All right. Welcome everyone. We have got an exciting lineup for you today. Very glad that all of you were able to attend swampUP 2026. I think there is a lot of announcements that we will be discussing, and certainly getting your feedback and questions and answers in this session today in the investor hour that we are hosting for swampUP 2026. First, what I would like to do is I would like to introduce our CRO, Tali Notman, and a key customer of ours from Keysight Technologies. They are here today to talk about the DevGovOps solution and why Keysight found JFrog as the solution provider for their governance solution. With that, I would like to introduce Tali Notman and Christophe from Keysight Technologies. Thank you. Hello. Hi. Welcome on stage. Thank you. Well, I am not sure why they did not give us the keynote session. I think we are going to be really good for this one. Hello, welcome everyone, and welcome you on stage. Thank you. Well, we have Christophe with us, Keysight CISO today, and we are here to have a very interesting discussion. Before I will start, maybe you can share with us a little bit more about Keysight in the new era of AI, and how is it touching you and your role specifically? Sure. Keysight, as of last year, was a $5 billion diversified company in the technology sector. We sell mostly into communication market, aerospace, defense, autonomous vehicles. Our value proposition has always been in the R&D segment for our customers, where we provide test, measurement, and design solutions as our customers develop their products and solutions. As a part of that, we have sold hardware, we're a legacy HP company, for about 80, 90 years, but more and more of our value proposition has declined in software, and we never sell hardware that doesn't include software inside of it. We have quite a few standalone software products. As we look at that technology evolution, the speed at which we've been developing software internally has accelerated tremendously, I think, like every software shop in the world. Our use of AI technology, the amount of code we generate because of it, has increased significantly. We're also working on embedding AI into the solutions we sell to our customers, in their markets for them to work their products. And well, we just saw in the last session the role of the CISO and how it evolved, right? Maybe you want to share a little bit about the specific role that you are now playing. Sure, sure. I work in central technology, so we are very much of an R&D company internally, and I own all of our DevSecOps organization, which now also includes all of our AI initiatives. All the use of AI tooling internal to the development work that we do across around 5,000 developers is governed from within our org. Yep. We are going to jump right into the discussion about DevGovOps. I think this is why we are all here this afternoon. But the first thing, really, when you are thinking about software governance, what is it? I am really confused at this point. Is it more security? Is it compliance? Is it a more developer or engineering productivity issue? Is it all of the above? Yes, yes, and yes. I think the role of the software developer has changed. It is continuing to change, and we need to really enable continued productivity or production of our software so that we can continue to accelerate our revenues. As a part of that, as a governance or a compliance function, we need to keep up with our developers to never stop writing code at the speed that they can ship it. I think in the market we serve, we have seen the advent of several regulations, both past and upcoming, so Secure Software Development Framework, and now this year for us, the EU Cyber Resilience Act, which adds a lot of regulatory burden on R&D teams to catalog, capture artifacts, Software Bill of Materials, alongside the products that we ship. For us, it is really a question of we want our developers writing code. We don't really want them spending time capturing compliance or filling in compliance checklists or managing those artifacts that then go into Software Bill of Materials that get archived alongside the software for future regulatory compliance needs. Yeah, and I think that this is where we met and discussed AppTrust at that point. Absolutely. You recently chose to invest in AppTrust, JFrog AppTrust, and would love for the audience also to hear about what was missing, really, in your existing environment. Sure. That made application-level trust and evidence really so important to address. Yep, yep. I think even before AI significantly accelerated the way we build software, we saw a gap in that our DevOps or DevSecOps worked very well, right? We had fast pipelines. We were able to ship code, put it out the door quite effectively, but we still had a fairly manual process around the capturing and archiving of compliance materials, whatever they may be. That was resulting in a slowdown of our R&D activity, which really led us to believe we needed to do something about it. That is where it became a natural evolution of the conversation with JFrog, since we have been Artifactory customers for many years, to say, at the end of the day, all of these regulatory and compliance materials are artifacts to the same extent that binaries are. It kind of makes sense for them to live alongside a lot of binaries that we already store there, live with projects. So as R&D teams take code bases and generate new versions of builds and then manage them into products that have versions and all of that, the compliance artifacts just follow that same chain. Oh, well, AI is only adding complexity. Yes. Obviously, AI and scale. As AI and coding agents really get into the flow, how do you see this impact the governance problem? I think if we had continued down a path of manually managing that, we would either have to spend significant portion of our R&D or developer hours to do more of this while