JFrog Platform is now listed in the Government of Canada’s Software Licensing Supply Arrangement (SLSA), giving federal agencies a streamlined path to procure trusted software artifact management and AI governance capabilities.
JFrog platform is now available for procurement through the Government of Canada’s Software Licensing Supply Arrangement (SLSA) Catalogue via Data Centre Intelligence (DCI), an Ottawa-based partner with deep public sector experience.
JFrog’s listing gives federal departments and Crown corporation buyers an approved, trusted route to acquire the JFrog Platform at a critical moment when software supply chain attacks are accelerating, AI-generated code is introducing new categories of risk and Canadian government organisations face growing expectations around software transparency, governance and software supply chain security.
“With software supply chain security and governance becoming an increasing focus for federal departments navigating AI adoption, SBOM requirements and automated decision-making directives, this listing puts the JFrog Platform on the approved path for the teams that need it most,” said Rafael Santiago, SVP Global Sales, JFrog. “We are excited about the partnership with DCI, which brings over a decade of experience helping the Canadian government adopt cutting-edge technologies.”
According to JFrog’s 2026 Software Supply Chain Security State of the Union report, more than 48,000 new CVEs were disclosed in 2025 – a 20% year-over-year increase partially driven by AI-generated code.
For government organisations responsible for critical infrastructure and citizen-facing services, the ability to continuously scan, govern and prove the integrity of every software component is no longer optional. DCI’s established relationships across federal departments and its fluency in the Government of Canada’s procurement processes gives buyers a knowledgeable, locally grounded path to evaluate, acquire and adopt the JFrog Platform through the SLSA Catalogue.
Why now: Canada’s software governance moment
Canadian federal departments are facing a convergence of new requirements that make software supply chain security and governance increasingly important, including:
AI Governance: The federal government’s AI Strategy for 2025-2027 sets expectations for responsible deployment, transparency and safeguards across every department using AI tools – including governance over the software supply chains those tools produce.
SBOM Transparency: In September 2025, the Canadian Centre for Cyber Security (CCCS) joined CISA and 19 international partners in publishing A Shared Vision for the Software Bill of Materials for Cybersecurity – guidance encouraging organisations to adopt SBOMs as a foundation for understanding, securing and managing software risk.
Automated Decision-Making Compliance: The Treasury Board’s amended Directive on Automated Decision-Making requires federal institutions to comply by June 2026 – demonstrating governance over the automated systems and the software supply chains behind them that power public services.
Procurement Efficiency: The SLSA Catalogue listing means JFrog is available through PSPC’s Software Licensing Supply Arrangement with pre-negotiated terms and pricing ceilings in place – streamlining acquisition and shortening the path from decision to deployment compared with full procurement cycles.
“Technology alone doesn’t solve government challenges – it takes the right partner to help organisations bridge the gap between evolving cybersecurity priorities and practical implementation,” said Adam DaCosta, President of Data Centre Intelligence. “Making the JFrog Platform available through the Government of Canada’s Software Licensing Supply Arrangement gives departments a straightforward way to evaluate, procure and implement a trusted solution while working with a partner that understands both government technology priorities and public sector procurement.”
Delivering a system of record for government organisations
The JFrog Software Supply Chain Platform gives departments a single source of truth for every binary they build, secure and release. It can also be deployed on-premises/self-managed, in the cloud or in hybrid environments to meet the security requirements of Canada’s most sensitive networks.
Key components include:
JFrog Artifactory – the Single Source of Truth: The authoritative repository for all binaries, dependencies and build artifacts across the software delivery lifecycle. Provides enterprise-grade binary artifact management that meets stringent government security standards, with deployment flexibility for self-hosted cloud environments to support sovereignty and compliance requirements.
JFrog Xray – Automated Security Scanning: Delivers open-source binary vulnerability and licence compliance scanning with deep visibility into all underlying layers and dependencies of binaries and container images. Enables government organisations to find, fix and fortify software artifacts while maintaining continuous security posture across the software supply chain.
JFrog Curation – Proactive Software Supply Chain Defense: Designed to stop risky open-source components at ingestion and guides developers to pre-vetted, compliant package versions – essential for organisations facing increased scrutiny over software supply chain security and needing to demonstrate control over what enters their development environments.
JFrog AI Catalog and MCP Registry – AI Asset Governance: Extends proven software supply chain security controls to AI models and agent-based development assets. As government organisations adopt AI-generated code, this provides the visibility and trust layer needed to ensure only approved AI components enter production environments.
JFrog AppTrust – Verifiable Compliance and Policy Enforcement: Replaces manual approvals and disconnected evidence trails with immutable evidence and automated policy gates across the entire software supply chain. Enables security and compliance teams to demonstrate continuous policy enforcement with auditable proof – critical for government organisations facing demanding security audits.
SBOM Evidence – Transparency and Accountability: Provides detailed Software Bills of Materials showing all components that make up software releases, with enhanced VEX support aligned to CycloneDX and SPDX 3.0 standards. Delivers the verifiable documentation trail government auditors and regulators require to confirm that vulnerabilities were assessed, risk decisions were documented and compliance obligations were met.


