Home / Solutions / Software Trust Solution

Software Trust Solution

From development and iteration to signing, packaging, security scanning and release, DigiCert Software Trust Manager offers a full-lifecycle security and compliance platform — cloud-based signing with secure key management, easily integrated into your existing DevOps toolchain.

  • Centralized signing & key control
  • 25B+ vulnerability-sample scanning
  • CI/CD automation
  • Automatic SBOM generation

Background

  • Centralized control: a platform that centralizes signing access control and unified policy.
  • Vulnerability scanning: over 25 billion vulnerability samples make software trust safer.
  • CI/CD automation: meets software supply-chain integrity frameworks and fits the SDLC.
  • SBOM: more scenarios require a Software Bill of Materials for security review.

Use cases

Cloud-based code signing with secure key management; easily integrated into your existing DevOps toolchain; automatic threat and vulnerability detection with full SBOM generation — securing and governing the whole path from development and signing to scanning and release.

Highlights

Unified management

Manage the whole software supply-chain lifecycle with visible, multi-role, multi-region, auditable security from build to release.

Threat detection

Powerful vulnerability scanning, online and on-premise, keeps the whole lifecycle free of security threats.

Built on DigiCert ONE

Onboard a mature software trust-chain system quickly, without worrying about key security.

Architecture

6Deliver signed filesProductionPublic trustPrivate trustApp StoreDevice firmwareAssembly lineOTA updateBuild serverCode repoCompileCICDDeveloperAccount adminManage assets,accounts, usersFilesFiles, Applications,Executables, Containers,Scripts, etc.Unsigned hashSigned hashDigiCert Signing Tool / 3rd-party Signing Tool / CI-CD integrationPKCS11KSPRESTSignTool / Jarsigner /ApkSigner / RL scan Tool1HTTPS, REST2Auth, check status & role3Unsigned hash5Get signed hash4Sign the hashSECURE SOFTWARE MANAGERon DigiCert ONEPrivate CAPublic CA (DigiCert)Private key storageThreat & vuln detectionAsset managementUser interface (UI)Command line (CLI)Revocation check OCSP / CRL

Where it applies

Full software lifecycle
Code signing
Key mgmt
Vuln scan
CI/CD
SBOM
Release
Solutions