JFrog Q2 2026 Earnings Call Transcript

Key Takeaways

  • Positive Sentiment: Q2 results exceeded guidance across all key metrics: Revenue rose 29% year over year to $163.8 million, while record free cash flow reached $53.8 million, or a 33% margin.
  • Positive Sentiment: Cloud growth remained the primary growth engine. Cloud revenue increased 53% to $87.5 million and represented 53% of total revenue, supported by strong usage, AI-driven software artifact volumes, and increased security adoption.
  • Positive Sentiment: Enterprise expansion and security demand strengthened. Customers spending over $1 million annually grew 59% to 97, net dollar retention reached 121%, and 80% of new customers entering the million-dollar cohort added security products.
  • Positive Sentiment: Management raised its full-year outlook: 2026 revenue guidance increased to $648 million-$652 million, baseline cloud growth was raised to 41%-43%, and the net dollar retention floor was lifted to 120%.
  • Neutral Sentiment: Management discussed a self-hosted Artifactory vulnerability identified by an OpenAI model; JFrog said its SaaS environment was not breached, rapidly issued a patch for self-hosted customers, and characterized the incident as reinforcing demand for cloud and security offerings, though it highlights ongoing software supply-chain risk.
AI Generated. May Contain Errors.
Earnings Conference Call
JFrog Q2 2026
00:00 / 00:00

Transcript Sections

Skip to Participants
Operator

Ladies and gentlemen, thank you for joining us and welcome to the JFrog Second Quarter 2026 Financial Results Earnings Call. After today's prepared remarks, we will host a question-and-answer session. If you would like to ask a question, please raise your hand. If you have dialed into today's call, please press star nine to raise your hand and star six to unmute. I will now hand the conference over to Jeffrey Schreiner, Head of Investor Relations. Jeffrey, please go ahead.

Jeffrey Schreiner
Jeffrey Schreiner
VP of Investor Relations at JFrog

Thank you, Nicole. Good afternoon, and thank you for joining us as we review JFrog's Second Quarter 2026 Financial Results, which were announced following the market close today via press release. Leading the call today will be JFrog CEO and Co-Founder, Shlomi Ben Haim, and Ed Grabscheid, JFrog CFO. During this call, we may make statements related to our business that are forward-looking under federal securities laws and made pursuant to the safe harbor provisions of the Private Securities Litigation Reform Act of 1995, including statements related to our future financial performance and including our outlook for the third quarter and full year of 2026. The words anticipate, believe, continue, estimate, expect, intend, will, and similar expressions are intended to identify forward-looking statements or similar indications of future expectations.

Jeffrey Schreiner
Jeffrey Schreiner
VP of Investor Relations at JFrog

You are cautioned not to place undue reliance on these forward-looking statements, which reflect our views only as of today and not as of any subsequent date. Please keep in mind that we are not obligating ourselves to revise or publicly release the results of any revisions to these forward-looking statements in light of new information or future events. These statements are subject to a variety of risks and uncertainties that could cause actual results to differ materially from expectations. For a discussion of material risks and other important factors that could affect our actual results, please refer to our Form 10-Q for the quarter ended March 31st, 2026, which is available on the investor relations section of our website, and the earnings press release issued earlier today.

Jeffrey Schreiner
Jeffrey Schreiner
VP of Investor Relations at JFrog

Additional information will be made available in our Form 10-Q for the quarter ended June 30th, 2026, and other filings and reports that we may file from time to time with the SEC. Additionally, non-GAAP financial measures will be discussed on this conference call. These non-GAAP financial measures, which are used as measures of JFrog's performance, should be considered in addition to, not as a substitute for, or an isolation from GAAP measures. Please refer to the tables in our earnings release for a reconciliation of those measures to their most directly comparable GAAP financial measures. A replay of this call will be available on the JFrog Investor Relations website for a limited time. With that, I'd like to turn the call over to JFrog CEO, Shlomi Ben Haim. Shlomi?

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Thank you, Jeff. Good afternoon, and thank you all for joining the call. We are pleased with our second quarter results, which exceed the high end of our guidance across all metrics. Our first half 2026 achievements reflect strong execution and the clear strategic importance of JFrog in enterprise software supply chains. It is clear now that the world is moving at the speed of AI. What began as a technology shift is becoming the foundation of every business and increasingly ambient infrastructure as they build and deliver software. As AI accelerates software creation, engineering velocity, and code quality, the challenge is no longer generating source code, but managing the tsunami of binaries compiled. It is now about establishing trust in these software artifacts, models, agents, and packages that AI and human increasingly produce without sacrificing speed.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

