SignetKeys

Your signing key should never touch your CI.

Hardware custody for Apple code signing. Your Developer ID key is born inside a dedicated hardware token in our signing vault — yours alone, PIN‑locked, and it has never existed as a file.

Check my installer for free No account. Upload a .pkg, get the diagnosis.
Today
base64 developer_id.p12
→ MACOS_CERTIFICATE secret
→ temp keychain on runner
→ codesign

A readable string inside your build. Exfiltration is one line in a workflow file.
With SignetKeys
OIDC token from your CI
→ policy: repo, ref, workflow
→ key sealed in hardware
→ signed artifact returns

Zero secrets in your pipeline. Nothing to steal, nothing to rotate, nothing to leak.
Signature with RFC 3161 timestamp
Apple notarization ticket, stapled
AU, VST3, standalone, and pkg
Hash-chained log tied to your commit
Hardware attestation: proof your key was born on-device
Signed within 2 hours — jobs queue, never fail your release

Solo

$39/mo
  • 1 signing identity in hardware custody
  • 200 signed builds / month
  • Notarization, stapling & evidence chain

Subscribe →

Label

$349/mo
  • 5 signing identities, 15 team seats
  • 5,000 signed builds / month
  • Evidence chain export

Subscribe →

Prices exclude tax/VAT, calculated at checkout by Paddle, our merchant of record. Cancel any time — your evidence chain and signing history stay readable.