agents write code— Yeah. —which really didn't make sense, or hire a whole new bunch of people to do the work. It wasn't even a question for us where we knew we had to automate this, and it was more of a decision of did we want to build it ourselves or did we want to actually buy a solution? And that's where AppTrust came about. Yeah. Where do you want to invest, really, the time and effort of your teams? That makes sense. And now we're sitting here looking ahead of where this is all going. When you're looking two or three years ahead from where we are today, and you're thinking about the DevGovOps, really this whole new discipline. I s it becoming a standard practice specifically for highest risk application for the enterprises, or do you believe it's going to be just part of the practice for any application that the enterprise builds? I guess I'll start by saying, if you'd asked me two, three years ago to predict where we were today, I probably would've been wildly inaccurate. I think at the end of the day, it doesn't make sense for us to invest differently in high sensitivity. I don't want to have to create two different pipelines or models. I think that the governance should be internalized into everything we build. To the extent it's automated, the cost to R&D as a burden is zero. Once you've done the work to automate the tasks that need to occur on every build, on every release, it's no longer a question of, do I only want to apply it to this area? Do I want to apply it everywhere? You have the tools available, why wouldn't you? Mm-hmm. So you're saying for basically any application. Yeah. This is the plan for you as well. Yeah. Excellent. By the way, do you think it's going to take two, three years or? I think— Probably faster than that. Yeah. I think at the speed things are going at the moment, we'll probably get there faster. I think for us, we have a big milestone October of next year with regulatory compliance, so we want to make sure— Mmm. —we're trying to really kit up to be ready for that. So that— Mmm. —the flow is already in place, and we don't have to add a lot of— At this point— —manual things. —you are saying there is already timelines that are being forced from the regulators. Yeah. Well, there is some tense between the need to stay compliant with regulation, but you also have to run fast with innovation. This is probably where you are standing in the role where you can either enable the speed or take care of the trust for the organization. I hope that today in our sessions, the keynote you found, as we work together, of course, you found that there is a platform and a solution that can help you— Absolutely. —address that. Absolutely. I think what's nice with the solution and its implementation will be that it no longer is a trade-off between compliance and velocity. It's just if you do the tooling work right and you onboard it into your pipelines, then it just happens, and you don't need to slow down. You can keep going faster. Yeah. Very well. I want to say that my feeling is that it was not just a session with Keysight. I feel like it was a session with great and key insights, so thank you for that, and thank you for joining us today. Absolutely. Thank you, Tali. Thanks again. I just want to say thank you for your loyalty and for your trust with JFrog. Appreciate it a lot. Absolutely. Thanks. Great working with you. Thank you. All right. Well, thank you, Tali. Thank you, Christophe. As we arrange the stage here for the Q&A and C-suite panel, I just wanted to go over a couple highlights of some of the announcements today so we can recap those and have those top of mind for you in terms of what you may be thinking about as the management team gets up here and is ready to answer your questions. I think there's themes that you should take away from today. I think the themes of today from swampUP 2026 is protect, remediate, and control. That's what we're going to enable in organizations to do going forward in the world of AI. When we talk about protect, we talk about the Package Traffic Controller, protecting the heart of an organization in Artifactory, not allowing an agent to circumvent that and access packages through the internet and circumvent the use of Artifactory, but partnering with SASE security customers like Zscaler, Netskope, and others to now make this a network tool interfacing with Curation and keeping Artifactory at the heart of your organization's software development. We've also now got the new set of first-class citizens in Artifactory, MCP, models, skills. Those registries are becoming critical in the era of AI, and Artifactory is the place, again, the heart of your software development, where many organizations are choosing to reside these types of binary packages. We also want to talk about the Wiz integration. Not only we were working out to the edge with the SASE guys, but we're continuing to extend further into runtime, working with a great partner and a leader in security alongside JFrog in Wiz, and look forward to working further with them as we find other ways in which to collaborate on our security offerings. When we talk about remediate, we're talking about a self-healing software supply chain with zero-touch remediation. Allowing the customer to decide how much interaction or development interaction is going to be needed to repair these vulnerabilities that we are going to find daily as we begin to see more and more vulnerabilities be exposed. The key will not be who can find the vulnerability. The key will be who can remediate the vulnerability and protect the customer as the race to exploit that vulnerability between the hacker and the customer will begin on the release of the CVE. We also want to talk about control and the further adopting of AppTrust and what we have brought into AppTrust to expand that. You're bringing in AppTrust into your organization, as you heard Christophe talk about, for continuous