Cloud code signing

Cloud Code Signing Service

The sslTrus cloud code signing service is an innovative code signing solution. It centrally protects the signing key through the cloud hardware Hardware Security Module (HSM)(HSM), replacing the traditional physical hardware UKey. Users can conveniently obtain globally trusted code signing certificates without managing physical devices and easily achieve automated signing using professional tools or apis.

HSM Secure Enclave
FIPS 140-3
Private key generation is isolated from hardware Generate the private key internally in the cloud Hardware Security Module (HSM)and force it to be marked as Non-extractable to ensure that the private key will never be removed from the database.
Identity verification and Automated Certificate Issuance After the identity verification is successful, the CA issues the public key of the certificate and seamlessly binds it to the corresponding HSM physical security partition at the infrastructure layer.
Cloud-based secure hash signature Locally, only the code Hash is calculated and encrypted for transmission. The encryption and signature operation is completed within the HSM to fully ensure that the enterprise source code is not leaked.

A revolutionary cloud signature experience

Compared with traditional physical Ukeys, the sslTrus cloud code signing service offers you unparalleled security, agility and collaboration capabilities.

Safety Compliance

The private key is generated and stored in the cloud Hardware Security Module (HSM)that complies with FIPS 140-3 certification and never leaves the device, eliminating the risk of business interruption caused by hardware loss or damage.

Audit traceability

Generate an unalterable complete operation record and timestamp for each signature, facilitating auditing and tracking, and meeting the security and compliance requirements of the supply chain.

Cross-regional collaboration

Support development teams distributed in different regions to share the same signature service, and achieve unified signature policies and auditing standards.

Service ready to use

The Certificate Issuancecan be activated and used online immediately without waiting for the hardware to be mailed, significantly reducing the project start-up time.

cost-effectiveness

It eliminates the costs of purchasing, logistics and management of hardware Ukeys, and allows payment based on the actual number of uses.

Cloud code signing Package

Multiple versions are provided, with the main difference lying in the number of signatures per year, fully meeting the cloud code signing needs of teams of different sizes.

7-day trial period

Trial Version

Zero-cost free experience, early access to cloud signature capabilities, code signing without UKey.

Free Trial
  • Zero-cost 7-day trial
  • Cloud Signature Capability Experience
  • No UKey hardware required
  • Production Environment Integration
Contact customer service at
1000 times per year

Basic Version

Meet the release requirements of basic developers, including seamless integration of certificates and cloud management capabilities.

¥500/ Year
  • Signature count: 1000 times per year
  • Seamless integration of code signing certificates
  • Safety compliance, audit traceability
  • Cross-regional collaboration
  • Service ready to use
Grab now
15,000 times per year

Enterprise Edition

Designed for large software developers and distributed multinational teams, it offers extremely high signature frequency authorization.

¥4500/ Year
  • Signature count: 15,000 times per year
  • Seamless integration of code signing certificates
  • Safety compliance, audit traceability
  • Cross-regional collaboration
  • Service ready to use
Grab now

Service activation only takes four steps

Simplify signing and free yourself from physical hardware for an agile digital signing journey.

1. Select the package

Select a service plan on the sslTrus platform and submit your application details.

2. Certificate Issuance

After the verification is completed, the platform will issue a code signing certificate and activate the signing service.

3. Tool Configuration

Download the signature tool or configure it in the development environment (such as CI/CD).

4. Start Signing

Sign software safely and efficiently using tools or command lines.

Empower every aspect of modern software development

Distributed team collaborative management

Address the security risks and efficiency bottlenecks in the transmission and handover of physical Ukeys within cross-regional teams.

Agile and auditable team security management

All the granting, modification and recovery of permissions are fully digitized to fundamentally eliminate the risk of private key abuse, and all operations have complete logs.

Realize true DevOps full automation

Eliminate the "breakpoints" of physical Ukeys on the automated pipeline to achieve full-process automation from development, build to signature and release.

Audit Assurance for High-Compliance Industries

Provide signature services that comply with strict regulatory requirements for industries such as finance, healthcare, and government, and easily handle internal and external security audits.

Seamlessly integrate into your existing technology stack

Natively supports the world's mainstream development environments and file formats, injecting cloud signature capabilities into your business lines like flowing water, without the need to change your existing build habits at all.

Deeply integrated with mainstream CI/CD platforms

Flexible plugins and rich APIs for modern agile development and automated deployment environments

Microsoft Azure
GitHub Actions
Jenkins
GitLab CI
CircleCI
Apache Ant
Gradle
Maven

Microsoft Authenticode

Fully supports mainstream Windows platform formats, including executable files such as. exe,. dll,. ocx,. msi, and. cab, as well as signature protection for kernel driver software.

Apple Code Signing

Provides trusted digital signatures for macOS applications that pass the system-level Gatekeeper security verification.

Java code signing

Support high-strength tamper-proof digital signatures for any JAR file and Java runtime environment program to protect the underlying code logic.

Mozilla extensions and others

Seamlessly support application packages such as signed Firefox extensions (. xpi files), Adobe AIR, Microsoft Office (macros /VBA), and Silverlight.

Frequently Asked Questions

What are the differences between remote code signing and traditional UKey signing?

In the traditional way, private keys are stored in physical Ukeys, which pose risks of loss, borrowing and abuse, as well as inability to collaborate remotely. Remote code signing hosts the private key in a FIPS 140-3-certified cloud HSM. The private key never lands, and cross-regional teams can sign safely anytime and anywhere.

Does it support CI/CD automated integration?

Support. It provides professional signature tools and API interfaces, which can be seamlessly integrated with pipelines such as Jenkins, GitLab CI, and GitHub Actions to achieve automatic signature after build without manual intervention.

Which platforms and file formats are eligible for signing?

Fully compatible with multiple platform formats such as Microsoft Authenticode (. exe/. DLL /. mSI /. sys driver), Java, Adobe AIR, etc. The signed product is completely consistent with the local certificate and trusted by the global system.

How to control and audit signature operations?

The platform offers role-based permission control, multi-person approval flow and complete signature logs. Every signature behavior can be traced, meeting the internal control and compliance audit requirements of enterprises.

From Manual Certificate Operations to Automation

From SSL/TLS certificate discovery, enrollment and deployment to continuous monitoring, alerting and automatic renewal, sslTrus helps enterprises build a unified certificate automation platform—reducing the operational burden of growing certificate inventories and shorter validity periods.

  • Overview
  • Certificate Requests
  • Certificate Deployment
  • Discovery Agents
  • Compliance & Alerts
  • Settings
Global Overview
Total Certificates
12,458
Pending
34
Expiring in 30 Days
15
Expired
2
Automated Deployments · 30 Days
Expiration Risk · Next 6 Months
Overall Compliance Rate
96%

Certificates Meet the Latest Security Baseline

Device & Cloud Asset Mix
Alibaba Cloud (40%)
AWS (25%)
Azure (15%)
F5 (10%)
Cisco (10%)