The JFrog Platform is evolving for a future where AI agents become first-class citizens of the software supply chain. By extending our platform to treat AI agents as trusted participants alongside human developers, we believe JFrog is building the control plane for the next generation of software delivery. We see software engineering evolving into software supply chain engineering, not because every developer becomes a supply chain expert, but because every developer or AI agent must rely on a trusted software supply chain delivered by the organization. For this new era, our customers are reaffirming JFrog as the single source of truth. We believe this reality is fueling the momentum we are seeing across our business. During the second quarter, JFrog's total revenue was $163.8 million, representing 29% year-over-year growth.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Cloud revenue grew 53%, driven by increased secure binary consumption through Artifactory, reinforcing its central role as the single source of truth for software supply chains. In addition to continued strength in cloud growth, our enterprise focus go-to-market strategy continues to deliver strong result at the high end of our customer base. Customers with annual spend exceeding $1 million grew to 97, up from 61 a year ago, representing 59% year-over-year growth. Customers spending more than $100,000 annually grew to 1,291 compared to 1,076 in the prior year, an increase of 20% year-over-year. On today's call, I will walk you through the second quarter in more detail. Ed will then follow with additional financial insights and outlook. First, I will cover our cloud business, where strong consumption trends continue to drive demand across traditional and AI software artifacts. Second, I will discuss our security business.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

As software supply chain attacks grow in scale and sophistication, customers are looking for unified security integrated with their system of record. Last, I will discuss governance and compliance. The era of agentic software development is driving the industry's next evolution, DevGovOps. I'll start with cloud. In Q2, our cloud business continued to expand as we supported the scaling volume of software artifacts flowing through our customers' software supply chain pipelines. As AI accelerates software development, customers are creating, storing, and distributing more binaries than before. Over the past several quarters, even more since the beginning of the year, we have observed the following key trends driving this change in cloud consumption.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

First, the rapid adoption of AI tools accelerates software development activity and increases the volume of binaries moving through our platform as agents and tools consume more software at a pace and scale no human workflow ever could. Second, the increase in the number of AI-specific software packages such as MCP Skills and others that organizations create and manage. Third, continued uncertainty is making forecasting difficult for customers in the evolving AI economy, leading them to sometimes favor the flexibility of a consumption-based, on-demand cloud model. These trends and the first-half results validate our strategy and business model, continuing to reinforce the value of our cloud offering, which enables customers to scale with demand while maintaining efficiency and operational flexibility. Our enterprise sales teams remain focused on securing long-term enterprise commitments, allowing customers better unit economics in the evolving AI spending environment.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

At the same time, as always, we give customers the flexibility to determine the balance between committed capacity and on-demand usage. Consistent with our guidance philosophy, we continue to exclude usage above committed levels from our outlook. Ed will refer to it later on the call. Now to the continued momentum we're seeing in security. JFrog provides the infrastructure for creating, managing, and securing software artifacts at enterprise scale. By integrating comprehensive software supply chain security directly with Artifactory, our customers' single source of truth, we enable them to build and deploy software with trust at the scale and speed of AI. As software supply chain threats continue to grow in scale and sophistication, CISOs increasingly see JFrog Security as a mission-critical component of their software infrastructure, not an optional capability.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Validating this fact, JFrog was recently named a leader in the Gartner Magic Quadrant for software supply chain security, based not only on our highest-rated ability to execute, but also on our strategy of incorporating security alongside the software supply chain single source of truth in one platform. We continue to see strong momentum in our security business reflected in higher attach rate on new customer wins, continued expansion with existing accounts, and an increasing number of larger security-led transactions. In the second quarter, more than 80% of the customers that joined our over $1 million cohort added security. This momentum extends to our new logo business, where over 40% of overall new logo wins included security as part of their initial land with JFrog. In addition, AI-powered software supply chain attacks continued to escalate this quarter, with threat actors increasingly targeting open source package ecosystems.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

As AI accelerates software creation, it also accelerates the pace and sophistication of software supply chain attacks. Throughout these incidents, customers using JFrog Curation remain protected. By tightly integrating Curation with Artifactory, JFrog delivers a trusted, policy-driven software supply chain firewall that blocks malicious and risky packages before they enter the enterprise, allowing developers and AI coding agents to move fast without compromising trust or security. In Q2, we will focus on making sure our security solutions become too integrated to fail, powered by the AI ecosystem. In the past, we focused on securing human developers. Today, we are extending that same trusted experience to AI agents that increasingly interact with the JFrog Platform.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Consistent with our universal trust layer strategy, we recently announced integrations with leading AI coding agents, including Claude Code and Cursor, protecting our customers, developers, and agents from vulnerable or malicious dependencies, enforcing enterprise security policies, and receiving trusted remediation guidance in real time. By embedding security directly into AI-driven development workflows, JFrog helps customers accelerate software delivery while preserving trust across the entire software supply chain. The continued validation of our strategy by security leaders, accelerating customers' adoption, expanding platform usage, larger security-driven transactions, and our deep partnerships across the AI ecosystem reinforce our confidence in JFrog's security roadmap. We expect our Security Core to remain one of JFrog's most significant long-term growth drivers. On security, we are excited to welcome keynote security executive from both Anthropic and Cursor as speakers at our annual swampUP user conference this September in New York City.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

