Firmware · Embedded · Secure boot

Sign your software.
Simple, secure and traceable.

bitSign is a turnkey service for protecting your signing keys, approving every signature and shipping software your customers can trust – without building the infrastructure yourself.

Swedish security engineering by bit42 AB bit42 AB
Log in to the portal
Create request
// Keys
Never leave the HSM
// Approvals
Multi-party with 2FA
// Logging
Tamper-evident audit trail
// Onboarding
Days, not months
01 — The risk

Every unsigned – or wrongly signed – release is a liability.

Product risk
/ 01

Product risk

Tampered firmware can harm your customers – and your reputation.

Compliance risk
/ 02

Compliance risk

Regulated industries demand secure code signing (e.g. ISO 27001, IEC 62443, automotive).

Operational risk
/ 03

Operational risk

Building and maintaining your own signing environment is expensive and slow.

02 — The flow

From file to signed code – through a flow you can trust.

1

Create a request

Send your file to the portal.

2

Approve

You decide who has to sign off – and how many.

3

Sign

bitSign signs with your HSM-protected keys inside our trusted environment.

4

Download

Your signed software is ready – with a complete audit trail.

03 — Key model

Decide how you want to own your keys

Zero-copy model

/ A

You store your own cold keys and own your disaster recovery. We provision our HSM on your premises using the PkOS security system. The key exists only inside the HSM – we can never recreate or leak your private key.

  • Maximum control – the keys are entirely yours
  • Secure on-site provisioning with PkOS
  • You build your own DR model
Recommended

Cold escrow (default)

/ B

We handle your private key securely with PkOS and create disaster recovery kits – we keep one, you get one. Redundancy is built in: if bit42 ever disappears, you hold a copy; if your office burns down, we hold one. Stored encrypted in a high-security safe.

  • Redundancy built in – two independent copies
  • Straightforward for any security firm to restore
  • Encrypted storage in a high-security safe
Zero-copy model Cold escrow
Control Maximum High
Disaster recovery Your own DR model Dual protection
Technical safeguards PkOS + HSM PkOS + security safe
04 — Demo

See the portal in action

Watch how easily your developers and security officers manage signings – from request to finished, signed software.

Effortless onboarding

Keys never leave the HSM

Approval flows you control

Audit-ready logging

bitSign solves the signing of our Infix releases in an elegant way. You can tell it was built by someone who understands the practical challenges developers face. A real gamechanger!
Joachim Wiberg

Joachim Wiberg

Kernel Kit Organization

05 — Integrations

Works with industry-leading tools & platforms

Integration Partner
Integration Partner
Integration Partner
Integration Partner
Integration Partner
Integration Partner
Integration Partner
Integration Partner
Integration Partner
Integration Partner
Integration Partner
Integration Partner
06 — API & Automation

Automate your signing – keep control

Integrate secure code signing straight into your CI/CD pipelines. Speed, without compromising on security.

Faster time-to-market

Make signing part of every build and release. No manual steps slowing your team down.

Defence against supply-chain attacks

The workflow pauses and waits for human approval – protecting you even if your CI/CD environment is compromised, or an insider goes rogue.

A complete audit trail

Every signature is logged automatically, with timestamps and approvals. Compliance reporting becomes trivial.

Simple API integration

3 straightforward endpoints
Plain REST + JSON
API-key authentication
GitHub Actions-ready

The workflow

CI/CD → HSM
1
CI/CD pipeline
Builds and packages your software (automated)
2
API: create a signing request
Your workflow calls the bitSign REST API (automated)
3
Human approval required
Trusted signers are notified by email and approve with 2FA
4
Secure signing
The HSM signs your software (automated)
5
Download the signed result
Your pipeline continues with signed software (automated)
bitSign approval on a phone
Workflow pauses here
signing session — bitSign CLI HSM · ONLINE

The same flow — whether you run it from your terminal, your CI/CD or straight against our API.

View the example on GitHub
07 — Security

We've thought of everything – so you don't have to

From implementation to physically protected keys, we cover the whole chain – so you can stay focused on your core business.

// DR kit Confidence when the unexpected happens — a physical DR kit for every key.

Proven security expertise

MAINLINE LINUX Accepted & Merged

nvmem: add new NXP QorIQ eFuse driver

Add SFP (Security Fuse Processor) read support for NXP QorIQ series SOC's

commit 0861110b View Details →

Contributing secure-boot support to the mainline Linux kernel – our expertise, proven in practice.

// Under the hood
PkOS
Our in-house OS for key generation & management.
bitFrost
A data diode for isolated internal transfers.
I'm fairly sure Alex still has a copy of the private key on a USB stick somewhere

A concern we hear from security officers all the time — bitSign eliminates it completely.

08 — FAQ

Frequently asked questions

09 — Plans

A plan to match your needs

// Base
4,900 SEK / month

A perfect fit for smaller companies that need secure signing without the complexity.

  • 3 users
  • 1 key
  • Approvals & traceability
  • Signing in a trusted environment
  • Complete audit log
  • Email support
Book a walkthrough
// Advanced
Custom

A tailored solution for organisations with specific requirements on hosting and isolation.

  • Tailored on-premise environment
  • Approvals
  • DR setup to your requirements
  • Customer-hosted / bespoke
  • Can run fully isolated from the internet
Book a walkthrough

Every plan includes HSM-backed key storage, approvals and signing in a trusted environment.

Annual contract · Prices excl. VAT

10 — Contact

Ready to secure your code signing?

We reply within 24 hours

Phone
+46 79 102 30 35
PGP Fingerprint
B1C7 05C6 B1BF 719C A5CD
6739 8BEE 8379 084B C511