Artifact Signing

Only approved code ever runs in production

Artifact Signing cryptographically signs every build artifact in your CI pipeline and verifies it at deployment, so unsigned or tampered code can't run — and every running artifact traces back to its source commit, build pipeline, and SBOM in minutes.
Flowchart titled 'Sign in CI, verify at deploy' showing a pipeline process: 'CI pipeline' builds artifact, then 'Sign' with ephemeral cert, then 'Registry' stores artifact. From Registry, flow moves to 'Verify' for admission control. If verification fails, it goes to 'Blocked' for unsigned or tampered code; if successful, it proceeds to 'Production' allowing only approved code.
Loved by security teams, painless for developers at:

How Artifact Signing works

Make sure only approved code ever runs in production
A hash confirms an artifact wasn't altered in transit, but not that it came from a trusted pipeline. Artifact Signing verifies every artifact at deployment through admission control, so unsigned or tampered builds — including shadow deployments no one approved — are blocked or terminated.
Trace any production artifact back to its source in minutes, not days
After a CNAPP or SOC alert, responders can burn days working out which pipeline produced an affected container. Signatures carry provenance that links every running artifact to its source commit, build pipeline, and owning team, so incident scoping drops to minutes.
Prove build integrity to auditors without new infrastructure
Signatures connect each deployed artifact to its verified SBOM and VEX, so compliance requests get the right data the first time. Everything stays private to your tenant and runs on your existing SSO — no public transparency log and no new PKI to operate.
Diagram showing how sign and verify works. Left side (IN CI - SIGN) shows four steps: SSO identity with keyless auth, ephemeral cert single-use from trusted CA, sign the artifact with digest and provenance, and tamper-resistant log stored in your tenant. Right side (AT DEPLOY - VERIFY) shows admission controller checks verifying signed by trusted CA, signature valid (cert and time window), provenance claims hold, and not revoked or blocklisted. If all checks pass, deployment is allowed; if any check fails, deployment is blocked or terminated. Run-time checks catch deployments bypassing admission control.
Sign and verify
Cryptographically sign every container image, binary, or build artifact in CI, then verify it at deployment before anything runs.
Sign each artifact with a single-use ephemeral certificate issued by a trusted CA — no new PKI to manage.
Verify signatures at deployment via Kubernetes admission control, blocking or terminating artifacts that fail.
Catch deployments that bypass admission control with run-time operational checks.
Learn more
Bi-directional traceability
Provenance metadata links every artifact from source commit to deployed copy — and back again — for rapid incident response.
Trace a CNAPP or SOC alert back to the source commit, build pipeline, and owning team in minutes instead of days.
Hunt a newly disclosed vulnerability across production using the signature, not a manual cross-reference of container tags.
Connect every signed artifact to its verified SBOM and VEX so compliance responses use the right data the first time.
Learn more
Diagram illustrating bi-directional traceability between commit and deployed copy with vertical steps: Source commit, Build pipeline, Signed artifact, and Deployed copy. To the right is a software artifact summary panel for jscott932/app-java-demo showing artifact digest with signature, certificate identity, build configuration with container signing test running on github-hosted environment, and source repository details pointing to refs/heads/main.
Diagram showing a keyless authentication process between a Cert OIDC issuer and Your Endor Labs tenant with a private signature log labeled 'Signatures and provenance stay yours'.
Private and drop-in
Built on the same principles as Sigstore, but kept private to your tenant and simple enough to adopt with a few lines of pipeline config.
Keep all signature and verification data private to your tenant — no public transparency log exposing provenance metadata.
Authenticate keylessly with existing SSO identities like Okta, Azure AD, and Google Workspace — no new identity system.
Start signing with a few lines of config in GitHub Actions or endorctl — no new infrastructure or key management.
Learn more
Flowchart showing integration paths from GitHub, GitLab, and PHP to Slack and Microsoft platforms, with a C# icon connected to Slack.

Your Tools, Your Languages
— All Secured

Learn how Endor Labs fits into your ecosystem.
Flow diagram connecting software development tools and platforms including .NET, JetBrains, GitHub, Google, and Vercel.

FAQs

How is this different from just checking a hash?

A hash confirms an artifact wasn't altered in transit, but not that it came from a trusted build pipeline. Artifact Signing verifies both the integrity and the origin of every artifact, so only code produced by an approved pipeline can run.

Why not just use Sigstore?

Endor Labs' signing is built on many of the same principles as Sigstore, but keeps everything private to your tenant. There's no public transparency log exposing provenance metadata, and no separate PKI or identity system to deploy and manage.

What can I sign?

Container images, application binaries, configuration files including infrastructure as code, media assets — any artifact you're willing to sign and verify.

How does verification block bad deployments?

At launch, your admission controller calls Endor Labs to confirm the artifact is signed by a trusted CA, the signature is valid, the provenance claims hold, and the version hasn't been revoked or blocklisted. Run-time checks can terminate and report unsigned or invalid artifacts.

Do we need new key infrastructure?

No. endorctl establishes identity through secretless authentication in your AWS, GCP, or GitHub Actions runners — optionally backed by your SSO — and generates single-use ephemeral certificates. A few lines of pipeline config is all it takes to start.

How does signing speed up incident response?

Signature metadata links each artifact to its package, SBOM, VEX, and source git ref. Code-to-cloud tracing finds where a vulnerable version runs, and cloud-to-code tracing identifies an artifact's owner and build — turning a research task that took hours or days into minutes.

Code without compromise