I want to briefly address governance and DevGovOps. It is becoming increasingly clear that AI will only be adopted at enterprise scale if it is trusted. That trust requires governance, compliance, and auditability to be engineered directly into the software development workflows, not introduced as a separate manual step. The challenge is not whether these controls can be enforced, but how they can be enforced in a multi-agent and hybrid development environment without slowing AI-driven delivery. This is why we believe DevGovOps represent the next evolution of software supply chain management and automation, embedding governance into the software delivery life cycle so organizations can move fast while remaining secure, compliant, and auditable. In Q2, a leading publicly traded provider of electronic design, simulation, validation, and test solutions for AI infrastructure signed a seven-figure agreement with JFrog, adopting JFrog Artifactory, bundled with our software supply chain security solutions.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Building on JFrog's role as the customer's system of record, they expanded their investment to embed DevGovOps across the software delivery life cycle, enabling centralized governance, compliance, trusted software consumption, and policy enforcement to meet evolving global regulatory and audit requirements for distributed software assets. Governance, compliance, and DevGovOps continue to rise to the boardroom level, we believe JFrog is uniquely positioned to capture this opportunity. The infrastructure layer powering the software supply chain, JFrog sits at the center of the software delivery life cycle, enabling customers to automate governance, enforce policies, and embed compliance natively into their development pipelines rather than relying on manual downstream processes. We execute on the security expansion of our platform, we continue to invest in expanding our platform to help enterprises not only build and secure software but also govern it with the same level of control, automation, trust, and scale.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

I want to deliver comments on AI adoption and revenue. AI is meaningfully impacting our customers' software supply chain as they increasingly see the need for JFrog to function as their infrastructure for the software that both machines and humans build and consume. We see their usage of AI-specific packages and their dependencies expanding on top of their traditional DevOps and DevSecOps workload goals. In Q2, we were excited to announce partnerships and integrations that are solidifying JFrog as the enterprise standard for AI-powered software supply chain infrastructure. These investments included the tight integration with Anthropic that brings JFrog security and governance solutions to the millions of Claude Code developers. We also announced the partnership with Cursor, which powers over a million daily users that now have access to development and governance workflows directly in their development environment.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

We also continue to expand our footprint with the world's leading AI-native companies, welcoming a new logo, displacing a competitive solution that failed to scale with its growth. This customer migrated to JFrog Platform as its software supply chain system of record and binary distribution engine across a multi-region hybrid deployment. As AI leaders increasingly build software with AI for AI, this win further validates our strategy and reinforces JFrog's position as the trusted software infrastructure for the next generation of AI-native, autonomous, and multi-agent software development. The accelerating adoption of AI development practices and coding agents across our customer base, combined with our deep partnerships with the world's leading AI companies, is also helping us navigate the enterprise shift toward token economy optimization. As organizations increasingly govern and cap token consumption, the economics of software development are changing.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

JFrog's value proposition is fundamentally aligned with this transition because we are focused on the compiled output of software, the binary, not on the number of prompts or lines of code generated. Whether software is written by a human developer, an AI agent, or both, it ultimately results in more trusted binaries that must be secured, managed, governed, and distributed. As AI reshapes how software is created, we remain focused not only on what is growing, but also on why it's growing and what matters most, the trusted binaries that power production. With that, I will hand it over to Ed for a detailed review of our second quarter financials and our updated outlook for the third quarter and full year of 2026. Ed?

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

Thank you, Shlomi, and good afternoon, everyone. We are incredibly energized by our second quarter results, which, as Shlomi noted, exceeded the top end of our guidance range across every key metric. These results once again showcase our consistent strategic execution and operational discipline. During the second quarter, total revenues equaled $163.8 million, up 29% year-over-year. These results demonstrate the continued execution of our go-to-market strategy, fueled by our cloud revenues, growing demand for our Security Core products, and expansion in our Enterprise+ portfolio. Cloud revenues in the second quarter accelerated to $87.5 million, up 53% year-over-year, now representing 53% of total revenues versus 45% in the prior year. Our outperformance in the cloud was driven by robust usage across our customer portfolio, which continues to exceed contractual minimum commitments and increased adoption of our Security Core products.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

We strategically work towards converting this usage into higher annual commitments. During the second quarter, our self-managed or on-prem revenues were $76.3 million, up 9% year-over-year. We continue to proactively engage our on-prem customers to migrate workloads to our cloud or hybrid offerings as they explore solutions better aligned with the rapidly changing security environment. In Q2, 59% of total revenues came from Enterprise+ subscriptions, up from 55% in the prior year. Driven by the ongoing execution of our enterprise go-to-market strategy and broader customer adoption of the JFrog Platform, revenue contribution from Enterprise+ subscriptions grew 39% year-over-year in Q2 2026. Net dollar retention for the four trailing quarters was 121%, representing a year-over-year increase of three percentage points and a one percentage point improvement sequentially.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

