SignPath

Web · Windows · Mac · Linux · Self-hosted · API

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely4 of 6 device platforms
  • DocumentedPlans, terms and facts published

SignPath provides code signing and software integrity tools to enforce policies across software builds and releases. Its format-aware signing covers executables, packages, installers, containers, scripts, manifests, SBOMs, and configuration files. Before a release is trusted, the platform can check its source repository, branch, build system, approvals, and CI/CD context. It can generate signed, machine-readable attestations, including SLSA provenance, validation summaries, and signed SBOMs. Listed integrations include plugins and REST APIs for GitHub Actions, GitLab, Jenkins, Azure DevOps, and TeamCity. SignPath says private keys stay in FIPS-compliant hardware security modules and are never exposed or shared. Role-based controls specify who may sign particular artifacts, when, and with which certificate. Logs capture the user, file, certificate, policy, and result; reports can be exported, with optional WORM-style archiving. Deployment choices are SaaS, self-hosted, or hybrid. The free Open Source Code Signing plan has eligibility conditions: projects must be actively maintained and released, use an OSI-approved open source license, and have no proprietary components.

Who it is for

SignPath suits development teams and enterprises that need signing policies and integrity checks across builds and releases. Its free plan is specifically for eligible open source projects.

What is good

  • Supports signing across many artifact formats.
  • Checks repository, build, approval, and CI/CD context.
  • Private keys are held in FIPS-compliant HSMs.
  • Offers SaaS, self-hosted, and hybrid deployment.

What to know first

  • Free plan requires an eligible open source project.
  • Eligible projects must have no proprietary components.

Verdict

SignPath ties artifact signing to build and release policies, with attestations, access controls, and audit logs. Its free plan is restricted to qualifying open source projects.

SignPath plans and pricing

All plans
Open Source Code Signing Free For open source projects · eligibility conditions apply signpath.org · 29 Sept 2026

Compared on code signing software

Free plan
Yes
Supported targets
Windows PE files, PowerShell, MSI, CAB, catalog, APPX, MSIX, NuGet, Java archives, containers, Linux packages, macOS code, and custom artifacts
Certificate provided
Yes
Cloud signing
Yes
HSM key protection
Yes
Trusted timestamping
Yes
CI/CD signing
Yes
Approval workflows
Yes

Best SignPath alternatives

See all 20