-

AppViewX SIGN+ Bolsters Software Supply Chain Security by Ensuring the Authenticity and Integrity of Code

New code-signing solution integrates with CI/CD development pipelines to validate with speed, agility and flexibility that software is from a trusted source and has not been tampered with

NEW YORK--(BUSINESS WIRE)--AppViewX, the leader in automated machine identity management (MIM) and application infrastructure security, today launched AppViewX SIGN+, a flexible and secure code signing solution that enables DevOps teams to quickly and easily secure their software supply chain. With multiple deployment options, including code signing as a service, AppViewX SIGN+ seamlessly integrates into DevOps processes to enable frictionless code signing to validate the integrity of software applications and their components.

.@AppViewX SIGN+ bolsters software supply chain security by ensuring the authenticity and integrity of code with code-signing that integrates with CI/CD development pipelines to validate software is from a trusted source

Share

“The recent CA/Browser (CA/B) Forum requirements for code signing certificates and keys to be stored on secure hardware is in direct response to increasing threats targeting weak code signing processes and critical software supply chain vulnerabilities,” said Ravishankar Chamarajnagar, Chief Product Officer at AppViewX. “Code-signing certificates and keys have become high-value targets for attackers, as evidenced in the SolarWinds compromise. With AppViewX SIGN+, we are offering a fully compliant code signing solution that allows developers to easily sign code, maintain speed and agility, and prove the integrity, validity, and security of code throughout the software development lifecycle.”

Using a centralized and integrated approach, AppViewX SIGN+ simplifies and secures code signing for source code, binaries, containers, and firmware. AppViewX SIGN+ integrates with native signing tools, CI/CD pipelines and workflows to ensure all code is signed before deployment, and meets security and compliance requirements. It also provides full visibility and policy-driven control over private key storage, code-signing certificate management, and access.

AppViewX SIGN+ provides the following capabilities and benefits:

Secure and Protected Code Signing

  • Supports private and public code signing certificates for both internal and external use cases
  • CA/B Forum compliant private key protection – FIPS 140-2 (and higher) certified HSMs
  • Timestamping to support long term validation of signatures
  • Supports all standard asymmetric cryptographic algorithms, RSA, ECDSA, and DSA, and is Post-Quantum Cryptography ready

Seamless and Flexible Deployment and Integrations

  • Deployment options include on-premises and SaaS offerings for enterprise DevOps teams and outsourced development operations
  • Integration with native signing tools and CI/CD pipelines to integrate code signing in build processes
  • Option to upload and sign code in the AppViewX SIGN+ console

Code Signing Policy and Access Control

  • Centralized control of code signing certificates and private keys
  • Role based access control and policy controlled signing to ensure user permissions and authorization and key protection
  • Visibility into signing events including usage, signing and audit trails

“As a cloud-based HSM provider, Fortanix quickly enables DevOps teams to implement a solution that meets the CA/B Forum requirement for protecting their code signing private keys,” said Faiyaz Shahpurwala, Chief Product and Strategy Officer at Fortanix. “With our partnership with AppViewX, we can now jointly offer an end-to-end code signing solution that makes the process secure, seamless and controlled for distributed development teams of all sizes.”

With flexible deployment and integration options, AppViewX SIGN+ is available now and is part of the AppViewX Digital Trust Platform that includes AppViewX CERT+, AppViewX PKI+, and AppViewX KUBE+ for automating PKI and certificate lifecycle management across complex hybrid multi-cloud environments. To learn more and request a personalized demo, visit the AppViewX SIGN+ product page: https://www.appviewx.com/products/sign/.

About AppViewX
AppViewX is trusted by the world’s leading organizations to reduce risk, ensure compliance, and increase visibility through automated machine identity management and application infrastructure security and orchestration. The AppViewX platform provides complete certificate lifecycle management and PKI-as-a-Service using streamlined workflows to prevent outages, reduce security incidents and enable crypto-agility.

Fortune 1000 companies, including six of the top ten global commercial banks, five of the top ten global media companies, and five of the top ten managed healthcare providers rely on AppViewX to automate NetOps, SecOps, and DevOps. AppViewX is headquartered in New York with offices in the U.K., Australia and three development centers of excellence in India. For more information, visit https://www.appviewx.com and follow us on LinkedIn and Twitter.

Contacts

Editorial Contact:
Marc Gendron
Marc Gendron PR for AppViewX
marc@mgpr.net
617-877-7480

AppViewX


Release Summary
Using a centralized and integrated approach, AppViewX SIGN+ simplifies and secures code signing for source code, binaries, containers, and firmware.
Release Versions

Contacts

Editorial Contact:
Marc Gendron
Marc Gendron PR for AppViewX
marc@mgpr.net
617-877-7480

Social Media Profiles
More News From AppViewX

AppViewX Appoints Troy Dankworth as Channel Chief

NEW YORK--(BUSINESS WIRE)--Troy joins AppViewX from Keyfactor where he served as Vice President of Channels. He has held leadership roles at SolarWinds, Snow Software and NetApp...

AppViewX Expands Leadership Team to Fuel Innovation and Names Paul Trulove as Chief Product Officer

NEW YORK--(BUSINESS WIRE)--AppViewX, a leader in automated certificate lifecycle management (CLM) and public key infrastructure (PKI) software, today announced the appointment of Paul Trulove as Chief Product Officer (CPO). Paul will help define the company’s strategic product direction and lead the global product management organization. AppViewX also announced Madhu Venkatarajan as the company’s new Chief Technology Officer (CTO), and that Chris Bailey has joined as a new board member. These...

AppViewX Wins Five Global InfoSec Awards at RSAC Conference 2025

NEW YORK--(BUSINESS WIRE)--AppViewX is showcasing AVX ONE at RSAC Conference 2025 in booth N-4608....
Back to Newsroom