SignPath
SignPath GmbH is a Vienna-based software supply chain security company that provides policy-driven code signing and pipeline integrity verification through its SignPath DevSec360 Zero Trust platform, serving enterprises, development teams, and open source projects.
- Company typePrivate
- Founded2017
- HeadquartersVienna, Austria
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What SignPath does
SignPath GmbH is a Vienna-based, privately held cybersecurity company founded in 2017 that builds software supply chain security infrastructure centered on policy-driven code signing. Its flagship platform, SignPath DevSec360, is positioned as a Zero Trust Software Integrity Platform that combines pipeline integrity verification (provenance checks across repository, branch, commit, and build agent) with format-aware code signing (EXE, MSI, JAR, XML, nested artifacts, container images via Notary/Cosign). The platform enforces end-to-end policy gates from source to release and protects signing credentials through centralized key management with HSM/KMS support, including Thales DPoD Cloud HSM.
SignPath generates revenue primarily through SaaS subscriptions billed annually, with published tiers ranging from a Starter plan at $500/year through Basic Single at $1,000/year and Basic Team at $2,000/year, plus add-on projects and users. Enterprise contracts (undisclosed) anchor the customer base, evidenced by named reference customers Airbus, Hitachi Energy, and SolarWinds in aerospace, energy, and IT management respectively. The company also distributes a free open-source program through signpath.org (SignPath Foundation) and offers self-service free trials, creating a hybrid GTM that pairs developer-led adoption with direct enterprise sales.
The company became fully independent from founding parent RUBICON IT GmbH at the end of 2023, closed a €5 million Series A led by TIN Capital in January 2025, and is expanding from its DACH roots into the broader European and US markets. The management team, led by founder and CEO Stefan Wenig, was expanded at the start of 2024 with CSO Stephan Brack and CPO Paul Savoie to support international growth. EV certificates issued by GlobalSign are bundled into the subscription offering, and the platform integrates with major CI/CD systems (Jenkins, GitHub, GitLab, Azure DevOps, TeamCity, AppVeyor) plus identity, key management, and signing ecosystem partners.
SignPath firmographics
Firmographics- Name
- SignPath
- Legal name
- SignPath GmbH
- Website
- https://signpath.io
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SignPath GmbH is a Vienna-based software supply chain security company that provides policy-driven code signing and pipeline integrity verification through its SignPath DevSec360 Zero Trust platform, serving enterprises, development teams, and open source projects.
- Ownership category
- akta.pro rank
SignPath industry classification
Industry- Product category
- Software Supply Chain Security
- NAICS
- Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industry
- Access Management & Policy Enforcement (Zero Trust) (BPAMAEAH)
Keywords
Where SignPath is headquartered
LocationHeadquarters
- HQ city
- Vienna
- HQ country
- Austria
- HQ region
- Europe
Offices1 record
Markets served
SignPath business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Subscription - Code Signing Platform: SignPath generates revenue primarily through subscription-based SaaS pricing tiers (Starter at $500/year, Basic Single at $1000/year, Basic Team at $2000/year). Pricing is based on number of projects, users, and signing requests. Annual billing with optional multi-year contracts available.
- Extended Validation (EV) Certificates: EV certificates are provided by GlobalSign and can be issued in the name of a legally registered organization. Revenue generated from certificate issuance and management.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Starter - $500/year for 1 project, 20 release-signing requests, 100 test-signing requests |
| Subscription | Annual | Basic Single - $1000/year for 1 project, 50 release-signing requests, 250 test-signing requests |
| Subscription | Annual | Basic Team - $2000/year for 3 projects, 150 release-signing requests, 750 test-signing requests |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
SignPath product offering
Product offeringCore offering
SignPath sells a Zero Trust Software Integrity Platform (SignPath DevSec360) that enforces security and compliance policies at every stage of the software build pipeline and uses cryptographic signatures as the gatekeeper for releasing only trusted, policy-compliant software. The platform combines Pipeline Integrity (origin verification, CI/CD provenance, policy enforcement) with DeepSign (format-aware and nested artifact signing) and is delivered as a SaaS subscription with optional EV certificates from GlobalSign.
Product overview
SignPath is a software supply chain security platform offering a modular architecture centered on SignPath DevSec360 (Zero Trust Software Integrity Platform). DevSec360 encompasses two core integrated modules: Pipeline Integrity for verifying build pipeline steps and enforcing policies before signing, and DeepSign for format-aware code signing. Additional products include MacroSign for Office macro protection, Code Signing Gateway for cryptographic provider access, and a free Open Source tier. The platform supports multiple subscription tiers from Starter ($500/year) through Basic and Advanced levels, serving organizations from small development teams to large enterprises.
