Cloudsmith

Universal registry platform with integrated security scanning for managing artifacts across your software supply chain

Also known as
cloudsmith

Available worldwide

What is Cloudsmith?

A cloud-native platform for centralizing, securing, and distributing software artifacts in 30+ formats, featuring built-in vulnerability scanning, malware detection, and policy-based access controls.

Independently observed

What Cloudsmith does

The capabilities that matter for container registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Deployment
Hosting
Cloud only
Standards
OCI Distribution Spec compliant
Scope
Artifact types
Universal (images + language packages)
Security
Built-in vulnerability scanning
Image signing (Cosign/Notation)
SBOM generation / storage
Access
Fine-grained RBAC / robot accounts
Private repositories
Distribution
Geo-replication / mirroring
Pull-through cache / proxy
Integration
Native cloud IAM integration
Pricing
Pull-rate limits
Tiered by plan
UX
Web UI / console
Ops
High-availability deployment
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
Deployment
  • Cloud / SaaS

Integrations (38)

Independently observed
  • AWS CodeBuild
  • Aikido
  • Ansible
  • Argo CD
  • Azure AD SSO
  • Azure DevOps
  • Bitbucket Pipelines
  • Buildkite
  • Chainguard
  • Chef
  • CircleCI
  • Codefresh
  • Datadog
  • Dependabot
  • Drone CI
  • GitHub Actions
  • GitHub Secret Scanning
  • GitLab CI/CD
  • Google SSO
  • Harness
  • Jenkins
  • JumpCloud SSO
  • Kusari
  • Microsoft Teams
  • Octopus Deploy
  • Okta
  • OneLogin SSO
  • Ping Identity
  • Puppet
  • Roadie
  • Semaphore CI
  • Slack
  • Terraform Provider
  • Travis CI
  • VS Code Extension
  • Webhooks
  • Zapier
  • GridLight

Cloudsmith FAQ

Common questions about Cloudsmith, answered from independent, dated evidence.

What is Cloudsmith?

A cloud-hosted system that secures your software supply chain by scanning all artifacts for vulnerabilities and policy violations, blocking risky items, and providing comprehensive audit trails of what's deployed where. It is indexed under Container Registries.

Source: https://cloudsmith.com

What platforms does Cloudsmith support?

Cloudsmith supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://cloudsmith.com

Can Cloudsmith be self-hosted?

We have only confirmed a cloud / SaaS deployment for Cloudsmith, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.

Source: https://cloudsmith.com

What does Cloudsmith integrate with?

We have confirmed 38 integrations for Cloudsmith, including AWS CodeBuild, Aikido, Ansible, Argo CD, Azure AD SSO, Azure DevOps, Bitbucket Pipelines and Buildkite, plus 30 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://cloudsmith.com

What security certifications does Cloudsmith have?

We have independently confirmed SOC 2 and ISO 27001 for Cloudsmith. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Cloudsmith not holding them. Always confirm compliance directly before you rely on it.

Source: https://trust.cloudsmith.com

Cloudsmith alternatives

Other container registries we track, ranked by the same independent score.

All Cloudsmith alternatives, ranked →

Compare Cloudsmith

Side by side against other container registries, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Cloudsmith, not the verdict.

Balanced composite 63 / 100
medium · 52%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security posture700.1812.3
Capabilities1000.043.9
Reliability500.052.7
Integrations380.041.7
Price level00.030.0-
Pricing transparency00.040.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Content

AttributeValueEvidence
Faq5 itemsmediumsource · 2026-09-10 · 62%

Features

AttributeValueEvidence
CapabilitiesRbac: Yes · Web ui: Yes · Hosting: cloud · Sbom support: Yes · Image signing: Yes · Oci compliant: Yesmediumsource · 2026-09-18 · 60%

Integrations

AttributeValueEvidence
Count20mediumsource · 2026-09-18 · 60%

Market

AttributeValueEvidence
AvailabilityPrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-09-03 · 75%

Pricing

AttributeValueEvidence
Modelcommercialmediumsource · 2026-08-03 · 60%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-09-03 · 60%

Security

AttributeValueEvidence
Disclosure policyYesmediumsource · 2026-08-13 · 60%
Iso27001Yeshighsource · 2026-08-03 · 75%
Soc2Yeshighsource · 2026-08-03 · 75%
Still deciding?

Is Cloudsmith the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank Cloudsmith against the rest of the container registries we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of Cloudsmith

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Cloudsmith up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows Cloudsmith's independent score and links back to this profile.

Cloudsmith, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/cloudsmith" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/cloudsmith.svg" alt="Cloudsmith, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![Cloudsmith, verified on vioscaleAI](https://www.vioscale.ai/badge/software/cloudsmith.svg)](https://www.vioscale.ai/software/cloudsmith)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Cloudsmith. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim Cloudsmith

Not the owner? How vendor profiles work