compliance, not just for all my builds for the week, but for every build that occurred that week, I will now be required to have this information. You heard Christophe talk about regulatory issues such as CRA and NIST that are driving a deadline to implement governance type solutions within the EU. These are obviously things that continue to drive our business forward as we enhance the offerings that we've brought. Finally, I think something that a lot of our customers are talking about, and you'll hear more about, is the federated and the doing once of integrating all of your workflows within the organization to have a centralized point in which you're examining your entire software supply chain, the binaries that are brought in, the securing and storage of those binaries, and the management of binaries. With that, I'm going to go ahead and stop speaking so that you guys can get to who you came here for today. I'd like to introduce to the stage our CTO, Yoav Landman, our CEO, Shlomi Ben Haim, and our CFO, Ed Grabscheid. Thank you, guys. Well- No, not at all. I said too much. Thank you, everyone. Thank you, Jeff. Thank you, Tali, and Christophe, if he is still here. Hope you guys had very insightful, packed with information first half of the day. We were very excited about what was presented on stage. Jeff just went over the highlights of the announcement. Some of you probably know how to connect the dot between what we committed last year before we knew that 2026 would look like 2026, and what was delivered here on stage and the performance, the numbers you know very well just a few weeks after earning. With that, I think we will open it for Q&A. Guys, how we are going to do Q&A is I will walk the mic up to you. I would ask that you speak into the mic with your questions so those on the webcast can hear the question as well as the answer. We will start up here with Kingsley Crane. Great, thanks. Look, the pace of vulnerabilities coming out is staggering, and I think that you have done such a good job with the Hugging Face security incident. There has been more in recent weeks too, with other CVEs. The question being, what kind of visibility do you have into patching for on-prem customers versus cloud? Do we think this could drive a sustainable shift towards cloud? Or just why is it not untenable to be an on-prem customer with the pace of vulnerabilities coming out right now? First of all, many of these vulnerabilities, when it comes, they manifest themselves in on-prem installations because of the setup that has to be in place in order to exploit those vulnerabilities. Obviously, there is more exposure for these vulnerabilities when it comes on-prem. JFrog is equipping customers with best practices to how to configure their on-prem installations in the most secure way. Another thing that we are doing is we are creating patches immediately, and one of the key benefits of the JFrog Platform is that when you upgrade it is with no downtime. Applying all those patches in place as you are running a system that is so scalable and serving sometimes hundreds of thousands of consumers is becoming a practice that you can apply in runtime as the system is up. Shlomi? Yeah, I will add, obviously, Yoav covers the technology side. I want to add few things that I have learned during the past six weeks since this happened. When you say tsunami of binaries, you need to stand behind what you say. Tsunami is a tsunami. It is not just another wave that is coming. What we have learned, and Jeff mentioned it just now, what we have learned is that Artifactory became the heart of the system. Some of the people here, and Jason actually said it better than me, Artifactory is not anymore the system of record. It is the system of trust of what happened. You had three companies in one of the world's probably most dangerous, potentially, event that happened. Three companies, OpenAI, Hugging Face, JFrog. Now, we partnered with OpenAI. You heard it from them. You heard it several times in different reports. We remediate fast. We patched fast. Very unfortunate, but this is the life that we will live in. A real-time vulnerabilities will be your day-to-day reality. You will only hear about the products that became the kind of the center under the spotlight. I am for sure not happy about what happened. But when I promised you guys that the primary asset is the binaries and the heart is Artifactory, that is yet another proof. We are honored to have a customer like OpenAI that collaborated with us. By the way, for you guys, I know that you bet on it before, but we couldn't say that they are our customers, so maybe one good thing came out of it. But it is another thing to serve all of these AI labs that have unlimited token budget, and they stretch your product. If it is in their critical path, they stretch your product to the limit. We hope that together with them, we will also build better product because AI also make this environment much more sophisticated and not just vulnerable. Thank you, Jeff. Thank you to the JFrog team for hosting us. Hi, Shlomi, Ed, and Yoav. Two technology questions for me. Number one is, I am trying to figure out what is the next Artifactory. Artifactory was a concept 15, 20 years ago, but don't worry, you guys look young. Today, you were talking about AI models, MCP, agentic workflow, JFrog Fly at the keynote speech. Which of these new asset class, Shlomi and team, do you think is the new Artifactory going forward? My second part of the question is to follow what Kingsley's uincy first question is, since you guys are working with the top frontier AI labs. They have unlimited budgets. They are operating at light speed ahead. What are you seeing in the product roadmap that you think that the hockey puck is going and that you think that you could capture upside from there? Yeah. I will start and obviously, I will hand it over to Yoav to speak about the roadmap. I