These results continue to highlight the strong adoption of our Security Core products, increased cloud usage, and conversion of customers into higher annual contracts. We continue to demonstrate the strategic value of JFrog as a mission-critical, trusted system of record for our customers' software supply chain, with gross retention of 97% as of the second quarter 2026. I'll review the income statement in more detail. Gross profit in the quarter was $136.2 million, representing a gross margin of 83.2% versus 83.1% in the year-ago period. We remain focused on cloud hosting cost optimization as we anticipate a larger share of our revenues being generated from the cloud. Given our expected increase in cloud revenue contribution to total revenue, we reiterate annual gross margins to be in the range of 82%-83% in 2026. Operating expenses in the second quarter were $103.6 million, equaling 63% of revenues.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

This is compared to $86.4 million, or 68% of revenues in the year-ago period. Our operating profit in Q2 was $32.6 million, or an operating margin of 19.9%, compared to 15.2% operating margin in the second quarter of 2025. The continued balance between strategic investment and operational efficiency demonstrates our ongoing commitment to profitable growth. Cash flow from operations equaled $57.1 million in the second quarter. After taking into consideration CapEx requirements, our free cash flow reached a record $53.8 million, or 33% margin, compared to $35.5 million, or 28% margin in the year-ago period. Turning to the balance sheet. We ended the second quarter with $824.5 million in cash and short-term investments, compared to $704.4 million at the end of 2025.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

As of June 30th, 2026, our RPO totaled $659 million, a 38% increase year-over-year, once again highlighting the successful execution of our go-to-market strategy as customers continue to make larger commitments to the JFrog Platform. As a reminder, RPO excludes any benefit from the customer's usage over contractual minimum commitments. Let's turn to the outlook and guidance for the third quarter and full year of 2026. As we enter the third quarter of 2026, we remain optimistic by the strength in our pipeline and the tailwinds of emerging AI workload trends driving increased cloud usage and Security Core product adoption. Even as usage trends accelerated through the first half of 2026, our guidance philosophy will remain unchanged as we continue to de-risk large deals due to timing uncertainties and any benefit from cloud usage above contractual commitments.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

Looking ahead, our outlook remains anchored by three key drivers, growing contributions from Security Core products, ongoing adoption of our full Platform, and cloud growth driven from higher annual customer commitments. We are raising our estimated full-year 2026 baseline cloud growth to be in the range of 41%-43%. Given the anticipated contribution from our Security Core products and increased baseline cloud growth assumptions, we now expect our net dollar retention floor to be 120% for 2026. Turning to our operating expenses, we continue to focus investments on innovation across our entire Platform. We remain committed to a disciplined spending philosophy and confident in our ability to drive ongoing operational efficiency in line with prior execution.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

For Q3, we anticipate revenues to be in the range of $164 million and $166 million, with non-GAAP operating profit anticipated to be between $27 million and $29 million, and non-GAAP earnings per diluted share of $0.22 to $0.24, assuming a share count of approximately 130 million shares. For the full year of 2026, we are again raising our revenue guidance, now anticipating a range of $648 million to $652 million, representing 22% year-over-year growth at the midpoint. Non-GAAP operating income is expected to be between $116 million and $120 million, and non-GAAP diluted earnings per share of $0.96 to $1.00, assuming a share count of approximately 129 million shares. I'll turn the call back to Shlomi for some closing remarks before we take your questions.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Thank you, Ed. Our second quarter reflected the strength of our strategy and the dedication of our team. We delivered continued cloud expansion, security as a meaningful growth engine, strong enterprise execution, increasing customer platform consolidation, and solid free cash flow momentum, all while maintaining the discipline to grow responsibly and efficiently. To every Frog around the world, thank you. These outstanding results are your achievements. Together, you turned Q2 into a major win for JFrog. Your passion, resilience, and focus on our customers didn't just deliver another great quarter, but laid the foundation for future growth. As we conclude today's call, we look forward to welcoming many of you to swampUP New York in just a few weeks.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Together with customers and industry leaders from Anthropic, Cursor, Morgan Stanley, Microsoft, CoreWeave, NVIDIA, and many others, we'll demonstrate how the software supply chain is evolving for the AI era and how JFrog is helping enterprises control, secure, govern, and scale software creation and delivery in a world powered by developers and AI agents alike. May the frog be with you. Operator, we are ready for questions.

Operator

We will begin the question-and-answer session. Please limit yourself to one question. If you would like to ask a question, please raise your hand now. If you have dialed in to today's call, please press star nine to raise your hand and star six to unmute. Please stand by while we compile the Q&A roster. Your first question comes from the line of Mike Cikos with Needham. Your line is open. Please go ahead.

