JFrog: The System of Record for the World's Binaries
I. Introduction & Episode Roadmap
Every few seconds, somewhere on Earth, an automated build server wakes up, reaches across a network, and pulls down a file it did not write and cannot read. The file is a binary — a compiled, machine-ready blob of software, often hundreds of megabytes, sometimes gigabytes. A container image. A Java library. A model weight. The build server does not care what the file says; it cares only that the file is exactly, byte-for-byte, the file it expected, and that it arrives fast enough to keep the assembly line moving. Multiply that single transaction by the tens of millions of developers, robots, and pipelines running on the planet's software factories, and you have described one of the least glamorous and most load-bearing jobs in all of technology.
That job — storing, versioning, securing, and shipping the world's binaries — is the business of JFrog Ltd.
There is a slogan that circulates among the company's engineers: code is cheap, binaries are expensive. It sounds like a throwaway line, but it encodes the entire strategic wager the company made. For twenty years the technology industry has lavished attention, capital, and cultural mythology on source code — the human-readable text that programmers type. Git, GitHub, GitLab, the whole religion of version control grew up around it. JFrog's three Israeli founders bet on the other half of the software life cycle: the heavy, immutable output that actually runs in production. Source code is written once and read by humans. Binaries are produced constantly and consumed by machines, at a scale several orders of magnitude larger. If you owned the place where those binaries lived, the founders reasoned, you owned something closer to plumbing than to fashion — and plumbing, once installed, tends to stay.
JFrog is dual-headquartered in Sunnyvale, California and נתניה Netanya, Israel, and it trades on the NASDAQ under the fitting ticker FROG. In fiscal 2025 it reported revenue of $531.8 million, up 24% year over year, having crossed a half-billion-dollar run rate roughly five years after going public.1 Its flagship product, Artifactory, sits at the center of the software delivery pipeline at a large share of the Fortune 100, and the company has spent a decade wrapping security, distribution, and now AI-model management around that core.
The organizing idea behind all of it is what the founders call Liquid Software — the vision that software updates should flow continuously and securely, like water from a tap, invisible to the person using the app. No download prompts, no "please restart," no version anxiety. For water to flow that smoothly, someone has to build the reservoir and the pipes. JFrog's claim is that it is that someone. Whether that claim holds up under competitive pressure from Microsoft and GitLab — companies that would very much like to bundle the reservoir into products developers already use — is one of the central questions this story has to test rather than assume.
Here is the road we will travel. First, the consulting crucible in Netanya, where three Java consultants got tired of the same problem breaking every client's build and decided to fix it once and for all. Then the birth of Artifactory as an open-source project, and the pivotal decision to make it universal rather than Java-only — the move that separated JFrog from its early rivals. We will walk through the platform's expansion into security, the COVID-era IPO that valued a profitable infrastructure company like a growth rocket, and the capital the company deployed afterward, including two acquisitions bought near market tops. We will sit inside the brutal August 2024 earnings call that erased roughly a third of the company's market value in a day, and we will examine the 2025–2026 recovery, in which cloud revenue finally crossed half of the total and management began arguing that the AI coding boom is a tailwind rather than a threat. Finally, we will war-game the bull and bear cases through the lens of competitive strategy, and ask the question the whole enterprise now hangs on: can the repository of record for human software become the repository of record for machine-generated software too?
Let us start where it started — not in Silicon Valley, but in a consulting shop on the Israeli coastal plain.
II. The Netanya Crucible: Founders & AlphaCSP Origins
Picture a Java consultant in the mid-2000s, on-site at yet another enterprise client, staring at a build that has just failed for the third time that afternoon. The code is fine. The logic is fine. What broke is something dumber and more maddening: somewhere in the tangle of third-party libraries the project depends on, a single JAR file — a packaged chunk of Java code — is the wrong version, or corrupt, or was downloaded from a mirror that has since changed its contents. The build server does not tell you which one. It just turns red. And so the consultant spends the rest of the day doing detective work on plumbing, while the actual problem the client is paying to solve sits untouched.
This was the daily texture of life at אלפא-סי-אס-פי AlphaCSP, a premium Java consulting firm where the three future founders of JFrog worked together. It is worth pausing on the trio, because the division of labor among them turned out to be unusually clean and durable — the same three people still ran the company two decades later, a rarity in an industry where founding teams tend to fracture.
Shlomi Ben Haim was the business engine, the one who ran AlphaCSP and would run JFrog as CEO — the founder who thought in terms of markets, customers, and the long survival of the enterprise. Yoav Landman was the technical architect, the CTO-to-be, the person who actually sat with the failing builds and had both the frustration and the skill to build a machine that would end them. Fred Simon rounded out the group as the third technical founder, later carrying the title of Chief Data Scientist. Two builders and one seller, all fluent in the same problem — that is close to the ideal founding chemistry for an infrastructure company, because the product is deeply technical and the buyers are enterprises who need to be sold with patience.2
What they were experiencing had a name in developer folklore: dependency hell. Modern software is assembled, not written from scratch — a typical application pulls in dozens or hundreds of open-source libraries, each of which depends on other libraries, each of which has versions that may or may not agree with one another. Managing that web by hand, across a team, across many machines, was the structural breakdown that recurred at every single client engagement. It was not one client's problem. It was the problem, and consulting had given the founders a privileged vantage on it: they had seen it break at company after company, which is exactly the kind of pattern recognition that tells you a pain is universal rather than local.
Yoav Landman, the technical mind of the group, did what good engineers do when a problem keeps recurring: he decided to build a machine to solve it. He began writing the initial code for what became Artifactory — a dedicated binary repository manager, a single trusted place where all those libraries would be stored, versioned, and served, so that every developer and every build server on a team pulled from one canonical source of truth rather than scavenging the internet independently. The analogy that helps here: before Artifactory, each developer was fetching their own ingredients from whichever grocery store happened to be open, and dinner broke whenever two people bought slightly different flour. Artifactory was the shared, inventory-controlled pantry. It was, by JFrog's account, the world's first tool built specifically for that job.
