Key security

Protect the key that makes every licence trustworthy.

Your application receives only a public key. DYCRYPT protects the private signing key and uses modern algorithms and certificate options to produce licences your application can verify.

PUB

Public-key verification

Your SDK ships with the public half, which can verify licences but cannot create one.

ALG

Modern algorithms

Paid plans support Ed25519, RSA 2048/3072/4096, and EC P-256/P-384 signing.

CRT

Flexible key formats

Use a raw public key, a self-signed X.509 certificate, a keystore, or supported PKCS#11 hardware.

ISO

Protected signing boundary

Signing is isolated from everyday product and licence management so private key material stays inside the protected signing path.

IAM

Controlled access

Use passkeys, team roles, and scoped API tokens to limit who can manage products and issue licences.

SDK

Fail-closed SDKs

Unsupported formats, wrong products, bad signatures, and machine mismatches return an invalid result instead of being guessed at.

Enterprise on-premises

Bring DYCRYPT into your security perimeter.

Run the platform in your own environment when policy, residency, or integration requirements make SaaS unsuitable.

Hardware-backed signing

Enterprise deployments can include custom integration with your HSM or PKCS#11 hardware. The private key can remain on the device while DYCRYPT requests signatures through the protected signing boundary.

Discuss an on-premises deployment →

Choose your deployment

Start in SaaS. Move on-premises when your requirements call for it.

Your application integration remains centred on the same signed licences and SDK behavior.