We enforce a strict policy requiring all commits to be signed. Currently, we've implemented a workaround to achieve this, but native built-in support for signed commits would be a significant improvement — reducing friction and maintenance overhead for teams with similar security requirements.