The founders did not immediately spin out. AlphaCSP was acquired, and the trio stayed on for a stretch before concluding that consulting — trading hours for money, solving the same problem over and over for different logos — was not the life they wanted. Their calling was to build a product company: to solve the binary problem once, globally, and let it scale without them in the room. In April 2008 they founded JFrog Ltd. in Netanya.2
The timing was, to put it gently, inauspicious. They raised a small seed round from Israeli venture firm Gemini Israel Ventures just as the Global Financial Crisis began freezing technology funding worldwide.10 A trio of engineers with an open-source project and a modest check, launching into the teeth of the worst capital markets in a generation — this is not the setup for a triumphant montage. And it shaped the culture in a way that mattered later. The founders have described their early ethos in terms of a camel rather than a unicorn: an animal built to cross deserts, to store its own water, to survive long stretches with no external nourishment, rather than a mythical creature that runs on venture cash and dies when the funding stops.11 That instinct — conserve, endure, build for distance — would show up again and again, most visibly in the fact that JFrog reached profitability and free cash flow generation while many of its cloud-software peers were still lighting money on fire.
There is a useful piece of skepticism to plant here, because founder-origin stories are told by winners and polished by public relations. The camel framing is genuinely reflected in how the company later operated with capital, so it is more than a slogan. But the neat narrative — three consultants, one eureka, one product — flattens years of grinding, unglamorous engineering and a market that did not yet know it wanted what they were building. The interesting part of JFrog's early history is not the myth of the insight. It is that the insight, correct as it was, took the better part of a decade and a fortunate shift in how the entire industry built software before it turned into a real business. That shift is the subject of the next section.
III. Building the "System of Record": The Rise of Artifactory
In 2009, Artifactory went public — not in the stock-market sense, but in the open-source sense. JFrog released it as a free, open Java repository manager, and let it spread the way developer tools spread: one frustrated engineer at a time, adopting it inside a company because it solved a real problem on a Tuesday afternoon, with no purchase order and no salesperson involved.3 This is the classic bottoms-up motion of infrastructure software. You give away the useful thing, it colonizes engineering teams from the ground up, and years later a procurement department discovers that a tool nobody officially bought has become load-bearing across the entire organization. That discovery is where the money is.
But the decision that actually made JFrog was not to build a good Java repository. It was to stop being a Java repository at all.
Yoav Landman's architectural bet was that software was going polyglot. In the early 2010s, the industry was fragmenting into a dozen ecosystems, each with its own packaging format and its own way of distributing binaries. JavaScript had npm. Python had PyPI. Microsoft's .NET world had NuGet. And then, transformatively, Docker arrived and made the container image — a self-contained bundle of an application and everything it needs to run — the fundamental unit of modern deployment. Each of these was its own island with its own conventions. JFrog's rivals, most notably Sonatype and its Nexus product, were deeply anchored in the Java and Maven world where repository management had been born. JFrog made the harder, more expensive choice: build native support for all of them, and keep going, until Artifactory spoke every packaging language a developer might use.9 Over time that grew into support for more than forty package formats under one roof.
Why did this matter so much? Because it changed what Artifactory was. A Java-only repository is a tool. A universal repository is a standard. If your organization writes some services in Java, some in Python, some in JavaScript, ships them all as Docker containers, and wants one consistent place to store, secure, and govern every one of those artifacts, a universal repository is the only thing that fits. The competitors optimized for depth in one ecosystem; JFrog optimized for breadth across all of them, and breadth is what a large enterprise with a hundred teams and a dozen languages actually needs. This is the moment a utility becomes infrastructure.
Here it is worth slowing down on a distinction the whole investment case rests on, because it is easy to blur. The industry talks about systems of engagement versus systems of record. Git — GitHub, GitLab — is a system of engagement: it is where developers interact, write source code, review each other's work, argue in comment threads. It is human-facing and it is where the cultural energy lives. Artifactory is a system of record: it is where the compiled binaries that actually run in production are stored, the authoritative ledger of what exists and what shipped. The economic difference between the two is enormous and underappreciated. Source code is written by humans and read by humans; the volume is bounded by how fast people can type and think. Binaries are produced by machines and consumed by machines — pulled millions of times a day by build servers, container orchestrators, and production fleets that never sleep. A source repository traffics in megabytes of text. A binary repository traffics in gigabytes and terabytes of compiled packages, moving constantly. The system of record sits on the heavy, high-volume, machine-driven side of that line, and that is the side where storage, bandwidth, and switching costs compound.
It is worth being explicit about how a free, open-source tool becomes a half-billion-dollar business, because the mechanism is not obvious and it is central to the economics. JFrog runs a version of the open-core model: the base of Artifactory is open and free, which is what drives grassroots adoption and builds the installed base, but the features that large organizations genuinely need to run it in production — high availability so the repository never goes down, the multi-site replication described below, fine-grained access control, enterprise support — sit behind a paid commercial license. Individual developers and small teams use the free tier and spread the tool virally through the industry; the enterprises that come to depend on it pay for the capabilities that turn a useful tool into critical infrastructure. The genius of this motion is that the sales cost of the free tier is nearly zero — developers adopt it themselves, with no salesperson in the room — and by the time a procurement department gets involved, the tool is already entrenched and the conversation is about upgrading rather than convincing. The open-source project is, in effect, the world's most efficient lead-generation engine.
There was one more hard problem Artifactory had to solve to be enterprise-grade, and it is the kind of problem that only shows up at scale: replication. A global company might have developer hubs in Sunnyvale, Bangalore, and Netanya, all pulling from and pushing to the same body of binaries. If every engineer in Bangalore has to reach across the planet to a server in California every time they need a multi-gigabyte artifact, the whole operation grinds. JFrog's answer was multi-site federation — the ability to replicate heavy binaries across regions in near real time while preserving absolute transactional integrity, so that a build in one city and a build in another are guaranteed to be working from identical, verified copies. Solving global replication with integrity is not a feature you appreciate in a demo; it is a feature you cannot live without once your engineering organization spans continents, and it is exactly the sort of capability that makes ripping the system out later feel unthinkable.
By the middle of the 2010s, then, JFrog had quietly become the pantry, the ledger, and the distribution network for an increasingly polyglot software world. The natural next question — the one that turned a repository company into a platform company — was whether the thing sitting in the middle of every software pipeline could also be the thing that secured it.
