

FortiCNAPP and JFrog Xray are competing in the cybersecurity and software management category. JFrog Xray seems to have the upper hand due to its feature richness and integration capabilities, making it appealing for development-heavy environments.
Features: FortiCNAPP is known for its extensive security integrations, impressive threat intelligence capabilities, and a focus on security posture. JFrog Xray excels with advanced vulnerability detection, policy enforcement, and seamless integration into CI/CD pipelines, enabling detailed software artifact analysis.
Room for Improvement: FortiCNAPP could benefit from enhancements in integration with development tools, improvement in scalability for larger enterprises, and more user-friendly interfaces. JFrog Xray might improve its initial cost-effectiveness, expand its deployment documentation, and enhance its customer support for more personalized assistance.
Ease of Deployment and Customer Service: FortiCNAPP offers a straightforward setup process and robust support, facilitating quick problem resolution. JFrog Xray features a user-friendly deployment model, emphasizing comprehensive documentation and knowledge bases to aid customer assistance, with tailored solutions for various environments.
Pricing and ROI: FortiCNAPP has a competitive pricing structure focused on reducing long-term costs through comprehensive security protection, promising favorable ROI. JFrog Xray may have higher initial costs, but it provides substantial returns by minimizing security breaches and enhancing operational efficiency, offering significant justification for investment in software-focused businesses.
Technical support from Fortinet is good; I get feedback and responses quickly.
On a scale of 1 to 10, I would rate the technical support of JFrog Xray an eight because they are very knowledgeable.
When we need clarifications, we contact our account manager, and they arrange demos.
According to my use case, it is highly scalable.
I use JFrog Xray primarily for security purposes, and I find it reliable.
We did experience crashes, downtimes, and performance issues with JFrog Xray.
The vulnerability part is not systematically organized; it is all clumsy in the web UI, and it is not user-friendly.
somehow you need to adapt your GitLab pipeline and turn them into JFrog pipeline, and this is something they don't really advertise at first—you're obliged to use the JFrog CLI.
When we have given a very long tag, it doesn't work as expected and requires excessive scrolling.
X-ray needs improvement in supporting more than one database, as it currently only supports PostgreSQL.
JFrog Xray provides a free trial of 14 days.
The basic scanning capabilities come with Artifactory, however, curation requires additional licenses.
The machine learning capability in Lacework FortiCNAPP is used for threat detection.
The policy-driven approach of JFrog Xray helped me maintain security standards by integrating it in the development pipeline.
The most valuable features of JFrog Xray are its curation capabilities, its native integration with Artifactory, scanning for vulnerabilities, and license compliance features.
With other registries such as ECR, we can use the images only in the AWS cloud. With JFrog, we can use this registry from any cloud or work locally as well.
| Product | Market Share (%) |
|---|---|
| JFrog Xray | 1.4% |
| FortiCNAPP | 1.7% |
| Other | 96.9% |

| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 4 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 1 |
| Midsize Enterprise | 3 |
| Large Enterprise | 6 |
FortiCNAPP is a comprehensive cloud security platform focusing on ease of use and machine learning-driven anomaly detection. It offers robust compliance reporting, seamless integration, and continuous monitoring, making it an essential tool for organizations managing multi-cloud environments and security configurations.
FortiCNAPP provides significant capabilities in cloud security, compliance, and vulnerability management. Designed for organizations needing efficient monitoring, it enables detection of anomalies across cloud infrastructures while optimizing security posture and ensuring compliance with environments like AWS and GCP. The platform offers in-depth insights through scanning of IAC scripts, host systems, and cloud configurations. Recognized for effectively managing security posture, it safeguards Kubernetes and container environments, providing comprehensive threat detection and response. However, some areas like visibility, IAM security controls, and compliance metrics need improvement. Users face challenges with alert setup and lack intuitive design, alongside issues like FedRAMP authorization absence and complexity in the data model.
What are the key features of FortiCNAPP?FortiCNAPP is implemented extensively by industries needing reliable cloud security, such as finance, healthcare, and technology sectors. It supports organizations in enhancing cloud infrastructure protection, ensuring compliance, and strengthening vulnerability management. By integrating with platforms like AWS and GCP, businesses can optimize security posture in their cloud deployments.
JFrog is on a mission to enable continuous updates through Liquid Software, empowering developers to code high-quality applications that securely flow to end-users with zero downtime. The world’s top brands such as Amazon, Facebook, Google, Netflix, Uber, VMware, and Spotify are among the 4500 companies that already depend on JFrog to manage binaries for their mission-critical applications. JFrog is a privately-held, global company, and is a proud sponsor of the Cloud Native Computing Foundation [CNCF].
If you are a team player and you care and you play to WIN, we have just the job you're looking for.
As we say at JFrog: "Once You Leap Forward You Won't Go Back!"
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.