Prove your software is genuine — before it runs on anyone’s machine
Every piece of software you ship carries your name. SSL's code signing certificates and cloud signing service let you cryptographically sign executables, drivers, scripts, and firmware — so users, platforms, and operating systems can verify that your software is authentic and hasn't been tampered with since you signed it.
Unsigned or improperly signed code is one of the leading software supply chain attack vectors
Software supply chain attacks — from SolarWinds to XZ Utils — show that the integrity of code between the developer and the end user is not guaranteed without cryptographic signing. Operating systems, platforms, and security tools increasingly require signed binaries. Regulators and compliance frameworks (SLSA, SSDF, SOC 2) are mandating software integrity controls.
SSL’s Software Integrity products address two distinct needs:
- Code Signing Certificates — validated certificates that cryptographically bind your identity to the code you sign, at three validation levels (IV, OV, EV)
- eSigner for Code — a cloud-based signing service that eliminates the hardware token requirement for EV code signing, enabling seamless CI/CD pipeline integration
Two ways to sign and protect your software
Code Signing Certificates
Sign your code with a validated identity. IV for individuals, OV for organizations, EV for maximum trust and instant SmartScreen.
eSigner for Code — Cloud Signing
Sign from the cloud. No hardware token required. Integrates with GitHub Actions, Jenkins, Azure DevOps, and more.
Which solution do you need?
Compliance & Standards
Microsoft Authenticode
All Windows executable signing — OV and EV trusted
Windows Kernel Mode Drivers
Requires EV Code Signing certificate
Microsoft SmartScreen
EV delivers immediate reputation — no first-download warnings
Apple Gatekeeper / Notarization
macOS distribution requires Developer ID signing and notarization
CA/B Forum Code Signing BR
All SSL certificates comply with Code Signing Baseline Requirements
Why SSL
eSigner cloud signing
Cloud HSM-backed signing — purpose-built for CI/CD, no hardware token required.
WebTrust for Code Signing BR
Audited annually by BDO — CA/B Forum Code Signing BR compliance.
SWS API
Programmatic certificate management and signing integration.
In operation since 2002
Over two decades of PKI infrastructure experience.