Differentiator
Problem solved
Functional benefit
Brands
- SignPath DevSec360: Zero Trust Software Integrity Platform that ensures every signed release is verifiably secure, policy-compliant, and fully auditable.
- SignPath Pipeline Integrity
- SignPath DeepSign
Products and services
- SignPath DevSec360 Zero Trust Software Integrity Platform that unifies pipeline security and code signing, ensuring every signed release is verifiably secure, policy-compliant, and fully auditable through end-to-end policy enforcement from source to release.
- SignPath Pipeline Integrity Verifies every step of the build pipeline before signing, including source and build provenance (repo, branch, build agent, configurations), policy enforcement for reviews/scans/approvals, protection against compromised pipelines, and a full audit trail of build and signing context.
- SignPath DeepSign Provides full control over what gets signed with format-aware signing for EXE, MSI, JAR, and XML, nested artifact support, built-in AV scanning, signature and metadata validation, and timestamping.
- SignPath MacroSign Office macro signing solution that enables policy-based code signing for Office macros to protect against macro malware.
- Code Signing Gateway Provides cryptographic provider access (KSP, CSP, PKCS#11, CryptoTokenKit, Notation, Cosign, GPG) for hash-based signing with external tools while maintaining HSM key security.
- SignPath Open Source Code Signing (DevSec360 Community) Free code signing and software integrity solution for open source projects, offered through the SignPath Foundation at signpath.org, providing certificates and signing policies for open source projects at no cost.
Quantifiable outcome
- 91% of organizations faced a software supply chain attack
Companies that use SignPath
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles3 records
SignPath technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration18 records
AI capability1 record
Feature9 records
SignPath partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core and strategic.
- RUBICON ITcoreSignPath was founded in 2017 as a subsidiary of RUBICON IT GmbH, a leading European software development company providing software and related services to the public sector and enterprise customers in Central and Western Europe. Stefan Wenig served as head of R&D at RUBICON IT before founding SignPath. SignPath became fully independent at end of 2023.
- GlobalSigncoreGlobalSign provides Extended Validation (EV) code signing certificates for SignPath's platform. EV certificates are issued in the name of legally registered organizations with stricter identity checks by the CA. GlobalSign code signing certificates are issued on secure hardware (USB token or HSM) and provide full reputation for Microsoft SmartScreen.
- ThalesstrategicThales DPoD Cloud HSM integration allows customers to use Thales Luna Network HSMs or cloud-based DPoD HSM instances for secure signing key storage. Status page shows DPoD integration incidents and maintenance windows.
- MicrosoftstrategicSignPath integrates with Microsoft Azure for hosting, Microsoft Authenticator/Okta for identity management, and supports Microsoft SmartScreen reputation for signed code. Platform supports Azure DevOps CI/CD integration and Windows artifact formats (EXE, MSI, MSIX).
- GitHubstrategicGitHub Actions integration with SignPath through submit-signing-request action. SignPath verifies origin from GitHub repositories and supports branch-based signing policies for GitHub projects.
- JenkinsstrategicNative Jenkins connector for pipeline integrity verification. Trusted Build System integration validates Jenkins build configurations and agent security.
- GitLabstrategicGitLab CI/CD integration with SignPath for automated code signing and origin verification in GitLab pipelines.
- Azure DevOpsstrategicNative Azure DevOps connector for CI/CD pipeline integration with SignPath signing workflows.
- OktastrategicSignPath uses Okta for identity provider and account management. Platform supports directory synchronization and identity management through Okta.
- Notary Project (CNCF)strategicSignPath supports Notary (Notation) for signing container images - the CNCF project recommended by Microsoft (AKS) and Amazon (EKS) for Kubernetes environments.
- SigstoreSignPath supports Sigstore Cosign for signing container images, enabling open source projects to use Cosign with HSM-protected keys through SignPath's PKCS#11 module.
Scale indicators3 records
Recent moves8 records
Expansion highlights6 records
SignPath competitors and assessment
Company assessmentDirect peers
- Venafi (CyberArk): Venafi is a direct competitor in machine identity management and code/certificate signing. Acquired by CyberArk in 2024, it offers code sign, key management, and TLS automation — overlapping with SignPath's enterprise pipeline-integrity and HSM-protected signing capabilities, targeting the same CISO/AppSec buyers.
