Dozens of IPA signing services compete on the surface. They mostly look the same: list two packages, take payment, deliver an install link. The real differences are operational — and they only matter once a certificate gets revoked or an install fails. Here's the honest 7-point checklist for picking a service that won't burn you.

1. Certificate freshness and rotation

A signing service is only as good as the certificate behind it. Older certificates accumulate Apple scrutiny — the more public installs Apple sees from a cert, the higher the revoke probability. Quality services rotate Enterprise certificates frequently (often monthly) and limit how many simultaneous installs come from any single cert.

What to ask: "When was your current Enterprise certificate issued?" or "Do you rotate certs?" Vague answers are a red flag.

2. Re-sign policy after revoke

Revokes happen. The question is what happens to your install when it does. Good services automatically re-sign within hours and notify customers; bad ones ghost you or demand additional payment.

What to ask: "If the certificate gets revoked, is the re-sign free?" Yes is the only good answer.

3. Turnaround time

Signing is technically fast — minutes — but services often introduce manual review or bottleneck steps that add hours. Real-world turnaround should be 5-30 minutes for Enterprise, slightly longer for Developer (because UDID registration is involved).

What to look for: Stated turnaround time on the homepage. "1-24 hours" usually means closer to 24.

4. Payment security and refund policy

If a service won't accept Stripe or PayPal — only crypto, or only direct bank — that's a fraud signal. Legitimate services accept mainstream payment processors because they can afford the disputes. Refund policy matters too: if signing fails, you should get your money back without a fight.

5. Customer communication

Look for: a real support address (not just a contact form), response time SLA, clear documentation. Avoid: services that only respond on Telegram or Discord. The communication channel tells you everything about the operational maturity.

6. App data preservation

When you re-sign, your app's bundle ID should stay the same — that preserves user data on re-install. Services that mangle bundle IDs (sometimes done to evade Apple detection) leave users with broken data on every update.

What to ask: "Will my bundle ID stay the same after signing?" Yes is the right answer.

7. Transparent pricing

Hidden add-ons after checkout, surprise "VIP" tiers, escalating fees — all warning signs. Honest services show the full price plus a small list of $5 add-ons (extra devices, IPAs, re-signs) on the package page.

Our pricing: $99 Developer (extras at $5 each), $259 Enterprise (flat). No hidden fees.

Red flags that should make you walk away

  • Price under $20 for "unlimited Enterprise" — that's a scam. Real Enterprise certs cost the operator $299/year minimum and they need to make margin.
  • "Lifetime" signing offers — Apple revokes certs. Nothing in this space is lifetime.
  • No Terms of Service or contact info
  • Crypto-only payment
  • Promises of "no revoke ever" — impossible to guarantee

Honest evaluation matrix

CriterionGood serviceRed flag
Cert rotationFrequent, transparent"Same cert for years"
Re-sign on revokeFreeExtra cost
Turnaround< 1 hour stated"24-48 hours"
PaymentStripe/PayPalCrypto only
SupportEmail, < 24h SLATelegram only
Bundle IDPreservedChanged silently
PricingFlat + clear add-onsHidden fees

If you've been burned before

If you've used services like Scarlet (shut down) or ESign and want alternatives, see: Scarlet and ESign alternatives.