  • Kostenlos starten
Resources
  • Blog
  • Events
  • Integrationen
  • JFrog Documentation
  • JFrog Fly Documentation
  • Open Source
  • JFrog Trust
  • Compare JFrog
Company
  • Über
  • Management
  • Investor Relations
  • Partner
  • Kunden
  • Stellenangebote
  • Nachhaltigkeit
  • Presse
  • Kontaktieren Sie uns
  • Markenrichtlinien
Community
  • Community
  • Downloads
  • Community Events
  • Community-Forum
  • Anwendungen
lang-switcherGermanarrow
  • English
  • Francais
  • German
  • 日本語
  • 简体中文
© 2026 JFrog Ltd All Rights Reserved
Terms of Use Privacy Policy Cookies Policy Impressum
Privacy Options Cookies Settings
Accessibility Notice Accessibility Mode

Success

Your action was successful

Ups ... Da ist etwas schiefgelaufen

Bitte versuchen Sie es später noch einmal.

Information

frog hand

Modale Nachricht

US Flag
Click Here
JFrog Logo
Chinese Flag
请点这里