IV. Platform Expansion & The DevSecOps Inflection
Consider where Artifactory sits in the flow of software, because its position is the whole strategic gift. Every third-party library, every open-source package, every container image an organization uses has to pass through the repository on its way from the outside world into production. That is an extraordinary vantage point. It is the single chokepoint through which the entire supply chain of software components must travel. And in 2016, JFrog looked at that chokepoint and asked the obvious question: if everything flows through here, why not inspect it here?
The answer was JFrog Xray, unveiled in 2016, a product that scans binaries sitting in Artifactory for known security vulnerabilities and open-source license problems.[^4] To understand why this was clever, you have to understand the prevailing security fashion of the era, which went by the slogan shift left — the idea that you should catch problems earlier in development, closer to the developer, rather than after deployment. JFrog's insight was subtler and arguably better positioned: don't just shift left, secure the source of truth. Because everything passes through the repository, scanning at the repository catches problems no matter which developer, which team, or which pipeline introduced them. If an engineer unknowingly pulls in a compromised open-source package, Xray can flag it the moment it lands, before it propagates into a hundred downstream builds. The repository is not just where binaries live; it is the natural border checkpoint where they can be examined.
That border-checkpoint logic later hardened into a product called JFrog Curation, which flips scanning from reactive to preventive: rather than flagging a malicious package after it has entered the developer's environment, Curation blocks it at the boundary, refusing to let it in at all.[^4] The distinction matters because the software supply chain has become an active attack surface — adversaries deliberately publish poisoned packages to public registries hoping some enterprise pulls them in. Owning the gate through which packages enter is a genuinely defensible place to stand.
In November 2016, JFrog made a move that looks small on the balance sheet and shrewd in hindsight: it acquired Conan, the leading open-source package manager for C and C++.4 To appreciate the chess here, you need one piece of context. C and C++ are among the oldest and most important programming languages alive — they run operating systems, embedded devices, cars, industrial controllers, game engines. And unlike the newer ecosystems, C/C++ never developed a clean, standardized way to manage dependencies. It was, for decades, the wild frontier of packaging. By adopting Conan, JFrog planted its flag in exactly the industries where C/C++ dominates — automotive, embedded systems, aerospace, gaming — and made Artifactory the natural enterprise hub for a language ecosystem that had never had a good one. It was a cheap acquisition that bought a durable position in verticals competitors found hard to reach.
Around the security push, JFrog was also assembling the rest of what it needed to call itself a platform rather than a product. It built Distribution, a system for pushing released binaries out to the edge — to the servers, devices, and clusters where software actually runs — at scale and with integrity, which is the practical machinery behind the Liquid Software vision of updates that flow continuously. It added automation tooling to orchestrate the pipeline from commit to production. And it wrapped the whole thing in an annual developer conference, swampUP, which functions as the community gathering where new products are unveiled and the faithful are cultivated — the kind of ritual that turns a vendor into an ecosystem. None of these individually was revolutionary, but together they let JFrog tell a story no point-solution rival could tell: a single, continuous, secured path from a developer's commit all the way to the binary running in production.
All of this accumulation of capability created a strategic risk that JFrog was clearly aware of: the risk of being seen as a collection of point solutions — a repository here, a scanner there, a distribution tool over there — each of which some competitor could pick off. The company's defense was to bundle. Artifactory, Xray, Distribution, and its automation tooling were packaged together and sold as a single Software Supply Chain Platform, offered in tiered enterprise subscriptions — Pro, Enterprise, and Enterprise Plus — that pulled customers up an escalator of value and price. The strategic logic of bundling is straightforward: a platform is harder to displace than any of its parts, and a customer who buys the suite is far stickier than one who bought a single tool. Whether the bundle delivers enough additional value to justify itself, versus best-of-breed alternatives a customer could assemble, is a question that only the retention numbers can answer honestly — and we will hold JFrog to those numbers later.
By 2020, JFrog had a universal platform, a security story, a foothold in hard-to-reach verticals, and a genuinely differentiated position in enterprise software delivery. What it did not yet have was a public currency. That was about to change, in the strangest capital-markets environment in a generation.
V. The COVID SaaS Peak & The NASDAQ IPO
By September 2020 the world had been locked down for six months, offices had emptied, and — in one of the great counterintuitive turns in market history — technology stocks were not crashing but levitating. Every company on Earth had discovered simultaneously that its future was digital, cloud budgets had become recession-proof overnight, and public investors were paying dizzying prices for anything that smelled like software-as-a-service. Into this fever, JFrog filed its Form S-1 and walked toward the NASDAQ.
The IPO priced on September 16, 2020 at $44.00 per share — well above the initially marketed range of $33 to $37, a sign of the demand crowding into the deal.[^6] Then the stock did what 2020 IPOs did: it launched. Shares opened around $71 and closed their first day near $65, a first-day gain of roughly 47%, which valued the company at well over $5 billion on a market-cap basis versus the roughly $3.9 billion implied by the offering price.5 It is worth correcting a bit of folklore here, in the spirit of separating what happened from what gets remembered: the stock's first-day close was in the mid-$60s, not "past $80." It would touch higher levels later in the frenzy, but the debut itself, while spectacular, was a 47% pop and not a doubling. Precision matters, because the gap between the offering price and the trading price is money that left on the table, and the size of that gap is one of the enduring critiques of the 2020 IPO vintage.
Two features of how JFrog came public deserve real attention, because they reveal something about the company rather than the moment.
The first is governance. JFrog went public with a one-share-one-vote structure — a single class of ordinary shares, no dual-class founder super-voting stock.[^6] This was, and remains, unusual for a founder-led technology company of its era. The fashionable structure was the opposite: founders retaining voting control through supercharged shares that let them override public shareholders indefinitely. JFrog's founders chose to remain directly accountable to the market from day one. For an investor, this is a genuinely favorable governance fact — it means the people running the company answer to owners on the same terms as everyone else, and it removes a whole category of entrenchment risk. It should be weighed as a real positive, not a footnote.
