Fortanix and Sectigo Partnership Helps Enterprises Uplevel Software Supply Chain Security

Collaboration Automates the Issuance of Code Signing Certificates, Enabling Enterprises to Accelerate, Scale and Secure Rapid Development Processe
SANTA CLARA, Calif., October 21, 2024

Fortanix, Inc., a leader in data-first cybersecurity and pioneer of Confidential Computing, today announced a new partnership with Sectigo, a global leader in certificate lifecycle management (CLM) and WebPKI solutions, enabling enterprises to secure their software supply chain by automating the issuance of code-signing certificates. The partnership gives enterprises a fast, scalable solution to automate and control their urgent and ballooning need to create, track, and attest private key security without slowing down developer workflows.

Businesses rely on securing their CI/CD pipelines with public key infrastructure (PKI) and certificates to certify the integrity and origin at each stage of development -- code signing. This process is necessary to ensure a high level of security, but its time-consuming nature often disrupts developer workflows and stifles innovation. The Fortanix and Sectigo partnership addresses this by enabling enterprises to automate and scale the security of their digital supply chains with purpose-built platforms that meet modern business needs.

Specifically, Sectigo now accepts Fortanix key provenance attestations with a code signing request (CSR), proving that private keys are created and stored in a hardware security module (HSM), a requirement from the Certificate Authority/Browser Forum as of 2023.

“Fortanix, like Sectigo, has built its services for automation, which is the only way for enterprises to truly scale and secure their CI/CD pipelines,” said Anand Kashyap, CEO and co-founder of Fortanix. “Security and speed are two elements that help separate dev teams from the competition, and this partnership delivers both.”

“We're thrilled to work with Fortanix and help modern enterprises scale their secure code signing and bring operations to the next level,” said Nick France, chief technology officer at Sectigo. “Enabling the Sectigo Certificate Manager to cryptographically verify that joint customers use a FIPS-validated hardware security module for their private keys is a game-changer that impacts the entire software development lifecycle.”

Benefits of this new partnership include:

    • Verifiable trust. Certificates issued by an authority such as Sectigo can be validated through digital signatures, which can only be trusted if the associated private key is deemed to be stored as securely as possible.
    • Enhanced peace of mind. Meets CA/Browser Forum mandates that certificate requestors generate, store and use private keys with a FIPS 140-2 Level 3 validated HSM, which must be able to cryptographically attest that the private key indeed is hosted on such secure hardware.
    • A purpose-built platform. The Fortanix unified data security platform was built from the ground up to secure and manage enterprises’ most valuable secrets with Confidential Computing technology. Adding Sectigo Certificate Manager platform capabilities automates the attestation verification and certificate issuance process.

For more information on the Fortanix-Sectigo partnership, visit https://www.fortanix.com/partners.

About Fortanix

Fortanix is a global leader in data security. Our unified platform, powered by Confidential Computing, future-proofs your data security and makes it simple for organizations to discover, assess, and remediate cybersecurity risks. Our post-quantum-ready cryptographic solutions help organizations thwart cloud and AI data exposure threats and enable secure innovation. Trusted by leading brands and government agencies, Fortanix empowers enterprises to secure their most sensitive data at rest, in motion, and in use and remain compliant with regulations worldwide. For more information, visit www.fortanix.com.

Contact
BOCA Communications for Fortanix
Fortanix@bocacommunications.com

Fortanix and Runtime Encryption are registered trademarks of Fortanix, Inc. Fortanix Data Security Manager is a trademark of Fortanix, Inc. All other marks and names mentioned herein may be trademarks of their respective companies.
FIPS 140-1 and FIPS 140-2 TM: A Certification Mark of NIST, which does not imply product endorsement by NIST, the U.S. or Canadian Governments

Share this post:
Fortanix-logo

4.6

star-ratingsgartner-logo

As of August 2023

SOC-2 Type-2ISO 27001FIPSGartner LogoPCI DSS Compliant

US

Europe

India

Singapore

US:

3910 Freedom Circle, Suite 104,
Santa Clara CA 95054

+1 408-214 - 4760|info@fortanix.com

Europe:

High Tech Campus 5,
5656 AE Eindhoven, The Netherlands

+31850608282

India:

UrbanVault 460,First Floor,C S TOWERS,17th Cross Rd, 4th Sector,HSR Layout, Bengaluru,Karnataka 560102

+91 080-41749241

Singapore:

T30 Cecil St. #19-08 Prudential Tower,Singapore 049712