think that what you see is not an old product versus a new product. When Yoav first created Artifactory, he was much younger and handsome. He is becoming better. Putting jokes aside, the evolution of a product is something that we take very seriously. I will tell you what, I was never misled by our customers. Look around you. Don't speak with us. Go speak with them. You have 500 customers here from the world's biggest organizations. This is trillions of dollars of market cap in this room only. We are limiting swampUP to 500 people. Just go speak with them about the evolution of Artifactory, of what it became. I said it this morning, and I meant it. Not so long ago, if you would say, even to you guys, after JFrog went public, if you would say the heart of your software supply chain is the binary, it is the machine language management, some people will doubt that and say, "Maybe." GitHub, GitLab, Atlassian, source code, chief left, developers, we will speak a lot about this and at the background, the binaries. We insisted, and we stay focused, and we stayed loyal to our roadmap and vision. By doing so, we developed some expertise that others just don't have. This expertise lead us to where Artifactory is now, becoming the control plane of the software infrastructure, not only for the banks and the retail and the car manufacturers of the world, but also for the AI labs. It is not an old Artifactory versus a new Artifactory. It is actually, can Artifactory be the solution that the future requires? If we add more and more binary type to it, the more the merrier, because it is aligned with our philosophy of universality, even before AI happened. If we speak about scalability, it sounds like going back to basics. It sounds like going back 10 years. But scalability today matters more than any day, because it is not just the developers that are now pushing us to the limit, it is the developers plus the agents, and it will be even more. The other thing that we keep hearing from you have to be able, at some point, to distinguish the amount of source code. I do not want to say that it is not important. It is important, even for JFrog developers themselves. But the amount of source code does not represent the desired outcome of what you want to see at the end of the pipeline when AI is being deployed. In a year from now, two years from now, when we will have a fully autonomous solution, you will see a deployment of a binary. So the desired outcome of a successful AI implementation is more binaries, not more source code, and more binaries in a higher quality. If JFrog will be able to maintain that, it is only because of the fact that Artifactory remain the heart of software supply chain. Now, regarding the roadmap and AI items. I think we signaled today where the roadmap is going. Why binaries are becoming the main currency of software. You have agents and you have humans orchestrating the whole operation on the left, and then the middle slowly gets wiped out. Code is code. It becomes unimportant. You saw some quotes from Musk and other that are speaking about the disappearance of code. Virtually, we have the agents. The agents are massive consumers of binaries. They pull everything they can in order to achieve the task. They create many more binaries that are becoming your software. The key thing is to instill trust into this new reality. It is an entirely new reality that developed over the last year since the beginning of the year, mainly. Putting more control points around what binaries we allow agents to pull in, making sure that the heart of the software factory, which is Artifactory, is protected. Making sure that metadata around releases is becoming part of your system of record so that you can apply policies on top of it. This is the future where JFrog is aiming. Instilling automated trust in this new age of software supply chain that is driven by agents. Maybe one last word about the why of the roadmap. We understand the demand, but I think two years ago we heard in the same session, a question coming from one of you, asking us if we think that security from JFrog will happen. Because honestly, you said JFrog is not a security company, so why do you think security will happen? You remember this question? What I have just described is the way JFrog expands to a new addressable market from the system of record, from the system of trust. Going to a new budget line, having someone like Christophe signing another check because of governance would not happen because of a compliance scandal. It will only happen if you have the full chain from the evidence to the compliance. That is how, from the business perspective, this is how we think about the roadmap. Can we penetrate more and more addressable market and expand it? Mark Cash from Raymond James. Couple parts here on Traffic Controller. I think maybe, Shlomi, for you first, if you could talk about how much of that growth of Curation is coming from Zscaler, and then if you could talk about maybe the trajectory you could see of Curation because of Cloudflare and Netskope and other SASE players. Because it is kind of a new motion go-to-market for you through that partnership. Then, Ed, I am kind of curious on this too, if we start thinking about a different pricing model, because maybe security experts are not the right economics for a Traffic Controller versus the amount of traffic you are pushing to your Curation. Thank you. Yeah. Traffic Controller is, I think, implementation of everything we believe in. First, the system of record. Everything, every binary, every artifact, no matter what type of artifact that comes into your organization, should end up in your system of record. If you chose Artifactory as your system of record, fine. If another tool, fine. But that is the discipline. What happened was that our customers started to tell us, "Listen, it was easy." We did not expect to hear it, but they said, "It