The second is the financial profile, which was rare for the class of 2020. Most cloud software companies that IPO'd in that window were burning cash prodigiously, trading growth for losses on the theory that profitability could wait. JFrog arrived with an unfashionable combination: solid revenue growth, gross margins north of 80%, and positive free cash flow. The camel had, in fact, crossed the desert. That profile is a direct inheritance of the survivalist culture forged in the 2008 seed round — a company that learned to fund itself does not suddenly forget the habit when public money becomes available. For a fundamental investor, this is the tell that separates JFrog from a lot of its cohort: it was a real business with real unit economics wearing a growth-stock valuation, rather than a growth story hoping to become a business.
There is a subtler point buried in the pandemic IPO that is easy to miss and worth surfacing. A company that goes public profitable and cash-generative is making an implicit statement about its confidence and its independence: it does not need the public market's money to survive, which means it is raising capital on its own terms rather than out of desperation. That posture — going public from a position of strength rather than as a last cash grab before the runway ends — is the same camel instinct dressed in a banker's suit. It also meant that when the market turned hostile, JFrog had the luxury most of its 2020 IPO cohort did not: it could keep investing and executing without the existential pressure of a closing funding window, because it was funding itself out of operations. The strength of the balance sheet at the IPO is what let the company treat the subsequent valuation winter as weather rather than as an emergency.
The valuation, of course, could not hold — not because anything was wrong with JFrog, but because the entire regime that produced it ended. Starting in 2021 and accelerating through 2022, interest rates rose sharply, and rising rates are gravity for long-duration growth assets. The mechanism is worth stating plainly, because it explains a lot of what happened to JFrog's stock and to its peers: when money is free, investors will pay almost anything for revenue that arrives years in the future; when money costs 5%, that same future revenue is discounted far more harshly, and the multiples that looked reasonable at zero rates collapse. JFrog's shares fell from the highs into the high teens — a brutal de-rating that had little to do with the company's operations, which kept executing, and everything to do with the price the market was willing to assign to those operations. This decoupling of stock price from business performance is one of the most important things for a long-term investor to internalize, and JFrog is a clean case study: for a stretch, the company got steadily better while the stock got steadily cheaper.
The temptation, when your stock has tripled and then halved, is to do something dramatic with the currency while it is still elevated. JFrog did exactly that — twice — and how those two bets aged tells us a great deal about management's judgment.
VI. Post-IPO Capital Deployment & M&A Benchmarking
Capital allocation is where management teams reveal who they really are. Anyone can run an operating business in a straight line; the character shows up in what they do with the money and the stock, especially when the stock is expensive and the temptation to spend it is highest. JFrog made two significant acquisitions in the years after its IPO, and they make an instructive pair — because on the surface both look like they were bought at rich prices, and yet the analytical verdict on the two is quite different.
Vdoo: overpaying for the right thing
In June 2021 — very near the absolute top of the SaaS bubble, when JFrog's own stock was still richly valued — the company agreed to acquire Vdoo, an Israeli security startup, for approximately $300 million in a mix of cash and stock.6 By any conventional yardstick, this was an enormous price. Vdoo had minimal commercial revenue; on a pure revenue-multiple basis, JFrog paid a staggering premium for a business that was barely selling anything yet. A skeptical investor looking only at the numbers would call it a classic bubble-era overpayment, and on the arithmetic they would be right.
And yet Vdoo is the harder, more interesting case, because acquisitions are not bought for their trailing revenue — they are bought for what they let you build. Vdoo's binary security-analysis technology became the engine of JFrog Advanced Security, which the company rolled out around late 2022.7 That product moved JFrog well beyond the basic software-composition analysis of Xray — which mostly told you whether you were using a known-vulnerable open-source component — into a much richer security suite: secrets detection (finding passwords and keys accidentally left in code), infrastructure-as-code scanning (catching misconfigurations before they ship), and contextual analysis (determining whether a vulnerability is actually reachable and exploitable in your application, rather than merely present). These are high-margin capabilities sold as upsells to customers who already run Artifactory, and they expanded the average revenue the company earns per customer.
So the honest verdict on Vdoo is a paradox worth stating clearly: JFrog almost certainly overpaid on any financial multiple you could have written down in 2021, and it was probably a good deal anyway, because it bought a product transition JFrog could not easily have built itself, in a security market expanding faster than the core repository business. The lesson for investors is that "overpaid" and "good acquisition" are not opposites in technology — the question is whether the asset unlocks durable, high-margin revenue that would otherwise have been unavailable, and on the evidence of the Advanced Security franchise, this one did. That is a genuinely favorable data point about management's strategic judgment, even if their sense of price discipline in a bubble is fair to question.
Qwak: buying an option on the AI era
Three years later, in June 2024, JFrog acquired Qwak, an Israeli MLOps company, for approximately $230 million.8 The context had completely changed. This was no longer a bubble; it was the early, uncertain dawn of the generative-AI era, and JFrog was buying a position in it. Qwak had raised a $12 million round in early 2023 that reportedly doubled its private valuation, so JFrog again paid a substantial step-up over the last private mark — the precise multiple is not something to state with false confidence, since Qwak's exact prior valuation was not publicly disclosed, but the direction is clear: JFrog paid a large premium for an early-stage asset.8
The strategic thesis behind Qwak is the single most important forward-looking idea in the entire JFrog story, so it is worth stating carefully and then stress-testing. Here is the thesis: large language models and neural networks are, at the end of the day, binary files — enormous bundles of numerical weights and parameters. They are versioned, they are heavy, they are pulled into production systems, they need to be secured and governed and rolled back when they misbehave. In other words, an AI model has essentially the same life-cycle problems as a traditional software binary, only bigger. If Artifactory is the system of record for conventional binaries, the argument goes, it is the natural system of record for AI models too — and Qwak provides the MLOps orchestration layer to manage those models from training through deployment.
