Cloudsmith
Universal registry platform with integrated security scanning for managing artifacts across your software supply chain
- Also known as
- cloudsmith
Available worldwide
What is Cloudsmith?
A cloud-native platform for centralizing, securing, and distributing software artifacts in 30+ formats, featuring built-in vulnerability scanning, malware detection, and policy-based access controls.
What Cloudsmith does
The capabilities that matter for container registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Hosting
- Cloud only
- OCI Distribution Spec compliant
- ✓
- Artifact types
- Universal (images + language packages)
- Built-in vulnerability scanning
- ✓
- Image signing (Cosign/Notation)
- ✓
- SBOM generation / storage
- ✓
- Fine-grained RBAC / robot accounts
- ✓
- Private repositories
- ✓
- Geo-replication / mirroring
- ✓
- Pull-through cache / proxy
- ✓
- Native cloud IAM integration
- ✓
- Pull-rate limits
- Tiered by plan
- Web UI / console
- ✓
- High-availability deployment
- ✓
Platform & deployment
Independently observed- CLI
- Web
- Cloud / SaaS
Integrations (38)
Independently observed- AWS CodeBuild
- Aikido
- Ansible
- Argo CD
- Azure AD SSO
- Azure DevOps
- Bitbucket Pipelines
- Buildkite
- Chainguard
- Chef
- CircleCI
- Codefresh
- Datadog
- Dependabot
- Drone CI
- GitHub Actions
- GitHub Secret Scanning
- GitLab CI/CD
- Google SSO
- Harness
- Jenkins
- JumpCloud SSO
- Kusari
- Microsoft Teams
- Octopus Deploy
- Okta
- OneLogin SSO
- Ping Identity
- Puppet
- Roadie
- Semaphore CI
- Slack
- Terraform Provider
- Travis CI
- VS Code Extension
- Webhooks
- Zapier
- GridLight
Cloudsmith FAQ
Common questions about Cloudsmith, answered from independent, dated evidence.
What is Cloudsmith?
A cloud-hosted system that secures your software supply chain by scanning all artifacts for vulnerabilities and policy violations, blocking risky items, and providing comprehensive audit trails of what's deployed where. It is indexed under Container Registries.
Source: https://cloudsmith.com
What platforms does Cloudsmith support?
Cloudsmith supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.
Source: https://cloudsmith.com
Can Cloudsmith be self-hosted?
We have only confirmed a cloud / SaaS deployment for Cloudsmith, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.
Source: https://cloudsmith.com
What does Cloudsmith integrate with?
We have confirmed 38 integrations for Cloudsmith, including AWS CodeBuild, Aikido, Ansible, Argo CD, Azure AD SSO, Azure DevOps, Bitbucket Pipelines and Buildkite, plus 30 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.
Source: https://cloudsmith.com
What security certifications does Cloudsmith have?
We have independently confirmed SOC 2 and ISO 27001 for Cloudsmith. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Cloudsmith not holding them. Always confirm compliance directly before you rely on it.
Source: https://trust.cloudsmith.com
Cloudsmith alternatives
Other container registries we track, ranked by the same independent score.
- HarborOpen-source container image registry with built-in security, signing, and vulnerability scanning for cloud-native environmentshigh · 78%
- Google Artifact RegistryA hosted repository service for organizing and managing build artifacts and package dependencies across multiple formatsmedium · 54%
- Docker HubA central registry for storing, managing, and sharing container images with your team and the broader developer communityhigh · 75%
- Azure Container RegistryHosted storage for containerized application imagesmedium · 53%
- CNCF DistributionA cloud-hosted registry for discovering, publishing, and managing containerized applicationsmedium · 67%
- Chainguard RegistryContainer images and open source packages maintained without known vulnerabilitiesmedium · 73%
Compare Cloudsmith
Side by side against other container registries, attribute by attribute, with a source on every value.
The vioscaleAI score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Cloudsmith, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Security posture | 70 | 0.18 | 12.3 | ✓ |
| Capabilities | 100 | 0.04 | 3.9 | ✓ |
| Reliability | 50 | 0.05 | 2.7 | ✓ |
| Integrations | 38 | 0.04 | 1.7 | ✓ |
| Price level | 0 | 0.03 | 0.0 | - |
| Pricing transparency | 0 | 0.04 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Content
| Attribute | Value | Evidence |
|---|---|---|
| Faq | 5 items | mediumsource · 2026-09-10 · 62% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Rbac: Yes · Web ui: Yes · Hosting: cloud · Sbom support: Yes · Image signing: Yes · Oci compliant: Yes | mediumsource · 2026-09-18 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 20 | mediumsource · 2026-09-18 · 60% |
Market
| Attribute | Value | Evidence |
|---|---|---|
| Availability | PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: … | highsource · 2026-09-03 · 75% |
Pricing
| Attribute | Value | Evidence |
|---|---|---|
| Model | commercial | mediumsource · 2026-08-03 · 60% |
Reliability
| Attribute | Value | Evidence |
|---|---|---|
| Status page | Yes | mediumsource · 2026-09-03 · 60% |
Security
Is Cloudsmith the right choice for you?
Tell us the job, the constraints and what you weigh most, and we will rank Cloudsmith against the rest of the container registries we index, using the same dated evidence weighted your way.
Free to run, no account needed to start. How the evaluation works
Is this your product?
This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Cloudsmith up or down: nobody can buy rank here, including you.
Take the badge
Live, always current, and free to use on your own site. It shows Cloudsmith's independent score and links back to this profile.
<a href="https://www.vioscale.ai/software/cloudsmith" target="_blank" rel="noopener">
<img src="https://www.vioscale.ai/badge/software/cloudsmith.svg" alt="Cloudsmith, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>Markdown, for a README →
[](https://www.vioscale.ai/software/cloudsmith)Claim the profile
Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Cloudsmith. Free, and it does not change the score.
- Correct anything wrong, with evidence
- Point our crawler at the pages that matter
- See which AI systems are reading this profile
Not the owner? How vendor profiles work