was easy for us to mandate the discipline when it was only engineers. But now a receptionist with a cloud built software for scheduling. This cloud went out, bought packages, ended up on her desktop." Do you hear what I am saying? We all celebrate the cloud consumption and how much comes in, but we do not ask what reservoir is being kind of pulled into the organization. Discipline will not be able to maintain and sustain without the tools that will enforce that. When we started to ask our customers who are the leading SASE providers, we heard Zscaler, Cloudflare, Netskope. Those are the top three. Now the challenge was how can we build a mechanism that does not slow down the workflow, does not slow down the developer now every time that it comes? So behind the scene, we just navigate those binaries, whatever binary comes, navigate it to Artifactory as your system of record. But that was not enough. So you might end up with a pile of garbage in your system of record. So the reason that from business perspective, go-to-market perspective, we bound it together with Curation, is also to be responsible of what comes in. So when you drink from Artifactory, you know that the water are not poisoned. So now, every package go through this Traffic Controller, through the firewall, through Curation, to Artifactory. You not only apply the discipline, you also apply the policies of the company, filter out what you don't want, bring in what you want. By the way, there is also a way to say, "This is not coming in," but there is another version of the same thing that can come in, and Artifactory will become a reliable system of record. That's the Traffic Controller, by the way. Moving next, we are expanding this relationship with other providers. I believe that I don't have to repeat the need for scale, because if you bring something like that, you also want to be scalable. So far, the design partners that used it was just announced last week, there is a lot of excitement around it. Yeah. More to come on that. Regarding the pricing, Shlomi's talking about an expansion of capabilities with Curation, and Curation is on a per seat basis for contributing developers, and we'll continue on that. But what you're also seeing here is what Shlomi talks about, trusted binaries going into Artifactory and steering all of those into Artifactory, driving more storage, more consumption into Artifactory, that the pricing will change. There will be some type of pricing change. Hybrid is what a lot of organizations are talking about. JFrog is not going to drive that change. We're certainly keeping a close eye on the trends, but I do see some evolution that will happen in pricing. There's more to come on that. We're not ready to disclose how we're going to do that, but there is more to come, and we want to make sure that we can continue to capture the value as we further enhance our products. Just to add a little bit on that. One of the main concerns of our customers is extending the binary trust to knowledge workers. If you have someone, Shlomi mentioned the secretary, I am not sure about secretary, but the knowledge workers in the company, when they use tools like Cowork, which is essentially underneath, it is running Claude Code and similar tools, they are going to be pulling in binaries and this is where the concern of extending this trust is. Hi, Sanjit Singh, Morgan Stanley. I had two questions on just terms of how the broader software supply chain is evolving. On one hand, we have, I think, GitHub, the former GitHub CEO is now leaving to build an agentic Git. I want to understand what the implications are on the broader software supply chain from that. You guys have also been experimenting, right? Last year, you guys announced JFrog Fly. I wanted to see what the early conclusions were from that. Do you feel that there has to be a separate platform for enterprise and to launch their AI initiatives versus how a model lab or a large AI native has to conduct their software development through Artifactory? Do we need a fork of Artifactory? This is the question. I will start answering about, if I understand correctly, Sanjit, what you are asking about enterprise versus not enterprise solution. Listen, one of the biggest challenge in the world that we are living in is to stay in focus. Everyone, like my developers are so excited about what happened. It is almost like a candy store for them. They do all type of magics all day. We can say that we want to do everything, but the honest truth is that what the enterprise needs is not what a small company will need. However, this definition is being changed because yesterday a company with 100 developers was a company with 100 developers. Today, because we are dealing with binaries, a company with 100 developers might mean 100,000 users because of the agents. We are learning this as we go, but I have to admit that when we look at building the business, growing the business, we have to stay loyal to the demand that we get from the enterprise. We made this choice, if you remember, almost four years ago, that we are going all-in on the enterprise. We build our go-to market that way. We build our support that way, customer success, solution engineer, professional services, and our product roadmap. That is a decision we took. Something that will not surprise you is that all of the others, you saw the list of the startups that are doing self-healing now. These are all startups. All of them want to integrate with JFrog, A, I hope because we are great guys, but mainly because of the people that sit in the crowd. So by definition, you kind of attract this new generation that pulls in innovation, inject innovation into your roadmap. Regarding Fly, like we said on stage, we incorporated the capabilities of Fly into the platform. We use Fly as a learning platform to what is the best way to integrate agents with a binary repository to make them kind of bound