PROOF — Software Trust & Code Signing by ADDIE
Five Pieces. One Seal.
PROOF is ADDIE's programme for provably secure software: a release that can show who made it, that it is unchanged, and that it will stay trusted. Five pieces lock together to form that seal. Move over a piece to see what it adds.
Publisher verified
Before anything is signed, the organisation behind the software is verified: legal registration, business identifiers, domain and the identity of its representative.
Anyone can claim to be you. Systems report an unknown publisher and leave the decision to the person installing.
Your organisation's name is shown on every release, backed by an independent verification.
Your File Never Leaves. Only Its Fingerprint Does.
The build computes a fingerprint of the release, a certified vault signs that fingerprint and returns the signature. Source code and binaries stay in your environment from start to finish.
- Your buildsource + binaries stay here
- Fingerprintonly a hash leaves
- Signing vaultFIPS 140-3 L3 · 24 h certs
- Signed releasesignature + timestamp
- Your usersverified publisher shown
Assess
We map what you ship, how you build it and what your organisation needs to qualify.
Verify
Your organisation's identity is verified. We prepare the application and steer it through review.
Integrate
Signing and timestamping are wired into your build pipeline with scoped access and a full log.
Release
You ship as before. Every build is signed automatically, every day, under your name.
Software Is Judged Before It Runs
Every download is a trust decision made in a fraction of a second, by the person, by their device and by their organisation's policies. Software that cannot show who made it and that it is unchanged loses that decision quietly.
Turned away at first contact
Systems flag software from an unknown publisher before it runs. Many people stop there, and every abandoned install is a lost user.
Left off the shortlist
Companies, schools, hospitals and public bodies allow only signed software on their devices. Unsigned products are set aside without a conversation.
Changed without a trace
A release can be altered anywhere between your build and the person using it. If something goes wrong, there is no way to show what you actually shipped.
With PROOF
The software carries a verified name, proof that it is unchanged, and a record of every release. The decision goes your way, and keeps going your way with every version.
PROOF for Your Software
PROOF covers four kinds of trust. Each engagement below is fixed in scope and agreed in a first call; every one includes training for the people who will run it afterwards.
Code
Applications, installers, scripts, containers and packages for every platform you ship to.
Documents
PDFs, reports, certificates and learning packages sealed under your organisation's identity, valid across the EU.
Media
Video, image and audio carrying Content Credentials that show who produced them and that they are unaltered.
Evidence
Software bills of materials, build provenance and signing records that regulators and enterprise buyers ask for.
Signing assessment
2 to 3 weeksWe inventory everything you sign or should sign, score your current practice and map the gaps against industry rules and the EU Cyber Resilience Act.
You receiveInventory, gap register, target architecture, 90-day plan
PROOF set-up
3 to 6 weeksYour organisation is verified, signing is wired into your build pipeline and every release comes out signed and timestamped under your name.
You receiveVerified identity, pipeline templates, signing policies, signed reference releases
Policy and compliance pack
2 to 3 weeksThe written rules behind the signatures: who may sign what, how keys live and die, what happens in an incident, and how each control maps to the requirements you must meet.
You receiveSigning policy, roles matrix, incident runbook, control mapping
Managed signing operations
12-month retainerWe watch expiries and renewals, review every signing exception, onboard new pipelines and report monthly, so trust never lapses between releases.
You receiveMonthly signing report, renewal calendar, annual health check
Supply-chain hardening
2 to 4 weeksSigned build provenance, software bills of materials and verification gates added to your existing pipeline, taking you to the level enterprise and public-sector buyers expect.
You receiveProvenance attestations, SBOM per release, verification policies
Document and media trust
3 to 5 weeksOrganisation seals for documents and Content Credentials for video and images, integrated into how you already publish, with a verification page your audience can use.
You receiveSealing pipeline, media signing step, public verification page
Who verifies the publisher?
An independent authority. In ADDIE's case it is Microsoft, whose signing infrastructure is also mandatory for the security-software industry. Verification covers the legal entity, its registration, its domain and the identity of its representative.
Do you sign software written by other organisations?
A signature is a publisher's statement of responsibility, so we sign what we build. For your products we set up your own verified identity and integrate it into your release process. Your name appears on your software.
What can be signed?
Code: executables, installers, libraries, scripts, user-mode drivers, add-ins, update packages and container images, for Windows, macOS, Linux, mobile and Java, each through the identity source its platform trusts. Documents: PDFs, reports and learning packages under an organisation seal. Media: video, image and audio with Content Credentials. Kernel-mode drivers follow a separate Microsoft programme and are out of scope.
Ship Software People Trust
Talk to us about signed delivery, publisher verification or regulatory readiness for your organisation.
Talk to an expert