Department of Information Technology
Code Signing Service
Secure Your Software with Confidence
The Library of Code, Inc. Signing Authority Team provides a trusted Code Signing Service through our Department of Information Technology. Our service ensures your software’s authenticity and integrity, giving your users the confidence to trust and install your application.
We’re providing this service as a resource to developers and IT professionals at a free or reduced cost (to be determined by the Signing Authority Team after application submission).
This service is currently in beta/interest stage. The system isn’t fully launched. We will determine if we will launch the service based on the interest received from applications. If we receive a substantial amount of applications for code signing, the Department of Information Technology will launch the service, otherwise without substantial interest the service will be cancelled and all outstanding applications will be rejected.
By leveraging our secure code signing certificate, your software is verified as tamper-free and authentic. This service is available to all eligible developers and organizations submitting requests in compliance with our Code Signing Service Agreement.
What Is Code Signing?
Code signing is a process that uses a digital certificate to confirm the authenticity and integrity of your software. It assures users that:
- The software is from a trusted developer or source.
- The software has not been altered or tampered with after being signed.
Code signing builds trust and protects your users from malicious or counterfeit software.
How It Works
Our process is simple, transparent, and secure:
- Submit a Request
Complete the online request form at the bottom of this page with your software details, documentation, and files. - Review & Approval
Our Signing Authority Team will:- Conduct a thorough review of your submission for compliance and integrity.
- Perform automated and manual checks to ensure the software is malware-free and aligns with your stated purpose.
- Code Signing
Once approved, we’ll sign your software using our secure digital certificate. - Delivery
Receive your signed application securely via email with a checksum for verification.
Important Things to Note
- You must agree to the Code Signing Service Agreement which is available at the bottom of this page
- For applications deemed high-risk by the Signing Authority Team, you may be asked to provide further verification. Please note, you may be asked to cover the cost of verifications. These verifications may consist of:
- Phone verification (The Signing Authority Team may request a phone number to text a code to or request verbal authorization of signing.)
- Email verification (The Signing Authority Team may request that you verify a code sent to the email address specified in the application.)
- ID Document verification (The Signing Authority Team may request that you verify your identity by providing an ID number or a photo of an ID that is issued by a governmental authority. These verifications will be handled by our partner, Stripe Identity.)
Eligibility Requirements and Policies
To use our Code Signing Service, you must:
- Be the rightful owner of the software or have the legal authority to submit it.
- Agree to our Code Signing Service Agreement.
- Ensure the software complies with all applicable laws and regulations.
- Provide clear and accurate details about the software’s purpose, functionality, and target platforms.
Attribution Requirement
As part of our service, signed software must include an attribution notice stating:
“This software has been digitally signed by Library of Code, Inc. to verify its authenticity and integrity, however it does not imply endorsement, functionality guarantees, or assurance of safety by Library of Code, Inc. Code signing ensures that the software has not been tampered after signing but does not guarantee functionality or safety. For more information, please visit https://loc.sh/code-signing.”
The notice must be included in:
- The software’s About or Credits section.
- The documentation or release notes.
- The download page or distribution platform where the software is available.
Important Policies
- Review and Approval: All submissions are subject to a rigorous review process. We reserve the right to reject any submission that violates our policies or is found to contain malicious, harmful, or illegal content.
- No Warranties: While we ensure the signing process is secure, we do not guarantee the functionality or safety of the software.
- Indemnification: Applicants are fully responsible for their software and agree to indemnify Library of Code, Inc. for any legal claims arising from its use.
How to Get Started
- Read the Code Signing Service Agreement.
- Complete the Code Signing Request Form at the bottom of this section or by following the link.
- Submit your software for review and approval.
Our team will review your request and notify you of approval or rejection within 48 business days.
Frequently Asked Questions (FAQ)
Q: Is the service free?
A: It depends. Our Code Signing Service is currently offered free of charge to eligible applicants, or at a reduced cost as determined by the Signing Authority Team.
Q: What platforms do you support?
A: We support a wide range of platforms, including:
- Windows (x86, x86-64, ARM32, ARM64)
- macOS (Intel x86-64, Apple Silicon ARM64)
- Linux (x86, x86-64, ARM32, ARM64, RISC-V)
- Android (ARMv7, ARMv8, x86, x86-64)
- iOS (ARM64)
Q: What happens if my request is rejected?
A: If your request is rejected, we’ll provide specific reasons and guidance for resubmission.
Q: Can I use the service for proprietary software?
A: Yes, you retain full ownership of your software. By submitting, you grant us a temporary license to sign your application.
Contact Us
Questions? Email the Department of Information Technology at it@libraryofcode.org.