JFrog Unveils AI Software Supply Chain Controls at swampUP 2026

JFrog (NASDAQ:FROG) used its swampUP 2026 investor session to outline product updates aimed at securing, remediating and governing software supply chains as enterprises deploy more AI-assisted development tools. Executives also discussed customer adoption of its AppTrust governance offering, integrations with security providers and the company’s approach to managing AI-generated software artifacts.

The company framed its strategy around three themes: “protect, remediate, and control.” The event’s operator highlighted the Package Traffic Controller, integrations with SASE providers including Zscaler and Netskope, expanded support in Artifactory for AI-related assets, a Wiz integration, zero-touch vulnerability remediation capabilities and enhancements to AppTrust.

Keysight Discusses Governance Needs

Christophe Romatier, chief information security officer at Keysight Technologies, said the test, measurement and design-solutions company has increased its software development activity and use of AI. Keysight has about 5,000 developers, according to Romatier, and its DevSecOps organization also oversees internal AI initiatives.

Romatier said governance has become both a security and compliance issue, as well as a developer productivity concern. He cited the Secure Software Development Framework and the European Union’s Cyber Resilience Act as regulations that require organizations to catalog artifacts and software bills of materials alongside products.

“We don’t really want [developers] spending time capturing compliance or filling in compliance checklists,” Romatier said. “We want our developers writing code.”

Keysight selected JFrog AppTrust after identifying a manual process for capturing and archiving compliance materials that was slowing research and development work, he said. Since Keysight had used JFrog Artifactory for years, the company viewed compliance evidence as another class of artifact that could reside alongside binaries and follow products through their release lifecycle.

Romatier said AI coding tools increased the urgency to automate governance. Without automation, Keysight would have needed to devote more developer time to compliance activities or hire additional personnel, he said. Looking ahead, he said Keysight intends to apply governance across its applications rather than maintain separate processes for higher-sensitivity software.

“Once you’ve done the work to automate the tasks that need to occur on every build, on every release, it’s no longer a question of, do I only want to apply it to this area?” Romatier said. He added that Keysight is working toward a regulatory compliance milestone in October of the following year.

Artifactory Positioned as AI Control Plane

JFrog Chief Executive Officer Shlomi Ben Haim and Chief Technology Officer Yoav Landman said the growing volume of binaries produced and consumed by AI agents reinforces the importance of artifact management.

Ben Haim described Artifactory as evolving beyond a system of record into a “system of trust.” He said AI labs and other organizations are putting greater demands on software infrastructure as agents consume packages and generate more software artifacts.

Landman said AI agents are substantial consumers of binaries and also create more binaries that ultimately become deployed software. He said JFrog’s roadmap centers on adding controls around the packages agents can access, protecting Artifactory and retaining release metadata that customers can use to apply policies.

“The key thing is to instill trust into this new reality,” Landman said.

Landman also addressed a question about vulnerabilities affecting on-premises installations. He said some vulnerabilities have greater exposure in on-premises environments because of the configurations needed to exploit them. JFrog provides configuration guidance and issues patches, he said, while platform upgrades can be applied without downtime.

Traffic Controller and AppTrust Expansion

Ben Haim said the new Package Traffic Controller is intended to direct incoming software packages through Artifactory rather than allowing users or agents to bypass the repository and pull packages directly from the internet. The company is working with SASE providers including Zscaler, Cloudflare and Netskope, he said.

According to Ben Haim, the Traffic Controller works with JFrog Curation to screen packages against organizational policies before they enter Artifactory. He said the approach is designed to maintain developer workflow speed while preventing unapproved or potentially risky artifacts from entering an organization’s software environment.

Chief Financial Officer Ed Grabscheid said Curation is currently priced on a per-seat basis for contributing developers. He said that directing more trusted binaries into Artifactory could drive additional storage and consumption, and that JFrog expects pricing to evolve over time. He did not provide details of potential pricing changes.

On the governance side, executives said AppTrust is designed to support continuous compliance at the level of every build, rather than periodic compliance reviews. The operator said regulations such as the Cyber Resilience Act and NIST-related requirements are contributing to governance deadlines for organizations.

JFrog Fly and Enterprise Strategy

Landman said JFrog incorporated capabilities from JFrog Fly, which had been presented as an agentic repository initiative, into the broader platform. The company used Fly to learn how agents could interact with binary repositories and to capture metadata created through developer and coding-agent interactions, he said. Two of Fly’s capabilities were integrated into Artifactory, while another was incorporated into AppTrust, Ben Haim said.

When asked about the impact of agent-focused Git platforms, Landman said JFrog sees Git increasingly serving as intermediate storage for code before it becomes binaries. He said the company believes binaries remain the more relevant layer for trust, policy and release management.

Ben Haim said JFrog remains focused on enterprise customers, citing its investments in enterprise go-to-market operations, support, customer success, professional services and product development. He said AI-related risks, including shadow AI and code snippets copied into software, are expanding the security needs of both existing and new customers.

Grabscheid said JFrog is focused on executing through 2027 under its existing long-term model. He said the company would revisit its guidance framework as it progresses through that period, while continuing to provide investors with metrics including remaining performance obligations, security-related RPO and net dollar retention.

About JFrog (NASDAQ:FROG)

JFrog is a software company specializing in DevOps solutions designed to streamline the management, distribution and security of software binaries. Its core offering, JFrog Artifactory, serves as a universal artifact repository manager compatible with all major package formats, enabling development teams to store, version and share build artifacts across the software delivery pipeline. The company’s platform also includes tools for continuous integration and delivery (CI/CD), security scanning and release automation.

Among JFrog’s flagship products are JFrog Xray, a security and compliance scanning service that analyzes artifacts and dependencies for vulnerabilities; JFrog Pipelines, a CI/CD orchestration engine that automates build and release workflows; and JFrog Distribution, which accelerates the secure distribution of software releases to edge nodes and end users.