Matt Calitri
Matt Calitri
Analyst at Needham

Hey, guys, this is Matt Calitri for Mike Secos over at Needham. Thank you for taking our questions. We were hoping you could share some color on the conversations you've been having since the OpenAI models discovered the self-hosted Artifactory zero-day vulnerability. It's worth noting from our perspective, it seemed like the whole ordeal was very well handled, but we were just curious if it's delayed pipeline conversions at all, or if there's any plan to continue to leverage these AI models to search for other potential patches going forward. Just anything you could share on that whole experience would be helpful.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Well, thank you for the question. Obviously, one that we were dealing with in the past 2 weeks in great partnership with OpenAI. As you mentioned, OpenAI have a self-hosted Artifactory, and they ran a model that walked on a sandbox with limited guardrails. AI models in today world should not be treated as free. They should be treated with zero trust, with the security practices that are required around that. Once this AI model found a vulnerability within Artifactory, they contacted the JFrog team immediately. We remediated fast, worked in great partnership with the security researchers of OpenAI and, throughout the last week, kept improving this communication between us. Obviously, this is also a great opportunity to discuss the cloud solution, the SaaS solution that, to remind everyone, was not breached, and also to discuss the security solution that JFrog can provide on top of Artifactory.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Great relationship will build a better product. More and more vulnerabilities will be found as models are getting into the pipelines, and I think that what counts is how fast vendors are remediating. We are very pleased, very honored with the relationship we built with OpenAI before and during the incident.

Matt Calitri
Matt Calitri
Analyst at Needham

That's great. Thanks so much

Operator

Your next question comes from the line of Miller Jump with Truist Securities. Your line is open. Please go ahead.

Miller Jump
Miller Jump
Analyst at Truist Securities

Hey, great. Thank you for taking my question. Congrats on the continued really strong momentum here. I want to stay on security. It was really great to hear about the momentum you saw in the quarter. There were a number of pretty significant open source vulnerabilities that came to light at the end of Q1. I am wondering, did that have an impact on the Q2 security contribution in your view? Was there any of the second half pipeline of security that actually got pulled forward into the first half as a result of those vulnerabilities? Thanks.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Yes, Miller, that is a great question that represents everything we have seen the past few quarters. Software supply chain attacks are becoming a daily thing. Just two days ago, another massive attack, over millions of open source packages coming from NPM, yet another one. Obviously, we start to see that every CISO ask herself or himself, "What is the right firewall we should put from the get go? What the right scanner we should put on top of our system of record?" Obviously, this generates a lot of traction around JFrog, because JFrog is one of the unique security solution that is not just providing a security solution, but also the system of record that needs to be protected. Yes, the pipeline is impacted by it. We were very pleased to see the results in Q2 that are showing yet another growth after the results of Q1.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

It supports not only our penetration into the DevSecOps world, but also the growth in the cloud. Looking forward, we are very optimistic, as mentioned on the call, that the security will keep being a very strong growth engine for the company.

Operator

Your next question comes from the line of Mark Cash with Raymond James. Your line is open. Please go ahead.

Mark Cash
Mark Cash
Analyst at Raymond James

Thanks. Shlomi, if I could go back to the OpenAI incident. Look, absolutely novel, your team was great and transparent with disclosing what happened, had solutions in place, take care of customers, and I completely understand this is a strong argument for adopting cloud and for security. I did want to ask, though, considering 47% of your business is self-hosted, how have customers reacted? What have you done to ensure customers are patched and the risk wouldn't spread? Then could you actually turn this to a positive for demand, as we've seen with some other security companies that used incidents to actually get closer to customers and then drive broader platform adoption? That's it for me. Thank you.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Thank you, Mark. A great point. I'm thinking about how fast you remediate and how fast you take it to the market, but there is also a very responsible way to treat your customers, and that's transparency. The moment it happened, the first thing that our team did was protecting our cloud customers and releasing a patch to the self-hosted customers. Obviously, this is not in our control, so it can become a tailwind of customers that see the SaaS as a more secured environment. We immediately release the patched version. It was confirmed by OpenAI as resolving the vulnerability. We were very happy to see that they keep running their models to check if Artifactory is secured and bulletproof, and the answer was yes. Just yesterday, on a Black Hat stage, they shared with more transparency what happened there.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Obviously, some of it has to do with how you configure your environment and what guardrails you put around models. I think that the entire industry is learning about it. What I see inside JFrog is how fast we remediated, the level of transparency with the market, no hidden stuff, like going straight and bold to our customers and demand that they will protect the software supply chain. I also see an opportunity here to say, "Hey, you can be much more secured in the cloud. You can even be more secured with security around models' behavior." What we will see next, and have no doubt about that, we will see more models getting more sophisticated, finding more vulnerabilities. It's not a matter of being the scanner anymore. It's a matter of how fast and how efficient you are in remediating and communicating to your customers.

Operator

Your next question comes from the line of Howard Ma with Guggenheim. Your line is open. Please go ahead.