It is an elegant thesis, and it may well be right. But a neutral observer has to note what it is at this stage: an option, not a proven business. Qwak is early, it is not yet a material driver of total revenue, and the MLOps market is crowded with well-funded specialists and cloud-platform incumbents who would like to own model management themselves. The bet rests on an analogy — models are like binaries — that is conceptually sound but not yet validated by a large book of paying customers managing their models in Artifactory. So the correct way to hold the Qwak acquisition is as strategic optionality: a modestly-sized, sensibly-motivated wager that, if the analogy holds and JFrog executes, could extend the franchise into the defining technology wave of the decade — and if it doesn't, will have cost a manageable amount. Two hundred thirty million dollars for a credible option on being the repository of record for AI is not obviously unreasonable. It is also not yet proven, and no amount of narrative should let it masquerade as proven.
Both deals, then, were bought at prices that would make a value investor wince, and both are defensible on strategic grounds — a pattern that tells you JFrog's management thinks in terms of platform position rather than entry multiple. That instinct served the company well through the acquisitions. It was about to be tested far more painfully in the core business itself.
VII. The Mid-2024 Guidance Crisis
On the evening of August 7, 2024, JFrog held its second-quarter earnings call, and by the next morning roughly a third of the company's market value was gone.12 For a business that had built its reputation on steadiness — the camel, the profitable infrastructure company, the reliable operator whose stock suffered only because of macro forces beyond its control — this was a genuine shock, and the kind of moment that separates what a company says about itself from what is actually true.
The proximate cause was guidance. Management cut its full-year 2024 revenue outlook to roughly $422 million to $424 million and pulled down its expectation for full-year cloud growth to around 40%, a meaningful step down from the trajectory the market had priced in.12 In a company whose entire narrative was accelerating cloud adoption, cutting the cloud growth number was the deepest possible wound. Markets do not punish a miss so much as they punish the revision of the story, and this was a revision of the story.
The root cause is where the real lesson lives, and it is a lesson about the double edge of the very business model that had powered the company's growth. JFrog's cloud revenue is substantially consumption-based — customers pay in proportion to how much they store and how much they transfer. During good times, this is a beautiful model: as customers do more, they pay more, automatically, with no renegotiation. But the same mechanism runs in reverse. In mid-2024, management pointed to a sudden deceleration in what it called non-committed monthly cloud consumption. Translated: a cohort of smaller and mid-market customers, many on flexible credit-card SaaS plans with no long-term commitment, simply used less as the macro environment tightened and every company on Earth started scrutinizing its cloud bills. Nobody had to cancel a contract or switch vendors. They just consumed less, and because JFrog got paid by consumption, revenue softened directly. Compounding it, enterprise migrations from self-managed on-premises deployments to the cloud were taking longer than expected, snagged on the complex compliance and hybrid-architecture constraints that large regulated organizations carry.
What happened next, on the analyst Q&A, is the part worth listening to closely, because it reveals the deeper fear the market was pricing in. Analysts pushed hard — the pointed, slightly hostile pushing that happens when a stock is in free fall — and the sharpest questions circled a single existential worry: were the Git-native package registries bundled into GitHub and GitLab finally commoditizing Artifactory? Was JFrog's whole reason for existing being quietly absorbed into tools developers already paid for? This is the bear case in its purest form, and the analysts put it directly to CEO Shlomi Ben Haim.
His response was a refutation and a redirection. Ben Haim rejected the commoditization narrative, arguing that the enterprise customers were not switching to anything — they were migrating slower. The demand had not gone to a competitor; it had been deferred by macro caution and migration complexity. It is worth being appropriately skeptical here: "customers are pausing, not leaving" is exactly what every management team says when demand softens, and it is not independently verifiable in the moment. The question is whether subsequent behavior confirms it. But management did more than offer reassurance — it changed the plan. Rather than chasing cheap, volatile monthly SaaS users whose consumption could evaporate with the macro mood, JFrog pivoted deliberately toward locking enterprises into multi-year, annually committed cloud contracts, and toward cross-selling security into its existing base to deepen relationships and raise the floor under revenue. In other words, management diagnosed the flaw in its own model — that non-committed consumption is wonderful on the way up and treacherous on the way down — and set out to re-engineer the revenue base toward commitment and stability.
That is the right response if the diagnosis was correct. The only way to know whether it was correct, rather than convenient, is to watch what happened over the following eighteen months. As it turned out, the following eighteen months are the most encouraging chapter in the company's recent history — and the strongest available evidence that the commoditization bears were, at least for now, wrong.
VIII. The Great 2025–2026 SaaS Acceleration & Recovery
If the August 2024 call was the company's dark night, the numbers filed a year and a half later were the sunrise — and, more importantly for a skeptical investor, the receipts that let us grade management's crisis-era promises against reality.
On February 12, 2026, JFrog reported its fiscal 2025 results, and they told the story of a business that had not just stabilized but reaccelerated. Full-year revenue reached $531.8 million, up 24% year over year — an acceleration from the growth rate that had so alarmed the market in 2024.1 The metric that matters most for judging the "customers are pausing, not leaving" thesis is net dollar retention, which measures how much more (or less) an existing cohort of customers spends this year versus last. NDR came in at 119% on a trailing four-quarter basis.1 Read plainly: the average existing customer spent 19% more than the year before, which is close to definitive evidence that customers were not defecting to GitHub or GitLab — a departing base does not expand at that rate. The commoditization narrative, whatever its long-term merit, was not visible in the retention data.
The rest of the fiscal 2025 picture reinforced the point that this is a genuinely high-quality business rather than a growth story propped up on losses. The large-customer cohorts — the enterprises that anchor the pivot toward committed contracts — grew markedly: customers generating more than $1 million in annual recurring revenue jumped to 74, up from 52 a year earlier, and customers above $100,000 in ARR reached 1,168.1 That upmarket migration is exactly what management said it would pursue in the depths of 2024, and here it was, showing up in the account counts. On profitability, non-GAAP operating income reached $92.1 million, a 17.3% margin, and free cash flow was $142.3 million — a striking 26.7% of revenue.1 A company converting more than a quarter of its revenue into free cash flow is not merely growing; it is a cash machine, the camel proving once again that it can cross the desert while its flashier peers run dry.
