24/7 Validation Support · Certificates issued in minutes
0
DEVSECOPS & SUPPLY CHAIN SECURITY

DigiCert Software Trust Manager

Build trust into every line of code. Securing your software supply chain is no longer optional. DigiCert Software Trust Manager is a next-generation code signing solution that protects signing keys, automates security policies, and empowers teams to release software with confidence.

CENTRALIZED CLOUD HSM KEY STORAGE

Private signing keys are stored in secure, FIPS 140-2 Level 2 cloud HSMs. Developers and CI/CD pipelines sign code without ever having physical access to raw cryptographic keys.

AUTOMATED SBOM & THREAT DETECTION

Automatically generate Software Bill of Materials (SBOM) and scan binaries for vulnerabilities, malware, and exposed secrets before code release.

SUPPLY CHAIN LIFECYCLE

Built to Secure Every Step of Your Software Lifecycle

Five integrated steps protecting code from source commit to production release:

FAQ

Frequently Asked Questions

Common questions about features, integration, and security assurance.

As of June 2023, the CA/Browser Forum mandates that private keys for all code signing certificates (OV and EV) must be stored on FIPS 140-2 Level 2 or Common Criteria EAL 4+ hardware. Cloud HSMs meet this requirement without physical USB token logistics.
It inspects binary artifacts at the time of signing to automatically catalogue open-source libraries, package dependencies, and license metadata, outputting standard SPDX or CycloneDX formats.
No. Software Trust Manager provides high-performance API signing and CLI wrappers designed for sub-second signing operations in high-throughput build environments.
0