Howard Ma
Howard Ma
Analyst at Guggenheim

Hey, guys. Thanks. Congratulations on a really strong quarter and the full-year guidance raise. One for Ed. If you look at the Q2 outperformance, how would you compare the mix of higher commitments and overages relative to Q1? If you could comment on if there was any contribution from the fourth Frontier Lab customer that you added in the quarter, and for the full year as well. Two questions there. Thank you.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

Thanks for the question, Howard. We don't necessarily split out in terms of providing guidance or updates of what was over-committed revenue versus commitment revenue. What I can tell you is In Q2, we saw something very similar to what we saw in Q1, which was strong usage across a diverse group of customers in our install base, continuation of packages going through the software development life cycle and Artifactory. We didn't see a decline by any means in the usage over that minimum commitment, and we're very pleased with the end result. In addition to that, we also had, as Shlomi talked about in the prepared statements, we extended our foundational AI labs. We have four of those customers, Shlomi can share a little bit more about that customer that we landed during the quarter.

Operator

Your next question comes from the line of George McGreehan with Bank of America. Your line is open. Please go ahead.

George McGreehan
George McGreehan
Analyst at Bank of America

Hi, this is George McGreehan on for Koji Ikeda at Bank of America. Thank you for taking our question. I wanted to ask about the contribution you guys are seeing from your suite of security products between the three Advanced Security, Runtime Security, and Curation. How do you stack rank the contribution from those?

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

I'll take it, George, thank you for the question. We spoke a moment ago about the amount of software supply chain attack and the, I don't want to say panic, but alerted response from customers and prospects. Obviously, the first thing that they are applying is a firewall between the software supply chain, the organization, and the open source apps. This is JFrog Curation, and we saw JFrog Curation being adopted rapidly and also referred on the call. JFrog Curation by itself is an amazing firewall, but when it comes with the Artifactory integration, that's a bulletproof solution that prevents any malicious package, any vulnerability known, any type of unrequired packages to come into your organization. Because it's so simple and because it's implemented in very high integration with Artifactory, obviously our customers and prospects are betting on Curation.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

As mentioned on the script, none of our customers got affected by this massive attack of software supply chain out there. The second thing is what happens once you start to run your pipeline. This is where JFrog Xray, JFrog Advanced Security are providing a comprehensive, holistic solution on top of your source code, on top of your system of record to make sure that all the binaries, all the software packages, and everything that you will distribute will not only be secured but also known, traceable, and monitored. Later on, when you need to govern it, when you need to audit it, you have all the information.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Obviously, because of the amount of software supply chain attack, Curation gets the spotlights now, but our customers are requiring more and more security solutions from JFrog, mainly because of the advantage that we also manage all the binaries for them, and we also play as the single source of truth.

George McGreehan
George McGreehan
Analyst at Bank of America

That makes a lot of sense. Thank you. If I could follow up with a second question here. Last quarter, in cloud consumption there was usage above commitment. This quarter you guys noted as well. I'm kind of wondering if there's any change in customer behavior in terms of are customers getting a better sense of maybe how much they're going to be consuming on JFrog over in the future and getting more comfortable committing at higher levels of usage? Is that maybe not the case? Thank you.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Well, George, this is a wonderful question. What we see is what I'm going to share. A, we see more AI tools being part of the software supply chain that drive scale. B, we see more AI software packages, unique software packages, and we call some specifics like MCP and Skills. Just half a year ago, you wouldn't hear those terms. There are new assets. These are all binaries, so new assets with new software packages. The third thing is the uncertainty. JFrog provides this flexibility that is amazing, not only for the CIO but also for the CFO. They need to settle on what is the right estimation a moment before they decide what would be the budget of 2027.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

With our philosophy of guiding you guys with the commitment only, if you combine that with the number of customers over $1 million, a number of customers over $100,000, the growth in the cloud, you probably understand that our team is doing great work converting those over usage to commitment. We provide you with the full predictability and the certainty around our model, and this is why we follow commitments and not usage. Usage over commitment is growing, and we will still be focused on the commitment and the cloud migration of our self-hosted customers to the cloud.

Operator

Your next question comes from the line of Radi Sultan with UBS. Your line is open. Please go ahead.

Radi Sultan
Radi Sultan
Analyst at UBS

Awesome. Thanks for taking the question. Just one from me. Shlomi, wanted to ask on the shift we're seeing towards increased adoption of open source and open weight models, could you just walk through how you see that trend impacting demand and usage? I'd imagine maybe this increasing pull-through on the security side, but be curious if this could increase the need on Artifactory as well. Thank you.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Well, yeah, if you refer to the security, you are very much right. That's a great driver that fuels the growth and the adoption of our security solution. It's not only because of the open source that is brought into the organization, it's also because of the new practices that requires new packages to be managed and secure. Now every vendor provide an MCP software package. You need to govern that. You need to have an MCP registry, and you need to make sure that it's secure. JFrog Security provide all of these assets on top of JFrog Artifactory, which makes the solution far more comprehensive and holistic. I'm not talking now about who has a better scanner. I'm talking about the outcome, what's the real value that we bring? Of course, we see growth there, Radi.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

The second thing, it's also the speed and how fast things are happening. We also mentioned that AI start to be a wallpaper. It start to be ambient infrastructure. People just use AI every day for everything, and they expect the software supply chain to be secure. They expect the pipeline to be secured. Now, with the amount of attacks that they see out there, our customers were not affected by it. Just think about the amount of time that they save for not having the need to remediate and recover. I think that more and more customers put their trust in JFrog Security and the holistic solution. Coming up next, also governance, because you also need to trust those software packages that you mentioned before you ship them.