to the repository to pull in artifacts and to release artifacts to the binary repository. Another thing that we integrated out of Fly is capturing this new generation of metadata that encompasses the release so that we can apply policies where a lot of the decisions that surround the release do not come from code anymore. They come from the interaction of the developer with the coding agent, and with the agentic harness, and this is a capability we actually merged into AppTrust. Yeah. One last thing about Fly. Sorry I missed that. The announcement of Fly last year was amazing, and the project itself, as we told you, is going to be incubated in order to build, sorry, the first agentic repository. We managed. Then our people, our customers, our team, our partners told us, "Yes, this is the capability we want in Artifactory." So instead of insisting on having something that disrupts Artifactory, we took those three capabilities that were built for the entire year with the community and duplicate it into Artifactory, two to Artifactory, one to AppTrust. If you could just hit on the implications for the- Again. Sorry, just the first part of the question. With the Git sort of being agentified, do you see any implications for JFrog from that perspective? Sorry, could you repeat it? The idea that the Git is being revolutionized for agents, right? I think the former GitHub CEO has left to build that, and you have companies like GitLab trying to remodernize their Git for agents. I just want to see if there's any downstream effects from the implications of the Git being agentified for JFrog. We're actually seeing the opposite. I think that we're seeing Git being commoditized to just an intermediate storage level for the code before it becomes binaries. From that respect, I don't know that it even makes sense to add metadata into this layer because this layer is so transitive. That's my point of view. All right. Thanks. Sorry. Howard Ma with Guggenheim Securities. First off, I want to say it is pretty cool to see household names like AT&T and Morgan Stanley and Anthropic, which is, I guess now also a household name, express the confidence in JFrog in running their business. My question is, JFrog is clearly on the cutting edge of DevSecOps, right? You guys made these big announcements, inroads in Agentic Security. You have integrations, partnerships with the Frontier Labs. I kind of want to zoom out, and I am newer to the JFrog story, so if we zoom out kind of like 30,000 feet, a lot of people do not even know what a binary is, right? I am sure you still have to explain that to folks. You have less than 7,000 customers. When I think system of record, I think companies like Salesforce, for instance, they probably have well over 500,000 customers, and that is obviously a great aspirational target. My question is, can you help us kind of bridge the gap between, say, a global 20,000 customer? If you are targeting those customers, some of them are more behind on software engineering. Most of their engineering team is not, or their R&D team, I should say, is not software engineering, right? Meanwhile, you are focused on the cutting edge, the leading engineering teams that are using these AI coding tools at very high velocity. Do those two groups kind of converge and do the slower moving pack very quickly adopt these AI coding tools and leapfrog, no pun intended, the rest? Essentially, could usage of Claude, OpenAI, Codex be the same as usage of JFrog at some point, whereby all the artifacts generated are stored in JFrog? I am not sure that I understand the question. I will try to repeat it, and maybe we can, Jeff, maybe one of the speakers can be turned to our direction because it is very hard for us to hear here on stage. Correct me if I am wrong. The question was about DevSecOps and about the usage of DevSecOps when we are focusing on the cutting edge. What happened to the rest of the use cases that we saw so far in the world of DevSecOps? Customers that are not as forward, what happens to them? Do they end up all using our. Do they end up using the Frontier Labs, the AI coding tools, and then by way of that, they naturally become JFrog customers? Does that push your customer count from something that's not great today, or it's not unimpressive, but could it be manyfold within a short amount of time because you're hitched to this very fast-moving race car, if you will? Yeah, well, I'll tell you what. The journey of DevSecOps and JFrog didn't start with AI, right? It started with another pain. Most of our customers told us over our software supply chain, we have approximately 5- 20 different tools that we need to consolidate. This is how it started. If you remember, the first move was consolidating capabilities under JFrog Advanced Security, seven different capabilities there, including secure detection, including contextual analysis that Morgan Stanley spoke about today, including infrastructure as code, including all of those capabilities that each one of them was a startup a day before or was a solution, not a startup a day before. So, I think that that's how the journey started, and then expanded to Curation, right? Just make sure that it's not only what in the system of record being protected, but also what comes in. JFrog Runtime that now expanded, as you heard, if you read the announcement regarding the integration with Wiz, and what we are now able to do from the runtime backward to your software supply chain. So take this holistic dome over your software supply chain, and this is how we started the journey of DevSecOps. Now, what happened is that a completely new risk came into every organization, no matter if it's old, new, modern, not modern. If they started to use AI, whether they know it or not, they started to ask for other things. The first thing that they started to ask for is that we want to know if we have AI in our organization. Shadow AI is something