SignPath
About
SignPath provides code signing and software integrity controls for software builds and releases. Its format-aware signing covers executables, packages, installers, containers, scripts, manifests, SBOMs and configuration files. Before trusting a release, it can check the source repository, branch, build system, approvals and CI/CD context. The platform can generate signed, machine-readable attestations, including SLSA provenance, validation summaries and signed SBOMs. Integrations include plugins and REST APIs for GitHub Actions, GitLab, Jenkins, Azure DevOps and TeamCity. SignPath says private keys are kept in FIPS-compliant HSMs and are never exposed or shared. Role-based controls determine who may sign which artifacts and with which certificate. Logs capture signing-request details, while reports can be exported and optional WORM-style log archiving is available. Deployment choices are SaaS, self-hosted or hybrid. The free Open Source Code Signing subscription is conditional: eligible projects must be actively maintained and released, use an OSI-approved open source license and contain no proprietary components.
Who it is for
SignPath suits development teams and enterprises that need signing policies, release checks and audit records across build pipelines. Its free plan is for qualifying open source projects that meet the stated eligibility conditions.
What is good
- Supports a broad range of artifact formats
- Checks repository, build and approval context
- Integrates with GitHub Actions, GitLab, Jenkins, Azure DevOps and TeamCity
- Private keys are kept in FIPS-compliant HSMs
- SaaS, self-hosted and hybrid deployment options
What to know first
- Free plan requires eligible open source projects
- Eligibility excludes proprietary components
- WORM-style log archiving is optional
Verdict
SignPath links signing controls to build context, access policy and auditable release records, with SaaS, self-hosted and hybrid deployment options. Open source teams should verify that their project meets every free-plan eligibility condition.
Compared on code signing software
- Free plan
- Yessignpath.io
- Supported targets
- Windows PE files, PowerShell, MSI, CAB, catalog, APPX, MSIX, NuGet, Java archives, containers, Linux packages, macOS code, and custom artifactssignpath.io
- Certificate provided
- Yessignpath.io
- Cloud signing
- Yessignpath.io
- HSM key protection
- Yessignpath.io
- Trusted timestamping
- Yessignpath.io
- CI/CD signing
- Yessignpath.io
- Approval workflows
- Yessignpath.io
Facts
- Purpose
- SignPath provides code signing and software integrity tools that enforce policies across software builds and releases.signpath.io · 29 Sept 2026
- Signing
- Its semantic code signing supports format-aware signing for executables, packages, installers, containers, scripts, manifests, SBOMs, and configuration files.signpath.io · 29 Sept 2026
- Pipeline integrity
- The platform can verify source repositories, branches, build systems, approvals, and CI/CD context before trusting a release.signpath.io · 29 Sept 2026
- Attestation
- SignPath can generate signed, machine-readable attestations including SLSA provenance, validation summaries, and signed SBOMs.signpath.io · 29 Sept 2026
- Integrations
- The company lists plugins and REST API integrations for GitHub Actions, GitLab, Jenkins, Azure DevOps, and TeamCity.signpath.io · 29 Sept 2026
- Key security
- SignPath says private keys are stored in FIPS-compliant HSMs and are never exposed or shared.signpath.io · 29 Sept 2026
- Access controls
- Role-based access controls define who can sign which artifacts, when, and with which certificate.signpath.io · 29 Sept 2026
- Audit and compliance
- The platform logs signing requests with the user, file, certificate, policy, and result, and offers exportable reports and optional WORM-style log archiving.signpath.io · 29 Sept 2026
- Deployment
- SignPath describes its deployment options as SaaS, self-hosted, or hybrid.signpath.io · 29 Sept 2026
- Support
- SignPath provides a support portal and lists [email protected] as a contact address.signpath.io · 29 Sept 2026
- Open source eligibility
- Free SignPath Foundation subscriptions require an actively maintained, released project using an OSI-approved open source license without proprietary components.signpath.org · 29 Sept 2026
- Audience
- The company says it serves customers worldwide, from small development teams to large enterprises.signpath.io · 29 Sept 2026
Company
- Founded
- 2017signpath.io · 23 Sept 2026
- Headquarters
- Vienna, Austriasignpath.io · 23 Sept 2026
Best SignPath alternatives
See all 12
7.3 Bamboo Deploy $15/mo first paid tier
7.3 SignServer Free free plan, no paid price published Free plan
7.2 Sigstore Free free plan, no paid price published Free plan 7.0 DigiCert Software Trust Manager See plans price on the maker's page
7.0 SSL.com Certificate Lifecycle Management See plans price on the maker's page
6.9 Keyfactor Platform See plans price on the maker's page Free trial Where it ranks on Inferse
Sources
- signpath.io· checked 29 Sept 2026
- signpath.io/platform/features· checked 29 Sept 2026
- signpath.io/support· checked 29 Sept 2026
- signpath.org/terms.html· checked 29 Sept 2026
- signpath.io/company· checked 29 Sept 2026