Radi Sultan
Radi Sultan
Analyst at UBS

Awesome. Thank you.

Operator

Your next question comes from the line of Brian Essex with JPMorgan. Your line is open. Please go ahead.

Brian Essex
Brian Essex
Analyst at JPMorgan

Hi, good afternoon, and thank you for taking the question. Congrats on the results. Hey, just want to follow up to a previous question that was asked about the way that customers are may or may not be managing their overages. It seems like demand is pretty healthy. Shlomi, are you privy to any conversations with your customers in terms of how they might be addressing more efficient spend, just in general, but also on your platform? That's question number one. As we approach swampUP, just wanted to get a sense of sometimes it's difficult to time product releases with a specific conference. Sometimes companies release products when they're ready. What should we expect as we head into swampUP, being kind of relatively new to the story here? Thank you.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Brian, thank you for bringing swampUP up. It's going to be an amazing conference again. We already see the speakers line up. I'll start with that. I'll just say that, obviously, the main thing that we see at swampUP is that the world's biggest organization are using JFrog and willing to share their best practices, and this is gold for our users. Alongside that, there are the JFrog announcement, which are exciting, very much aligned with the future roadmap. In the world of AI, if I will wait for swampUP to release our product, our company will go backward and not leap forward.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Expect a lot of excitement also on stage, but also with the customers' conversation. Regarding the efficiency and management of budget, what is it that we see, right? We see more token being spent that generates more software because AI agents are being fueled, and that generates probably a higher cloud consumption. People are asking, will that be forever like that? The answer, for sure not.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

We are transforming from the CIO FOMO, which was around technology, to the CFO FOMO, which is around budget control. We have to ask ourselves, what is the desired outcome of software pipeline, of software supply chain, of the AI world? What's the desired outcome? The desired outcome is that you will have more software being shipped in a higher quality. What I just said equals binary, and this is what JFrog is monetizing on. We are monetizing on binary traffic. We think, we suspect that CFOs will be smart enough, and disciplined enough not to block innovation.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Inside JFrog, we keep saying that you can also optimize how much you want to pay for the electricity you consume at home but you still don't sit in the dark, right? You just train yourself to close the light before you leave. That's the difference between source code and binaries. The desired outcome of a better AI is better binaries in high quality and higher consumption.

Brian Essex
Brian Essex
Analyst at JPMorgan

Got it. Thank you very much. I appreciate it

Operator

Your next question comes from the line of Andrew Sherman with TD Cowen. Your line is open. Please go ahead.

Andrew Sherman
Andrew Sherman
Analyst at TD Cowen

Oh, great. Thanks, guys, and congrats on another quarter of acceleration here. Ed, the billings at RPO were extremely strong. RPO added a record $84 million. Could you talk about the breadth and nature of the big deals that went into that? Was there any pull forward from the second half pipeline, and how is the second half pipeline looking? Thanks.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

Thanks for recognizing that in the RPO. We're very proud of that, and that actually comes from the efforts that we have around our security products. That's a driving increase in our ASPs, and you saw that in the million-dollar number. 80% of the million-dollar customers that we added this quarter had security attached to it, and that, along with even the new customer lands, 40% of those customers with security, are driving much of the RPO. In addition to that, customers that land with security typically take a multi-year agreement as well. The construct is a larger ASP, longer in duration, and that results in strong RPO. That's what we're seeing. We did not pull really anything in from Q3.

Ed Grabscheid
Ed Grabscheid
CFO at JFrog

We just had strong build in the quarter and execution from the team, and that pipeline that we built really came from the swampUP events that started in Q3 of last year, and it continued to build the sales organization executed on those deals, and it's reflected in our results.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

I might just add to it is that completely agree with everything that Ed said. Some of those macro impact of open source attack is out of our control, obviously. AI also make the hacker more sophisticated, and this software supply chain rapid attack might expedite some of the opportunities we have in the pipeline.

Andrew Sherman
Andrew Sherman
Analyst at TD Cowen

Great. Thanks, guys.

Operator

Your next question comes from the line of Jason Celino with KeyBanc. Your line is open. Please go ahead.