Then came the proof point. On May 7, 2026, JFrog reported first-quarter results that beat expectations across the board. Revenue was $154.0 million, up 26% year over year — growth still accelerating.13 But the headline was the cloud line: cloud revenue reached $78.9 million, up 50% year over year, and for the first time in the company's history crossed above half of total revenue, landing at roughly 51%.13 This is the milestone the entire post-2024 recovery was built toward. The whole crisis had been, at its heart, about whether JFrog could get its customers over the friction of migrating from self-managed software to the cloud. Cloud passing 50% of revenue, and growing at 50%, is the operational answer: the migration engine that stalled in 2024 was running again, and running hard. On the strength of it, management raised full-year 2026 revenue guidance to a range of $628 million to $632 million.13
But this is Empor, not an investor-relations department, so the appropriate posture toward a triumphant quarter is to read the fine print — and there is fine print. On the Q1 2026 call, management itself cautioned that a meaningful chunk of the cloud outperformance came from usage above contractual minimums — precisely the non-committed, overage consumption that proved so treacherous on the way down in 2024.14 Because guidance conservatively excludes those overages until customers convert them into formal commitments, the company carries a timing risk: strong usage does not automatically become recognized, guided revenue, and the same consumption elasticity that is a tailwind now can reverse if the macro mood sours again. It is genuinely to management's credit that they flagged this themselves rather than letting the market assume the overages were permanent — that is the kind of disclosure discipline that builds credibility over time. But the honest read is that the model's fundamental double edge, the thing that cut the company in 2024, has not been abolished. It has been managed, hedged with commitments, and is currently pointing the right way.
Underneath the cloud headline sat a second engine that matters for the durability of the recovery: security. The Advanced Security franchise built on the Vdoo acquisition, together with Curation, had grown into a distinct revenue driver that management increasingly broke out and leaned on, packaging its security capabilities as a "Security" tier that customers add on top of the core repository subscription. This is the DevSecOps consolidation thesis turning into dollars — the same customers, paying more, because JFrog now secures the supply chain it already stores. On the recent calls management framed security as growing faster than the core repository business, which, if it holds, means the company is expanding into the far larger security budget rather than merely growing its share of the repository budget.13 For an investor, security cross-sell is the most legible of JFrog's expansion stories: it targets a proven, urgent enterprise need, it sells into an installed base that is already captive, and it shows up cleanly in net dollar retention. It is the part of the growth story that depends least on any speculative analogy — which is precisely why it deserves weight against the flashier AI narrative that follows.
Which brings us to the tailwind management is most excited about, and the one most worth scrutinizing: artificial intelligence. The bull argument runs like this. AI coding assistants — Cursor, GitHub Copilot, Gemini Code Assist — let developers produce code far faster than they could by hand. More code, written faster, means exponentially more commits, more automated builds, and therefore more binaries pouring out the other end of the pipeline. And every one of those binaries has to be stored somewhere, scanned somewhere, distributed somewhere — inside a repository like Artifactory, consuming storage and bandwidth, which in a consumption-priced cloud model translates directly into revenue. In this framing, the AI coding boom is not a threat that could disintermediate JFrog; it is a firehose pointed straight at its meter. There is real logic to this — if binary volume genuinely explodes, a company paid by binary volume benefits mechanically. The caveats a careful investor should hold are two: first, this is still more thesis than demonstrated line item, harder to isolate in the financials than the clean cloud-migration story; and second, the same AI wave empowers JFrog's platform competitors, who sit even closer to where that AI-generated code is born. The tailwind is plausible and directionally supported by the accelerating consumption, but it is not yet a proven, quantified engine, and it should be held as promising rather than banked.
The recovery, in sum, is real and well-evidenced in the retention and cloud-mix data — management largely did what it said it would after the 2024 crisis, which is the highest compliment you can pay an operator. The question that remains is not whether JFrog executed its turnaround. It is whether the position it has rebuilt is defensible against the largest software companies in the world. That is a strategy question, and it deserves its own war-game.
IX. Playbook: Business & Investing Lessons
Step back from the quarter-to-quarter narrative and JFrog offers a compact set of durable lessons — the kind that generalize beyond this one company to how infrastructure businesses are built, defended, and occasionally undone.
The defensibility of boring plumbing. The most counterintuitive lesson is that JFrog's moat comes precisely from the unglamorous nature of what it does. The industry's attention, talent, and capital flowed toward source code and the developer-facing tools around it — the systems of engagement, where the demos are pretty and the community is loud. JFrog planted itself on the other side, in the heavy, machine-facing system of record, and that turned out to be the more defensible ground. Here is the mechanism, and it is worth understanding as a general principle: it is relatively easy to switch systems of engagement, because they hold state that is light and portable — you can move a Git repository between providers in an afternoon. It is extraordinarily hard to switch a system of record that holds state that is heavy and entangled — petabytes of compiled, certified binaries, wired into thousands of CI/CD pipelines, security policies, and production deployment scripts that would all have to be re-plumbed and re-certified. The boring, heavy layer is the sticky layer. Investors hunting for durable businesses should look for exactly this signature: not where the excitement is, but where the switching pain is.
Universalism beats native integration. JFrog's second structural advantage is its neutrality. It is cloud-agnostic and tool-agnostic by design — it works across AWS, Azure, and Google Cloud, and alongside any developer toolchain, without belonging to any of them. This matters because large enterprises have learned to fear lock-in. They do not want their software supply chain welded to a single cloud provider whose prices they cannot escape, or to a single vendor's developer suite. An independent, hybrid bridge that spans everyone's infrastructure has a reason to exist that a single vendor's bundled feature does not. The lesson: in a world of powerful platforms each trying to enclose the customer, the neutral connective tissue between them can be a genuinely valuable and resilient position — as long as the platforms don't make their bundled version good enough that neutrality stops being worth paying for. That caveat is the bear case, and we will get to it.
The danger of usage-based revenue. The third lesson is the one JFrog learned the hard way in 2024, and it is a corrective to a fashionable idea. Consumption-based pricing — paying per gigabyte stored or transferred — was celebrated across SaaS as the perfectly aligned model: customers pay exactly for the value they get, and revenue grows automatically with usage. What 2024 exposed is the model's hidden fragility. When the macro turns and customers hunt for costs to cut, usage-based revenue can soften instantly and without warning, because customers can optimize their consumption down without any of the friction of canceling a contract. High-beta on the way up, high-beta on the way down. The stabilizer, as JFrog discovered, is to convert volatile consumption into committed, multi-year contracts — to trade some of the upside elasticity for a firmer floor. The general lesson for investors evaluating any consumption-priced company: ask what share of revenue is committed versus discretionary, because that ratio is the difference between a smooth compounder and a cyclical one wearing a compounder's costume.
