Online Code Signing
for Windows Apps
No certificate to buy. Upload your installer, we scan and sign it, and your users stop seeing the SmartScreen warning "Windows protected your PC". $45/quarter, cancel anytime.
How It Works
From upload to signed binary on the same day. No certificate to buy, no USB token mailed to you.
Upload your binary
Drop your .exe, .msi, or .dll in the dashboard. Or POST it from your CI pipeline.
Scan and verify
Before code signing, scan your application binaries for packers, suspicious imports, and false-positive triggers.
Static analysis + malware checksDownload signed file
Authenticode-signed binary delivered to the dashboard and the API. No SmartScreen warnings for your users.
Authenticode SHA-256, EV certificateFeatures
Everything you need to go from build to trusted download.
App Scanning
Upload and scan your app for harmful components, privacy issues, and performance risks before it’s made public.
Custom Setups
Portable apps can be automatically bundled in an installer, giving you full control of installer settings.
App Certification
Apps running clean and safe code can become certified, allowing for frictionless deployment across client systems.
Deployment Hosting
If you don't have anywhere to publish your apps, let us host them for you with up to 1GB of storage space.
CLI, CI, and electron-builder
Sign from any build pipeline: npx github:bamboodeploy/cli sign app.exe, a GitHub Action step, or an electron-builder hook. Docs.
Sign from your CI pipeline
One CLI command, one GitHub Action step, or an electron-builder hook. Same REST API the dashboard uses, with API keys you can revoke. Read the developer docs for GitLab, Azure Pipelines, CMake, Tauri, PyInstaller, Inno Setup, and .NET.
Built for indie developers shipping Windows apps
What developers say after switching from traditional code-signing certificates.
"I was about to drop $560 on an EV cert and a USB token. Bamboo Deploy signed my installer the same afternoon and saved me the renewal headache. Worth every cent."
"Plugged the API into our GitHub release workflow and SmartScreen warnings stopped showing up on download. Our support email volume dropped overnight."
"PyInstaller exe used to get flagged as malware on half my users' machines. After signing through Bamboo Deploy, the false positives basically disappeared."
Pricing
Publishing a Windows app shouldn't require expensive certificates, weeks of verification, or a registered business. One simple plan, everything included.
Premium
Billed $45 every 3 months. Cancel anytime.
Everything you need to deploy your Windows app with confidence. No annual contracts. No business verification required.
- Deep Security Scanning & Analysis
- App Certification & Signing
- 1GB Cloud Hosting
- Custom Installer Bundling
- Up to 50 Apps
- GitHub Actions Integration
Have a question? Check out the FAQ
Here are some common questions about publishing, safety checks, and hosting your app with us.
What is Bamboo Deploy?
Bamboo Deploy is a cloud code signing service for Windows app developers. Upload your .exe, .msi, or .dll, and we scan, certify, and sign it so your users get a clean, trusted download. No certificate to buy, no USB token, no business verification, no annual contracts. Plans start at $45 per quarter (that works out to $15 per month) with same-day signing and a 30-day money-back guarantee.
Which Windows file types and languages does Bamboo Deploy support?
We code sign Windows executables, installers, and libraries: .exe, .msi, and .dll files, both 32-bit and 64-bit, plus MSIX and APPX packages. Apps built with any Windows-compatible compiler are supported, including PyInstaller, Electron, Tauri, .NET (C#, Visual Basic .NET, VB6), C++, Rust, Go, Delphi, Java (jpackage), Inno Setup, and NSIS.
Will signed apps still trigger SmartScreen, "Windows protected your PC", or Windows Defender warnings?
Apps signed through Bamboo Deploy carry a valid Authenticode SHA-256 signature from our Sectigo Extended Validation (EV) certificate, so Windows shows a verified publisher instead of "Unknown publisher", and most Windows Defender false-positive flags clear for your signed binaries. Microsoft no longer gives any certificate type instant SmartScreen reputation (EV lost that in 2024), so reputation now comes from a certificate's signing history. Ours has signed hundreds of clean builds, which a new certificate of your own would have to earn from zero. A brand new file can still see an occasional prompt until it has some downloads.
Do I need a USB token, HSM, or any signing hardware?
No, you don't need any signing hardware on your end. You upload your binary, our service signs it, and you download the signed file. No USB tokens to plug in, no signing software to install on your machine, no expensive hardware to rent.
How is Bamboo Deploy different from buying a certificate from a traditional Certificate Authority?
Traditional certificate authorities like DigiCert, Sectigo, and SSL.com sell yearly code signing certificates. Standard OV certificates typically cost several hundred dollars per year, while EV certificates can run a thousand dollars or more annually, plus they require business identity verification and ship a physical USB token to your address. Bamboo Deploy is a $45 per quarter subscription (that works out to $15 per month) with EV-grade code signing included, no certificate purchase, no identity validation paperwork, no shipped token, no minimum contract, and a 30-day money-back guarantee. Cancel anytime.
Can I sign apps from GitHub Actions or another CI pipeline?
Yes. Bamboo Deploy exposes a REST API at api.bamboodeploy.com. Generate an API key from the dashboard and call it from GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure Pipelines, or any tool that can make HTTP requests. A few API calls return a fully signed Authenticode binary as a CI artifact, ready to ship with your release.
My PyInstaller, Electron, NSIS, or Inno Setup app gets flagged as a virus. Will code signing fix that?
In most cases, yes. Bundlers and installers like PyInstaller, Electron, Tauri, NSIS, Inno Setup, AutoIt, and py2exe package an interpreter or runtime alongside your code, and antivirus engines often flag the unsigned executable as suspicious because of the packing pattern, not because of malicious code. A valid Authenticode signature signals to Windows Defender, SmartScreen, and third-party antivirus that the binary comes from a verified, EV-validated publisher, which clears most false positives. Avoiding generic compression packers before signing further reduces flags.
If I have a portable app, can I convert it to a Windows installer?
Yes. Most portable apps can be bundled into a Windows installer (.msi or signed .exe setup file) for a cleaner user install experience. You can add multiple files, configure installer settings such as icon, app name, default install directory, wizard image, and more. The resulting installer is then code signed like any other binary.
What does Bamboo Deploy's security scan check for?
Every uploaded binary runs through a multi-stage security analysis before signing. We check the file structure, scan for known malware indicators, look for risky behavioral signals, and detect signs of obfuscation or packing. We also surface the Authenticode status of any pre-existing signature. The full scan report is visible in your dashboard for each upload.
What happens if my app fails the security scan?
A flagged scan does not auto-reject your app. The scan report appears in your dashboard with the specific indicators that triggered the flag, so you can see exactly what the scanner saw. False positives are common for bundled apps built with PyInstaller, Electron, Tauri, Inno Setup, or NSIS, since the packing pattern looks unusual to generic security tools. If you believe your app was flagged in error, contact support and we will review it. Apps that match high-confidence malicious indicators will not be signed.
How fast is the signing process?
Most apps are signed within minutes of upload. The security scan runs first, typically completing in under a minute, then the file is signed and made available for download or via the REST API.
What happens to my signed apps if I cancel my subscription?
All apps you signed during your active subscription stay signed and continue to work for your users. If you cancel, you simply lose the ability to sign new apps or new versions until you resubscribe. Apps already in your users' hands keep running normally.
Is there a free trial or money-back guarantee?
Bamboo Deploy comes with a 30-day money-back guarantee. Sign up, sign as many apps as you want during the first 30 days, and if it is not the right fit, contact support for a full refund.
Contact
Complete the contact form below, and we’ll be happy to assist you.