# bitSign > bitSign (https://bitsign.se) is a code signing service for firmware and > embedded systems, operated by bit42 AB in Sweden. Companies sign their > software releases through bitSign instead of building and operating their > own HSM/PKI signing infrastructure. ## What it does - Signing of firmware and software artifacts as a service: upload or request, approve, sign inside an HSM, download the signed artifact. - Private keys are generated and kept in Hardware Security Modules (HSM) and can never be exported. - Multi-party approval (attestation / four-eyes) before anything is signed, with 2FA. - Complete, auditable logging of every signing operation - supports ISO 27001 and IEC 62443 compliance work. - Disaster Recovery Kit for every key. Two key-ownership models: "zero-copy" (an HSM only the customer owns) or "cold escrow" (default; an offline copy in a separate secure facility). - Integrations / supported flows: RAUC, Yocto, U-Boot, Barebox, Android (APK/OTA), PGP-based signing, secure boot chains. Custom flows on request. - CLI and web portal; onboarding typically takes days, not months. ## Who it is for Product companies in Sweden and the EU that ship firmware or embedded software - from small teams to large industrial vendors - and need secure, traceable code signing without operating their own HSMs. ## Pricing (SEK, 2026) - Bas: 4 900 kr/month - for smaller companies, essential signing. - Standard: 9 900 kr/month - recommended; regular signing, higher security demands. - Advanced: custom quote - special operational or isolation requirements. ## Pages - Swedish: https://bitsign.se/ - English: https://bitsign.se/en/ ## Contact - Email: info@bitsign.se - Phone: +46 79 102 30 35 - Operator: bit42 AB (https://bit42.se)