Skip to Content

PROOF — Software Trust & Code Signing by ADDIE

Software Trust & Code Signing
The programme

Five Pieces. One Seal.

PROOF is ADDIE's programme for provably secure software: a release that can show who made it, that it is unchanged, and that it will stay trusted. Five pieces lock together to form that seal. Move over a piece to see what it adds.

Publisher verified

Before anything is signed, the organisation behind the software is verified: legal registration, business identifiers, domain and the identity of its representative.

Without

Anyone can claim to be you. Systems report an unknown publisher and leave the decision to the person installing.

With PROOF

Your organisation's name is shown on every release, backed by an independent verification.

How it works

Your File Never Leaves. Only Its Fingerprint Does.

The build computes a fingerprint of the release, a certified vault signs that fingerprint and returns the signature. Source code and binaries stay in your environment from start to finish.

signature returns · file never movesYour buildsource + binaries stay hereFingerprintonly a hash leavesSigning vaultFIPS 140-3 L3 · 24 h certsSigned releasesignature + timestampYour usersverified publisher shown
  • Your buildsource + binaries stay here
  • Fingerprintonly a hash leaves
  • Signing vaultFIPS 140-3 L3 · 24 h certs
  • Signed releasesignature + timestamp
  • Your usersverified publisher shown
1

Assess

We map what you ship, how you build it and what your organisation needs to qualify.

2

Verify

Your organisation's identity is verified. We prepare the application and steer it through review.

3

Integrate

Signing and timestamping are wired into your build pipeline with scoped access and a full log.

4

Release

You ship as before. Every build is signed automatically, every day, under your name.

Without it

Software Is Judged Before It Runs

Every download is a trust decision made in a fraction of a second, by the person, by their device and by their organisation's policies. Software that cannot show who made it and that it is unchanged loses that decision quietly.

Turned away at first contact

Systems flag software from an unknown publisher before it runs. Many people stop there, and every abandoned install is a lost user.

Left off the shortlist

Companies, schools, hospitals and public bodies allow only signed software on their devices. Unsigned products are set aside without a conversation.

Changed without a trace

A release can be altered anywhere between your build and the person using it. If something goes wrong, there is no way to show what you actually shipped.

With PROOF

The software carries a verified name, proof that it is unchanged, and a record of every release. The decision goes your way, and keeps going your way with every version.

Working together

PROOF for Your Software

PROOF covers four kinds of trust. Each engagement below is fixed in scope and agreed in a first call; every one includes training for the people who will run it afterwards.

Code

Applications, installers, scripts, containers and packages for every platform you ship to.

Documents

PDFs, reports, certificates and learning packages sealed under your organisation's identity, valid across the EU.

Media

Video, image and audio carrying Content Credentials that show who produced them and that they are unaltered.

Evidence

Software bills of materials, build provenance and signing records that regulators and enterprise buyers ask for.

Signing assessment

2 to 3 weeks

We inventory everything you sign or should sign, score your current practice and map the gaps against industry rules and the EU Cyber Resilience Act.

You receiveInventory, gap register, target architecture, 90-day plan

PROOF set-up

3 to 6 weeks

Your organisation is verified, signing is wired into your build pipeline and every release comes out signed and timestamped under your name.

You receiveVerified identity, pipeline templates, signing policies, signed reference releases

Policy and compliance pack

2 to 3 weeks

The written rules behind the signatures: who may sign what, how keys live and die, what happens in an incident, and how each control maps to the requirements you must meet.

You receiveSigning policy, roles matrix, incident runbook, control mapping

Managed signing operations

12-month retainer

We watch expiries and renewals, review every signing exception, onboard new pipelines and report monthly, so trust never lapses between releases.

You receiveMonthly signing report, renewal calendar, annual health check

Supply-chain hardening

2 to 4 weeks

Signed build provenance, software bills of materials and verification gates added to your existing pipeline, taking you to the level enterprise and public-sector buyers expect.

You receiveProvenance attestations, SBOM per release, verification policies

Document and media trust

3 to 5 weeks

Organisation seals for documents and Content Credentials for video and images, integrated into how you already publish, with a verification page your audience can use.

You receiveSealing pipeline, media signing step, public verification page

Who verifies the publisher?

An independent authority. In ADDIE's case it is Microsoft, whose signing infrastructure is also mandatory for the security-software industry. Verification covers the legal entity, its registration, its domain and the identity of its representative.


Do you sign software written by other organisations?

A signature is a publisher's statement of responsibility, so we sign what we build. For your products we set up your own verified identity and integrate it into your release process. Your name appears on your software.


What can be signed?

Code: executables, installers, libraries, scripts, user-mode drivers, add-ins, update packages and container images, for Windows, macOS, Linux, mobile and Java, each through the identity source its platform trusts. Documents: PDFs, reports and learning packages under an organisation seal. Media: video, image and audio with Content Credentials. Kernel-mode drivers follow a separate Microsoft programme and are out of scope.

Ship Software People Trust

Talk to us about signed delivery, publisher verification or regulatory readiness for your organisation.

Talk to an expert