Software Trust Manager
Control every signature. Trust every release.
Govern software signing and release trust across every artifact, tool, and team—without locking into one ecosystem.
Govern releases
Define who can sign what, when, and why—and standardize controls across repos, tools, and teams.
Automate everywhere
Eliminate manual signing across CI/CD pipelines—integrated with the tools teams already use.
Monitor continuously
View vulnerabilities, issues, and risks of code in development and post-deployment.
Explore Software Trust Manager
Deliver policy, protection, and proof for secure releases.
Enforce signing policies
- Define access and privileges for each project
- Standardize policies with templates and workflows
- Require approvals for high-risk signing actions
Automate signing workflows
- Sign containers, binaries, and artifacts across your existing tools
- Integrate via native connectors, GitHub actions, CLI, and APIs
- Automatically sign releases after passing all security checks
Track every signature
- See signing and issue status across repos, pipelines, and environments
- Trace each signature to an owner, time, and policy
- Use logs for incident response, audit evidence, and compliance reporting teams
Secure keys in HSMs
- Keep keys in secure storage—even during signing
- Store keys in FIPS 140-2 Level 3 or Common Criteria EAL4+ HSMs
- Use regional key storage for global teams
Trusted in real-world environments
"Now every time we do a release build, Software Trust Manager automatically signs it, places it wherever it needs to be deployed, and secures it."
Grace Young, Chief Innovation Officer
Wattwatchers Digital Energy
Built for secure releases
Automate signing, enforce governance, and track what ships across all tools so teams release secure software with audit proof.
Govern software releases
On March 15, 2027, the industry reaches its next major milestone: 100-day certificates.
The Road to 100 Days is your opportunity to understand what shorter lifecycles mean for your environment, identify where manual processes may struggle, and build greater visibility and automation before the next change arrives.
Global development teams
Standardize signing across regions and tech stacks with centralized keys, approvals, and visibility.
CI/CD-driven delivery
Fast, efficient workflows where a single signing tool handles all file types, signs in bulk, and signs only necessary files.
Firmware, devices, and OT
Protect firmware signing and updates across fleets with verification controls that reduce operational and safety risk.
Reduce release risk and toil
Strengthen security, accelerate releases, and prove compliance—all from one governed platform.
Increase confidence
Know what’s signed and why across all artifacts before release.
Reduce toil
Automate policy-driven signing in CI/CD—no tickets, no delays.
Prove audit readiness
Show who signed what, when, and under which policy.
Protect market access
Meet industry and government requirements with compliant signing and audit logs.
Why security leaders choose DigiCert
90%+
Fortune 500
100+
Patents in PKI & signing
25+
Annual compliance audits
Insights to strengthen your trust strategy
Select your solution
Foundational Trust
Essentials
Best for developers and startups that need secure code signing.
Key Features:
- Public trust code signing keypair
- Secure key storage in cloud HSM
- Visibility into release vulnerabilities
- Email and GitHub alert notifications
Centralized Control
Advanced
Best for scaling teams that need centralized signing control, automated workflows, and vulnerability monitoring.
Choose Advanced if your environment requires:
- Public and Private code signing keypairs
- Multiple signers per keypair
- Continuous monitoring of release vulnerabilities
- Signature and activity audit logs
Ultimate Assurance
Premium
Best for organizations that require code signing and release governance, automation for high-volume signing, vulnerability monitoring, and remediation guidance.
Choose Premium if your environment requires:
- Release automation acceleration for signing in high volume
- More ways to control access and privileges
- Container and Apple signing
- Connection to on-premises HSMs
{{anchor:Talk to an expert}}
Talk to an expert about Software Trust Manager
Govern software signing and release trust across every artifact, tool, and team, without locking into one ecosystem.
{{anchor:Essentials}}
Buy Software Trust Manager Essentials
Best for developers and startups that need secure code signing.
{{anchor:Advanced}}
Buy Software Trust Manager Advanced
Best for scaling teams that need centralized signing control, automated workflows, and vulnerability monitoring.
{{anchor:Premium}}
Buy Software Trust Manager Premium
Best for organizations that require code signing and release governance, automation for high volume signing, vulnerability monitoring, and remediation guidance.