JFrog Trust JFrog AI Transparency

JFrog integrates AI capabilities across its platform to help development and security teams move faster and smarter. JFrog holds its AI providers to the same data protection standards it applies to its own infrastructure. AI features are customer-controlled and AI development is governed by JFrog’s Data Strategy and AI Legal Group.

Data used for training

JFrog does not use customer artifacts or binaries to train AI language models. JFrog may use anonymized usage data for fine-tuning and adapting language models to our product. Third-party AI providers are contractually bound not to use customer content for training or fine-tuning.

Read More

AI features availability

AI features can be enabled, configured, and disabled at any time by the JFrog Platform Administrator. Specific defaults vary by customer tier and geography. Individual users cannot enable AI features independently.

Read More

Underlying models

JFrog uses third-party large language models (LLMs — AI systems trained on large datasets to generate text and code based on user inputs) provided by external AI providers.

Read More

Data retention (AI interactions)

Raw interaction data, including inputs and outputs, is retained for up to 60 days from submission to support troubleshooting and service operations. After 60 days, raw data is deleted.

Read More

Regulatory positions

EU AI Act: JFrog AI features do not touch any of the areas classified as high-risk.

GDPR / CCPA: JFrog AI features are designed with data minimization and privacy-by-design principles. JFrog processes minimal personal data through its platform — primarily business contact details of authorized users.

Read More

Automated decision-making

JFrog’s AI features are not designed for automated decision-making. JFrog AI features provide suggestions and recommendations only. All decisions remain with the user. JFrog AI features are not designed to pose significant risks to health, safety, or fundamental rights.

Bias and fairness

JFrog does not develop the underlying AI language models and does not test them for bias. Frontier model providers publish their own responsible AI documentation, which customers can review independently. JFrog applies guardrails at the query and output level. Customers retain responsibility for evaluating outputs for their specific context and use case.

Read More

Data residency

Customers choose their hosting location. AI language model providers operate under regional fallback configurations (typically EU and US) to maintain service availability. JFrog selects language model regions to be as close as possible to the customer’s region. This is standard for enterprise AI services.

Privacy and security

JFrog’s AI features adhere to the same security standards as the JFrog Platform, including data encryption in transit and at rest, logical interaction segregation, and ephemeral session design. We prioritize data minimization and privacy-by-design, processing only minimal authorized user contact details while prohibiting the upload of sensitive data.

Read More

Further Resources

AI Addendum – contractual terms governing the use of JFrog AI features

Sub-Processors – list of third-party AI providers used by JFrog

Powering the Software
that Powers the World

It’s our Liquid Software vision to automatically deliver software
packages seamlessly and securely from any source to any device.