Third Party Index

JFrog

jfrog.com

Transparency

Exemplary

Breakdown
Subprocessor list30 / 30
Processing locations8 / 8
Purposespartial0 / 7
Data processing addendum12 / 12
Trust center8 / 8
Privacy policy6 / 6
security.txt6 / 6
Security pagenot found0 / 5
Status page5 / 5
Vulnerability disclosure5 / 5
Pages still reachable8 / 8
Total88 / 100

Only documents we can retrieve count: a page behind a login or a broken link scores nothing.

Badge

JFrog transparency rating

For JFrog's own site; it updates with the rating.

<a href="https://thirdpartyindex.com/vendors/jfrog"><img src="https://thirdpartyindex.com/badge/jfrog.svg" alt="JFrog transparency rating on Third Party Index" height="20"></a>
[![JFrog transparency rating on Third Party Index](https://thirdpartyindex.com/badge/jfrog.svg)](https://thirdpartyindex.com/vendors/jfrog)

Documents

DocumentVerifiedChangedEvidence
Trust center snapshot
Subprocessor list snapshot
Data processing addendum snapshot
Privacy policy snapshot
Terms snapshot
security.txt snapshot
Status page statuspage snapshot
Security advisories snapshot

Subprocessors

11 third parties, 4 affiliates. CSV · Atom

NamePurposeLocationListed since
Amazon Application AI Functionality. United States.
Amazon Web Services, Inc. (AWS) Cloud Computing Services. Controllers can choose the location and region in accordance with the list available here.; Logs cloud hosting services. United States.
Anthropic Application AI Functionality. United States.
Coralogix, Inc. Log aggregation and correlation services. United States.
Google Application AI Functionality. United States.
Google Cloud Platform, LLC (GCP) Cloud Computing Services. Controllers can choose the location and region in accordance with the list available here.
Mailgun Technologies, Inc. Email notification services. United States.
Meta Application AI Functionality. United States.
Microsoft Application AI Functionality. United States.
Microsoft Azure, Corp. (Azure) Cloud Computing Services. Controllers can choose the location and region in accordance with the list available here.
SendGrid (Twilio, Inc.) Email notification services. United States.
JFrog affiliates (4)
NamePurposeLocationListed since
JFrog Ltd. Israel; United States
JFrog India Pvt Ltd. India
JFrog Japan KK Japan
JFrog Singapore Pte. Ltd. Singapore

Security record

What public security catalogs list for JFrog, in their words.

Known exploited vulnerabilities

4 vulnerabilities in JFrog's software that CISA lists as exploited in the wild.

CVEProductVulnerabilityListed
CVE-2026-42016ArtifactoryJFrog Artifactory Incorrect Authorization Vulnerability evidence
CVE-2026-42018ArtifactoryJFrog Artifactory Improper Authentication Vulnerability evidence
CVE-2026-82329ArtifactoryJFrog Artifactory Improper Authentication Vulnerability evidence
CVE-2026-66384ArtifactoryJFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability evidence

Source: CISA Known Exploited Vulnerabilities catalog.

Service status

1 incident in the last 4 days (0 major or critical, 0 minor, 1 with no stated impact)

BeganIncidentImpactLasted
Potential UI bug for a subset of customers on JFrog Cloud Platformnone— evidence

As JFrog's status page reports its own incidents (scheduled maintenance left out), read every few hours since .

Changes

None since tracking began.