Signing keys
Every product signs with a private key and gives verifying applications the corresponding public key or certificate.
DYCRYPT protects private signing keys and keeps signing separate from everyday product and licence management. The Free plan supports Ed25519. Paid plans support Ed25519, RSA 2048/3072/4096, and EC P-256/P-384.
Certificate and key options include raw public keys, self-signed X.509 certificates, keystores, and supported PKCS#11 configurations. Enterprise on-premises deployments can include custom integration with your HSM or PKCS#11 hardware.
Rotating a product key does not change already delivered licences. Keep the prior public key available anywhere those licences still need to verify, and plan rotation as an application release rather than a transparent switch.