Software Trust Manager

Control every signature. Trust every release.

Govern software signing and release trust across every artifact, tool, and team—without locking into one ecosystem.

Explore Software Trust

Talk to an expert

Sign everything integrate anywhere
Governance project

Govern releases

Define who can sign what, when, and why—and standardize controls across repos, tools, and teams.

Automation 2 gears

Automate everywhere

Eliminate manual signing across CI/CD pipelines—integrated with the tools teams already use.

Cloud key

Monitor continuously

View vulnerabilities, issues, and risks of code in development and post-deployment.

Explore Software Trust Manager

Deliver policy, protection, and proof for secure releases.

Governance

Enforce signing policies

  • Define access and privileges for each project
  • Standardize policies with templates and workflows
  • Require approvals for high-risk signing actions
Enforce signing policy
Automation

Automate signing workflows

  • Sign containers, binaries, and artifacts across your existing tools
  • Integrate via native connectors, GitHub actions, CLI, and APIs
  • Automatically sign releases after passing all security checks
Automate signing workflows
Visibility

Track every signature

  • See signing and issue status across repos, pipelines, and environments
  • Trace each signature to an owner, time, and policy
  • Use logs for incident response, audit evidence, and compliance reporting teams
Code signing
Protection

Secure keys in HSMs

  • Keep keys in secure storage—even during signing
  • Store keys in FIPS 140-2 Level 3 or Common Criteria EAL4+ HSMs
  • Use regional key storage for global teams
Secure keys in hsm

Trusted in real-world environments

Wattwatchers Digital Energy

"Now every time we do a release build, Software Trust Manager automatically signs it, places it wherever it needs to be deployed, and secures it."

Grace Young, Chief Innovation Officer

Wattwatchers Digital Energy

watt-watchers.svg

Read the case study

Quote image

Built for secure releases

Automate signing, enforce governance, and track what ships across all tools so teams release secure software with audit proof.

Govern software releases

On March 15, 2027, the industry reaches its next major milestone: 100-day certificates.

The Road to 100 Days is your opportunity to understand what shorter lifecycles mean for your environment, identify where manual processes may struggle, and build greater visibility and automation before the next change arrives.

Govern software releases

Global development teams

Standardize signing across regions and tech stacks with centralized keys, approvals, and visibility.

Global development teams

CI/CD-driven delivery

Fast, efficient workflows where a single signing tool handles all file types, signs in bulk, and signs only necessary files.

CI/CD delivery

Firmware, devices, and OT

Protect firmware signing and updates across fleets with verification controls that reduce operational and safety risk.

Firmware, devices, and OT

Reduce release risk and toil

Strengthen security, accelerate releases, and prove compliance—all from one governed platform.

Code signing

Increase confidence

Know what’s signed and why across all artifacts before release.

Automation settings

Reduce toil

Automate policy-driven signing in CI/CD—no tickets, no delays.

Search relevance

Prove audit readiness

Show who signed what, when, and under which policy.

Compliance

Protect market access

Meet industry and government requirements with compliant signing and audit logs.

Why security leaders choose DigiCert

90%+

Fortune 500

100+

Patents in PKI & signing

25+

Annual compliance audits

Why DigiCert

Insights to strengthen your trust strategy

Guide

Top 5 strategies to secure your software supply chain

Get the guide

Data sheet

Software Trust Manager Data Sheet

Get the data sheet

Case study

Canon Software Trust Manager case study

Get the case study

Quiz

How mature is your software supply chain?

Take the quiz

Guide

Scalable Signing Policies for Software Teams

Get the guide

Select your solution

Foundational Trust

Essentials

Best for developers and startups that need secure code signing.

Contact Sales

Key Features:

  • Public trust code signing keypair
  • Secure key storage in cloud HSM
  • Visibility into release vulnerabilities
  • Email and GitHub alert notifications

Centralized Control

Advanced

Best for scaling teams that need centralized signing control, automated workflows, and vulnerability monitoring.

Contact Sales

Choose Advanced if your environment requires:

  • Public and Private code signing keypairs
  • Multiple signers per keypair
  • Continuous monitoring of release vulnerabilities
  • Signature and activity audit logs

Ultimate Assurance

Premium

Best for organizations that require code signing and release governance, automation for high-volume signing, vulnerability monitoring, and remediation guidance.

Contact Sales

Choose Premium if your environment requires:

  • Release automation acceleration for signing in high volume
  • More ways to control access and privileges
  • Container and Apple signing
  • Connection to on-premises HSMs

See Software Trust Manager in action

Try it yourself

Talk to an expert

Storylane screenshot

{{anchor:Talk to an expert}}

Talk to an expert about Software Trust Manager

Govern software signing and release trust across every artifact, tool, and team, without locking into one ecosystem.

form sheet template
/forms/eloqua-gtm-system-master-form-contact-us
toc
701Vu00001q2THWIA2
redirect
https://www.digicert.com/campaigns/thank-you
contactUsType
sales

{{anchor:Essentials}}

Buy Software Trust Manager Essentials

Best for developers and startups that need secure code signing.

form sheet template
/forms/eloqua-gtm-system-master-form-contact-us
toc
701Vu000032vV6GIAU
redirect
https://www.digicert.com/campaigns/thank-you
contactUsType
sales

{{anchor:Advanced}}

Buy Software Trust Manager Advanced

Best for scaling teams that need centralized signing control, automated workflows, and vulnerability monitoring.

form sheet template
/forms/eloqua-gtm-system-master-form-contact-us
toc
701Vu000032vTnWIAU
redirect
https://www.digicert.com/campaigns/thank-you
contactUsType
sales

{{anchor:Premium}}

Buy Software Trust Manager Premium

Best for organizations that require code signing and release governance, automation for high volume signing, vulnerability monitoring, and remediation guidance.

form sheet template
/forms/eloqua-gtm-system-master-form-contact-us
toc
701Vu000032wUJFIA2
redirect
https://www.digicert.com/campaigns/thank-you
contactUsType
sales