JFrog integrates AI capabilities across its platform to help development and security teams move faster and smarter. JFrog holds its AI providers to the same data protection standards it applies to its own infrastructure. AI features are customer-controlled and AI development is governed by JFrog’s Data Strategy and AI Legal Group.
Data used for training
JFrog does not use customer artifacts or binaries to train AI language models. JFrog may use anonymized usage data for fine-tuning and adapting language models to our product. Third-party AI providers are contractually bound not to use customer content for training or fine-tuning.
Read MoreWhere usage data is utilized to fine-tune product models, it is anonymized within the retention pipeline, not at runtime; customer artifacts and binaries are strictly excluded from this pipeline.
AI features availability
AI features can be enabled, configured, and disabled at any time by the JFrog Platform Administrator. Specific defaults vary by customer tier and geography. Individual users cannot enable AI features independently.
Read MoreAI access is entirely at the customer’s discretion, and individual users cannot enable features independently. To ensure transparency, the user experience clearly indicates when interacting with AI systems, allowing users to make informed decisions. JFrog does not control access at the team or project level; these are managed by customer administrators.
Underlying models
JFrog uses third-party large language models (LLMs — AI systems trained on large datasets to generate text and code based on user inputs) provided by external AI providers.
Read MoreJFrog leverages models developed by third-party LLMs listed and updated at: https://jfrog.com/trust/privacy/sub-processors/.
These are typically “frontier models” meaning the most advanced LLMs currently available, developed by leading AI providers. You can read more about their safety and AI practices at their respective sites.
Data retention (AI interactions)
Raw interaction data, including inputs and outputs, is retained for up to 60 days from submission to support troubleshooting and service operations. After 60 days, raw data is deleted.
Read MoreBeyond the 60-day operations period, only PII-masked summarizations and anonymized analytics data are retained, in accordance with usage terms. AI sessions are ephemeral by design, with data limited strictly to the active session and purged automatically upon timeout, idle state, or system crash.
Regulatory positions
EU AI Act: JFrog AI features do not touch any of the areas classified as high-risk.
GDPR / CCPA: JFrog AI features are designed with data minimization and privacy-by-design principles. JFrog processes minimal personal data through its platform — primarily business contact details of authorized users.
Read MoreJFrog’s AI features pose limited risk as they do not involve automated decision-making that produces legal or similarly significant effects on individuals, thus, they do not fall within the categories of high-risk AI systems. When AI systems interact with humans, transparency obligations may apply, and these are fulfilled by the AI features available through our services.
Automated decision-making
JFrog’s AI features are not designed for automated decision-making. JFrog AI features provide suggestions and recommendations only. All decisions remain with the user. JFrog AI features are not designed to pose significant risks to health, safety, or fundamental rights.
Bias and fairness
JFrog does not develop the underlying AI language models and does not test them for bias. Frontier model providers publish their own responsible AI documentation, which customers can review independently. JFrog applies guardrails at the query and output level. Customers retain responsibility for evaluating outputs for their specific context and use case.
Read MoreAI-generated outputs are not always 100% reliable. JFrog recommends that customers apply human review before acting on any AI-generated output, particularly in high-stakes contexts. The underlying LLMs used by JFrog do not provide step-by-step explanations for individual outputs, and JFrog does not have visibility into the language model architecture or training data.
Data residency
Customers choose their hosting location. AI language model providers operate under regional fallback configurations (typically EU and US) to maintain service availability. JFrog selects language model regions to be as close as possible to the customer’s region. This is standard for enterprise AI services.
Privacy and security
JFrog’s AI features adhere to the same security standards as the JFrog Platform, including data encryption in transit and at rest, logical interaction segregation, and ephemeral session design. We prioritize data minimization and privacy-by-design, processing only minimal authorized user contact details while prohibiting the upload of sensitive data.
Read MorePersonal data processing is governed by the Cloud Data Processing Addendum. Our security posture is monitored via ongoing risk assessments (TPRM, SSDLC), CSPM, DSPM, and SSPM. AI-specific risks and incidents are managed within our unified Incident Management Framework, complemented by AI threat modeling, secure coding standards, and red/purple team exercises.
Further Resources
AI Addendum – contractual terms governing the use of JFrog AI features
Sub-Processors – list of third-party AI providers used by JFrog