Skip to content
Y2· Roadmap

Signing & Custody

Signatures that verify in 2045.

Quantum-safe firmware and supply-chain signing using stateful hash-based signatures (LMS/XMSS) plus ML-DSA, for assets with 15–25 year lifetimes where the signature must still verify long after RSA is broken.

Built for

Firmware leadPlatform leadSecurity Architect

Overview

A closer look at Sign.

Quantum-safe firmware and supply-chain signing using stateful hash-based signatures (LMS/XMSS) plus ML-DSA, for assets with 15–25 year lifetimes where the signature must still verify long after RSA is broken.

Dhiti Sign lives in the Signing & Custody of the platform, whose job is simple: signatures that still verify in 2045. It ships as part of Dhiti Secure, software platform, the saas that funds the company, so it carries the same sovereignty posture as everything else Dhiti runs: region pinning, keys that stay inside the HSM, and an air gapped deployment for estates that need it.

Nothing here works in isolation. Every product on the platform reads and writes to one shared cryptographic asset graph, so what Sign produces becomes usable everywhere else: a finding here becomes a prioritised task there, and a change becomes a line of audit evidence a regulator will accept. You can adopt Sign on its own, fold it into an edition, or grow into it as your estate matures. It is built to sit above the tools you already bought rather than replace them.

At a glance

Plane
Signing & Custody
Line
Dhiti Secure
Status
Y2· Roadmap
Capabilities
3
Pricing
Connect for pricing

Why it matters

The problem it solves.

Most teams cannot answer a basic question about their own cryptography: where is it, what algorithms are in use, and what breaks when one of them is deprecated. That gap is not a tooling failure so much as an ownership failure. The SIEM, the EDR, the scanner and the GRC spreadsheet each see a slice, and none of them owns the cryptographic picture.

Sign closes its part of that gap in a way you can measure. Instead of a point in time report that is stale the day it ships, you get a living view that updates as your estate changes, ranked by real risk rather than raw volume, and expressed in the language your auditors and your board already use.

Capabilities

What Sign does.

Stateful hash signatures

LMS/XMSS plus ML-DSA, with state management (the hard part).

HSM-backed signing

Signing service backed by hardware.

Transparency log

Attestation logged for long-lived verification.

Strengths

Why teams choose Sign.

Stateful hash signatures

LMS/XMSS plus ML-DSA, with state management (the hard part).

HSM-backed signing

Signing service backed by hardware.

Runs on what you already own

It operates inside your existing Splunk, Sentinel, QRadar, CrowdStrike, cloud and CI/CD rather than asking you to rip anything out. Adoption is additive, not a migration in itself.

Sovereign by architecture

Data is region pinned to Mumbai, Singapore or Frankfurt at the schema level, keys are handled by reference and never leave the HSM, and a dedicated air gapped edition exists for critical infrastructure.

Honest about what ships

Every capability carries a status token. Nothing is dressed up as available today when it is on the roadmap, which is exactly what a compliance buyer needs to hear.

Priced to the Indian enterprise

The cost structure is built for regulated Indian buyers first, and pricing is quoted against your actual estate rather than a Western enterprise list price.

How it works

Four steps, one asset graph.

01

Connect

Sign wires into your sources, clouds and tools through the Dhiti connector fabric, read only wherever it can be, so it starts from the estate you actually run.

02

See

Stateful hash signatures: LMS/XMSS plus ML-DSA, with state management (the hard part). Everything it finds flows into the shared cryptographic asset graph.

03

Act

HSM-backed signing: Signing service backed by hardware. Work is ranked by blast radius and confidentiality lifetime, not by raw count.

04

Prove

Posture rolls up to Dhiti Command and evidence to Dhiti Comply, region pinned and audit ready, so the work you do is the work you can show a regulator.

What we measure

We don't invent metrics. This product is measured by the outcomes customers track, exposure reduced, evidence produced, migration rate. Ask us for the current baseline.

Frequently asked

Questions a buyer actually asks.

Does Sign replace the tools we already have?
No. It runs alongside your existing security stack and adds the cryptographic layer none of those tools cover. You keep your SIEM, EDR and scanners; Sign makes them part of one picture.
Where does our data live, and who can see the keys?
Data is pinned to your chosen region at the schema level, tenants are isolated row by row, and keys are handled by reference so they never leave the HSM. For government, defence and critical infrastructure there is an air gapped Sovereign deployment.
Is Sign available today?
Sign carries the status token Y2, which means it is on the roadmap rather than generally available today. We will always tell you plainly where a capability sits before you plan around it.
What does it work with?
It compounds with Vault, Orchestrate, Attest and the rest of the suite through the shared asset graph. Discover finds it, Orchestrate fixes it, Comply proves it.
How is it priced?
Pricing is quoted per estate rather than published as a list price. Tell us your sector and scale and we will put a number to it. Every edition includes cryptographic discovery, so even at the entry tier you leave with a CBOM.

Related reading

Every capability carries a status token. Anything not shipping today renders as Roadmap, we never imply a roadmap item ships now.

Get started

See Dhiti Sign on your estate.