JFrog Partners with Wiz to Close the Gap on AI-Era Threats, Keeping Global Businesses Secure
JFrog Ltd,
creators of the JFrog
Software Supply Chain Platform, the system of record for trusted
software artifacts, binaries, and AI assets, announced a new integration with Wiz, now part
of Google Cloud,
that closes a critical gap in AI-Era security: shrinking the time between risk
detection and verified code fixes. The JFrog Platform serves as the single
source of truth for all software artifacts - from build to production - while
the Wiz cloud and AI security platform adds instant cloud runtime visibility.
Together, the
integration enables security and engineering teams with a unified
view of what's running, where it came from, whether it's trusted, and how to
fix it – enabling teams to keep pace with frontier AI models that move faster
than most organizations can respond.
"Today’s enterprise security teams are
caught between two sources of information: AppSec teams see what was built but
lose visibility once software ships. Cloud security teams see what is running
but lack the supply chain context to understand the real risks,” said Gal
Marder, Chief Strategy Officer, JFrog. “Our partnership and integration with
Wiz solves this by delivering a unified view from build to production – so
teams can move from detection to remediation in hours vs. days."
In the
Frontier AI era, the threat landscape has shifted fundamentally. Attackers now
weaponize vulnerabilities faster than defenders can respond – the median time
to exploit is now under a day, according to recent Forrester research. Yet Mean Time to Remediate (MTTR) –
already a critical metric – has become even more consequential. Previously,
teams measured remediation in days; now, the difference between hours and days
can determine whether an organization is breached. The bottleneck is no longer
detection – it is manual investigation. AppSec teams see what was built and scanned;
cloud security teams see what is running. That visibility gap forces teams to
manually stitch together context across disconnected tools, turning threat
response into a weeks-long investigation rather than a hours-long fix.
The
JFrog-Wiz integration is designed to close this gap by connecting both halves
of the picture in real time. The integration operates through an API-based data
workflow. Wiz identifies vulnerable and exposed workloads across cloud
environments and JFrog traces each workload back to its source artifact in JFrog Artifactory,
enriches it with JFrog Advanced Security vulnerability findings,
Contextual Analysis, and AppTrust provenance
data. Together, security teams get a unified view and full control: what's
running, where it came from, whether it's trusted, and how to fix it – without
building custom dashboards or manual correlation. The result: teams spend less
time reconstructing context and more time remediating.
The JFrog integration with Wiz delivers:
· Faster risk-to-fix
motion: What previously took days of manual investigation now takes hours.
Security teams see Wiz findings and JFrog supply chain context in one unified
view on the Wiz Security Graph with no manual correlation required.
· Continuous compliance instead
of periodic audits: JFrog AppTrust cryptographic
verification confirms every running workload matches what was signed and
approved. This creates an environment for continuous compliance validation
rather than snapshot-based periodic assessments.
· Ownership clarity and
automatic routing: Every artifact carries the team, build pipeline, and individual who
promoted it. When a threat is identified, ownership routes automatically – no
time wasted chasing down who owns the fix.
· Automatic detection of
untrusted deployments: Untrusted images running from unapproved registries are flagged
automatically. Remediation paths trace directly to the build pipeline, with fix
availability confirmed against existing Artifactory artifacts.
· Zero-friction integration: Based on an API connection,
the integration requires no new agents, no cluster instrumentation, and no
elevated cloud permissions. Customers running both JFrog Advanced Security and
Wiz can operationalize this integration in just minutes.
“We’re happy to collaborate with JFrog to bring
cloud runtime visibility and software supply chain context together in one
unified view,” said Oron Noah, VP of Product, Extensibility & Partnerships
at Wiz. “This integration helps customers spend less time on manual correlation
and more time remediating risk.”





























Leave A Comment