that JFrog can pull out from Artifactory. Snippet detection, if someone at home copy-paste something into her or his code and bolt it the day after, JFrog can detect that with snippet detection. So the elements of adopting AI are the basic elements of what we started with, and then the integration with all the agents, especially in 2026. Now, we started the year, you guys remember February 20th? Of course you do. That was a day that I couldn't believe what I saw. In 15 minutes, 12 million shares of JFrog were sold because of Anthropic announcement. You remember this day? Of course. I bet you do. We were trying to understand what the heck happened. It is exactly what you said. It is not even AI. We protect the software supply chain of our customers. Slowly, when Opus came out and the world of cyber has been changed for all of us, we also got this new demand from our customers, old and new, for saying, "Listen, but we also need to protect agents." It is not necessarily modern versus old. It is evolution of the software supply chain and what is involved. Great. Lucky Schreiner with D.A. Davidson. I wanted to pivot to the financials, actually, and get Ed involved here. Ask about the- He came with his own microphone. Use it. Ask about the long-term targets. You helped shape those originally, and you are the only company in my coverage, at least, that is committed to those still from back when you introduced them, so congrats on that. Do you have an updated perspective on those targets? Do the new product releases impact your views on those at all moving forward? What can you update investors on those long-term goals? Thanks. I certainly have a new updated perspective on it, because a year ago, it was a bit of a weapon against us, and today I think it is something we are clearly on track and very excited about where we are heading in the second half of 2026, and that is what we are really focused on right now. When we start to make our way through 2026 and we get towards 2027, we will take a look at the guidance, and we will follow a similar philosophy to what we have done in the last two years. I think it has been effective. I think that there is a model confidence in what we are doing, and we will continue to use that same philosophy going forward. Let us get through 2027. Not only did you mention building that model and sticking with the model, probably one of the only companies in Wall Street that stuck with a five-year model. Once we are done with 2027, we will think about where the market is and what we would decide to do, but I think we have earned the right and earned the trust to just get through the model at this stage. By the way, first of all, credit to this transparency goes to Ed and Jeff and how they communicate with you guys. I think JFrog is an open book, but even without a long-term model that we are committed and delivering, look at the amount of information we gave you about the future of JFrog, the growth of the RPO, the growth of the CRPO, the portion of security out of the RPO, the net dollar retention, the full trailing quarter net dollar retention. You guys are smarter than me. You can do the math with or without the long-term model. You see where it goes. Right here, Jason Celino with KeyBanc Capital Markets. Shlomi, you are great with quotes. I love the Iron Dome example or the supply chain. Talking to your customers, it seems like there is tremendous demand for Curation and AppTrust. It seems like customer knowledge or customer, what is the word? JFrog is not known for software security supply chain. Software security supply chain is new in general. How does JFrog fully capitalize on becoming the go-to here? Is it more partnerships? Is it more salespeople? Maybe just speak to the go-to-market of the demand. Well, first of all, that is an amazing question. The reason that I am really excited about this question is mainly because of the fact that this is the question I am asking myself every day. What do we see? We first see our own portfolio with 97% retention rate on our portfolio. Those customers keep renewing, keep going with JFrog, and we are excited about it. Out of which, the majority is still not using JFrog Security. In-house, I still have a lot to invest in making sure that they first take what we bake for them and not leaving me with the cakes. The second thing is that some publicity are not necessarily good publicity, but when you became the center, the heart of software supply chain, people are speaking about you a lot. I do not know if you remember, but two days before earnings, Elon Musk decided that he tweet something about binaries, and we got kind of a floods of questions because of Elon, which I have zero control over his tweet. Then in Black Hat, people spoke about JFrog because of Curation, not only Black Hat is, by the way, for those of you who might not know, but that is one of the world's biggest security event. People spoke about JFrog Curation, and the fact that the Shai-Hulud of the world, the PyPI of the world, the MCP of the world, all of these attacks were kind of flowing over their shoulders, and Tejun spoke about it today as well. I think that we are getting into the awareness of the very close security ecosystem that people thought that it is unbreakable. To be honest, it is not only happening because of JFrog, it is also happening because of what happened outside of JFrog and the fact that we were the first to protect our customers from what we knew that will happen. The third thing that happens is the movements of the CISO roles to a different responsibility. You saw Christophe. A few years ago, Christophe would take care of security and probably first network, then cyber, maybe one of his deputy will do software supply chain. Today, it flipped. Not only that, he is also responsible for governance and compliance before Keysight will have to pay a penalty for not being aligned with regulation. The things on the plate of the CISO are more than what it used to be, and some of them are very unique to JFrog. I think that if we will have patience, you will see JFrog growth engines not just being deployed by security, but also by governance, and that is how we planned it. I want to piggyback off of this because I think there is a lot of momentum that is being built in security, and we see the strength, and we committed to giving you the KPIs at the end of the year, but we also wanted to give you some signals, and this is why we gave the signals during the end of Q2. 