-

JFrog Delivers DevGovOps at Scale: Continuous Compliance for the AI-Era Software Supply Chain

New JFrog AppTrust capabilities automate regulatory compliance - cutting audit preparation from weeks to hours – while enforcing security policies and governance for autonomous agents at enterprise scale

SUNNYVALE, Calif. & NEW YORK--(BUSINESS WIRE)--swampUP 2026--JFrog Ltd. (“JFrog”) (NASDAQ: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets, today unveiled DevGovOps for the AI-era – a new class of capabilities in JFrog AppTrust that automates governance across the entire software supply chain to help organizations keep pace with agent-driven development and growing regulatory demands.

“With JFrog AppTrust, compliance enforcement is automatic. It's not about policies and code. It's about making sure governance keeps pace with your development velocity – whether human or agent driven. That's the next evolution of DevGovOps."

Share

"AI is changing how software gets built and shipped. Autonomous agents are now first-class members of our customers' development teams, committing code and shipping releases at machine speed. The challenge is - governance and compliance still run on human timelines. The reality is: governance can't be something you do after the fact, in a spreadsheet or a quarterly audit – it must be built into the release itself,” said Shlomi Ben Haim, Co-Founder and CEO, JFrog. “With JFrog AppTrust, compliance enforcement is automatic. It's not about policies and code. It's about making sure governance keeps pace with your development velocity – whether your code comes from a human or an agent. That's the next evolution of DevGovOps.”

Enterprises building AI factories face a fundamental operational challenge: autonomous agents and AI-assisted developers can plan, code, test, and deploy in hours. Manual governance processes take weeks. Additionally, regulatory requirements from the ECB AI Cyber Directive, EU Cyber Resilience Act (CRA), NIST SSDF, and FedRAMP mandate that organizations prove active compliance for every supported software version or face steep fines and restrictions. For example, CRA fines can reach up to €15 million or 2.5% of global annual turnover. Separately, under the EU's NIS2 Directive, management bodies, including named executives, can face personal accountability, up to temporary bans from managerial roles.

The Four Dimensions of DevGovOps at Scale: Codify, Attest, Enforce, Monitor

The new JFrog AppTrust capabilities embed governance into the software supply chain across DevGovOps’s four continuous pillars – Codify, Attest, Enforce and Monitor – making governance an always-on property of the infrastructure, not a checkpoint applied after the fact.

  • Codify: Automated policy enforcement. For custom compliance policies, JFrog's AI-assisted Policy-as-Code Playground lets security teams write and validate governance rules in plain English – without needing Rego expertise – then test against real application versions before deployment. Validated policies can be saved as reusable templates that are then enforced consistently and deterministically across the organization.
  • Attest: Automatic evidence-based capture. Prompt-to-Release Traceability collects approvals, builds, scans, and promotions with no manual logging step, bridging the gap created by a lack of provenance in AI agents. It connects the agent’s intent to the artifact that was shipped and delivers a full audit trail for every agent decision and consumed asset across the software lifecycle.
  • Enforce: Policy guardrails at machine speed. For common compliance requirements, JFrog offers new Out-of-the-Box (OOTB) Compliance Frameworks with pre-built rules aligned with regulatory standards and automatically enforced with one click. Templates for CRA and NIST SSDF are available now, with additional standards coming soon.
  • Monitor: DevGovOps that doesn’t stop at the release gate. With Post-Release Governance, JFrog AppTrust extends compliance visibility with continuous monitoring of every active production version within its support window, so organizations can prove compliance and track newly introduced security risks at any point in time.

Governance no longer has to slow teams down and control doesn’t have to be feared. JFrog AppTrust will bring DevGovOps at scale capabilities to JFrog Platform customers in Q3 2026. To learn more about JFrog AppTrust and DevGovOps check out this blog or register for the “Regain Control Over Compliance” webinar on Thursday, October 1 at 11 AM PT/2 PM ET.

Like this Story? Share this on X: Prove, don’t promise. @JFrog just unveiled #DevGovOps at scale – new JFrog AppTrust capabilities enforce policy as code, capture signed evidence automatically, and govern releases after production. Compliance as infrastructure, not paperwork. Learn more: https://jfrog.co/4xtd3NT #Compliance #SoftwareSupplyChain #AgenticAI

About JFrog

JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps, and AgentSecOps platform, is on a mission to create a world of trusted software delivery without friction from development to production. Driven by a “Liquid Software” vision, the JFrog Platform is a software supply chain system of record that is designed to power organizations as they build, manage, govern, and distribute secure software with speed and scale. Holistic security features help identify, protect, and remediate against threats and vulnerabilities. The universal, hybrid, multi-cloud JFrog Platform is available as both SaaS services across major cloud service providers and self-hosted. Millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation in the AI era. Learn more at https://jfrog.com or follow us on X @JFrog.

Cautionary Note About Forward-Looking Statements

This press release contains “forward-looking” statements, as that term is defined under the U.S. federal securities laws, including, but not limited to, statements regarding our expectations with respect to the anticipated performance of the JFrog AppTrust tool.

These forward-looking statements are based on our current assumptions, expectations and beliefs and are subject to substantial risks, uncertainties, assumptions and changes in circumstances that may cause JFrog’s actual results, performance or achievements to differ materially from those expressed or implied in any forward-looking statement. There are a significant number of factors that could cause actual results, performance or achievements to differ materially from statements made in this press release, including but not limited to risks detailed in our filings with the Securities and Exchange Commission, including in our annual report on Form 10-K for the year ended

December 31, 2025, our quarterly reports on Form 10-Q, and other filings and reports that we may file from time to time with the Securities and Exchange Commission. Forward-looking statements represent our beliefs and assumptions only as of the date of this press release. We disclaim any obligation to update forward-looking statements, except as required by law.

Contacts

Media Contact:
Siobhan Lyons, Director, Global Communications, siobhanL@jfrog.com

Investor Contact:
Jeff Schreiner, VP of Investor Relations, jeffS@jfrog.com

JFrog Ltd.

NASDAQ:FROG
Details
Headquarters: Sunnyvale, California
CEO: Shlomi Ben Haim
Employees: ~1800
Organization: PUB

Release Summary
JFrog Delivers DevGovOps at Scale: Continuous Compliance for the AI-Era Software Supply Chain
Release Versions
$Cashtags

Contacts

Media Contact:
Siobhan Lyons, Director, Global Communications, siobhanL@jfrog.com

Investor Contact:
Jeff Schreiner, VP of Investor Relations, jeffS@jfrog.com

Social Media Profiles
More News From JFrog Ltd.

JFrog Introduces Zero-Touch Remediation to its Self-Healing Software Supply Chain, Broadening its Footprint through Secure Open-Source Partnerships

SUNNYVALE, Calif. & NEW YORK--(BUSINESS WIRE)--JFrog Introduces Zero-Touch Remediation to its Self-Healing Software Supply Chain, Broadening its Footprint through Secure Open-Source Partnerships...

JFrog Embeds Security into the Agentic Workforce

SUNNYVALE, Calif. & NEW YORK--(BUSINESS WIRE)--JFrog Embeds Security into the Agentic Workforce...

JFrog Partners with Wiz to Close the Gap on AI-Era Threats, Keeping Global Businesses Secure

SUNNYVALE, Calif. & NEW YORK--(BUSINESS WIRE)--JFrog Partners with Wiz to Close the Gap on AI-Era Threats, Keeping Global Businesses Secure...
Back to Newsroom