Compliance Legal Disclaimer
JFrog AppTrust is intended to collect evidence to support your demonstration of controls effectiveness.
What JFrog Provides
AppTrust collects, aggregates, and presents evidence that you may use to support your demonstration of control effectiveness, informed by JFrog’s experience securing software supply chains at scale. Where evidence originates from third-party tools and integrations, AppTrust is designed to validate the origin and integrity of such evidence but does not independently verify its substantive accuracy. Evidence reflects the state of an artifact at the time a policy gate was evaluated and may not reflect subsequent conditions.
What you Manage
You are responsible for your compliance program, including the design, implementation, and operating effectiveness of your controls, the configuration of policies within AppTrust, and the accuracy of inputs from your environment. AppTrust is intended to assist, not replace, your compliance processes and professional judgment. Use of AppTrust is governed by your agreement with JFrog.
Configuration
AppTrust ships with defaults informed by common compliance requirements. Modifying default settings, thresholds, or policy gate configurations may affect the scope and effectiveness of evidence collection.
Updates and Changes
JFrog may update policy templates, integrations, and platform capabilities from time to time. Regulations, standards, and frameworks (such as EU CRA and NIST SSDF) may be amended, superseded, or replaced by their issuing authorities at any time. References to specific frameworks indicate AppTrust is designed to support relevant evidence collection and policy enforcement; they do not constitute certification or a guarantee of acceptance by any regulator, auditor, or certifying body.
Updated 12 days ago