80% of the customers that were million-dollar-plus customers during the quarter, we landed 17 of those, were with security. 40% of the new customer lands, and I think you know these statistics well, also came with security, but these were signals. In addition to that, Shlomi, Yoav, and I sat on a stage in Napa last year talking about security. We have more than doubled the number of customer accounts that landed with security across our portfolio. I think you are starting to see now the strength and that the awareness of JFrog in securing the software supply chain. Hey, guys. Koji Ikeda from Bank of America. Thanks for doing this. AI is accelerating innovation everywhere. I got to assume your competition is going to catch up to you guys technologically. What is the moat that is giving you confidence JFrog can grow durably over the long term, even if the competition gets better? Yeah. Koji, this is amazing question that we keep getting every few years. Before that, it was the cloud and the hyperscaler, like why do you think that Google Cloud or AWS or Azure will not build an Artifactory? Now we get it around the creators of AI. I want to focus on two things. The first thing is how we differentiate JFrog, and the second thing is the world of honesty. If OpenAI and Anthropic would like to build a JFrog, they can. They have enough money, smart people, a lot of agents, no token budget, whatever you want to call it. But why should they? JFrog is the seller of the pick and shovels of the AI or software supply chain infrastructure. We are the plumbers. Anthropic don't want to be the plumber, doesn't want to be the plumber. Same we hear from OpenAI and from other customers of ours. The second thing is that when you look at the differentiations we put, it's very authentic because they spoke with us about it as well. What are the differentiators that we put there? If you remember, when we spoke about the cloud, we said multi-cloud will be a differentiator for JFrog. We spoke about the cloud. We said hybrid will be a differentiator for JFrog, and it was. We grew on all three clouds, and you see the numbers. You see the numbers of the cloud consumption of JFrog. We built an amazing partnership with them. Although all of them have an ECR, ACR, whatever container registry. What do we do with the AI labs? First of all, if there is someone in this room that think that there would be one company on the planet that will have only one agent, then you're wrong. We already live in a multi-agent world. When it will come to security and governance, what would you expect? That Anthropic will govern OpenAI, that OpenAI will govern Copilot, that Copilot will govern something from China? What do you think will happen? You will have to bet on a system of record on one single source of truth to manage governance between different agents coming from different creators. The second thing is that open source, if we all believe that open source is staying, then bringing software packages to your organization and then building with it means that you have to manage to store, to maintain the software packages, the artifacts, the binaries, the models, the containers. It's all the same thing. You have to maintain it, and you have to maintain it in a universal way, not something that one vendor is leading. So open source is the second differentiator, and we also see it with the open-source software supply chain attack. The third thing is the legacy. We have customers here, if you want to stay for one of the session, Ford will speak with you about the regulation in the world of car manufacturing. Their retention per package is 45 years. 45 years. What they create now, after I will die, it will still be in Artifactory. But what you have to understand that legacy is not only what you keep from the past. Legacy packages that were built and certified by the organization are also being used by agents because it's already there. Legacy, what is the difference between source code and binary management? The dependency management requires some thinking about what is included and what you have showed on stage with Log4j from four years ago. That is still happening now. It is because of these dependencies. I think that we kind of planted in the ground very strong seeds of differentiations, plus the fact that we built a relationship with all of them, as you can see, plus the fact that it is not only the system of record. In JFrog, we call it protecting Camelot. Artifactory is Camelot. The moat around Camelot cannot just be a better feature or Artifactory is better than another repository. It has to be authentic. It has to be something that gives value to our customers. With that, I think that we will not only grow, we will grow with these AI labs that will use us as the infrastructure layer. All right. Well, unfortunately, I think there is probably more questions and more we would love to give, but I think some of that will have to occur here at the event, in conversations post this event. We want to thank all of you very much for coming and attending today, attending swampUP 2026. Hope you find value in your attendance. We want to thank all of you on the webcast today for attending. Now we are going to end today's Investor Hour and look forward to speaking with all of you again soon. Thank you very much. May the frog be with you.
Loading workspace