These three lessons — sticky heavy state, valuable neutrality, and the two-edged sword of consumption pricing — are the load-bearing beams of the investment case. They also frame the debate, because each one has a competitor's rebuttal. Time to war-game it.
X. Strategic Analysis: Bear vs. Bull & Hamilton Helmer's 7 Powers
To assess whether JFrog's position is truly defensible, it helps to run the business through the frameworks strategists actually use — Hamilton Helmer's 7 Powers and Porter's Five Forces — and then to argue the bull and bear cases against each other as honestly as possible.
Hamilton Helmer's 7 Powers
Of Helmer's seven durable sources of advantage, two apply to JFrog with real force, and it is important to be precise about which.
The primary power is high switching costs. This is the beam we have already identified, and in Helmer's specific sense it is close to a textbook case. Once Artifactory is woven into thousands of a customer's CI/CD pipelines, security policies, and production deployment scripts, and once petabytes of certified binaries live inside it, replacing it is not a procurement decision — it is a multi-year, high-risk operational migration that touches the parts of the business a company least wants to disturb. The customer is not locked in by a contract; they are locked in by the sheer cost and danger of leaving. The 119% net dollar retention is the quantitative fingerprint of this power: customers who found it easy to leave would not, in aggregate, keep spending more every year.
The supporting power is scale economies, though here one should be careful not to overclaim. JFrog's version of scale is not primarily about manufacturing cost curves; it is about the compounding R&D burden of maintaining native, first-class, continuously-updated support for more than forty dynamic package formats, each of which evolves on its own schedule. A point-solution competitor serving one ecosystem cannot easily match that breadth, because matching it means funding a level of sustained, sprawling engineering investment that only a large installed base can amortize. This is a real but bounded advantage — it protects JFrog against small specialists more than against the largest platforms, who have R&D budgets that dwarf JFrog's entirely. So the honest scorecard is: one strong, well-evidenced power (switching costs) and one supporting, partial power (scale in format breadth). That is a genuine moat, but not an impregnable one, and pretending otherwise would be exactly the kind of management-flattering analysis this platform exists to avoid.
Porter's Five Forces
The Porter lens sharpens where the pressure comes from. Most of the forces are benign for JFrog: supplier power is low (its inputs are open-source formats and commodity compute), and the threat of new entrants building a full universal platform from scratch is modest given the accumulated engineering. Two forces are where the action is.
Threat of substitutes is moderate-to-high, and it has a name: GitHub Packages and GitLab Registry. These are "good enough" binary registries bundled directly into the developer platforms teams already use. For a small or cloud-only startup, why pay for a specialized repository when a serviceable one comes free with the Git provider? This is the substitution pressure that the 2024 analyst Q&A was really about, and it is the single most important competitive risk in the whole story.
Bargaining power of buyers splits cleanly by customer size, and the split is revealing. For large enterprises with complex, hybrid, multi-site, compliance-heavy requirements, buyer power is low-to-moderate — they need exactly what JFrog uniquely provides, and they cannot easily assemble it elsewhere. For small, cloud-only startups with simple needs, buyer power is high — they have free and adequate alternatives and no switching costs to trap them. This tells you precisely where JFrog is strong and where it is exposed, and it explains the strategic wisdom of the post-2024 pivot upmarket toward committed enterprise contracts: management is deliberately steering the business toward the customers where its power is greatest and away from the ones where it is weakest.
The bull case
The optimistic case is grounded in demonstrated facts rather than hope. JFrog has completed the hard transition to a cloud-first model, with cloud past half of revenue and growing at 50%, at gross margins in the mid-80s and with free cash flow above a quarter of revenue.131 That is a rare quality profile. On top of the core, a DevSecOps expansion is underway — Advanced Security and Curation are growing the addressable market beyond repository management into the much larger security budget, and security cross-sell is the mechanism raising revenue per customer. And layered above that is the AI optionality: if binary volume explodes as AI writes more code, JFrog's consumption meter benefits mechanically, and if AI models become the next class of managed binaries, Qwak positions the company to be their system of record too. Strong core, expanding adjacency, real optionality — that is a legitimately attractive stack, and none of it is fabricated; it is visible in the filings.
The bear case
The pessimistic case is equally grounded, and it is not to be waved away. The central threat is long-term commoditization by Microsoft and GitLab. The bear does not claim GitHub Packages is better than Artifactory today — it plainly is not for complex enterprises. The bear claims that "better" is not the bar. The bar is "good enough, and already included." If GitHub's and GitLab's bundled registries slowly close the gap on enterprise federation and security — and both companies have enormous engineering resources and a structural incentive to do so — then buyers may increasingly choose single-vendor simplicity to reduce tool sprawl, even at some cost in capability. Enterprise software history is littered with best-of-breed independents that were slowly absorbed by "good enough" incumbents who owned the adjacent workflow. This is a real, structural, patient threat, and JFrog's switching-cost moat protects the installed base far better than it protects new logos, where the incumbent bundle competes on equal or better footing.
The second bear point is valuation and model sensitivity. The stock trades at an elevated enterprise-value-to-revenue multiple, which means it prices in continued strong execution. Any reversion in the consumption model — a macro slowdown that once again turns non-committed usage from tailwind to headwind, exactly as in 2024 — would hit both the growth rate and the multiple simultaneously, the double-punch that erased a third of the value overnight once before and could do so again. The overage caution management itself raised on the Q1 2026 call is not a footnote; it is the bear case's live ammunition.14
An activist or short-oriented investor would press on two further points worth naming. First, the acquisition pattern: two deals bought at rich prices near market tops, which — however strategically defensible each turned out to be — establishes that this management will pay up when it believes in an asset, a habit that rewards success and punishes misjudgment asymmetrically. Second, the fragility of the disclosure around consumption overages: guidance that depends on how much discretionary usage converts to commitment is inherently harder to trust than guidance backed by contracted revenue, and a skeptic would demand more visibility into that conversion. To management's credit, the one-share-one-vote governance structure removes the entrenchment complaint that usually tops an activist's list — there is no dual-class shield here, and accountability to owners is structurally intact.[^6]
Myth vs. reality
Two consensus narratives about JFrog deserve to be fact-checked directly, because both are half-true in ways that matter.
