SignPath provides code signing and software integrity tools to enforce policies across software builds and releases. Its format-aware signing covers executables, packages, installers, containers, scripts, manifests, SBOMs, and configuration files. Before a release is trusted, the platform can check its source repository, branch, build system, approvals, and CI/CD context. It can generate signed, machine-readable attestations, including SLSA provenance, validation summaries, and signed SBOMs. Listed integrations include plugins and REST APIs for GitHub Actions, GitLab, Jenkins, Azure DevOps, and TeamCity. SignPath says private keys stay in FIPS-compliant hardware security modules and are never exposed or shared. Role-based controls specify who may sign particular artifacts, when, and with which certificate. Logs capture the user, file, certificate, policy, and result; reports can be exported, with optional WORM-style archiving. Deployment choices are SaaS, self-hosted, or hybrid. The free Open Source Code Signing plan has eligibility conditions: projects must be actively maintained and released, use an OSI-approved open source license, and have no proprietary components.
Who it is for
SignPath suits development teams and enterprises that need signing policies and integrity checks across builds and releases. Its free plan is specifically for eligible open source projects.
What is good
- Supports signing across many artifact formats.
- Checks repository, build, approval, and CI/CD context.
- Private keys are held in FIPS-compliant HSMs.
- Offers SaaS, self-hosted, and hybrid deployment.
What to know first
- Free plan requires an eligible open source project.
- Eligible projects must have no proprietary components.
Verdict
SignPath ties artifact signing to build and release policies, with attestations, access controls, and audit logs. Its free plan is restricted to qualifying open source projects.
SignPath plans and pricing
All plansCompared on code signing software
- Free plan
- Yes
- Supported targets
- Windows PE files, PowerShell, MSI, CAB, catalog, APPX, MSIX, NuGet, Java archives, containers, Linux packages, macOS code, and custom artifacts
- Certificate provided
- Yes
- Cloud signing
- Yes
- HSM key protection
- Yes
- Trusted timestamping
- Yes
- CI/CD signing
- Yes
- Approval workflows
- Yes





