Enterprise Code Signing

Sign every artifact with HSM-protected keys.

Protect your software supply chain with automated code signing workflows. Sign executables, scripts, containers, and packages — with keys that never leave the HSM and complete audit trails.

Root CA
TigerTrust Root G3
RSA-4096 · SHA-384
Intermediate CA
Code Signing ICA-1
EC P-384 · SHA-256
tigertrust-agent-v2.4.1.tar.gz
SIGNED
TypeLinux ELF Binary
Size24.7 MB
Signerrelease-bot@tigertrust
Timestamp2026-08-28 · 09:12 UTC
SHA256: a3f8c29e1d74b560ca9d12e8f3a047bc
        d5e7f1829b043c6a8e291d74f5b260a1
SLSA verified
Sigstore
Notary v2
Cosign verified · CT log entry #8,291,042
Multi-platform

Sign code for every platform

Native support for Windows Authenticode, macOS code signing, JAR/APK, Debian and RPM packages, and OCI container artifacts. One workflow, every target.

How it works
  • Windows Authenticode signing
  • macOS code signing and notarization
  • JAR, APK, DEB, RPM signing
  • OCI container and Docker image signing
Multi-platform code signing pipeline
HSM protection

Signing keys never leave the HSM

FIPS 140-2 Level 3 hardware protects every private key. Sign operations happen inside the HSM, so an attacker who owns the build server still cannot exfiltrate the key.

How it works
  • FIPS 140-2 Level 3 HSMs
  • On-premise and cloud HSM support
  • Key material never exported
  • Per-key access policy enforcement
Hardware security module protecting signing keys
CI/CD integration

Plug into every build pipeline

Native integrations for Jenkins, GitHub Actions, GitLab CI, and Azure DevOps. REST API and CLI available for anything else your team runs.

How it works
  • Jenkins, GitHub Actions, GitLab CI
  • Azure DevOps pipelines
  • REST API and CLI tools
  • Signed provenance for SLSA
CI/CD pipeline signing integration
Governance

Approval workflows and time restrictions

Role-based access control, multi-party approvals, and time-based sign windows. Every signature attributed and logged to a tamper-proof audit trail.

How it works
  • Role-based access control
  • Multi-party approval for production
  • Time-based sign windows
  • Tamper-proof audit records
Signing approval and governance workflow
Everything code signing needs

Enterprise-grade signing. Zero key compromise.

The complete toolkit for signing every artifact your team ships.

RFC 3161 timestamping
Built-in TSA keeps signatures valid after certificate expiry.
  • RFC 3161 support
  • Built-in TSA
  • Long-term validation (LTV)
Compliance & audit
SOC 2 compliant with detailed signing logs and tamper-proof records.
  • SOC 2 compliance
  • Immutable audit logs
  • Regulatory reporting
Container signing
Sign Docker images and OCI artifacts for supply-chain trust.
  • Cosign compatibility
  • OCI registry integration
  • Notary v2 support
Key rotation
Rotate signing keys on policy without breaking previously-signed artifacts.
  • Policy-driven rotation
  • Multi-key support
  • Signature timeline preservation
Team delegation
Assign signing rights per team, per project, per certificate class.
  • Fine-grained delegation
  • Per-project keys
  • Departmental isolation
Signing observability
Track who signed what, when, and from where — in real time.
  • Real-time signing feed
  • Anomaly detection
  • Volume dashboards

From production signing operations

1M+
Artifacts signed
< 2s
Average signing time
100%
Audit coverage
Case study
Global · Software vendor

Signed 14M artifacts in one year with keys that never left the HSM.

After the SolarWinds fallout our board wanted every artifact signed with an HSM-resident key. TigerTrust plugged into our GitHub Actions in a day. No key ever hit disk.
Head of Product Security
14M
Artifacts signed in year one
0
Signing keys exposed to build hosts
100%
SLSA level 3 coverage
Integrations

Works with every tool in your stack

Signs inside your existing pipelines, backed by the HSMs and registries you already trust.

GitHub Actions
CI/CD
GitLab CI
CI/CD
Jenkins
CI/CD
Azure DevOps
CI/CD
CircleCI
CI/CD
Thales Luna
HSM
YubiHSM
HSM
AWS CloudHSM
HSM
Cosign
Signing
Sigstore
Signing
Docker Hub
Registry
JFrog Artifactory
Registry
FAQ

Frequently asked questions

Windows Authenticode (PE, MSI, CAB, PowerShell, VBS), macOS code signing and notarization, JAR/APK signing (jarsigner and apksigner compatible), Debian and RPM package signing, OCI container and Docker image signing via Cosign/Notary v2, generic PGP signing for release artifacts, and SBOM signing (CycloneDX, SPDX). Custom formats via the REST API for anything else. RFC 3161 timestamping is built-in so signatures stay valid after certificate expiry.
Signing operations happen inside the HSM — the build agent never sees the private key. Your pipeline authenticates to TigerTrust with a short-lived OIDC token (GitHub Actions, GitLab CI, Azure DevOps all supported) or a workload identity, sends the artifact hash, and receives a signature. Even a fully compromised build host cannot exfiltrate the key. Per-key policies let you require multi-party approval, restrict signing to specific branches, or gate production signing to time windows.
Yes. TigerTrust runs a Sigstore-compatible signing service that issues short-lived certificates tied to workload identity (OIDC), plus a Rekor-compatible transparency log for your artifacts. You can also use TigerTrust as the Fulcio-equivalent CA for a fully self-hosted Sigstore stack. Cosign works out of the box with either keyed (HSM-backed) or keyless (OIDC-bound) modes.
Rotate to a new signing key on any policy interval (annually, on team change, on incident). Because every signature includes an RFC 3161 timestamp and TigerTrust preserves the signing certificate for the entire artifact retention window, previously-signed artifacts remain verifiable indefinitely — even after the signing certificate expires or the key is retired. Long-term validation (LTV) metadata is embedded automatically.
Median signing latency is under 2 seconds for typical artifact hashes; batch endpoints amortise HSM round-trips for CI jobs signing hundreds of artifacts at once. Real-world throughput per HSM cluster is around 5,000 signatures per second sustained. If your pipeline pushes millions of container images per day, HSM partitions scale horizontally with per-team isolation.
Yes. Microsoft Authenticode signing meets the CA/B Forum requirement for FIPS 140-2 Level 2+ hardware key storage (we exceed with Level 3). EV code signing certificates are supported with the required hardware enforcement. Apple Developer ID signing and notarization work with keys stored in TigerTrust HSMs via Apple's notarization API. All standards updates (e.g. CA/B Forum 2024 EV requirements) are tracked and applied without you having to change your pipeline.

Protect every artifact you ship. Start signing today.