The first myth is that JFrog is a security company now. The DevSecOps story is real and growing, and management is happy to lean into it because security carries higher multiples and a larger addressable market. But the reality is that the overwhelming majority of JFrog's revenue and its entire defensive moat still rest on being the repository — the system of record for binaries. Security is the fast-growing upsell riding on top of that foundation, not a replacement for it. An investor who buys JFrog as a pure-play security company is misreading the business; the security growth is only as durable as the repository lock-in that gives JFrog the captive audience to sell it to. Get the causality backwards and you misjudge the risk.
The second myth is the mirror image, the bear's version: that Git-native registries have already commoditized Artifactory. This was the loud narrative in the August 2024 selloff, and the reality is that it has not shown up where it would have to show up first. A business genuinely being commoditized bleeds customers and sees its retention collapse; JFrog's net dollar retention sat at 119% and its million-dollar customer count grew by more than 40% in the same window the commoditization thesis was loudest.1 The honest reading is not that the bears are wrong forever — the bundling threat is real and patient — but that commoditization is, at most, a future risk being priced by some as a present fact. The data says the enterprise base is expanding, not eroding. The myth ran ahead of the reality, in both directions.
Key KPIs to watch
For all the complexity, three metrics carry most of the diagnostic signal for tracking this company going forward, and a long-term investor can watch them and ignore most of the noise:
-
Trailing four-quarter net dollar retention. This is the single truest read on the switching-cost moat and the commoditization debate. As long as it holds comfortably above roughly 115%, the base is expanding and the bears' disintermediation thesis is not showing up where it would show up first. If it drifts toward 110% and below, the moat is leaking.
-
Cloud (SaaS) revenue year-over-year growth. This is the health of the central strategic engine — the migration from self-managed to cloud. Sustained growth above the mid-30s signals the engine is running; a slip back toward the 2024 deceleration would be the earliest warning that the recovery is stalling.
-
Large-customer cohort growth — the counts of customers above $1 million and above $100,000 in ARR. This tracks the deliberate, post-crisis migration upmarket toward the committed, sticky, high-power accounts and away from the volatile long tail. Rising cohorts mean the stabilization strategy is working structurally, not just cyclically.
Watch those three, and you are watching the actual mechanism of the business rather than the sentiment around it.
XI. Epilogue & Outro
JFrog is, in the end, the great unsexy success story of modern software infrastructure. There is no consumer brand, no viral product, no charismatic founder mythology of the Silicon Valley variety. There is instead a coastal-plain consulting firm in Netanya, three engineers who got tired of the same problem breaking every build, and a twenty-year commitment to owning the heavy, boring, mission-critical layer that everyone else found too dull to fight over. By choosing the binaries over the source code — the system of record over the system of engagement — Shlomi Ben Haim, Yoav Landman, and Fred Simon built a tollbooth on a highway that the entire industry has to drive down, and then spent a decade making that tollbooth harder and harder to bypass.
The record they have earned the right to be judged on is genuinely strong: a profitable, cash-generative infrastructure business that survived a valuation collapse it did not cause, absorbed a self-inflicted credibility wound in 2024, and did roughly what it promised in the recovery — pushing cloud past half of revenue, holding retention near 120%, and steering the customer base toward the committed enterprise accounts where its moat is deepest. That is a management team that has, on balance, set targets and hit them, explained its miss without hiding behind it, and governed itself with an accountability structure most of its peers refused to adopt. None of that makes the future safe. The commoditization threat from Microsoft and GitLab is patient and structural, the consumption model's double edge has not been dulled so much as managed, and the valuation leaves little room for error.
Which leaves the one question the next era turns on. JFrog won the last decade by becoming the definitive system of record for human-written software. The bet it is now placing — through Qwak, through Artifactory, through the wager that a neural network is just another binary — is that it can become the definitive system of record for the AI models that are beginning to write the software themselves. If that analogy holds, the tollbooth sits on an even bigger highway than the one it was built for. If it doesn't, JFrog remains an excellent, defensible, and cyclically exposed infrastructure company — which is no small thing to be, but is a good deal less than the story its valuation is telling. The evidence over the next several years, read through those three KPIs, will tell us which it is.
References
-
JFrog Announces Fourth Quarter and Fiscal 2025 Results — JFrog, 2026-02-12 ↩↩↩↩↩↩↩
-
Rooted in Open Source: A Reflection on JFrog's Origins and Community — JFrog Community & Culture ↩↩
-
JFrog Artifactory — Universal Binary Repository Manager (product page) — JFrog ↩
-
JFrog Acquires Conan, Bringing DevOps to C/C++ — PR Newswire, 2016-11-17 ↩
-
JFrog IPO Surges 47% on Its First Day of Trading — Nasdaq / The Motley Fool, 2020-09-17 ↩
-
DevOps platform JFrog acquires connected-device security specialist Vdoo for $300M — TechCrunch, 2021-06-29 ↩
-
JFrog and Vdoo: Better Together (JFrog Advanced Security) — JFrog Blog ↩
-
JFrog buys Israeli AI company Qwak for $230m — Globes, 2024-06-25 ↩↩
-
JFrog Curation: securing the software supply chain — JFrog Blog ↩
-
A Camel in the Desert: The Story of JFrog — Globes Israel, 2020-09-17 ↩
-
Disappointing guidance follows mixed earnings results as JFrog stock craters — SiliconANGLE, 2024-08-07 ↩↩
-
JFrog forecasts $628M–$632M FY2026 revenue as cloud mix passes 50% — Seeking Alpha, 2026-05-07 ↩↩↩↩↩
-
JFrog Rides Cloud Surge Despite Cautious Outlook — TipRanks, 2026-05-07 ↩↩