bitSign is a turnkey service for protecting your signing keys, approving every signature and shipping software your customers can trust – without building the infrastructure yourself.
Tampered firmware can harm your customers – and your reputation.
Regulated industries demand secure code signing (e.g. ISO 27001, IEC 62443, automotive).
Building and maintaining your own signing environment is expensive and slow.
Send your file to the portal.
You decide who has to sign off – and how many.
bitSign signs with your HSM-protected keys inside our trusted environment.
Your signed software is ready – with a complete audit trail.
You store your own cold keys and own your disaster recovery. We provision our HSM on your premises using the PkOS security system. The key exists only inside the HSM – we can never recreate or leak your private key.
We handle your private key securely with PkOS and create disaster recovery kits – we keep one, you get one. Redundancy is built in: if bit42 ever disappears, you hold a copy; if your office burns down, we hold one. Stored encrypted in a high-security safe.
| Zero-copy model | Cold escrow | |
|---|---|---|
| Control | Maximum | High |
| Disaster recovery | Your own DR model | Dual protection |
| Technical safeguards | PkOS + HSM | PkOS + security safe |
Watch how easily your developers and security officers manage signings – from request to finished, signed software.
bitSign solves the signing of our Infix releases in an elegant way. You can tell it was built by someone who understands the practical challenges developers face. A real gamechanger!
Kernel Kit Organization
Integrate secure code signing straight into your CI/CD pipelines. Speed, without compromising on security.
Make signing part of every build and release. No manual steps slowing your team down.
The workflow pauses and waits for human approval – protecting you even if your CI/CD environment is compromised, or an insider goes rogue.
Every signature is logged automatically, with timestamps and approvals. Compliance reporting becomes trivial.
# Sign firmware in your pipeline – approval happens in the portal
- name: Sign firmware with bitSign
run: |
REQ=$(curl -s -X POST https://portal.bitsign.se/api/v1/requests \
-H "Authorization: Bearer $BITSIGN_API_KEY" \
-F "key=prod-secureboot-2026" \
-F "file=@build/firmware-${{ github.ref_name }}.img")
# The pipeline pauses until trusted signers approve (2FA)
bitsign wait --request $REQ --timeout 24h
bitsign fetch --request $REQ -o build/firmware.img.sig
# Create a signing request straight against our API
curl -X POST https://portal.bitsign.se/api/v1/requests \
-H "Authorization: Bearer $BITSIGN_API_KEY" \
-F "key=prod-secureboot-2026" \
-F "file=@firmware-v4.2.1.img"
# Response – the request now awaits human approval
{ "id": "SR-1847", "status": "awaiting_attestation" }
The same flow — whether you run it from your terminal, your CI/CD or straight against our API.
View the example on GitHubFrom implementation to physically protected keys, we cover the whole chain – so you can stay focused on your core business.
// DR kit Confidence when the unexpected happens — a physical DR kit for every key.
Add SFP (Security Fuse Processor) read support for NXP QorIQ series SOC's
Contributing secure-boot support to the mainline Linux kernel – our expertise, proven in practice.
There are scenarios where a private key must be handled in its raw, unencrypted form – when generating a new key, provisioning a Hardware Security Module (HSM), or verifying a key's integrity. This has to happen in a secure environment. Our Private Key Environment (PKE) is purpose-built for safely handling unencrypted private keys.
Every device in the PKE runs our purpose-built operating system PkOS, which boots from physically write-protected media. All storage is volatile by design – there is no scenario in which the unencrypted private key can be persisted.
Every device in our PKE is physically air-gapped (MSB1309). Our bitfrost data diode guarantees that nothing inside the PKE can leak out, while still allowing software updates and security patches in.
I'm fairly sure Alex still has a copy of the private key on a USB stick somewhere
A concern we hear from security officers all the time — bitSign eliminates it completely.
A leaked key lets anyone sign malicious code in your name.
With bitSign, keys are always protected inside an HSM and can never be exported.
Losing a key can mean losing the ability to update your products.
With bitSign, every key comes with a Disaster Recovery Kit.
Choose our default model (cold escrow) and we also keep a copy in a separate secure facility – redundancy without having to build it yourself.
If anyone in the organisation can sign code, a hacker – or a disgruntled employee – could ship malware in your name.
With bitSign, you can require sign-off from several trusted people before anything gets signed.
Everything is logged tamper-evidently – the logs cannot be manipulated.
Yes. You choose the model – either an HSM that only you own (zero-copy), or our default cold escrow model for maximum redundancy.
Most customers are up and running in days, not months.
Yes. We provide ready-made jobs for advanced flows, and can adapt to your setup where needed.
Yes. Every signing operation is auditable, with complete logging.
That makes it easier to satisfy ISO 27001, IEC 62443 and other relevant standards.
Absolutely. bitSign gives you the same level of security the large enterprises rely on.
Without having to build expensive infrastructure yourself.
A perfect fit for smaller companies that need secure signing without the complexity.
The complete solution for mid-sized companies with regular signing needs and high security requirements.
A tailored solution for organisations with specific requirements on hosting and isolation.
Every plan includes HSM-backed key storage, approvals and signing in a trusted environment.
Annual contract · Prices excl. VAT
B1C7 05C6 B1BF 719C A5CD
6739 8BEE 8379 084B C511