Jason Celino
Jason Celino
Analyst at KeyBanc

Great. Thank you. Shlomi, I don't think you've had the opportunity to talk about your important fourth AI customer here. It seems like the hybrid deployment model is unique and interesting. Maybe can you speak to why this is maybe different from your other AI native customer deals? Then secondly, we on the street always want more, right? Is there a pipeline or opportunity to land other AI natives of this magnitude? Thanks.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Well, listen, we are so honored and so excited to add more and more companies that are building the world of AI, and this one that we just won this quarter was a great win, and it was sweeter also because of the fact that we displaced a competitor that couldn't scale. The amount of binaries and the traffic that needed to be supported was not something that they could do. This AI factory moved to JFrog, and they moved to JFrog in a very interesting way. They took JFrog Platform as their mothership in the cloud and with some self-hosted Artifactory servers in their data center, so they will not only have the power of the JFrog Platform supported by our services, but also to have a super robust distribution mechanism from this mothership to all data centers, from Artifactory to Artifactory.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Working with these companies that build with AI for AI makes JFrog better. We spoke earlier about the OpenAI incident. This is how JFrog become 1,000x stronger because these guys, they take you to the limit with the security scanning, with the scaling, with different deployment environment, and we are very pleased and very honored to have them on board. Obviously, they look at JFrog as the planners of the pipelines, the providers of the infrastructure to the software supply chain.

Jason Celino
Jason Celino
Analyst at KeyBanc

Thank you.

Operator

Your next question comes from the line of Sanjit Singh with Morgan Stanley. Your line is open. Please go ahead.

Sanjit Singh
Sanjit Singh
Analyst at Morgan Stanley

Thank you for taking the questions. Congrats on an awesome quarter. It was great to see. Shlomi, I think you and I have discussed before in terms of some of the evolution that JFrog is going through. You guys were one of the key destinations for container registries and those kind of traditional software artifacts. You mentioned the initiative to be the home of models and some of the newer kind of AI native artifacts. Just to get a sense of how that trend is evolving in terms of winning those newer artifacts.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Yes, Sanjit, great to see you on the call. You are right, and you watched the JFrog transformation before AI and hopefully with AI. What do we see happening? We see that the world of software supply chain management moved from just managing the pipelines to also secure them and govern them. By being focused on the right asset, what we keep saying from the foundation days of the company, binary is the primary asset. By being focused on that, we are not only providing our customers with the smart storage that can scale in the cloud and on-prem, but we also provide them with a comprehensive security solution. Now, as you probably heard on the call, we just started to win our first DevGovOps customers and deals. People understand, and we saw it again this week with OpenAI, models need to be governed.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

To your point, Sanjit, we became the biggest container registry after Docker boom. Now we are becoming the biggest model registry for our customers, mainly because of the following. They can scale with us, they can trust, and they can secure, and they can govern. If we will provide them this fundamental, and it's on us to prove, then I think that you will see the next leap in our evolution. What also matters is that the AI companies, the AI native, and the AI labs companies, trust JFrog to do it for them. We are learning a lot. We are improving a lot. Just to stay humble, we are in the beginning of the journey.

Operator

Your final question comes from the line of Kingsley Crane with Canaccord. Your line is open. Please go ahead.

Kingsley Crane
Kingsley Crane
Analyst at Canaccord

Great. Thanks for taking the question, fitting me in. Just to build off what we've been talking about earlier, as novel agentic attacks, they become more apparent, how do you manage an intelligence that we don't necessarily fully understand that's now capable enough to be dangerous? You mentioned earlier that AI models should not be treated as free. Is it consensus that customers are treating coding agents with that same scrutiny they do with third-party packages, or are they still adjusting to that? Thanks.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Well, Kingsley, I'll be honest with you. With over 6,000 customers, you see everything. You see customers that are just kind of being attracted by the technology and adopt AI with no responsibility, and you see customers that are terrified and take it one step at a time. I think that what is special for the experience that we get from companies like OpenAI and other leading AI labs is that they are showing us not only what need to be done but also what happen if you don't do it right. If you don't do it right, models are becoming sophisticated and even smarter than our most senior developers and engineers. I believe that the world will become mature, and the regulation and guardrails and security around models will become a bit more powerful.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

What we are discussing with our customers is how important it is not only to host the models and to host the binaries and the outcomes for them, but also how we secure the entire pipeline. There is no better school than these AI labs to learn it from them. It's a great privilege to have all of these as our customers.

Operator

This concludes the question-and-answer session. I will now turn the call back to Shlomi for closing remarks.

Shlomi Ben Haim
Shlomi Ben Haim
CEO and Co-Founder at JFrog

Thank you, everyone, for joining our call. Obviously, Q2 was yet an amazing quarter for us. We are focusing on delivering what we committed in 2026. Looking forward to seeing you at swampUP, where we will host an investor meetup to keep answering your question in full transparency and with the right excitement. May the frog be with you. Take care.

Operator

This concludes today's call. Thank you for attending. You may now disconnect.

Executives
    • Jeffrey Schreiner
      Jeffrey Schreiner
      VP of Investor Relations
    • Shlomi Ben Haim
      Shlomi Ben Haim
      CEO and Co-Founder
    • Ed Grabscheid
      Ed Grabscheid
      CFO
Analysts