- DigiCert: DigiCert is a leading certificate authority offering EV code signing certificates, Secure Software Manager, and key management. Directly competes with SignPath's signing and EV cert resale, and serves the same enterprise and software publisher base.
- Keyfactor: Keyfactor provides PKI, certificate lifecycle management, and code signing solutions (including EJBCA). Directly comparable to SignPath's centralized key management, HSM integration, and CI/CD-driven signing workflows for enterprise security teams.
- Sectigo: Sectigo is a certificate authority with EV code signing, IoT/PKI, and DevOps signing offerings. Competes with SignPath in the certificate plus signing-infrastructure layer and serves the same software publisher and enterprise customers.
Others
- GlobalSign: GlobalSign is both a strategic technology partner to SignPath (providing EV certificates) and a competitor, since it sells its own code signing certificates and Atlas platform for enterprise PKI — overlapping in cert issuance and signing workflows.
Emerging players
- Chainguard: Chainguard is an emerging software supply chain security company focused on hardened container images and Sigstore-based signing. Overlaps with SignPath's policy-driven signing and origin verification, especially in cloud-native and Kubernetes environments.
- Cycode: Cycode is an emerging player in software supply chain security, with ASPM and pipeline integrity features that overlap with SignPath DevSec360's end-to-end policy enforcement from source to release, targeting similar DevSecOps and AppSec buyers.
- Sigstore: Sigstore is a CNCF-hosted open-source project for software signing and verification (Cosign, Fulcio, Rekor). It is the primary free/open-source alternative to SignPath's signing layer and shapes industry standards; SignPath actively integrates with Cosign via PKCS#11.
Broad incumbents
- JFrog: JFrog is a broad incumbent in binary/repository management (Artifactory, Xray) with growing capabilities in software supply chain security and artifact signing. Larger, publicly listed scale; competes for the same DevOps/AppSec budget as SignPath.
- HashiCorp (IBM): HashiCorp Vault provides secrets management and HSM-backed key protection used for code signing workflows. As a broader infrastructure incumbent (now part of IBM), it competes for the adjacent key/secret management budget that SignPath's centralized key management addresses.
Market position
Weaknesses1 record
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
SignPath social profiles
Digital presenceSignPath compliance and trust
Trust signalCompliance2 records
SignPath financial estimates
Financial estimateRevenue estimate
Valuation estimate
SignPath leadership team
Management profileNumber of profiles
Profiles6 records
SignPath funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SignPath M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SignPath
What does SignPath do?
SignPath sells a Zero Trust Software Integrity Platform (SignPath DevSec360) that enforces security and compliance policies at every stage of the software build pipeline and uses cryptographic signatures as the gatekeeper for releasing only trusted, policy-compliant software. The platform combines Pipeline Integrity (origin verification, CI/CD provenance, policy enforcement) with DeepSign (format-aware and nested artifact signing) and is delivered as a SaaS subscription with optional EV certificates from GlobalSign.
Is SignPath a public or private company?
SignPath is a private company. It is classified as venture growth investor backed and is currently operating.
When was SignPath founded?
SignPath was founded in 2017. It employs 11 to 50 people.
Where is SignPath based?
SignPath is headquartered in Vienna, Austria, in the Europe region.
How does SignPath make money?
Two revenue lines are on record. SaaS Subscription - Code Signing Platform is the primary driver. The others are extended Validation (EV) Certificates.
Who are SignPath's main competitors?
Direct peers on record are Venafi (CyberArk), DigiCert, Keyfactor and Sectigo. GlobalSign is listed as an others. Emerging players are Chainguard, Cycode and Sigstore. Broad incumbents are JFrog and HashiCorp (IBM).
Does SignPath have an API?
Yes. SignPath provides a REST API for integrating code signing into build pipelines and automating signing requests. The API supports submitting signing requests, retrieving signed artifacts, and managing certificates. A PowerShell module is also available with cmdlets including Submit-SigningRequest, Get-SignedArtifact, and Get-CertificateByMicrosoftTemplateId for CI/CD automation. Developer documentation is at docs.signpath.io.
What industry is SignPath in?
SignPath's product category is Software Supply Chain Security. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of BPAMAEAH, Access Management & Policy Enforcement (Zero Trust). Its NAICS code is 513210 and its SIC code is 7372.