SignPath is a Vienna-based software supply chain security and code signing vendor founded in 2017 by RUBICON IT and spun out as an independent company in 2023. Operating with a subscription and on-premises licensing model and a primary focus on EMEA (while expanding into North America), it targets organizations seeking verifiable software integrity throughout development and delivery—especially in regulated or high-risk environments where compliance and operational trust are critical.
The market context is shaped by a sharp rise in sophisticated software supply chain attacks, pushing organizations toward end-to-end visibility and integrity controls across source code, open-source dependencies, build tools, and deployment pipelines. Within this environment, SignPath positions itself around a Zero Trust model for software releases, emphasizing provenance and process integrity rather than vulnerability detection.
Its approach combines DeepSign (a code signing engine) with Pipeline Integrity (a build-condition verification system) to ensure releases are only signed when predefined criteria are met. Unlike conventional code signing that occurs at the end of the lifecycle, SignPath applies controls throughout the build process and validates metadata such as build agent identity, repository integrity, and branch protection settings. The DevSec360 platform supports synchronous and asynchronous workflows, integrates with CI/CD tools like Jenkins, GitHub, Azure DevOps, TeamCity, AppVeyor, and GitLab, and can incorporate external testing results into signing policies. DeepSign supports full-package and nested artifact signing, re-signing without rebuilds, crypto agility, reproducible builds, malware scanning, certificate management, and automated policy enforcement—aiming to reduce scripting effort and improve auditability.
Strengths include DevOps-first design, cloud/on-prem adaptability, momentum in Europe amid software sovereignty concerns, and a combined pipeline verification and signing solution. Key challenges are limited brand recognition outside Europe, a smaller team versus large competitors, growth-related execution risk, and the need to educate the market on a newer category beyond traditional code signing or AppSec.
See All Locations
See All Locations